Identification method for communication apparatus and related apparatus

By learning the messages between the devices to be detected and other devices online, and generating detection messages with the same protocol type, the problem of excessive interactions between the detection devices and the devices to be detected is solved, and the effect of reducing network pressure is achieved.

WO2025107947A1PCT designated stage expired Publication Date: 2025-05-30HUAWEI TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/125851
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-21
Filing Date
2024-10-18
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In an internal enterprise network, the detection device needs to interact with the device to be detected multiple times to determine the type of protocol it supports, resulting in increased network pressure.

Method used

By learning online the messages of interaction between the device to be detected and other devices, a detection message with the same protocol type is generated, reducing the number of interactions with the device to be detected.

Benefits of technology

It effectively reduces the number of interactions between the detection device and the device to be detected, reduces network pressure, and improves the effectiveness of the detection message.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024125851_30052025_PF_FP_ABST
    Figure CN2024125851_30052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communications, and discloses an identification method for a communication apparatus and a related apparatus, capable of reducing the number of interactions between a detection device and a device to be detected. In the method, a first communication apparatus acquires information of a first message sent by a second device to a first device, the information of the first message comprising a first port number, a first protocol type, and a first payload; and the first communication apparatus sends a first detection message to the first device, the first detection message comprising the first port number, the first protocol type, and the first payload.
Need to check novelty before this filing date? Find Prior Art

Description

A communication device identification method and related device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 21, 2023, with application number 202311571301.5 and invention name “A method for identifying a communication device and related devices”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The embodiments of the present application relate to the field of communication technology, and in particular to a communication device identification method and related devices. Background Art

[0003] With the deep integration of new technologies such as cloud computing, big data, and the Internet of Things with business, the boundary-based security architecture of enterprise internal networks is facing challenges, which in turn makes enterprise internal networks prone to vulnerabilities.

[0004] For example, an enterprise inventories the device information of its internal network assets. When a vulnerability is discovered in a particular device type, the enterprise can quickly determine how many devices within the network are affected by the vulnerability based on this device information. During the asset inventory, the port number of the device to be detected can be determined, and then the device fingerprint database can be used to search for all protocol types corresponding to that port number. Because it is impossible to determine the specific protocol types supported by the device to be detected, the detection device must generate a detection message for each protocol type listed in the fingerprint database. This requires multiple interactions with the device to be detected, increasing network pressure.

[0005] Therefore, how to reduce the number of interactions between the detection device and the device to be detected when detecting the device to be detected is a technical problem that needs to be solved urgently.

[0006] Summary of the Invention

[0007] The embodiments of the present application provide a communication device identification method and related devices, which can reduce the number of interactions between a detection device and a device to be detected.

[0008] In a first aspect, the present application provides a method for online learning of probe messages, which is applied to a first communication device. The method includes: the first communication device obtaining information about a first message sent by a second device to the first device, the information about the first message including a first port number, a first protocol type, and a first payload; and the first communication device sending a first probe message to the first device, the first probe message including the first port number, the first protocol type, and a first payload.

[0009] In this solution, the first detection message is obtained by learning the first message sent by the second device to the first device. Specifically, the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message. Because the protocol type of the first detection message is the same as the protocol type of the first message, the first device supports the protocol type of the first message, which means that the first device also supports the protocol type of the first detection message. Therefore, the present application can obtain the protocol type supported by the first device by online learning of the messages interacting between the first device and the second device, thereby obtaining the first detection message with the same protocol type. The detection device detects and identifies the device to be detected based on the detection message obtained by the above method, and there is no need to send a corresponding detection message to the device to be detected based on each possible protocol type, which effectively reduces the number of interactions between the detection device and the device to be detected, thereby reducing network pressure.

[0010] In a possible implementation of the first aspect, the first communication device obtains information of a second message sent by the first device to the second device, and the information of the second message includes a second payload; when the following conditions are met, the first detection message is a valid message, and the conditions include: after sending the first detection message, the first communication device receives a third message sent by the first device, and the third message includes the second payload.

[0011] In this solution, when the third message also includes the second payload, it indicates that the first probe message learned based on the first message is the same as the first message and can trigger the first device to send a message containing the second payload, which can prove the validity of the first probe message. Therefore, the first communication device determines whether the first probe message is valid by verifying whether the received third message includes the second payload. Thus, the first communication device can retain valid probe messages and discard invalid probe messages based on the verification result, thereby improving the validity of the resulting probe message.

[0012] In a possible implementation manner of the first aspect, a destination Internet Protocol (IP) address of the first detection message is a destination IP address of the first message or an IP address of a device to be detected.

[0013] In a possible implementation manner of the first aspect, a destination Media Access Control Address (MAC) address of the first detection message is a destination MAC address of the first message or a MAC address of the device to be detected.

[0014] In this solution, when the first probe message is the same as the destination IP address of the first message, the first probe message can be sent to the first device, and the validity of the first probe message can be determined based on the third message sent by the first device. When the first probe message is the IP address of the device to be detected, the first probe message can be sent to the device to be detected, thereby detecting the device to be detected. When the first probe message is the same as the destination MAC address of the first message, the first probe message can be sent to the first device, and the validity of the first probe message can be determined based on the third message sent by the first device. When the first probe message is the MAC address of the device to be detected, the first probe message can be sent to the device to be detected, thereby detecting the device to be detected.

[0015] In a specific design, the first port number is the destination port number of the first message.

[0016] In a specific design, the destination port number of the first detection message is the destination port number of the first message or the port number of the device to be detected. The port number of the device to be detected can be the port number of the server of the device to be detected or the port number of the application in the device to be detected.

[0017] In a possible implementation of the first aspect, the first communication device obtains information of a fourth message sent by the second device to the first device, wherein the information of the fourth message includes a second port number, a second protocol type and a third payload; the first communication device sends a second detection message to the first device, and the second detection message includes a second port number, a second protocol type and a third payload.

[0018] In this solution, the first detection message is generated by learning the first message sent by the second device to the first device, and the second detection message is generated by learning the fourth message sent by the second device to the first device. Therefore, when the first detection message is invalid, detection can be performed through the second detection message. Furthermore, since the information carried in the fourth message and the second message may be different, the second detection message finally obtained may also be different from the first detection message. This increases the diversity of the detection messages in this solution, making this solution applicable to more diverse scenarios.

[0019] In a specific design, the destination IP address of the second detection message is the destination IP address of the fourth message or the IP address of the device to be detected.

[0020] In a specific design, the destination MAC address of the second detection message is the destination MAC address of the fourth message or the MAC address of the device to be detected.

[0021] In a possible implementation of the first aspect, the first communication device obtains information of a fifth message sent by the fourth device to the third device, wherein the information of the fifth message includes a third port number, a third protocol type and a fourth payload; the first communication device sends a third detection message to the third device, and the third detection message includes the third port number, the third protocol type and the fourth payload.

[0022] In this solution, since the fourth device may belong to a different category of device from the second device, and the third device may also belong to a different category of device from the first device, the detection message is generated by learning the messages of different categories of devices, so that this solution can be applied to the detection of different categories of devices.

[0023] In a specific design, the third device and the first device are the same device, or the IP addresses of the third device and the first device belong to the same network segment.

[0024] In a specific design, the fourth device and the second device are the same device, or the IP addresses of the fourth device and the second device belong to the same network segment.

[0025] In a specific design, the destination IP address of the third detection message is the destination IP address of the fifth message or the IP address of the device to be detected.

[0026] In a specific design, the destination MAC address of the third detection message is the destination MAC address of the fifth message or the MAC address of the device to be detected.

[0027] In a specific design, the first communication device sends a fourth probe message to the first device, and the fourth probe message includes the first port number, the first protocol type and the first payload.

[0028] In this solution, the first detection message and the fourth detection message are generated by learning the first message, so that when the first detection message is invalid, the first communication device can detect the device to be detected through the fourth detection message.

[0029] In a specific design, the destination IP address of the fourth detection message is the destination IP address of the first message or the IP address of the device to be detected.

[0030] In a specific design, the destination MAC address of the fourth detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

[0031] In a possible implementation of the first aspect, the destination IP address of the first message is a multicast or broadcast IP address or the IP address of the first device; and / or the destination MAC address of the first message is a multicast or broadcast MAC address or the MAC address of the first device.

[0032] This solution does not limit the first message to only a message that supports only point-to-point communication, such as a Transmission Control Protocol (TCP) message. The first message in this solution may also be a message that can be multicast or broadcast, such as a SIP message. Therefore, the destination IP address of the first message may be a multicast or broadcast IP address or the IP address of the first device, and the same applies to the destination MAC address of the first message.

