Method and related device for private distribution network violation identification based on behavior simulation

CN122764618APending Publication Date: 2026-09-15CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610943000.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-26
Publication Date
2026-09-15

AI Technical Summary

Technical Problem

为控制运营成本,众多互联网企业开始采用融合CDN模式开展内容分发业务,同时大量依托家庭宽带或企业专线等未获得电信运营商授权的PCDN网络传输数据,该类违规使用网络资源的行为被称作“带宽下水道”,直接导致电信运营商IDC业务收入大幅缩减

Benefits of technology

[0015] The embodiments of this application include at least the following beneficial effects: This application provides a method and related equipment for identifying violations in private distribution networks based on behavioral simulation. This solution rapidly builds a distributed probe collection environment by preprocessing the target application installation package and deploying it in batches on terminals. It controls the terminal probes to simulate real user on-demand operations by combining natural person behavior parameters and simultaneously captures the original network data packets of the application layer. This can bypass encryption protocol barriers to completely obtain the application's underlying interactive traffic, making up for the shortcomings of traditional NetFlow and DPI monitoring solutions that cannot decrypt and identify encrypted private traffic. Furthermore, traffic standardization is completed through preprocessing and encrypted transmission to ensure the integrity and standardization of the collected data and secure transmission. By leveraging a core analysis engine that integrates a domain name resolver, a network address intelligence database, and a private distribution network identification unit, multi-dimensional source tracing and matching judgment are achieved, and multi-dimensional cross-verification of traffic behavior is performed to accurately locate the violating private distribution nodes and form a complete standardized evidence chain. Finally, the violation identification data can be output through a visualization rendering component and program interface, making it easy for the business side to quickly view and retrieve the judgment basis. The entire end-to-end process is integrated to realize behavior simulation, encrypted traffic capture, multi-dimensional compliance verification and result visualization output, which greatly improves the completeness, accuracy and feasibility of private distribution network violation identification, reduces blind spots in traffic monitoring, and fully retains all-dimensional evidence materials required for compliance governance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122764618A_ABST
    Figure CN122764618A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network data processing, in particular to a private distribution network violation identification method based on behavior simulation and related equipment. The method comprises the following steps: modifying a target application installation package, deploying a probe in batches, configuring a monitoring list, building a distributed collection environment; simulating natural person operation of the target application and capturing original traffic, and obtaining a standardized traffic dataset through cleaning extraction and encryption preprocessing; generating a violation evidence chain through multidimensional determination of a core engine containing a domain name resolver, a network address intelligence library and a private distribution network identification unit; finally, the violation identification data is visualized, encapsulated and opened for query and output, and the violation identification data is obtained. The application can directly associate the application with the IP, avoid monitoring failure caused by protocol iteration, reduce the cost, easily expand the monitoring range and application type, and improve the ability of identifying the violation distribution.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network data processing technology, and in particular to a method and related equipment for identifying violations in private distribution networks based on behavioral simulation. Background Technology

[0002] With the rapid popularization of high-bandwidth applications such as video and live streaming, the internet content distribution market is gradually showing characteristics of centralized supply and demand, technology privatization, and traffic encryption. To control operating costs, many internet companies have begun to adopt a converged CDN model for content distribution, while simultaneously relying heavily on PCDN networks (such as home broadband or dedicated enterprise lines) that are not authorized by telecom operators for data transmission. This illegal use of network resources is known as "bandwidth sewers," directly leading to a significant reduction in revenue for telecom operators' IDC (Internet Data Center) business. Currently, mainstream network monitoring methods in the industry all have significant shortcomings in addressing such network violations. While the NetFlow solution can accurately count traffic volume and direction and perform quantitative traffic analysis, it is difficult to match specific applications and can only rely on external information such as operator DNS for indirect inference. Its qualitative traffic analysis capability is weak, and there are obvious blind spots in monitoring. On the other hand, the DPI deep packet inspection solution is not only expensive to deploy and maintain, but it also cannot decrypt and effectively identify end-to-end encrypted private protocols such as HTTPS, DNS, or QUIC widely used by Internet companies. Moreover, with the continuous iteration and updates of various protocols, the identification accuracy of the DPI deep packet inspection solution continues to decline, making it unable to effectively cope with complex and ever-changing network environments in the long term.

[0003] In summary, the technical problems existing in the relevant technologies need to be improved. Summary of the Invention

[0004] The main objective of this application is to propose a method and related equipment for identifying violations in private distribution networks based on behavioral simulation. This method can directly associate applications with IP addresses, avoid monitoring failures caused by protocol iterations, reduce costs, and easily expand the monitoring scope and application types, thereby improving the ability to identify violations.

[0005] To achieve the above objectives, one aspect of this application proposes a method for identifying violations in private distribution networks based on behavioral simulation. The method includes the following steps: Preprocessing and batch deployment operations on the target application's original installation package; On each terminal to be monitored, the data acquisition agent program deploys probes and configures a simulation monitoring task list based on the original installation package of the target application, thereby obtaining a distributed probe acquisition environment. Based on natural person behavior parameters and terminal probes in the distributed probe acquisition environment, the system controls the full-process simulation on-demand interaction of the target application in the simulation monitoring task list on each terminal to be monitored, and captures the original network data packets at the application layer to obtain the original terminal traffic acquisition data. The raw traffic data collected from the terminal is preprocessed and encrypted to obtain a standardized encrypted traffic dataset; The standardized encrypted traffic dataset is subjected to multi-dimensional source tracing and matching judgment through the core analysis engine to obtain a standardized violation judgment evidence chain; wherein, the core analysis engine includes a domain name resolver, a network address intelligence database and a private distribution network identification unit; A visual report of the standardized violation determination evidence chain is generated by a visualization rendering component, and the standardized violation determination evidence chain is encapsulated through a program interface to output violation identification data.

[0006] In some embodiments, the data acquisition agent program is integrated into the terminal probe unit, and the terminal probe unit is disposed in the mobile terminal to be monitored. The terminal probe unit also includes an automated behavior simulation engine and a risk control countermeasure module. The automated behavior simulation engine is used for highly realistic user interface operation and traffic triggering, and the risk control countermeasure module is used for device fingerprint simulation and environmental camouflage.

[0007] In some embodiments, the step of performing full-process simulation on-demand interaction on the target application in the simulation monitoring task list based on natural person behavior parameters and terminal probes in the distributed probe acquisition environment includes the following steps: Based on the natural person behavior parameters, the target applications in the simulation monitoring task list are configured with realistic operation timing to obtain simulation execution control parameters. The automated behavior simulation engine automatically starts the target application, traverses the resource list, and triggers continuous video playback based on the simulation execution control parameters.

[0008] In some embodiments, capturing raw application layer network packets to obtain raw terminal traffic data includes the following steps: The data acquisition agent program performs data acquisition point mounting operations on the application bytecode based on the underlying network communication functions and Secure Sockets Layer encryption / decryption functions. The data acquisition agent program performs low-level secure socket layer decryption and capture operations on all network request packets and response packets of the target application to obtain the original encrypted traffic data of the terminal. The risk control countermeasure module performs spoofing and simulation processing on the terminal device fingerprint and operating environment; The risk control countermeasure module performs an additional operation on the original encrypted traffic data of the terminal to add a trusted collection identifier, thereby obtaining the original traffic collection data of the terminal.