[0033] In a possible implementation of the first aspect, the first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol. In a specific implementation, the first protocol includes: Open Network Video Interface Forum (ONVIF) protocol, Session Initiation Protocol (SIP), Multicast Domain Name Service (mDNS) protocol, or a protocol defined by the manufacturer of the first device and the device to be detected. In a specific implementation, the first protocol may also include: TCP, User Datagram Protocol (UDP), IP or Hypertext Transfer Protocol (HTTP).

[0034] In this solution, the first probe message and the first message are both first protocol messages because the protocol format of the first message is learned when the first probe message is generated, and a first probe message capable of detecting the device is constructed based on the protocol format of the first message. Constructing the probe message based on the protocol format of the message actually sent during device interaction can make the probe message in this solution more practical.

[0035] In a possible implementation of the first aspect, the first detection message is a first protocol message, the first message is a second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

[0036] In this solution, the first detection message is based on the first protocol, and the first message is based on the second protocol. At this time, it is only necessary to ensure that the device to be detected supports the first protocol, and to ensure that the first device supports both the first protocol and the second protocol. Therefore, it can be applied to the scenario where the device to be detected does not support the first protocol but only supports the second protocol.

[0037] In this solution, the first detection message can be an ONVIF protocol message, a SIP message, or an mDNS protocol message. Among them, ONVIF protocol messages are generally messages exchanged between devices when performing video services, SIP messages are generally messages exchanged between devices when conducting conversations, and mDNS protocol messages are generally messages used by hosts within a local area network to communicate with each other. Therefore, the first detection message can detect devices in these scenarios. It can be seen that the first detection message in this solution can be applied to a wide range of scenarios. The first detection message can also be based on the protocol defined by the manufacturer of the device to be detected. If the first detection message is sent to different types of devices to be detected, and messages sent by the devices to be detected from different manufacturers are received. Because the protocols defined by different manufacturers are different, the information carried in the messages sent by the devices to be detected from different manufacturers will be relatively different, so the manufacturer and other device information of the device to be detected can be determined based on this highly different information.

[0038] In a possible implementation of the first aspect, the first communication device mirrors the first message from a fifth device, where the fifth device is an intermediate device between the first device and the second device; and the first communication device obtains information of the first message based on the first message.

[0039] In a specific design, the first communication device can obtain the first message through port mirroring or traffic mirroring.

[0040] In a specific design, the fifth device is a network device, for example, the network device includes but is not limited to: a switch, a router or a firewall.

[0041] In a specific design, when the first communication device is a network device, the first communication device can directly mirror the first message through a local port without the help of an intermediate device.

[0042] In a specific design, the first communication device can read the first message and obtain information of the first message.

[0043] In a specific design, the first communication device receives information of the first message sent by the fifth device.

[0044] In a possible implementation manner of the first aspect, the first communication device receives information of the second message sent by the fifth device.

[0045] In a specific design, the fifth device mirrors the second message and sends the information of the second message to the first communication device.

[0046] In a specific design, the first communication device mirrors the second message from the fifth device to obtain information of the second message, wherein the fifth device is an intermediate device between the first device and the second device.

[0047] In a specific design, the first communication device can obtain the second message through port mirroring or traffic mirroring.

[0048] In a possible implementation of the first aspect, the first communication device obtains multiple messages sent by the first device to the second device; the first communication device matches the key fields of each message in the multiple messages with a field library; the first communication device obtains information of the second message based on the message in the multiple messages that successfully matches the field library.

[0049] In a specific design, after acquiring the plurality of messages, the first communication device may extract the key fields from the messages based on a data mining algorithm. For example, the data mining algorithm includes but is not limited to: term frequency-inverse document frequency (TF-IDF), TextRank, or linear discriminant analysis (LDA).

[0050] In a possible implementation of the first aspect, the field library is used to describe device information. In a specific implementation, the field library includes one or more of the following fields: a name field for a device brand, a name field for a device model, a device category field, or a device serial number.

[0051] In a specific design, the key field may be a field that appears more frequently in the message, and the fields in the field library describe the commonalities in the device information.

[0052] In a specific design, the first communication device can match the key field with the field library in the following manner: a similarity algorithm is used to calculate the similarity between the key field and the field in the field library; when the similarity is higher than a threshold, the key field is considered to be matched successfully; and when the similarity is equal to or less than a threshold, the key field is considered to have failed to match.

[0053] In a possible implementation of the first aspect, the first communication device responds to the second payload including the device information of the first device, and the first communication device obtains the information of the first message based on the information of the second message; the first communication device generates the first detection message based on the information of the first message.

[0054] In this solution, when the second payload includes the device information of the first device, it indicates that the first message carries the device information. During communication between the first device and the second device, the second device sends the first message to the first device, triggering the second device to send the second message to the first device. Therefore, the first communication device needs to obtain the first message, then learn the first message to obtain the first detection message, thereby triggering the first device to send a message containing device information similar to the second message through the first detection message.

[0055] In a possible implementation of the first aspect, the first communication device obtains information of the first message based on the source IP address of the second message and the destination IP address of the second message, wherein the information of the second message includes: the source IP address of the second message and the destination IP address of the second message, the source IP address of the second message is the IP address of the first device, and the destination IP address of the second message is the IP address of the second device; and / or the first communication device obtains information of the first message based on the source MAC address of the second message and the destination MAC address of the second message, wherein the information of the second message includes: the source MAC address of the second message and the destination MAC address of the second message, the source MAC address of the second message is the MAC address of the first device, and the destination MAC address of the second message is the MAC address of the second device.

[0056] In this solution, since the first message is a message sent by the second device to the first device, and the second message is a message sent by the first device to the second device, the source IP address of the first message is the destination IP address of the second message, and the destination IP address of the first message is the source IP address of the second message. Therefore, the source IP address and destination IP address of the second message can be determined based on the first message. When the first communication device obtains multiple messages, the first message can be found from the multiple messages based on the source IP address and the destination IP address.

[0057] In a possible implementation manner of the first aspect, the first communication device sends the first detection message to the device to be detected; receives a sixth message sent by the device to be detected; and parses device information of the device to be detected from the sixth message.

[0058] In this solution, after generating the first detection message, the first communication device can use the first detection message to detect the device to be detected, without having to send the first detection message to other devices and then use the other devices to detect the device to be detected. This approach reduces the time overhead caused by the first communication device exchanging the first detection message with other devices and also saves network resources.

[0059] In a possible implementation manner of the first aspect, the first communication device sends the second detection message to the device to be detected; receives a seventh message sent by the device to be detected; and parses device information of the device to be detected from the seventh message.

[0060] In a possible implementation manner of the first aspect, the first communication device sends the third detection message to the device to be detected; receives an eighth message sent by the device to be detected; and parses device information of the device to be detected from the eighth message.

[0061] In a specific design, the first communication device receives the fourth detection message sent by the fifth device, sends the fourth detection message to the device to be detected, receives the ninth message sent by the device to be detected, and parses the device information of the device to be detected from the ninth message.

[0062] In a specific design, the first communication device can also send the first detection message to the network segment to which the IP address of the device to be detected belongs, receive the tenth message sent by the device to be detected, and parse the device information of the device to be detected from the tenth message.

[0063] The second aspect of the present application provides a method for identifying a communication device, which is applied to a second communication device, including: the second communication device receives the network segment to which the IP address of the device to be detected belongs, and then sends a first detection message to the network segment, the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; the second communication device receives the second message sent by the device to be detected, and then parses the device information of the device to be detected from the second message.

[0064] In this solution, the second communication device can send the first detection message to the network segment to which the IP address of the device to be detected belongs. Even if the specific IP address of the device to be detected is unknown, but only the network segment to which the IP address belongs is known, this solution still detects the device to be detected. This shows that the communication device identification method of this application can broaden the scenarios for device detection.

[0065] In a possible implementation of the second aspect, the first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol. In a specific implementation, the first protocol includes ONVIF, SIP, mDNS, or a protocol defined by the manufacturers of the first device and the device to be detected. In a specific implementation, the first protocol may also include TCP, UDP, IP, or HTTP.

[0066] In a possible implementation of the second aspect, the first detection message is a first protocol message, the first message is a second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

[0067] In this solution, the first detection message is based on the first protocol, and the first message is based on the second protocol. At this time, it is only necessary to ensure that the device to be detected supports the first protocol, and to ensure that the first device supports the first protocol and the second protocol at the same time. Therefore, it can be applied to the scenario where the device to be detected does not support the first protocol but only supports the second protocol.

[0068] In this solution, the first detection message can be an ONVIF protocol message, a SIP message, or an mDNS protocol message. Among them, ONVIF protocol messages are generally messages exchanged between devices when performing video services, SIP messages are generally messages exchanged between devices when conducting conversations, and mDNS protocol messages are generally messages used by hosts within a local area network to communicate with each other. Therefore, the first detection message can detect devices in these scenarios. It can be seen that the first detection message in this solution can be applied to a wide range of scenarios. The first detection message can also be based on the protocol defined by the manufacturer of the device to be detected. If the first detection message is sent to different types of devices to be detected, and messages sent by the devices to be detected from different manufacturers are received. Because the protocols defined by different manufacturers are different, the information carried in the messages sent by the devices to be detected from different manufacturers will be relatively different, so the manufacturer and other device information of the device to be detected can be determined based on this highly different information.