[0009] In some embodiments, the preprocessing and encryption of the raw traffic data collected from the terminal to obtain a standardized encrypted traffic dataset includes the following steps: Invalid signaling packets are removed from the raw traffic data collected from the terminal with trusted environment tags by using data cleaning rules; The terminal raw traffic collection data, after invalid signaling packets have been removed, is processed by data cleaning rules to extract the five-tuple, timestamp, associated application identifier, and domain alias resolution link fields, thereby obtaining structured raw traffic feature data. After the structured raw traffic feature data is encrypted and encapsulated by the encrypted data encapsulation unit and the encrypted dedicated transmission tunnel unit, the encrypted and encapsulated structured raw traffic feature data is securely transmitted back to the data processing and analysis module to obtain a standardized encrypted traffic dataset.

[0010] In some embodiments, the step of performing multi-dimensional source tracing and matching on the standardized encrypted traffic dataset through the core analysis engine to obtain a standardized violation determination evidence chain includes the following steps: The domain name resolver performs alias resolution and link resolution processing on the data packets in the standardized encrypted traffic dataset to obtain complete domain name tracing results. Based on the network address intelligence database, the compliant content distribution network filing directory in the domain name database and network address database is retrieved. The target access address corresponding to the complete domain name tracing result is queried and cross-compared with the location, operator and filing customer information to obtain the network address filing matching comparison result. The private distribution network identification unit performs the following steps on the traffic packets in the network address registration matching and comparison results: it determines the characteristics of illegal private distribution network behavior, and statistically analyzes the proportion of high-frequency random user data packet port traffic and the number of concurrent connections to obtain port traffic behavior characteristic data. By using preset comprehensive judgment rules, the complete domain name tracing results, the network address filing matching and comparison results, and the port traffic behavior characteristic data are subjected to multi-dimensional feature fusion and suspected illegal node screening processing to obtain suspected illegal node marking information; After integrating and encapsulating the multi-dimensional data in the suspected violation node marking information, the standardized violation judgment evidence chain is obtained; wherein, the standardized violation judgment evidence chain includes Internet Protocol address basic data, communication port basic data, time basic data, user data packet protocol traffic ratio behavior evidence, standardized domain name resolution link resource evidence, and Internet Protocol address attribution customer analysis data.

[0011] In some embodiments, the determination criteria for processing the traffic packets to identify illegal private distribution network behavior characteristics include: Determine whether the target access address is not recorded in the list of compliant content distribution network filings in the network address database, and whether the target access address continuously carries a large volume of distribution traffic; Alternatively, determine whether the user datagram port and concurrent connection traffic characteristics of the target access address do not match the filing business type of the Internet Data Center customer; Alternatively, determine whether the target Internet Protocol address traffic source domain has not been properly registered or belongs to a commercial platform.

[0012] In some embodiments, the visualization rendering component is set in the data display layer, which calls the domain name database, network address database, and private distribution network list data source of the data processing and analysis module through the capability open interface; the visualization rendering component is used to realize the visualization of the domain name database, the network address database, and the visualization of the illegal nodes of the private distribution network. The program interface includes an external standardized query application programming interface, which is used to encapsulate the standardized violation determination evidence chain into a structured governance report and output the outputtable violation identification data.

[0013] To achieve the above objectives, another aspect of this application proposes a private distribution network violation identification system based on behavioral simulation, the system comprising: The data acquisition terminal module is used to preprocess the original installation package of the target application and perform batch deployment operations on the terminal; control the deployment of probes and configuration of the simulation monitoring task list on each terminal to be monitored through the data acquisition agent program based on the deployed original installation package of the target application to obtain a distributed probe acquisition environment; control the full-process simulation on-demand interaction of the target application in the simulation monitoring task list on each terminal to be monitored according to the natural person behavior parameters and the terminal probes in the distributed probe acquisition environment, and capture the original network data packets of the application layer to obtain the original terminal traffic acquisition data; The secure transmission module is used to preprocess and encrypt the raw traffic data collected by the terminal to obtain a standardized encrypted traffic dataset. The data processing and analysis module is used to perform multi-dimensional source tracing and matching judgment on the standardized encrypted traffic dataset through the core analysis engine to obtain a standardized violation judgment evidence chain; wherein, the core analysis engine includes a domain name resolver, a network address intelligence database and a private distribution network identification unit; The data display module is used to generate a visual report of the standardized violation judgment evidence chain through a visualization rendering component, and after encapsulating the standardized violation judgment evidence chain through a program interface, output violation identification data.

[0014] To achieve the above objectives, another aspect of this application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the method described above.

[0015] The embodiments of this application include at least the following beneficial effects: This application provides a method and related equipment for identifying violations in private distribution networks based on behavioral simulation. This solution rapidly builds a distributed probe collection environment by preprocessing the target application installation package and deploying it in batches on terminals. It controls the terminal probes to simulate real user on-demand operations by combining natural person behavior parameters and simultaneously captures the original network data packets of the application layer. This can bypass encryption protocol barriers to completely obtain the application's underlying interactive traffic, making up for the shortcomings of traditional NetFlow and DPI monitoring solutions that cannot decrypt and identify encrypted private traffic. Furthermore, traffic standardization is completed through preprocessing and encrypted transmission to ensure the integrity and standardization of the collected data and secure transmission. By leveraging a core analysis engine that integrates a domain name resolver, a network address intelligence database, and a private distribution network identification unit, multi-dimensional source tracing and matching judgment are achieved, and multi-dimensional cross-verification of traffic behavior is performed to accurately locate the violating private distribution nodes and form a complete standardized evidence chain. Finally, the violation identification data can be output through a visualization rendering component and program interface, making it easy for the business side to quickly view and retrieve the judgment basis. The entire end-to-end process is integrated to realize behavior simulation, encrypted traffic capture, multi-dimensional compliance verification and result visualization output, which greatly improves the completeness, accuracy and feasibility of private distribution network violation identification, reduces blind spots in traffic monitoring, and fully retains all-dimensional evidence materials required for compliance governance. Attached Figure Description

[0016] Figure 1 This is a flowchart of a private distribution network violation identification method based on behavior simulation provided in an embodiment of this application; Figure 2 This is a flowchart of the modification of the original installation package of the target application on the terminal and the deployment of probes; Figure 3 This is a flowchart simulating the entire process of on-demand interaction; Figure 4 This is a flowchart of capturing raw network packets at the application layer; Figure 5 yes Figure 1 The flowchart of step S140 in the middle; Figure 6 yes Figure 1 The flowchart of step S150 in the middle; Figure 7 This is a schematic diagram of the analysis and judgment process for standardized encrypted traffic datasets; Figure 8 This is a schematic diagram of the structure of the private distribution network violation identification system based on behavior simulation provided in the embodiments of this application; Figure 9 This is an architecture diagram of a private distribution network violation identification system based on behavior simulation; Figure 10 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0017] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit it. In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this application; they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.

[0018] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0019] Before providing a detailed description of the embodiments of this application, some of the nouns and terms involved in the embodiments of this application will be explained first. The nouns and terms involved in the embodiments of this application are subject to the following interpretations.

[0020] Original APK file: The original installation package of the target application to be monitored, without bytecode rewriting or the implantation of collection probes. It is the basic source file for carrying out traffic collection modification.

[0021] SSL encryption / decryption functions: These are the core program functions at the application level responsible for encrypting and decrypting HTTPS traffic. After being rewritten and injected into the collection point, they can directly capture and decrypt the original traffic. Probe SDK: A toolkit for developing acquisition probes, integrating data caching and encrypted transmission channels. When embedded in an application, it enables terminal traffic capture and secure data backhaul.

[0022] Probe version APK installation package: The original installation package of the target application is generated by rewriting the original APK bytecode, integrating the probe SDK, and then strengthening the signature. It is deployed on the terminal for traffic collection.

[0023] APK modification: The entire process of decompiling the original installation package, rewriting the bytecode, implanting collection probes, and strengthening the signature is used to build a distributed collection environment.

[0024] PCDN Identification and Analysis: An analysis process that uses IP intelligence databases and domain name resolution data to determine private distribution nodes in home broadband and construct a chain of evidence of violations through traffic behavior.

[0025] CNAME domain alias: An alias record in the domain name resolution chain. Tracking this record can locate the video resource distribution source and serve as core resource evidence for determining private distribution.

[0026] CDN providers: Service providers that provide compliant content distribution services.

[0027] UDP port: User Datagram port. PCDN nodes use this port extensively to distribute video traffic, making it a key behavioral characteristic for identifying private distribution.

[0028] IDC customer filing declaration business type: The business category for data center customer filing registration. Combining IP filing information can distinguish between compliant IDC nodes and non-compliant home PCDN nodes.

[0029] DPI: Deep Packet Inspection, a traditional network monitoring solution that relies on parsing protocol packets.

[0030] Figure 1 This is an optional flowchart of the private distribution network violation identification method based on behavior simulation provided in the embodiments of this application. Figure 1 The method may include, but is not limited to, steps S110 to S160.

[0031] Step S110: Preprocess the original installation package of the target application and perform batch deployment operations on terminals; Step S120: On each terminal to be monitored, the data acquisition agent program deploys probes and configures a simulation monitoring task list based on the original installation package of the deployed target application to obtain a distributed probe acquisition environment. Step S130: Control each terminal to be monitored to perform full-process simulation on-demand interaction on the target application in the simulation monitoring task list based on natural person behavior parameters and terminal probes in the distributed probe acquisition environment, and capture the original network data packets of the application layer to obtain the original terminal traffic acquisition data. Step S140: Preprocess and encrypt the raw traffic data collected from the terminal to obtain a standardized encrypted traffic dataset; Step S150: The standardized encrypted traffic dataset is subjected to multi-dimensional source tracing and matching judgment through the core analysis engine to obtain a standardized violation judgment evidence chain; wherein, the core analysis engine includes a domain name resolver, a network address intelligence database and a private distribution network identification unit; In step S160, a visual report of the standardized violation determination evidence chain is generated through the visualization rendering component, and the standardized violation determination evidence chain is encapsulated through the program interface to output violation identification data.

[0032] In steps S110 to S160 of this embodiment, a series of operations, including preprocessing the original installation package of the target application and batch deployment of terminals, are performed. Based on the modified installation package, the probes for monitoring terminals are deployed, and a simulation monitoring task list is configured simultaneously. This constructs a distributed probe acquisition environment capable of synchronously collecting traffic from multiple terminals. By reading natural human behavior parameters and using the probes of each terminal within the constructed distributed probe acquisition environment, a full-process simulated on-demand interactive operation, tailored to real user habits, is performed on all target applications recorded in the simulation monitoring task list. During the simulation interaction, all application-layer raw network data packets generated by the target application are captured simultaneously, and the capture results are integrated to generate raw terminal traffic collection data. Then, preset data cleaning rules, feature field extraction logic, and encrypted transmission mechanisms are invoked to uniformly preprocess the acquired raw terminal traffic collection data, completing preprocessing and encrypted encapsulation for transmission, generating a standardized encrypted traffic dataset that can be stably sent to the background analysis module. The core analysis engine, utilizing three main functional modules—a built-in domain name resolver, a network address intelligence database (IP intelligence database), and a private distribution network identification unit—performs multi-dimensional source matching and comprehensive judgment on the received standardized encrypted traffic dataset. This involves domain name tracing, IP attribution comparison, and port traffic characteristic statistics. It integrates multi-dimensional analytical information to construct complete evidence materials and outputs a standardized violation judgment evidence chain. Finally, it calls a visualization rendering component and a standardized program query interface to generate and encapsulate visual charts and structured governance reports based on the generated standardized violation judgment evidence chain. It also opens a program query and call channel to the outside world, ultimately outputting output violation identification data that can be directly used by business units to carry out violation governance work, thus completing the entire process of private distribution network violation identification.

[0033] In some embodiments, such as Figure 2 As shown, starting with the original installation package (original APK file) of the target application, the bytecode of the installation package is first decompiled, and then the bytecode is rewritten. On the one hand, traffic collection points are injected into network communication and Secure Sockets Layer encryption / decryption functions (two key functions: SSL encryption and decryption). On the other hand, a collection probe development toolkit (probe SDK) with a data caching module and encrypted transmission channel is integrated to complete the pre-embedding of collection capabilities. After rewriting, a probe version of the target application's original installation package (probe version APK installation package) is generated. Application hardening and signature verification are performed sequentially to avoid risk control interception, and then it is distributed to the terminal to complete device installation. After the terminal is deployed, highly simulated user operation behavior can be executed, and application network data packets can be captured based on the built-in collection points. The entire process is realized by the data collection agent program integrated into the terminal probe unit. The modified terminal is equipped with an automated behavior simulation engine and a risk control countermeasure module. After multiple modified terminals are uniformly configured with a monitoring task list, a distributed probe collection environment can be collaboratively built to provide the underlying collection carrier for subsequent simulated on-demand playback and traffic capture.

[0034] Specifically, in steps S110 and S120, the original APK file of the target application is read according to the data acquisition agent program integrated inside the terminal probe unit, and the original installation package is decompiled into bytecode to enter the bytecode rewriting process. During the bytecode rewriting stage, the acquisition capability is implanted simultaneously in three ways: first, traffic acquisition points are injected into network communication functions and secure socket layer encryption and decryption functions to realize the underlying capability of full capture of application network data packets; second, a probe SDK containing a data caching module and an encrypted transmission channel is integrated to provide program support for subsequent local traffic temporary storage and encrypted backhaul; and third, a probe version APK installation package is generated based on the bytecode file after the acquisition point injection and probe SDK integration, thus completing the bytecode rewriting and probe integration modification process of the original installation package of the target application.