[0069] In a possible implementation manner of the second aspect, the destination IP address of the first detection message is the destination IP address of the first message or each IP address included in the above-mentioned network segment.

[0070] In a possible implementation manner of the second aspect, the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

[0071] In this solution, when the first probe message is the same as the destination IP address of the first message, the first probe message can be sent to the first device, and the validity of the first probe message can be determined based on the message sent by the first device. When the first probe message is the IP address of the device to be detected, the first probe message can be sent to the device to be detected, thereby detecting the device to be detected. When the first probe message is the same as the destination MAC address of the first message, the first probe message can be sent to the first device, and the validity of the first probe message can be determined based on the two messages sent by the first device. When the first probe message is the MAC address of the device to be detected, the first probe message can be sent to the device to be detected, thereby detecting the device to be detected.

[0072] In a possible implementation of the second aspect, the second communication device sends a second detection message to the network segment, and the port number, protocol type and payload of the second detection message are the same as the port number, protocol type and payload of the third message sent by the second device to the first device; the second communication device receives a fourth message sent by the device to be detected; and parses the device information of the device to be detected from the fourth message.

[0073] In this solution, the first detection message is similar to the first message sent by the second device to the first device, and the second detection message is similar to the third message sent by the second device to the first device. Since the information carried in the third message and the second message may be different, the second detection message may also be different from the first detection message, so that different devices to be detected can be detected using diverse detection messages.

[0074] In a possible implementation of the second aspect, the second communication device sends a third detection message to the network segment, and the port number, protocol type and payload of the third detection message are the same as the port number, protocol type and payload of the fifth message sent by the third device to the fourth device; the second communication device receives the sixth message sent by the device to be detected; and parses the device information of the device to be detected from the sixth message.

[0075] In this solution, since the fourth device may belong to a different category of device from the second device, and the third device may also belong to a different category of device from the first device, the third detection message and the first detection message are similar to messages of different categories of devices, respectively, so that the second communication device can detect devices of different categories through the third detection message and the first detection message.

[0076] In a specific design, the second communication device sends a fourth detection message to the network segment, and the port number, protocol type and payload of the fourth detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device.

[0077] In this solution, in addition to sending the first detection message to the network segment, the second communication device also sends a fourth detection message to the network segment. The first detection message and the fourth detection message are similar to the first message. Therefore, when the first detection message is invalid, the second communication device can detect the device to be detected through the fourth detection message.

[0078] The third aspect of the present application provides a message sending method, which is applied to a third communication device, including: the third communication device receives a first detection message sent by a third device, the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; the third communication device sends a first detection message to the third device, and the first detection message includes the device information of the device to be detected.

[0079] In this solution, the third communication device does not need to receive the detection message formulated by the third device based on each possible protocol type, but only needs to receive the first detection message formulated by the third device based on the protocol type of the first message, thereby effectively reducing the number of interactions between the third communication device and the third device, thereby reducing network pressure.

[0080] In a fourth aspect of the present application, a communication device is provided, which includes a receiving module, a processing module, and a sending module, and is used to perform all or part of the operations described in the first aspect, the second aspect, or the third aspect. The communication device can be a network device such as a router or a switch, or a component of a network device used to perform related operations, such as a line card, an interface board, etc., or a chip system used to perform related operations, and the chip system can include one or more chips. When the communication device is a chip system, the receiving module and the sending module can be, for example, the interface circuit of the chip, and the processing module can be, for example, the processing circuit of the chip.

[0081] For example, when executing the method described in the first aspect, the processing module is used to obtain information of a first message sent by the second device to the first device, wherein the information of the first message includes a first port number, a first protocol type and a first payload; the receiving module is used to send a first detection message to the first device, wherein the first detection message includes the first port number, the first protocol type and the first payload.

[0082] In a possible implementation of the fourth aspect, the processing module is further used to obtain information of a second message sent by the first device to the second device, the information of the second message including a second payload; when the following conditions are met, the first detection message is a valid message, and the conditions include: after sending the first detection message, a third message sent by the first device is received, and the third message includes the second payload.

[0083] In a possible implementation of the fourth aspect, the destination IP address of the first detection message is the destination IP address of the first message or the IP address of the device to be detected; and / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

[0084] In a possible implementation of the fourth aspect, the processing module is further used to obtain information of a fourth message sent by the second device to the first device, wherein the information of the fourth message includes a second port number, a second protocol type and a third payload; the sending module is further used to send a second detection message to the first device, wherein the second detection message includes the second port number, the second protocol type and the third payload.

[0085] In a possible implementation of the fourth aspect, the processing module is further used to obtain information of a fifth message sent by the fourth device to the third device, wherein the information of the fifth message includes a third port number, a third protocol type and a fourth payload; the sending module is further used to send a third detection message to the third device, wherein the third detection message includes the third port number, the third protocol type and the fourth payload.

[0086] In a possible implementation of the fourth aspect, the destination IP address of the first message is a multicast or broadcast IP address or the IP address of the first device; and / or the destination MAC address of the first message is a multicast or broadcast MAC address or the MAC address of the first device.

[0087] In a possible implementation manner of the fourth aspect, the first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

[0088] In a possible implementation of the fourth aspect, the first detection message is the first protocol message, the first message is the second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

[0089] In a possible implementation manner of the fourth aspect, the first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by manufacturers of the first device and the device to be detected.

[0090] In a possible implementation of the fourth aspect, the processing module is further used to mirror the first message from a fifth device, where the fifth device is an intermediate device between the first device and the second device; and obtain information of the first message based on the first message.

[0091] In a possible implementation manner of the fourth aspect, the receiving module is further configured to receive information of the second message sent by the fifth device.

[0092] In a possible implementation of the fourth aspect, the processing module is also used to obtain multiple messages sent by the first device to the second device; match the key fields of each message in the multiple messages with the field library; and obtain information of the second message based on the message in the multiple messages that successfully matches the field library.

[0093] In a possible implementation manner of the fourth aspect, the field library includes one or more of the following fields: a name field of a device brand, a name field of a device model, a device category field, or a serial number of a device.

[0094] In a possible implementation of the fourth aspect, the processing module is further used to obtain information of the first message according to information of the second message in response to the second payload including device information of the first device; and generate the first detection message according to the information of the first message.

[0095] In a possible implementation of the fourth aspect, the processing module is further used to obtain information of the first message based on the source IP address of the second message and the destination IP address of the second message, wherein the information of the second message includes: the source IP address of the second message and the destination IP address of the second message, the source IP address of the second message is the IP address of the first device, and the destination IP address of the second message is the IP address of the second device; and / or obtain information of the first message based on the source MAC address of the second message and the destination MAC address of the second message, wherein the information of the second message includes: the source MAC address of the second message and the destination MAC address of the second message, the source MAC address of the second message is the MAC address of the first device, and the destination MAC address of the second message is the MAC address of the second device.

[0096] In a possible implementation of the fourth aspect, the sending module is further used to send the first detection message to the device to be detected; the receiving module is further used to receive the sixth message sent by the device to be detected; and the processing module is further used to parse the device information of the device to be detected from the sixth message.

[0097] In a possible implementation of the fourth aspect, the sending module is further used to send a second detection message to the device to be detected; the receiving module is further used to receive a seventh message sent by the device to be detected; and the processing module is further used to parse the device information of the device to be detected from the seventh message.

[0098] In a possible implementation of the fourth aspect, the sending module is further used to send a third detection message to the device to be detected; the receiving module is further used to receive an eighth message sent by the device to be detected; and the processing module is further used to parse the device information of the device to be detected from the eighth message.

[0099] For example, when executing the method described in the second aspect, the receiving module is used to receive the network segment to which the IP address of the device to be detected belongs; the sending module is also used to send a first detection message to the network segment, and the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; the receiving module is also used to receive a second message sent by the device to be detected; the processing module is used to parse the device information of the device to be detected from the second message.

[0100] In a possible implementation manner of the fourth aspect, the first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

[0101] In a possible implementation of the fourth aspect, the first detection message is the first protocol message, the first message is the second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

[0102] In a possible implementation manner of the fourth aspect, the first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by manufacturers of the first device and the device to be detected.

[0103] In a possible implementation of the fourth aspect, the destination IP address of the first detection message is the destination IP address of the first message or each IP address included in the network segment; and / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

[0104] In a possible implementation of the fourth aspect, the sending module is further used to send a second detection message to the network segment, and the port number, protocol type and payload of the second detection message are the same as the port number, protocol type and payload of the third message sent by the second device to the first device; the receiving module is further used to receive a fourth message sent by the device to be detected; the processing module is further used to parse the device information of the device to be detected from the fourth message.