[0035] The data acquisition agent performs application hardening and signature verification operations on the generated probe version APK sequentially to avoid runtime interception and risk control detection issues caused by repackaging, generating a probe application installer with trusted operating qualifications. After completing the hardening and signature processing, the terminal batch deployment process is initiated, and the modified probe version APK is distributed in batches to all Android mobile terminals to be monitored in different geographical locations to complete the application installation and realize the deployment of the data acquisition probes in each terminal. Each mobile terminal to be monitored is uniformly equipped with a terminal probe unit integrating the data acquisition agent, and is also equipped with an automated behavior simulation engine and a risk control countermeasure module to provide hardware program support for simulation interaction and anti-detection data acquisition.

[0036] After all the terminals to be monitored have completed probe deployment, the data acquisition agent program uniformly distributes and configures a list of simulation monitoring tasks to each terminal probe unit. The list records the identifiers of all video target applications to be monitored and clarifies the simulation on-demand and traffic capture monitoring tasks that each terminal needs to perform. All terminal probe units, which are distributed across multiple regions of mobile terminals, are equipped with complete probe acquisition components, and have uniformly configured standardized monitoring tasks, work together to ultimately build a distributed probe acquisition environment that covers the entire area and can simultaneously carry out traffic acquisition for multiple applications.

[0037] The APK modification, terminal deployment, and task configuration process based on the data acquisition agent program in this application achieves deep integration of probes and target applications through underlying bytecode rewriting. This allows for seamless capture of SSL encrypted network data packets without the need for additional packet capture tools, and the integrated encrypted transmission channel ensures local caching and secure backhaul of the terminal's original traffic. Furthermore, it leverages a batch deployment mechanism to rapidly build cross-regional distributed acquisition clusters. The accompanying automated behavior simulation engine can reproduce traffic triggered by genuine human actions, while the risk control and countermeasures module circumvents application-side anti-crawling and anti-collection risk control interception through device fingerprint simulation and runtime environment camouflage, significantly improving the authenticity of traffic acquisition behavior and the integrity of acquired data. A unified simulation monitoring task list enables standardized management of multi-terminal acquisition tasks, ensuring consistency in acquisition rules and monitoring scope for the same type of target application across different regions. This provides a standardized and highly reliable source of original terminal traffic data for subsequent unified multi-dimensional tracing and violation determination by the central platform.

[0038] In some embodiments, such as Figure 3 and Figure 4 As shown, in steps S131 to S132, based on the terminal probe units mounted on each mobile terminal to be monitored within the distributed probe acquisition environment, the automated behavior simulation engine built into the terminal probe unit is called to read the pre-configured natural human behavior parameters. The natural human behavior parameters include behavioral characteristic benchmarks such as the actual click interval, swipe duration, video playback dwell time, and page switching frequency when human users operate the APP. Based on the read natural human behavior parameters, the automated behavior simulation engine matches and adapts the humanized operation sequence to the interactive logic of each application registered in the simulation monitoring task list, such as various video platforms, and sets differentiated delay intervals for different operation nodes such as homepage loading, list swiping, video clicking, and video switching. This completes the standardized humanized operation sequence configuration and outputs simulation execution control parameters that can directly drive automated operations, thereby avoiding the risk control identification risks caused by mechanical, fixed-interval script operations from the source.

[0039] The automated behavior simulation engine reads the simulation execution control parameters output from the previous stage and drives the terminal probe to automatically execute the entire video-on-demand interaction process according to the timing rules. Specifically, it first wakes up and starts the target application specified in the simulation monitoring task list. After the application finishes loading its homepage, it simulates the user's swipe gestures to traverse the platform's video resource list, and then automatically clicks on video items to trigger continuous video playback. At the same time, it strictly follows the operation intervals and operation frequencies set by the simulation execution control parameters to execute continuous interactive actions such as swiping up and down on the page, switching videos, and pausing and replaying. The entire automated operation completely replicates the complete usage chain of a natural person watching short and long videos, without any machine-like fixed-rhythm operations running continuously, creating a realistic and credible business traffic scenario for subsequent traffic capture.

[0040] Before conducting simulated on-demand interaction, the entire process of modifying the original installation package of the target application was completed through a data acquisition agent program. Corresponding to the terminal probe APK processing flow, the original APK was decompiled and bytecode rewritten. Dedicated data acquisition points were attached to the application's underlying network communication functions and SSL encryption / decryption functions. The probe SDK and encrypted transmission module were integrated synchronously. Then, the application hardening and signature verification were completed in sequence to obtain the probe installation package. After the probe installation package was deployed in batches to each terminal to be monitored, a data acquisition agent program with underlying packet capture capabilities was generated inside the terminal probe unit. The data acquisition agent program is deeply embedded in the target application and does not rely on external third-party packet capture tools. It can directly reach the application's underlying network interaction link and has the underlying technical foundation for capturing encrypted data packets.

[0041] Figure 4 In steps S133 to S136, when the automated behavior simulation engine continuously outputs the network sending and receiving behavior generated by the target application, the data acquisition agent program in the terminal probe unit will rely on the data acquisition points pre-mounted on the network communication function and SSL encryption / decryption function to synchronously intercept all uplink network request packets and downlink response data packets generated by the target application; with the help of the integrated SSL decryption capability, it will complete the low-level decryption operation on the encrypted transmission data packets, completely extract the original interactive content inside the data packets, capture all business traffic generated during the entire simulation on-demand interaction process without omission, and uniformly summarize to form the unfiltered terminal original encrypted traffic data, realizing the application layer's full traffic collection without awareness and with full coverage.

[0042] The risk control and countermeasure module built into the terminal probe unit simultaneously initiates the protection process. It performs simulation and disguise processing on the unique device fingerprint, system operating environment, and application operating context of the terminal to be monitored. It modifies the device identifier and simulates the operating environment of an ordinary user terminal to prevent the security risk control system of the target application from recognizing the automated simulation and traffic collection behavior, thus preventing the collection process from being intercepted and data packets from being blocked. Based on the completion of the environment disguise, the risk control and countermeasure module adds a unique trusted collection identifier to the captured original encrypted traffic data of the terminal, marking the collection terminal, simulation task, collection time, and other traceability information corresponding to each piece of traffic data. Finally, it generates original terminal traffic collection data with anti-risk control attributes and complete traceability information, completing the entire process of simulation interaction and traffic capture output.

[0043] By constraining the automated simulation logic with natural person behavior parameters, the business traffic generated by the probe perfectly matches the characteristics of real user usage, effectively solving the problems of traditional fixed script simulation being easily intercepted by platform risk control and distorted traffic samples. Relying on bytecode rewriting to achieve low-level pre-embedding of collection points, it can directly decrypt and capture SSL encrypted data packets. Compared with port mirroring and external packet capture, it can obtain more complete application layer raw interaction data, without the defects of traffic omissions and unreadable encrypted content. Combined with the device and environment camouflage capabilities of the risk control countermeasure module, it ensures stable simulation and collection operations over a long period of time without collection interruption or data loss. The final output of raw terminal traffic collection data is accompanied by a trusted collection identifier. Each traffic can be associated with the corresponding simulation application, terminal and behavioral scenario, greatly improving the authenticity, completeness and traceability of the data, and providing a highly reliable raw data foundation for subsequent data preprocessing of the central platform and PCDN multi-dimensional traceability judgment.

[0044] In some embodiments, such as Figure 5 As shown, in steps S141 to S143, for the original terminal traffic data collected by the terminal probe unit and accompanied by trusted environment tags, the first-level preprocessing operation is carried out by calling the preset data cleaning rules, with the core operation being the removal of invalid signaling packets. During the terminal simulation on-demand interaction, redundant data packets such as video playback control signaling and heartbeat keep-alive signaling, which do not have PCDN identification and analysis value, will be generated simultaneously. The data cleaning rules will automatically identify and filter out such invalid signaling packets according to the judgment conditions such as data packet function type, message length, and interaction frequency, retaining only the real traffic packets carrying video distribution services, completing the stripping of redundant data, reducing the data processing volume of subsequent analysis, and filtering out interference information to ensure that the data entering the field extraction stage has business analysis value.

[0045] After removing invalid signaling packets, a standardized field extraction operation is performed on the remaining valid traffic packets. Four core feature fields are extracted from the packet payload and network header. Specifically, these are the five-tuple information identifying network connection relationships, the timestamp recording the traffic generation time, the associated application identifier binding the traffic source, and the CNAME domain alias resolution link field used for tracing CDN nodes. All extracted feature fields are standardized and integrated according to a unified data format to generate structured raw traffic feature data. This transforms fragmented raw data packets into standardized structured data with aligned fields and unified dimensions, eliminating data format differences in traffic packets generated by different terminals and applications. This provides a standardized data foundation for cross-sample matching and multi-dimensional correlation tracing by the upper-layer core analysis engine.

[0046] After generating the structured raw traffic feature data, the encrypted data encapsulation unit and the HTTPS / encrypted dedicated transmission tunnel unit are invoked sequentially to perform secure backhaul processing. The encrypted data encapsulation unit first performs full-domain encryption encapsulation on the structured raw traffic feature data to avoid the risk of data leakage or tampering during plaintext transmission of traffic features. The encapsulated data is then transmitted via a dedicated encrypted transmission tunnel to establish an isolated transmission channel between the terminal and the data processing and analysis module, bypassing security vulnerabilities in ordinary public network transmission links. The encrypted structured traffic data is then stably transmitted back to the backend analysis layer, where it is uniformly and standardized through the transmission channel and output, ultimately resulting in a standardized encrypted traffic dataset that can be directly read and processed by the core analysis engine.

[0047] The preprocessing mechanism, consisting of data cleaning, field extraction, and encrypted transmission, provides comprehensive protection across three dimensions: data quality, data standardization, and data security. The data cleaning stage proactively eliminates meaningless signaling redundancy, reducing the computational consumption of the backend analysis engine and minimizing interference from invalid data with violation judgment rules. Standardized field extraction unifies the feature dimensions of data collected by the fully distributed probes, enabling traffic data collected from multiple regions and terminals to have a unified standard for horizontal comparison and correlation matching, supporting IP intelligence databases and domain name resolvers in conducting accurate source tracing comparisons. A dual-layer encryption + dedicated tunnel transmission mechanism ensures the confidentiality and integrity of traffic feature data collected by terminals throughout the backhaul link, preventing the theft and tampering of collected business traffic intelligence. The final output standardized encrypted traffic dataset balances data validity, format uniformity, and transmission security, seamlessly connecting to subsequent multi-dimensional source tracing and matching judgment processes, and stably supporting core analysis tasks such as PCDN violation node identification and evidence chain construction.

[0048] In some embodiments, such as Figure 6As shown, in steps S151 to S155, after receiving the standardized encrypted traffic dataset, the domain name resolver built into the core analysis engine is invoked to perform deep domain name resolution. Recursive resolution is performed on the CNAME alias record carried by each data packet in the standardized encrypted traffic dataset, tracing the entire domain name redirection link to the actual service node at the end of the link, and outputting a complete domain name tracing result containing all levels of redirection records. The process of obtaining the complete domain name tracing result can penetrate multi-level domain name forwarding links, avoid the tracing breakpoint problem caused by multi-layer CNAME spoofing, accurately locate the resource service entity that the traffic ultimately points to, and provide complete original evidence of the domain name link for subsequent IP comparison and violation determination.

[0049] After obtaining complete domain name tracing results, the core analysis engine retrieves the built-in IP intelligence database, linking it with the underlying domain name database and network address database (IP database) to extract the list of compliant content delivery network (CDN) vendors with compliant registration. Based on the complete domain name tracing results, it identifies the corresponding target access address (target IP) and sequentially queries basic information such as the IP's physical location, carrier, and the registered client of the IDC. Then, it cross-matches the target IP, the tracing-obtained full-link domain name, and the compliant content delivery network with the compliant content delivery network with compliant registration to distinguish whether the node belongs to a legally registered CDN vendor or an unregistered commercial distribution node, generating a network address registration matching comparison result (IP registration matching comparison result) containing basic IP attributes and registration matching status. The process of obtaining the IP registration matching comparison result verifies information based on a standardized registration database, quickly distinguishing between legal and compliant nodes and IP carriers suspected of violations, thus narrowing the data scope for subsequent behavioral analysis.

[0050] The core analysis engine calls the private distribution network identification unit to read the original traffic packets corresponding to the IP filing matching results. It then performs a special judgment on the characteristics of illegal private distribution network behavior (typical illegal behavior characteristics of PCDN) for the packets. The unit automatically calculates the traffic ratio of high-frequency random user data packet ports (high-frequency random UDP ports) and the total number of concurrent connections in the entire network within the packets, generating quantified port traffic behavior characteristic data. At the same time, it pre-loads three types of violation judgment conditions to complete the initial screening and verification: First, it verifies whether the target IP is not included in the compliant CDN filing directory but continues to carry large-capacity video distribution traffic; second, it compares whether there is a significant deviation between the IP's UDP port and concurrent connection traffic characteristics and the business type declared in the IDC customer's filing; and third, it verifies whether the domain name at the end of the traffic traceability has completed compliant filing and whether it belongs to a commercial video platform without distribution qualifications. This transforms abstract traffic behavior into quantifiable and verifiable digital characteristics, accurately capturing the iconic behavior pattern of PCDN relying on large-scale traffic distribution through random UDP ports.

[0051] The core analysis engine reads three types of multi-dimensional information: complete domain name tracing results, IP registration matching and comparison results, and port traffic behavior characteristic data. It loads preset comprehensive judgment rules to complete feature fusion calculations and overlays the three-dimensional verification results to jointly filter IP nodes with potential violations, generating suspected violation node marker information with risk labels. Subsequently, it initiates an evidence chain integration process, uniformly collecting and structurally encapsulating all-dimensional raw data within the marker information, ultimately generating a standardized violation judgment evidence chain. This standardized violation judgment evidence chain comprehensively includes six categories of evidence materials, including basic raw data on IP and port, time dimensions, behavioral evidence formed by UDP traffic proportions, resource evidence constituted by complete CNAME resolution links, and customer analysis data formed by comparing IP attribution customer registrations, comprehensively covering all factual basis for determining violation nodes.