[0105] In a possible implementation of the fourth aspect, the sending module is also used to send a third detection message to the network segment, and the port number, protocol type and payload of the third detection message are the same as the port number, protocol type and payload of the fifth message sent by the third device to the fourth device; the receiving module is also used for the sixth message sent by the device to be detected; the processing module is also used to parse the device information of the device to be detected from the sixth message.

[0106] For example, when executing the method described in the third aspect, the receiving module is used to receive a first detection message sent by a third device, and the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; the sending module is used to send the first message to the third device, and the first message includes device information of the device to be detected.

[0107] In a fifth aspect, the present application provides a communication device, including a processor and a communication interface. The processor and the communication interface are configured to execute the method described in any possible implementation of the first, second, or third aspects.

[0108] In one specific design, the processor is coupled to a memory, for example, the memory is used to store programs or instructions. The at least one processor is used to execute the program or instructions to enable the device to implement all or part of the operations of the method described in any possible implementation of the first aspect, the second aspect, or the third aspect.

[0109] In a sixth aspect, the present application provides a computer-readable storage medium storing a program or instruction. When the program or instruction runs on a processor, the method described in any possible implementation of the first, second or third aspects is executed.

[0110] In a seventh aspect, the present application provides a computer program product, including a program or instructions. When the program or instructions are executed on a processor, the program or instructions implement all or part of the operations of the method described in any possible implementation of the first, second, or third aspects. In a specific implementation, the computer program product may be the computer-readable storage medium mentioned in the sixth aspect.

[0111] An eighth aspect of the present application provides a communication system, which includes the communication device of the fourth aspect or the communication device of the fifth aspect.

[0112] Among them, the technical effects brought about by any design method in the fourth to eighth aspects can refer to the technical effects brought about by the above-mentioned first to third aspects and their different design methods, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0113] FIG1 is a schematic diagram of a system architecture of a communication device identification method provided in an embodiment of the present application;

[0114] FIG2 is a flow chart of a method 100 for online learning detection messages provided in an embodiment of the present application;

[0115] FIG3 is a schematic diagram of the structure of message 1 and detection message 1 provided in an embodiment of the present application;

[0116] FIG4 is a flow chart of a communication device identification method 200 provided in an embodiment of the present application;

[0117] FIG5 is a schematic diagram of collaboration between devices in Example 1;

[0118] FIG6 is a schematic diagram of a process in Example 1;

[0119] FIG7 is a schematic diagram of collaboration between devices in Example 2;

[0120] FIG8 is a schematic diagram of a process in Example 2;

[0121] FIG9 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0122] FIG10 is another structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0123] In order to make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the implementation methods of the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.

[0124] The following are some terms involved in the embodiments of this application for explanation.

[0125] 1. The terminal devices involved in the embodiments of the present application include devices that provide voice services to users, devices that provide data connectivity to users, or devices that provide both voice and data connectivity to users. For example, they may include handheld devices with wireless connectivity or processing devices connected to wireless modems. They may also be referred to as terminals. The terminals can communicate with the core network via a radio access network (RAN), exchange voice or data with the RAN, or exchange voice and data with the RAN. The terminal may include user equipment (UE), wireless terminal, mobile terminal, device-to-device (D2D) terminal, vehicle-to-everything (V2X) terminal, road side unit (RSU), machine-to-machine / machine-type communications (M2M / MTC) terminal, Internet of Things (IoT) terminal, subscriber unit, subscriber station, mobile station, remote station, access point (AP), remote terminal, access terminal, user agent, or user device, etc. It may include a mobile phone (also called a "cellular" phone), a computer with a mobile terminal, a portable, pocket-sized, handheld, or computer-built-in mobile device, etc. This category includes personal communication service (PCS) phones, cordless phones, telephones, wireless local loop (WLL) stations, personal digital assistants (PDAs), and other devices. It also includes constrained devices, devices with low power consumption, limited storage capacity, or limited computing power. It also includes information sensing devices such as barcodes, radio frequency identification (RFID), sensors, global positioning systems (GPS), and laser scanners.

[0126] As an example and not a limitation, in the embodiments of the present application, the terminal device may also be a wearable device. Wearable devices may also be referred to as wearable smart devices or smart wearable devices, etc., which are a general term for wearable devices that are intelligently designed and developed using wearable technology for daily wear, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. Wearable devices are not only hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are fully functional, large in size, and can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, etc., as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets, smart helmets, and smart jewelry for vital sign monitoring.

[0127] The various terminals introduced above, if located on a vehicle, for example, placed in or installed in a vehicle, can be considered as vehicle-mounted terminals. For example, a vehicle-mounted terminal is also called an on-board unit (OBU).

[0128] In the embodiment of the present application, the device for implementing the function of the terminal can be a terminal, or a chip system that can support the terminal to implement the function, and the chip system can be installed in the terminal. In the embodiment of the present application, the chip system can include at least one chip, and can also include other discrete devices.

[0129] 2. The terms "system" and "network" in the embodiments of the present application can be used interchangeably. "At least one" means one or more, and "plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of A, B and C" includes A, B, C, AB, AC, BC or ABC. And, unless otherwise specified, the ordinal numbers such as "first" and "second" mentioned in the embodiments of the present application are used to distinguish multiple objects, and are not used to limit the order, timing, priority or importance of multiple objects.

[0130] The following is an example of the system architecture of the embodiment of the present application.

[0131] As shown in Figure 1, Figure 1 is a schematic diagram of a possible, non-limiting system architecture provided by this application. The solution provided by this application can be applied to the system 1000 shown in Figure 1.

[0132] System 1000 includes a communication device 101, switches 1, 2, 3, and a laptop 102. It should be noted that communication device 101 includes the device to be detected, and communication device 101 can be either a terminal device or a network device. Laptop 102 is an example of a detection device; detection devices can also be other terminal devices or network devices. Communication device 101 can be, for example, a printer, IP phone, camera, mobile phone, or other terminal as shown in Figure 1. Some terminals communicate with switch 3 via switch 1, while some communicate with switch 3 via switch 2. Switch 3 can mirror received messages to laptop 102.

[0133] It should be noted that switches 1, 2, and 3 are examples of intermediate devices between each communication device 101 and the laptop. These intermediate devices are network devices, such as firewalls or routers. Furthermore, system 1000 typically includes multiple switches, but may also include only one switch. For example, system 1000 may include only switch 1. In this case, communication device 101 reports a message to switch 1, which then mirrors the message to laptop 102.

[0134] When laptop 102 detects a device to be detected, one possible implementation is to determine the port number of the device to be detected and then search the device fingerprint library for all protocol types corresponding to that port number. Because it is unknown what specific protocol types the device to be detected supports, laptop 102 must generate a detection message based on each protocol type listed in the fingerprint library. This requires multiple interactions with the device to be detected, increasing network pressure. Furthermore, the fingerprint library only includes protocols such as TCP / IP that support point-to-point communication. Therefore, if the IP address of the device to be detected is unknown, detection of the device to be detected is impossible.

[0135] Therefore, when detecting a device to be detected, how to reduce the number of interactions between the detecting device and the device to be detected, and how to detect the device to be detected when the IP address of the device to be detected is unknown are technical problems that need to be solved urgently.

[0136] In order to solve the problem of too many interactions between the detection device and the device to be detected, an embodiment of the present application provides a method 100 for online learning of detection messages, and the method 100 can be applicable to the scenario shown in Figure 1. When the method 100 is applied to the scenario shown in Figure 1, the device 2 in the method 100 can be, for example, the communication device 101 shown in Figure 1, and the communication device 1 in the method 100 can be, for example, the notebook 102 or the switch 3 shown in Figure 1. Among them, the method 100 generates a first detection message by learning the first message sent by the device 2 to the device 1. In the method 100, there is no need to generate a detection message based on each protocol, but only needs to generate a detection message based on the protocol adopted by the first message, thereby reducing the number of interactions between the detection device and the device to be detected.

[0137] The method 100 provided by the embodiment of the present application is described in detail below with reference to FIG2 . As shown in FIG2 , the method 100 for online learning detection messages provided by the embodiment of the present application includes the following steps:

[0138] Step 201: Communication device 1 obtains message information of message 1 sent by device 2 to device 1, where the message information includes port number 1, protocol type 1, and payload 1.

[0139] Step 202 : The communication device 1 sends a probe message 1 to the device 1 . The probe message 1 includes the port number 1 , the protocol type 1 , and the payload 1 .

[0140] The communication device 1 can be a terminal device, such as the laptop 102 shown in FIG1 , or a network device, such as the switch 3 shown in FIG1 . When the communication device 1 is a network device, the network device may include, but is not limited to, a switch, a router, or a firewall. It should be noted that the protocol type 1 is the type of protocol underlying the message 1. For example, if the message 1 is a SIP message, the protocol type 1 is SIP.