[0052] The multi-dimensional source tracing and matching judgment process realizes a closed-loop analysis of three layers of data: domain name, IP, and traffic behavior, solving the shortcomings of single-dimensional judgment, which is prone to misjudgment and weak evidence. On the one hand, CNAME resolution breaks the disguise of domain name forwarding, the IP intelligence database enables standardized and rapid comparison of filing information, and the private distribution network identification unit quantifies the capture of UDP port distribution characteristics. The three-layer judgment conditions are mutually constrained, which greatly improves the accuracy of identifying illegal PCDN nodes and reduces the probability of false interception of legitimate business. On the other hand, the standardized evidence chain classifies and solidifies all judgment basis, and each violation mark is accompanied by complete and traceable multi-layer original evidence data, avoiding the problems of judgment conclusions without basis and inability to support subsequent violation governance. At the same time, the entire analysis logic is realized by decoupling the modular units of the engine. Domain name resolution, IP comparison, traffic feature statistics, and evidence encapsulation can be independently scheduled and operated. It can process a large number of standardized encrypted traffic datasets returned by terminals in batches, adapt to the high-concurrency analysis needs brought by multi-regional distributed probe collection, and the output standardized evidence chain can be directly connected to the upper-layer visualization display layer, providing complete and compliant data support for the ledger display, governance and disposal, and external query of illegal PCDNs.

[0053] In some embodiments, in step S160, the visualization rendering component located in the data display layer first initiates a data source call request to the upstream data processing and analysis module through a preset capability open interface, pulling three types of underlying business data: domain name database, IP database, and PCDN list. It then performs visualization rendering processing in conjunction with the generated standardized violation judgment evidence chain. Simultaneously, the rendering component completes the construction of three types of visualization views: specifically, it visualizes the domain name database based on the domain name database, the network address database based on the IP database (IP address database visualization), and the PCDN violation node based on the private distribution network list and violation evidence matching results. It transforms discrete evidence information such as IP ownership, CNAME resolution links, traffic behavior, and device associations in the evidence chain into visualization dashboards, statistical charts, and detailed reports, completing the generation of visualization reports for the standardized violation judgment evidence chain.

[0054] After the visualization report is rendered, the standardized external query program interface is invoked for data encapsulation. This interface reads the complete visualization report and the underlying standardized violation determination evidence chain, uniformly organizing multi-layered evidence content including basic IP data, UDP traffic behavior evidence, CNAME resolution resource evidence, and IP attribution customer analysis records. Following governance business specifications, it performs structured encapsulation to form a standardized data package containing a complete evidence collection chain, directly usable for business processing. Simultaneously, this program interface provides an external query channel, supporting external business systems and operations personnel to proactively initiate queries, enabling on-demand retrieval and batch export of violation identification data.

[0055] Once the entire visualization, encapsulation, and open query process is implemented, it ultimately generates outputtable violation identification data that can be directly used by external businesses. From the implementation results, layered visualization rendering intuitively presents the obscure underlying traffic, domain, and IP analysis data, lowering the operational threshold for identifying violation nodes and verifying evidence; standardized program interfaces unify the data output format, fully preserving the entire evidence chain, supporting platform violation handling and offline governance verification without secondary data processing; and the cross-layer capability open call mechanism connects the data channels between the analysis layer and the presentation layer, ensuring real-time synchronization of visualized content, query output data, and backend analysis and judgment results, providing intuitive, complete, and traceable data support for the routine governance of PCDN violation networks.

[0056] This method for identifying violations in private distribution networks based on behavioral simulation achieves precise association between applications and IPs by capturing and decrypting traffic on the terminal side, constructing a clear and reliable chain of evidence. This solves the problem of qualitative difficulties in traditional NetFlow and DPI monitoring. It can penetrate various encryption protocols such as HTTPS, DNS, and QUIC, remaining unaffected by protocol iterations and providing continuous and stable monitoring with significant advantages in terminal-side adversarial capabilities. The terminal probe hardware and software investment is low, supporting flexible distributed deployment and easy expansion of monitoring areas and target application types, offering significant cost and scalability advantages. This method can empower the governance of various businesses. For operators, it can identify illegal PCDN nodes in home broadband and enterprise leased lines, reducing bandwidth waste, increasing IDC business revenue, and recovering bandwidth losses, while saving the high hardware and maintenance costs of traditional DPI. For CDN and cloud service providers, it can complete compliance audits of customer P2P illegal distribution, mitigating cooperation risks. From an industry value perspective, it forms a sustainable encrypted traffic monitoring model, driving the iterative upgrade of network monitoring technology from protocol-dependent to behavior-related, possessing both considerable economic and industry ecosystem value.

[0057] In some embodiments, such as Figure 7 As shown, the process begins with a standardized encrypted traffic dataset as input. Data preprocessing is then performed, extracting key fields such as the 5-tuple, CNAME, and timestamp. Next, multi-dimensional correlation analysis is conducted using the IP registration database and domain name database. The data is then submitted to a rule engine for feature matching, marking IPs matching the characteristics of private distribution as suspected PCDN nodes. Following this, the evidence chain construction phase begins, simultaneously collecting four types of evidence: basic data including IP, port, and time information; behavioral evidence of UDP traffic percentage; domain name CNAME resolution link resource evidence; and customer analysis data regarding IP ownership. These are integrated to form a complete standardized evidence chain for violation determination, which is then output to a visualization component to generate a processing report.

[0058] The following is a detailed introduction and explanation of the solution in this application embodiment, using the example of a provincial operator conducting PCDN distribution monitoring: First, a distributed probe acquisition environment setup process was implemented. Based on the data acquisition agent program, the original APK installation package of the video platform was modified by bytecode rewriting, acquisition point injection, probe SDK integration, application hardening, and signature verification. Then, the modified probe version APK was distributed in batches to Android terminals in multiple cities within the province to complete the deployment of probes across the entire terminal. Simultaneously, a simulation monitoring task list containing the video platform application was configured for probes in various cities. Combined with the terminal's internal automated behavior simulation engine and risk control countermeasure module, a distributed probe acquisition environment covering multiple areas within the province and capable of simulating real human operation was built, providing the hardware and program foundation for the acquisition of traffic from the entire video platform.

[0059] Based on the distributed probe acquisition environment, natural person behavior parameters are loaded to control the terminal probes in various cities. Full-process simulated on-demand interaction is carried out for video platform applications in the simulation monitoring list: automatically launching the video platform APP, swiping to browse the short video list and continuously playing short videos. The operation interval and operation frequency are close to the real usage habits of ordinary users, thereby actively triggering video network requests from the video platform. At the same time, with the help of the acquisition agent injected into the underlying layer of the video platform by bytecode, SSL decryption is completed and all raw network data packets of the application layer of the video platform are captured. The traffic information captured by the terminals in various cities is summarized to generate raw terminal traffic acquisition data for analysis.