[0141] It's important to note that the payload carries the original data of a message. The name of the payload may vary across different protocols. For example, in a UDP message, the payload is called the UDP data; in a SIP message, the payload is called the message body.

[0142] It should be noted that the message information of message 1 may not include port number 1 and protocol type 1, but include information indicating port number 1 and protocol type 1. For example, the message information of message 1 includes information indicating the method for obtaining port number 1.

[0143] It should be noted that the embodiment of the present application does not limit message 1 to a message that can only support point-to-point communication, such as a TCP message. The message 1 in the embodiment of the present application can also be a message that can be multicast or broadcast, such as a SIP message. Therefore, message 1 can be sent in the form of unicast, multicast or broadcast. Accordingly, the destination IP address and destination media access control (MAC) address of message 1 can be in the following forms:

[0144] In a possible implementation, the destination IP address of the message 1 may be a multicast or broadcast IP address, or may be the IP address of the device 1 .

[0145] In a possible implementation, the destination MAC address of the message 1 may be a multicast or broadcast MAC address, or may be the MAC address of the device 1 .

[0146] In addition, the port number 1 mentioned above may be the destination port number of the message 1 , that is, the port number of the device 1 .

[0147] In step 201, message 1 can be obtained in various ways:

[0148] In a possible implementation, the communication device 1 mirrors the message 1 from the device 5 , which is an intermediate device between the device 1 and the device 2 ; the communication device 1 obtains the message information of the message 1 according to the message 1 .

[0149] In another possible implementation, the communication device 1 receives the message information of the message 1 sent by the device 5 .

[0150] In the first implementation described above, after mirroring message 1, device 5 sends message 1 to communication device 1. After receiving message 1, communication device 1 can read message 1 and obtain the message information of message 1. In the second implementation described above, after mirroring message 1, device 5 can read the message information of message 1 and then send the message information to communication device 1. Device 5 can also directly mirror the message information of message 1 and then send the message information to communication device 1.

[0151] Optionally, the device 5 is a network device. In addition, the communication device 1 does not necessarily need to obtain the message 1 through the device 5. When the communication device 1 is a network device, the communication device 1 can directly mirror the message 1 through a local port.

[0152] It can be understood that in order to better learn message 1 to detect the device to be detected, the composition of the detection message 1 should be as consistent as possible with the composition of message 1. Therefore, the port number, protocol type and payload included in the detection message 1 in step 202 are consistent with the port number, protocol type and payload of message 1.

[0153] Step 202 above describes some of the information that the detection message 1 needs to include. As for other information included in the detection message 1, the following possibilities exist:

[0154] Optionally, the destination port number of the detection message 1 may be the destination port number of the message 1. The destination port number of the detection message 1 may also be the port number of the device to be detected, the port number of the server of the device to be detected, or the port number of an application in the device to be detected.

[0155] In a possible implementation, the destination IP address of the detection message 1 is the destination IP address of the message 1 or the IP address of the device to be detected;

[0156] In a possible implementation, the destination MAC address of the detection message 1 is the destination MAC address of the message 1 or the MAC address of the device to be detected.

[0157] It should be noted that the above-mentioned device to be detected may be a terminal device or a network device.

[0158] In addition, there are various situations regarding the protocol based on which the probe message 1 is sent. Specifically:

[0159] In a possible implementation, the detection message 1 and the message 1 are both protocol 1 messages, and the device to be detected and the device 1 both support protocol 1.

[0160] In another possible implementation, the detection message 1 is a protocol 1 message, the message 1 is a protocol 2 message, the device to be detected supports the protocol 1, and the device 1 supports both the protocol 1 and the protocol 2.

[0161] In the first implementation, it is understood that since device 2 can communicate with device 1 via message 1, device 1 must support the protocol based on message 1. Therefore, probe message 1 can be generated based on the protocol format of message 1, and in this case, device 1 must also support the protocol based on probe message 1.

[0162] As for the detection message 1 and the specific protocol based on the message 1, it can be in the following ways:

[0163] In a possible implementation, the protocol 1 includes: ONVIF, SIP, mDNS protocol, or a protocol defined by the manufacturer of the device 1 and the device to be detected.

[0164] The above-mentioned "protocols defined by the manufacturers of device 1 and the device to be detected" refer to some proprietary protocols defined by the manufacturers of device 1 and the device to be detected in order to improve product performance, etc. For example, the model of device 1 is M. Manufacturer A, which produces device 1, customizes a proprietary protocol for M-type devices in order to enable fast communication between M-type devices.

[0165] The above implementation method only lists some protocols. The embodiments of this application are not limited to the above protocols. Protocol 1 can also be various types of IoT protocols, such as UDP, IP, etc.

[0166] Compared to the method of generating detection messages only through general protocols, the embodiments of the present application can generate detection messages based on dedicated protocols. Since proprietary protocols are unique to each manufacturer, the probability of duplication with device-related information defined by other manufacturers is relatively small. Therefore, when a detection message generated based on a proprietary protocol is sent to the device to be detected, the device-related information carried in the message sent by the device to be detected will be relatively different, so the device information of the device to be detected can be determined based on these highly different device-related information.

[0167] The information included in Probe Message 1 is explained in conjunction with Figure 3. Figure 3 takes Message 1 as an example, which is a SIP message. Probe Message 1 is also a SIP message. Message 1 is sent to Device 1, so the destination address is the address of Device 1. The address of Device 1 can be either the IP address or the MAC address of Device 1. Correspondingly, the destination address of Probe Message 1 is the address of Device 1 or the address of the device to be detected. Furthermore, the message bodies of both are Payload 1. For another example, both Probe Message 1 and Message 1 are UDP messages. Message 1 is sent to Device 1, so the destination port number is the port number of Device 1. Correspondingly, the destination port number of Probe Message 1 is the port number of Device 1 or the port number of the device to be detected. Furthermore, the data portion of both is Payload 1.

[0168] Since it is impossible to ensure that all detection messages generated based on message 1 can effectively detect the device to be detected, it is necessary to verify the detection message. Specifically, this can be achieved through the following methods:

[0169] In one possible implementation, information about message 2 sent by device 1 to device 2 is obtained, where the information about message 2 includes payload 2. When the following conditions are met, the probe message 1 is a valid message, where the conditions include: after sending the probe message 1, message 3 sent by device 1 is received, where message 3 includes payload 2.

[0170] It is understood that when device 1 and device 2 are in communication, device 2 sends message 1 to device 1, and device 2 replies to device 1 with message 2. The criterion for verifying the effectiveness of the learning process of probe message 1 is whether probe message 1 can trigger device 1 to send a message similar to message 2, namely message 3, as does device 2. Since device information is usually carried in the payload, and the embodiments of the present application require detection of device information, when the payload included in message 3 is consistent with the payload included in message 2, it can be confirmed that the probe message is valid.

[0171] When the communication device 1 obtains multiple messages, not all of these messages need to be learned. As mentioned above, what the embodiment of the present application needs to detect is the device information. Therefore, what the embodiment of the present application needs to learn is the message that can trigger the device to send device information. Taking device 1 and device 2 as an example, device 2 sends message 1 to device 1, and device 1 replies to device 2 with message 2. If message 2 includes device information, then by learning message 1 to generate detection message 1, and sending the detection message 1 to device 1, it can trigger device 1 to return a message similar to message 2 containing device information. Based on this, first obtain message 2 containing device information from multiple messages. Specifically, it can be implemented in the following way:

[0172] In one possible implementation, multiple messages sent by device 1 to device 2 are obtained; the key fields of each message in the multiple messages are matched with a field library; and information of message 2 is obtained based on the message in the multiple messages that successfully matches the field library.

[0173] It should be further explained that the purpose of the above implementation method is to find a message including device information among multiple messages. Therefore, the key field in the message is first determined. The key field is the field that appears more frequently in message 1. Then, the key field is matched with the field library. The fields in the field library describe the commonalities in the device information. Therefore, if the match is successful, it means that the key field is the field that describes the device information, so it can be determined that the message including the key field is a message carrying device information.

[0174] Optionally, after obtaining multiple messages, key fields in these messages can be extracted based on data mining algorithms. For example, natural language processing technologies such as TF-IDF can be used to analyze the text in the messages and extract key fields to obtain key fields such as category, manufacturer, model, etc. that appear in the messages.

[0175] In a possible implementation, the field library includes one or more of the following fields: a name field of a device brand, a name field of a device model, a device category field, or a serial number of a device.