[0060] For the raw traffic data collected from video platform terminals, a preset data cleaning, field extraction, and encrypted transmission mechanism is initiated for preprocessing. Matching the logic of the attached data preprocessing step, specifically, invalid signaling packets are filtered out, and core feature fields such as five-tuples, CNAME records, timestamps, and packet lengths are uniformly extracted to form structured traffic information. Then, through encrypted encapsulation and secure transmission through a dedicated tunnel, the data is sent back to the central analysis platform to complete the standardization processing of the raw traffic and generate a standardized encrypted traffic dataset that can be processed by the core analysis engine.

[0061] The core analysis engine, utilizing the built-in domain name resolver, IP intelligence database, and PCDN identification unit, performs multi-dimensional source tracing and matching to determine the standardized encrypted traffic dataset from video platforms. First, it matches the IP address registration database against the IP intelligence database and traces the complete CNAME resolution link of the video platform using the domain name resolver. Then, the PCDN identification unit statistically analyzes typical PCDN behaviors such as UDP traffic percentage and random port distribution. After judgment by the rule engine, suspected PCDN IP segments from home broadband used to distribute video resources from video platforms are marked. Subsequently, a four-layer complete standardized evidence chain for determining violations is constructed, storing basic IP data, basic port data, basic time data, UDP traffic percentage evidence, video platform domain name CNAME resolution resource evidence, and IP-attributed broadband customer analysis data, thus completely preserving all evidence information regarding the illegal distribution of video platform traffic by this IP segment.

[0062] The standardized evidence chain for determining violations by PCDN on video platforms is pushed to the data display layer. The visualization rendering component retrieves data sources including domain names, IP addresses, and PCDN lists to generate three types of visual dashboards and statistical reports: domain names, IP addresses, and violation nodes. Then, through a standardized external query program interface, the four-layer complete evidence chain is encapsulated into a structured governance report, outputting directly usable violation identification data. Operators can intuitively view the distribution of PCDNs on video platforms across the province through a visual interface, and can also call the program interface to export evidence materials in batches, clearly locating violating household broadband IP segments, fully supporting governance actions such as cleaning up illegal PCDN traffic and managing broadband service compliance within the province.

[0063] The multi-city distributed probe cluster in this application embodiment can recreate the actual video streaming traffic scenarios of users across the province. The underlying bytecode packet capture enables seamless and complete collection of encrypted traffic. Multi-level data preprocessing and multi-dimensional correlation analysis can accurately distinguish between legitimate CDNs and private distribution nodes of home broadband. The four-layer structured evidence chain has complete traceability, meeting the compliance and evidence collection requirements of operators. Visualized display and standardized data output simplify the operation and verification process, realizing the full-domain automated identification, evidence collection, and handling of private video distribution networks within the province, and significantly improving the efficiency of operators' PCDN violation governance.

[0064] Please see Figure 8 This application also provides a private distribution network violation identification system based on behavior simulation, which can implement the above-mentioned method. The system includes: The data acquisition terminal module is used to preprocess the original installation package of the target application and perform batch deployment operations on the terminal; it controls the deployment of probes and configuration of the simulation monitoring task list on each terminal to be monitored through the data acquisition agent program based on the deployed original installation package of the target application, thereby obtaining a distributed probe acquisition environment; it controls the full-process simulation on-demand interaction of the target application in the simulation monitoring task list on each terminal to be monitored based on natural person behavior parameters and terminal probes in the distributed probe acquisition environment, and captures the original network data packets at the application layer to obtain the original terminal traffic acquisition data; The secure transmission module is used to preprocess and encrypt the raw traffic data collected from the terminal to obtain a standardized encrypted traffic dataset. The data processing and analysis module is used to perform multi-dimensional source tracing and matching judgment on standardized encrypted traffic datasets through the core analysis engine to obtain a standardized chain of evidence for violation judgment; the core analysis engine includes a domain name resolver, a network address intelligence database, and a private distribution network identification unit; The data display module is used to generate a visual report of the standardized violation judgment evidence chain through the visualization rendering component, and after encapsulating the standardized violation judgment evidence chain through the program interface, it can output violation identification data.

[0065] It is understood that the content of the above method embodiments is applicable to this system embodiment. The specific functions implemented in this system embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.

[0066] like Figure 9As shown in the diagram, the architecture is divided into four layers from bottom to top: a data acquisition terminal module, a secure transmission module, a data processing and analysis module, and a data display module, fully realizing the entire business chain for identifying violations in private distribution networks. The bottom-level data acquisition terminal module is deployed on mobile terminals in various locations. It integrates a terminal probe unit and relies on an automated behavior simulation engine to simulate real-person interface operations to trigger video traffic. Through a risk control countermeasure module, it completes device fingerprint simulation and runtime environment spoofing to evade application risk control interception. Then, the data acquisition agent performs application bytecode injection and SSL traffic decryption, ultimately generating raw encrypted traffic data for output. The raw encrypted traffic data enters the second-layer secure transmission module, where it undergoes encrypted data encapsulation processing and is securely transmitted back via HTTPS or a dedicated tunnel, ensuring that the terminal-collected traffic is not leaked or tampered with during transmission. After transmission, the data flows into the third-layer data processing and analysis module. It first undergoes data cleaning, formatting, and auditing operations via the data access and preprocessing unit. The standardized preprocessed data is then sent to the core analysis engine (enclosed in a dashed box). This core analysis engine comprises three core units: a domain name resolver, an IP intelligence database, and a PCDN identification module. It simultaneously retrieves domain name databases, IP databases, and PCDN lists from the same layer to perform multi-dimensional correlation tracing, rule determination, and evidence chain construction. The database of the data processing and analysis module provides data support to the upper layers through open capability interfaces. At the top layer is the data display module, equipped with three types of visualization rendering components: domain name database visualization, IP address database visualization, and PCDN visualization. It receives data from the lower layers' open data sources to generate visual charts and reports. It also encapsulates a complete chain of evidence of violations using standardized program interfaces and provides query capabilities. The entire architecture forms a complete closed loop from bottom to top: traffic collection, encrypted transmission, intelligent analysis, and visualization output.

[0067] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described method. This electronic device can be any smart terminal, including tablet computers, in-vehicle computers, etc.

[0068] It is understood that the content of the above method embodiments is applicable to this device embodiment. The specific functions implemented by this device embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0069] Please see Figure 10 , Figure 10 The hardware structure of an electronic device according to another embodiment is illustrated. The electronic device includes: The processor 101 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application. The memory 102 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 102 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 102 and is called and executed by the processor 101 using the methods described in the embodiments of this application. Input / output interface 103 is used to implement information input and output; The communication interface 104 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 105 transmits information between various components of the device (e.g., processor 101, memory 102, input / output interface 103, and communication interface 104); The processor 101, memory 102, input / output interface 103 and communication interface 104 are connected to each other within the device via bus 105.

[0070] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0071] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.

[0072] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0073] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.

[0074] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0075] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0076] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0077] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0078] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0079] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.