[0176] It should be noted that the fields in the field library describe common features found in device information. For example, the key field for device 1 is A1, indicating that it is a first-generation device in the A series. The key field for device 2 is A2, indicating that it is a second-generation device in the A series. The commonality between A1 and A2 is that they are both A plus a numeric character. The field in the field library is AX, where X represents all possible numeric characters. Therefore, regardless of whether key fields such as A1 and A2 appear in a message, they can be successfully matched with AX in the field library, thus confirming that A1 and A2 are fields describing the device model information. When a new generation of model A devices appears, such as model A70, they can still be matched with the field library and the corresponding detection message can still be generated based on this information. Therefore, this solution can still be applied to the detection of new generation model A devices. This shows that this solution has good scalability for newly detected devices, or unknown devices, and can still be used to detect such devices. Furthermore, in this embodiment of the application, the field library only stores fields such as the device brand name and the device model name, without storing regular expressions or rules for determining device information. It can be seen that the field library in the embodiment of the present application has a small amount of data, which can save memory resources.

[0177] After obtaining message 2, communication device 1 needs to obtain message information of message 1. Specifically, this can be achieved in the following manner:

[0178] In a possible implementation, in response to payload2 including device information of device 1, communication device 1 obtains message information of message 1 according to information of message 2; communication device 1 generates detection message 1 according to the message information of message 1.

[0179] In one possible implementation, communication device 1 obtains message information of message 1 based on the source IP address of message 2 and the destination IP address of message 2, wherein the information of message 2 includes: the source IP address of message 2 and the destination IP address of message 2, the source IP address of message 2 is the IP address of device 1, and the destination IP address of message 2 is the IP address of device 2;

[0180] In one possible implementation, the communication device 1 obtains the message information of the message 1 based on the source MAC address of the message 2 and the destination MAC address of the message 2, wherein the information of the message 2 includes: the source MAC address of the message 2 and the destination MAC address of the message 2, the source MAC address of the message 2 is the MAC address of the device 1, and the destination MAC address of the message 2 is the MAC address of the device 2.

[0181] In the above implementation, message 1 is a message sent from device 2 to device 1, and message 2 is a message sent from device 1 to device 2. The source IP address of message 1 is the destination IP address of message 2, and the destination IP address of message 1 is the source IP address of message 2. Therefore, the source IP address and destination IP address of message 1 can be determined based on message 2. When communication device 1 obtains multiple messages, message 1 can be found from these multiple messages based on the source IP address and the destination IP address. Similarly, communication device 1 can also obtain message 2 based on the source MAC address and destination MAC address of message 1, or obtain message 2 based on the source port and destination port of message 1. In addition, the protocol types of message 1 and message 2 are also the same, and message 2 can be obtained in combination with the protocol type of message 1.

[0182] In addition to generating the probe message 1, the communication device 1 may also generate other probe messages to cope with situations where the probe message 1 is invalid, specifically, including the following situations:

[0183] In addition to generating a detection message 1 from a learning message 1, the communication device 1 can also generate a detection message 2 from a learning message 1. Specifically:

[0184] Optionally, the communication device 1 sends a detection message 2 to the device 1 , where the detection message 2 includes a port number 1 , a protocol type 1 and a payload 1 .

[0185] Optionally, the destination IP address of the detection message 2 is the destination IP address of the message 1 or the IP address of the device to be detected.

[0186] Optionally, the destination MAC address of the detection message 2 is the destination MAC address of the message 1 or the MAC address of the device to be detected.

[0187] The communication device 1 can also obtain other messages sent by the device 2 to the device 1, and generate the detection message 3 by learning the message. Specifically:

[0188] In one possible implementation, the communication device 1 obtains a message 4 sent by the device 2 to the device 1, wherein the message 4 includes a port number 2, a protocol type 2, and a payload 3; the communication device 1 sends a probe message 3 to the device 1, wherein the probe message 3 includes the port number 2, the protocol type 2, and the payload 3.

[0189] Optionally, the destination IP address of the detection message 3 is the destination IP address of the message 4 or the IP address of the device to be detected.

[0190] Optionally, the destination MAC address of the detection message 3 is the destination MAC address of the message 4 or the MAC address of the device to be detected.

[0191] It can be understood that the detection message 1 is similar to the message 1 sent by the device 2 to the device 1, and the detection message 3 is similar to the message 4 sent by the device 2 to the device 1. Since the information carried in the message 4 may be different from that carried in the message 2, the detection message 3 may also be different from the detection message 1. This increases the diversity of the detection messages in this scheme, making this scheme applicable to more diverse scenarios.

[0192] The communication device 1 can also obtain messages from other devices during communication and generate detection messages by learning the messages. Specifically:

[0193] In one possible implementation, the communication device 1 obtains a message 5 sent by the device 4 to the device 3, wherein the message 5 includes the port number 3, the protocol type 3 and the payload 4; the communication device 1 sends a probe message 4 to the device 3, wherein the probe message 4 includes the port number 3, the protocol type 3 and the payload 4.

[0194] In this solution, since device 4 may belong to a different category than device 2, and device 3 may also belong to a different category than device 1, the detection message obtained by learning messages of devices of different categories can be applied to the detection of devices of different categories.

[0195] Optionally, the destination IP address of the detection message 4 is the destination IP address of the message 5 or the IP address of the device to be detected.

[0196] Optionally, the destination MAC address of the detection message 4 is the destination MAC address of the message 5 or the MAC address of the device to be detected.

[0197] Optionally, device 3 can be the same device as device 1, or the IP addresses of device 3 and device 1 belong to the same IP network segment. When device 3 and device 1 are the same device, messages sent to device 1 by devices other than device 2 can be obtained, and probe message 4 can be generated based on these messages. Device 4 can be the same device as device 2, or the IP addresses of device 4 and device 2 belong to the same IP network segment. When device 4 and device 2 are the same device, messages sent to devices other than device 1 by device 2 can be obtained, and probe message 4 can be generated based on these messages. It is understandable that it is only necessary to ensure that there is a difference between device 4 and device 2, or that there is a difference between device 3 and device 1, and it is not necessary to ensure that there is a difference between device 4 and device 2, or between device 3 and device 1.

[0198] In method 100, the detection message 1 is obtained by learning the message 1 sent by device 2 to device 1. Specifically, the port number, protocol type and payload of the detection message 1 are the same as the port number, protocol type and payload of the message 1. Since device 2 can communicate with device 1 through message 1, device 1 must support the protocol on which message 1 is based, and also support the protocol on which the detection message 1 is based. Therefore, the embodiment of the present application only needs to learn message 1 to generate the detection message 1 and send the detection message 1, without having to send a corresponding detection message to the device to be detected based on each possible protocol type, thereby reducing the number of interactions with the device to be detected, thereby reducing network pressure.

[0199] In order to solve the problem that the device to be detected cannot be detected when the IP address of the device to be detected is unknown, an embodiment of the present application provides a detection method 200, which can be applicable to the scenario shown in Figure 1. When the method 200 is applied to the scenario shown in Figure 1, the device 2 in the method 200 can be, for example, the communication device 101 shown in Figure 1, the device 1 in the method 200 can be, for example, the communication device 101 shown in Figure 1, and the communication device 2 in the method 200 can be, for example, the notebook 102 or the switch 3 shown in Figure 1. Among them, in the method 200, the detection of the device to be detected is achieved by obtaining the IP segment to which the IP address of the device to be detected belongs and sending a detection message to the IP segment. In the method 200, detection can be completed by only knowing the IP segment to which the device to be detected belongs. Even if the IP address of the device to be detected is unknown, the device to be detected can still be detected.

[0200] It should be noted that the method 200 may use the detection message learned in the method 100 to detect the device to be detected. The method 200 may also use the detection message obtained by other means to detect the device to be detected, and this application does not limit this.

[0201] Please refer to Figure 4, which is a flow chart of a communication device identification method 200 provided in an embodiment of the present application. As shown in Figure 4, the method 200 provided in an embodiment of the present application includes the following steps 401 to 404.

[0202] Step S401: The communication device 2 receives the network segment to which the IP address of the device to be detected belongs;

[0203] It should be noted that the communication device 2 may be the communication device 1 in method 100, that is, the communication device 1 not only learns the detection message 1 online but also detects the device to be detected using the detection message 1. The communication device 2 may also be different from the communication device 1 in method 100. In this case, the detection message 1 of the communication device 2 may be sent by the communication device 1 or by another device.

[0204] It should be noted that the above-mentioned probe message 2 is not the same as the probe message 1 in method 100. The communication device will send a new message to the device to be detected. The reason why the probe message 1 is still used here to represent the probe message is that the probe message 1 in this stage contains the same content as the probe message 1 in the online learning stage of the probe message.

[0205] It should be noted that this solution can also obtain the IP address of the device to be detected. Optionally, the communication device 2 can receive the IP address of the device to be detected and then send a detection message 1 to the device to be detected. Specifically, the communication device 2 can use the IP address as the target IP address of the detection message 1, thereby being able to send the detection message 1 to the device to be detected.