Claims

1. A method for identifying violations in a private distribution network based on behavioral simulation, characterized in that, The method includes the following steps: Preprocessing and batch deployment operations on the target application's original installation package; On each terminal to be monitored, the data acquisition agent program deploys probes and configures a simulation monitoring task list based on the original installation package of the target application, thereby obtaining a distributed probe acquisition environment. Based on natural person behavior parameters and terminal probes in the distributed probe acquisition environment, the system controls the full-process simulation on-demand interaction of the target application in the simulation monitoring task list on each terminal to be monitored, and captures the original network data packets at the application layer to obtain the original terminal traffic acquisition data. The raw traffic data collected from the terminal is preprocessed and encrypted to obtain a standardized encrypted traffic dataset; The standardized encrypted traffic dataset is subjected to multi-dimensional source tracing and matching judgment through the core analysis engine to obtain a standardized violation judgment evidence chain; wherein, the core analysis engine includes a domain name resolver, a network address intelligence database and a private distribution network identification unit; A visual report of the standardized violation determination evidence chain is generated by a visualization rendering component, and the standardized violation determination evidence chain is encapsulated through a program interface to output violation identification data.

2. The method according to claim 1, characterized in that, The data acquisition agent program is integrated into the terminal probe unit, which is located in the mobile terminal to be monitored. The terminal probe unit also includes an automated behavior simulation engine and a risk control countermeasure module. The automated behavior simulation engine is used for highly realistic user interface operation and traffic triggering, and the risk control countermeasure module is used for device fingerprint simulation and environmental camouflage.

3. The method according to claim 2, characterized in that, The process of performing full-process simulation on-demand interaction on the target applications in the simulation monitoring task list based on natural person behavior parameters and terminal probes in the distributed probe acquisition environment includes the following steps: Based on the natural person behavior parameters, the target applications in the simulation monitoring task list are configured with realistic operation timing to obtain simulation execution control parameters. The automated behavior simulation engine automatically starts the target application, traverses the resource list, and triggers continuous video playback based on the simulation execution control parameters.

4. The method according to claim 3, characterized in that, The process of capturing raw network data packets at the application layer to obtain raw terminal traffic data includes the following steps: The data acquisition agent program performs data acquisition point mounting operations on the application bytecode based on the underlying network communication functions and Secure Sockets Layer encryption / decryption functions. The data acquisition agent program performs low-level secure socket layer decryption and capture operations on all network request packets and response packets of the target application to obtain the original encrypted traffic data of the terminal. The risk control countermeasure module performs spoofing and simulation processing on the terminal device fingerprint and operating environment; The risk control countermeasure module performs an additional operation on the original encrypted traffic data of the terminal to add a trusted collection identifier, thereby obtaining the original traffic collection data of the terminal.

5. The method according to claim 1, characterized in that, The process of preprocessing and encrypting the raw traffic data collected from the terminal to obtain a standardized encrypted traffic dataset includes the following steps: Invalid signaling packets are removed from the raw traffic data collected from the terminal with trusted environment tags by using data cleaning rules; The terminal raw traffic collection data, after invalid signaling packets have been removed, is processed by data cleaning rules to extract the five-tuple, timestamp, associated application identifier, and domain alias resolution link fields, thereby obtaining structured raw traffic feature data. After the structured raw traffic feature data is encrypted and encapsulated by the encrypted data encapsulation unit and the encrypted dedicated transmission tunnel unit, the encrypted and encapsulated structured raw traffic feature data is securely transmitted back to the data processing and analysis module to obtain a standardized encrypted traffic dataset.

6. The method according to claim 1, characterized in that, The process of performing multi-dimensional source tracing and matching on the standardized encrypted traffic dataset through the core analysis engine to obtain a standardized violation determination evidence chain includes the following steps: The domain name resolver performs alias resolution and link resolution processing on the data packets in the standardized encrypted traffic dataset to obtain complete domain name tracing results. Based on the network address intelligence database, the compliant content distribution network filing directory in the domain name database and network address database is retrieved. The target access address corresponding to the complete domain name tracing result is queried and cross-compared with the location, operator and filing customer information to obtain the network address filing matching comparison result. The private distribution network identification unit performs the following steps on the traffic packets in the network address registration matching and comparison results: it determines the characteristics of illegal private distribution network behavior, and statistically analyzes the proportion of high-frequency random user data packet port traffic and the number of concurrent connections to obtain port traffic behavior characteristic data. By using preset comprehensive judgment rules, the complete domain name tracing results, the network address filing matching and comparison results, and the port traffic behavior characteristic data are subjected to multi-dimensional feature fusion and suspected illegal node screening processing to obtain suspected illegal node marking information; After integrating and encapsulating the multi-dimensional data in the suspected violation node marking information, the standardized violation judgment evidence chain is obtained; wherein, the standardized violation judgment evidence chain includes Internet Protocol address basic data, communication port basic data, time basic data, user data packet protocol traffic ratio behavior evidence, standardized domain name resolution link resource evidence, and Internet Protocol address attribution customer analysis data.

7. The method according to claim 6, characterized in that, The determination criteria for processing the traffic packets to identify illegal private distribution network behavior characteristics include: Determine whether the target access address is not recorded in the list of compliant content distribution network filings in the network address database, and whether the target access address continuously carries a large volume of distribution traffic; Alternatively, determine whether the user datagram port and concurrent connection traffic characteristics of the target access address do not match the filing business type of the Internet Data Center customer; Alternatively, determine whether the target Internet Protocol address traffic source domain has not been properly registered or belongs to a commercial platform.

8. The method according to claim 1, characterized in that, The visualization rendering component is set in the data display layer, which calls the domain name database, network address database, and private distribution network list data source of the data processing and analysis module through the capability open interface; the visualization rendering component is used to visualize the domain name database, the network address database, and the private distribution network violation nodes. The program interface includes an external standardized query application programming interface, which is used to encapsulate the standardized violation determination evidence chain into a structured governance report and output the outputtable violation identification data.

9. A private distribution network violation identification system based on behavior simulation, characterized in that, The system includes: The data acquisition terminal module is used to preprocess the original installation package of the target application and perform batch deployment operations on the terminal; control the deployment of probes and configuration of the simulation monitoring task list on each terminal to be monitored through the data acquisition agent program based on the deployed original installation package of the target application to obtain a distributed probe acquisition environment; control the full-process simulation on-demand interaction of the target application in the simulation monitoring task list on each terminal to be monitored according to the natural person behavior parameters and the terminal probes in the distributed probe acquisition environment, and capture the original network data packets of the application layer to obtain the original terminal traffic acquisition data; The secure transmission module is used to preprocess and encrypt the raw traffic data collected by the terminal to obtain a standardized encrypted traffic dataset. The data processing and analysis module is used to perform multi-dimensional source tracing and matching judgment on the standardized encrypted traffic dataset through the core analysis engine to obtain a standardized violation judgment evidence chain; wherein, the core analysis engine includes a domain name resolver, a network address intelligence database and a private distribution network identification unit; The data display module is used to generate a visual report of the standardized violation judgment evidence chain through a visualization rendering component, and after encapsulating the standardized violation judgment evidence chain through a program interface, output violation identification data.

10. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the method according to any one of claims 1 to 8.