[0206] Step S402: Communication device 2 sends a probe message 1 to the network segment. The port number, protocol type, and payload of the probe message 1 are the same as those of the message 1 sent by device 2 to device 1.

[0207] The protocols based on the above detection messages also have multiple implementation methods:

[0208] In a possible implementation, the detection message 1 and the message 1 are both protocol 1 messages, and the device to be detected and the device 1 both support protocol 1.

[0209] In another possible implementation, the detection message 1 is a protocol 1 message, the message 1 is a protocol 2 message, the device to be detected supports the protocol 1, and the device 1 supports both the protocol 1 and the protocol 2.

[0210] In the first implementation, it is understood that since device 2 can communicate with device 1 via message 1, device 1 must support the protocol underlying message 1. Therefore, probe message 1 can be generated based on the protocol format of message 1. In this case, device 1 must also support the protocol underlying probe message 1, enabling communication with device 1 via probe message 1.

[0211] As for the detection message 1 and the specific protocol based on the message 1, it can be implemented in the following ways:

[0212] In a possible implementation, the protocol 1 includes: ONVIF, SIP, mDNS protocol, or a protocol defined by the manufacturer of the device 1 and the device to be detected.

[0213] In a possible implementation, detection message 1 is a message based on protocol 1, message 1 is a message based on protocol 2, the device to be detected supports protocol 1, and device 1 supports both protocol 1 and protocol 2.

[0214] In a possible implementation, protocol 1 includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by the manufacturers of device 1 and the device to be detected.

[0215] For detailed description of the above implementation, please refer to the description of the protocol of the detection message 1 and the protocol of the message 1 in method 100.

[0216] Optionally, protocol 1 may further include: TCP, UDP, IP or HTTP.

[0217] Since this solution does not limit the protocol type of message 1 to TCP / IP or other protocols that only support point-to-point communication, message 1 can also be based on a protocol that supports multicast or broadcast. For example, SIP, the destination IP address of detection message 1 can also be multiple IP addresses. Specifically:

[0218] In a possible implementation, the destination IP address of the detection message 1 is the destination IP address of the message 1 or each IP address included in the above network segment.

[0219] It is understood that when the destination IP address of probe message 1 is the same as that of message 1, probe message 1 can be sent to device 1, and the validity of probe message 1 can be determined based on message 2 sent by device 1. When probe message 1 is the IP address of the device to be detected, probe message 1 can be sent to the device to be detected, thereby detecting the device to be detected.

[0220] In a possible implementation, the destination MAC address of the detection message 1 is the destination MAC address of the message 1 or the MAC address of the device to be detected.

[0221] In addition to sending the detection message 1, the communication device 2 can also send other detection messages to the device to be detected:

[0222] In one possible implementation, the communication device 2 sends the detection message 2 to the network segment, and the port number, protocol type and payload of the detection message 2 are the same as those of the message 1 sent by the device 2 to the device 1; the communication device 1 receives the message 3 sent by the device to be detected; and the device information of the device to be detected is parsed from the message 3.

[0223] In one possible implementation, the communication device 2 sends the detection message 2 to the network segment, and the port number, protocol type and payload of the detection message 2 are the same as the port number, protocol type and payload of the message 4 sent by the device 2 to the device 1; the communication device 1 receives the message 5 sent by the device to be detected; and parses the device information of the device to be detected from the message 5.

[0224] In one possible implementation, the communication device 2 sends the detection message 3 to the network segment, and the port number, protocol type and payload of the detection message 4 are the same as the port number, protocol type and payload of the message 6 sent by the device 3 to the device 4; the communication device 1 receives the message 7 sent by the device to be detected; and parses the device information of the device to be detected from the message 7.

[0225] When communication device 2 receives multiple probe messages, optionally, if the category of the device to be detected is known, the multiple probe messages are first divided according to the applicable category. Then, a probe message corresponding to the category of the device to be detected is matched and sent. For example, if the device to be detected is a device from Manufacturer A, a probe message suitable for detecting Manufacturer A's device is matched and sent to the device to be detected. Alternatively, if the category of the device to be detected is unknown, all learned probe messages are sent to the device to be detected.

[0226] Step S403: the communication device 2 receives the message 2 sent by the device to be detected;

[0227] It is understandable that when the communication device 2 sends multiple detection messages, such as the detection message 1 and the detection message 2 mentioned above, the communication device 2 may receive multiple messages 2. In addition, when the communication device 2 does not receive the message 2 sent by the device to be detected, the communication device 2 may send another detection message to the device to be detected.

[0228] Step S404: the communication device 2 parses the device information of the device to be detected from the message 2.

[0229] Optionally, the above device information includes but is not limited to: the manufacturer of the device, the model of the device or the type of the device.

[0230] It should be noted that there is a field in message 2 for indicating device information. After reading this field, the communication device 2 obtains the device information. The communication device 2 can also use data mining to analyze the text of message 2 to obtain the device information of the device to be detected.

[0231] In this solution, communication device 2 can send a detection message 1 to the network segment to which the IP address of the device to be detected belongs. Even if the specific IP address of the device to be detected is unknown, but only the network segment to which the IP address belongs is known, this solution still detects the device to be detected. This shows that the communication device identification method of this application can broaden the scenarios for device detection.

[0232] For ease of understanding, the above methods 100 and 200 will be introduced below with reference to specific examples.

[0233] Example 1 is a specific example of the communication device 1 in method 100 being a Network Terminal Identification (NTID) module. The NTID in Example 1 is only a specific naming method for describing the function of the online learning detection message. NTID is only an example of a naming method. Other naming methods can also be used to describe the function. NTID and other naming methods are within the scope of protection of this application. The NTID module can be a computer program product. The computer program product can be configured in a network device, such as a switch, or in a terminal device, such as a notebook. Figure 5 is a specific example of the NTID module being configured in a switch. In Figure 5, the NTID module of the switch includes multiple submodules, each of which includes instructions or programs. When the instructions or programs of the submodules run on the processor of the switch, the following operations are implemented:

[0234] Message receiving submodule: receives the message mirrored from the communication device.

[0235] Probe message online learning submodule: performs online learning on mirror messages to generate probe messages.

[0236] The detection message storage submodule stores the detection messages learned by the detection message online learning submodule in the memory of the switch or in an external memory.

[0237] Message sending submodule: sends detection messages.

[0238] Data processing submodule: performs data processing on the messages obtained from the communication device.

[0239] FIG6 is a schematic diagram of Example 1. The specific process in FIG6 includes:

[0240] Step 601: The NTID module mirrors the message from the communication device.

[0241] It should be noted that the communication device includes a terminal device and a network device. The NTID module can receive a message mirrored from the communication device via the message receiving submodule, and then send the message to the detection message online learning submodule or the data processing submodule, so that the detection message online learning submodule or the data processing submodule executes step 602.

[0242] Step 602: The NTID module determines the key fields in each message;

[0243] In step 602, "each message" refers to each message obtained in step 601. In step 602, the NTID module can analyze the text of each message and extract key fields based on a data mining algorithm, such as the TF-IDF algorithm, to obtain key fields such as category, manufacturer, and model that appear in each message.

[0244] Step 603: The NTID module calculates the similarity between the key field and the fields in the field library;

[0245] The key fields in step 603 are the key fields extracted in step 602, and the field library is either a local field library or a cloud-based field library. The field library includes fields that describe common device information, such as a computer model number plus numeric characters. The NTID module uses a similarity algorithm to calculate the similarity between the key fields and the fields in the field library. If the similarity is above a threshold, the key field is considered to be a field describing device information, and the process continues to step 604. If the similarity is below or equal to the threshold, the field is considered not to be a field describing device information, and the process returns to step 601.

[0246] Step 604: The NTID module reads the message 1 with high similarity and obtains information such as the source IP address and destination IP address of the message 1.

[0247] When the similarity between the key field calculated in step 603 and the field in the field library is higher than the threshold, the message 1 to which the key field belongs is read.

[0248] Step 605: The NTID module obtains message 2 based on the source IP address, destination IP address and other information of message 1;

[0249] Assume that message 1 is a message sent from device A to device B, and message 2 is a message sent from device B to device A. More specifically, the source IP address of message 1 is the address of device A, and the destination IP address is the address of device B. The source IP address of message 2 is the address of device B, and the destination IP address is the address of device A. Therefore, the source IP address and destination IP address of message 2 can be determined based on the source IP address and destination IP address of message 1, and message 2 can be obtained based on the source IP address and destination IP address. Similarly, communication device 1 can also obtain message 2 based on the source MAC address and destination MAC address of message 1, or obtain message 2 based on the source port and destination port of message 1. In addition, the protocol type of message 1 and message 2 is also the same, and message 2 can be obtained based on the protocol type of message 1.

[0250] Step 606: The NTID module generates a detection message;

[0251] After receiving message 2, the NTID module generates a detection message by learning message 2. Specifically, the port number, payload, and protocol type of the detection message are consistent with those of message 2.

[0252] Step 607: The NTID module sends a detection message to the corresponding communication device;

[0253] The “corresponding communication device” in step 607 refers to the communication device that receives message 2 .

[0254] After step 607, the message sent by the corresponding communication device may not be received, that is, step 608 cannot be performed. In this case, the process returns to step 601 and re-learns the detection message.

[0255] Step 608: The NTID module receives the message sent by the corresponding communication device;

[0256] The purpose of steps 607 and 608 is to verify the validity of the probe message. The principle is to send a probe message to the communication device that received message 2. If the message sent by the communication device is received, and the key fields in the message are extracted through algorithms such as data mining, and the key fields are consistent with the key fields determined in step 602, then the probe message can trigger the communication device to send a message containing device information, just like message 2. Therefore, the probe message is valid, and the process continues to step 609. If the message sent by the communication device cannot be received, or the message sent by the communication device does not contain the key fields consistent with those in step 602, then the probe message is invalid, and the process returns to step 601 to re-learn the probe message.

[0257] Step 609: The NTID module stores the detection message, or sends the detection message to other devices.

[0258] After the detection message is verified to be valid through steps 607 and 608, the detection message may be stored in the detection message storage submodule of the NTID, or sent to other devices, such as a communication device that detects the device to be detected.

[0259] After step 609 , the NTID module may repeatedly execute steps 601 to 609 , continuously mirroring new messages from the communication device, and then learning detection messages based on the new messages.

[0260] Example 2

[0261] Example 2 is a specific example in which the communication device 2 in method 200 is an NTID module. The NTID in Example 2 is only a specific naming method for describing the device identification function. NTID is only an example of a naming method. Other naming methods can also be used to describe the function. NTID and other naming methods are within the scope of protection of this application. The NTID module can be a computer program product. The computer program product can be configured in a switch or in a notebook. Figure 7 is a specific example in which the NTID module is configured in a switch. As shown in Figure 7, the NTID module receives a detection message sent by the notebook and detects the device to be detected through the detection message. In Example 2, the NTID module of the switch includes multiple sub-modules, each of which includes instructions or programs. When the instructions or programs of the sub-modules run on the processor of the switch, the following operations are implemented:

[0262] Message receiving submodule: receives the detection message sent by the laptop, and receives the message returned by the device to be detected after sending the detection message to the device to be detected.

[0263] Probe message storage submodule: stores the probe message sent by the laptop in the switch's memory or external memory.

[0264] Message sending submodule: sends detection messages.

[0265] Data processing submodule: processes the messages returned by the detection device.

[0266] FIG8 is a schematic diagram of Example 2. The specific process in FIG8 includes:

[0267] Step 801: The notebook sends a detection message to the NTID module;

[0268] In Example 2, when a laptop learns a probe message using method 100, both the laptop and the communication device used to learn the probe message can be connected to a switch. The switch's NTID module can mirror the messages used by the communication device to the laptop. The laptop learns these messages to obtain a probe message, which it then sends to the NTID module.

[0269] Step 802: The NTID module receives the network segment to which the IP address of the device to be detected belongs;

[0270] The network segment to which the IP address of the device to be detected belongs can be sent to the NTID module by the network management.

[0271] Step 803: The NTID module sends a detection message to the network segment;

[0272] The network segment in step 803 is the “network segment to which the IP address of the device to be detected belongs” in step 802 , and the NTID module can periodically send detection messages to the network segment.

[0273] Step 804: The NTID module receives the message sent by the probe message;

[0274] The switch can divert the messages sent by the device to be detected to the NTID module

[0275] Step 805: The NTID module processes the message to obtain device information of the device to be detected.

[0276] The NTID module may extract device information from the text of the message based on a data mining algorithm, such as the TF-IDF algorithm.

[0277] The above describes the embodiment of the present application from the perspective of the method. The following describes the communication device in the embodiment of the present application from the perspective of specific device implementation.

[0278] Figure 9 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. As shown in Figure 9, communication device 900 includes a receiving module 901, a processing module 902, and a sending module 903. As an example, communication device 900 can implement the functions of communication device 1 in method 100 described above, and thus can also achieve the beneficial effects of method 100 described above.

[0279] Specifically, the processing module 902 is used to obtain information of the first message sent by the second device to the first device, wherein the information of the first message includes a first port number, a first protocol type and a first payload; the receiving module 901 is used to send a first detection message to the first device, wherein the first detection message includes a first port number, a first protocol type and a first payload.

[0280] In one possible implementation, the processing module 902 is further used to obtain information of a second message sent by the first device to the second device, where the information of the second message includes a second payload; when the following conditions are met, the first detection message is a valid message, and the conditions include: after sending the first detection message, a third message sent by the first device is received, and the third message includes the second payload.

[0281] In one possible implementation, the destination IP address of the first detection message is the destination IP address of the first message or the IP address of the device to be detected; and / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

[0282] In one possible implementation, the processing module 902 is further used to obtain information of a fourth message sent by the second device to the first device, wherein the information of the fourth message includes a second port number, a second protocol type, and a third payload; the sending module 903 is further used to send a second detection message to the first device, wherein the second detection message includes a second port number, a second protocol type, and a third payload.

[0283] In one possible implementation, the processing module 902 is further used to obtain information of a fifth message sent by the fourth device to the third device, wherein the information of the fifth message includes a third port number, a third protocol type, and a fourth payload; the sending module 903 is further used to send a third detection message to the third device, wherein the third detection message includes a third port number, a third protocol type, and a fourth payload.

[0284] In one possible implementation, the destination IP address of the first message is a multicast or broadcast IP address or an IP address of the first device;

[0285] In a possible implementation, and / or the destination MAC address of the first message is a multicast or broadcast MAC address or a MAC address of the first device.

[0286] In a possible implementation, the first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

[0287] In a possible implementation, the first detection message is a first protocol message, the first message is a second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

[0288] In a possible implementation, the first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by the manufacturers of the first device and the device to be detected.

[0289] In a possible implementation, the processing module 902 is further configured to mirror the first message from a fifth device, where the fifth device is an intermediate device between the first device and the second device; and obtain information of the first message according to the first message.

[0290] In a possible implementation, the receiving module 901 is further configured to receive information of a second message sent by a fifth device.

[0291] In one possible implementation, the processing module 902 is also used to obtain multiple messages sent by the first device to the second device; match the key fields of each message in the multiple messages with the field library; and obtain information of the second message based on the message in the multiple messages that successfully matches the field library.

[0292] In a possible implementation, the field library includes one or more of the following fields: a name field of a device brand, a name field of a device model, a device category field, or a serial number of a device.

[0293] In a possible implementation, the processing module 902 is further configured to, in response to the second payload including the device information of the first device, obtain the information of the first message according to the information of the second message; and generate a first detection message according to the information of the first message.

[0294] In one possible implementation, the processing module 902 is further used to obtain information of the first message based on the source IP address of the second message and the destination IP address of the second message, wherein the information of the second message includes: the source IP address of the second message and the destination IP address of the second message, the source IP address of the second message is the IP address of the first device, and the destination IP address of the second message is the IP address of the second device; and / or obtain information of the first message based on the source MAC address of the second message and the destination MAC address of the second message, wherein the information of the second message includes: the source MAC address of the second message and the destination MAC address of the second message, the source MAC address of the second message is the MAC address of the first device, and the destination MAC address of the second message is the MAC address of the second device.

[0295] In a possible implementation, the sending module 903 is further used to send a first detection message to the device to be detected; the receiving module 901 is further used to receive a sixth message sent by the device to be detected; and the processing module 902 is further used to parse device information of the device to be detected from the sixth message.

[0296] In a possible implementation, the sending module 903 is further used to send a second detection message to the device to be detected; the receiving module 901 is further used to receive a seventh message sent by the device to be detected; and the processing module 902 is further used to parse the device information of the device to be detected from the seventh message.

[0297] In one possible implementation, the sending module 903 is further used to send a third detection message to the device to be detected; the receiving module 901 is further used to receive an eighth message sent by the device to be detected; and the processing module 902 is further used to parse the device information of the device to be detected from the eighth message.

[0298] As another example, the communication device 900 can implement the functions of the communication device 2 in the above method 200, and thus can also achieve the beneficial effects of the above method 200.

[0299] Specifically, the receiving module 901 is used to receive the network segment to which the IP address of the device to be detected belongs; the sending module 903 is also used to send a first detection message to the network segment, and the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; the receiving module 901 is also used to receive a second message sent by the device to be detected; the processing module 902 is used to parse the device information of the device to be detected from the second message.

[0300] In a possible implementation, the first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

[0301] In a possible implementation, the first detection message is a first protocol message, the first message is a second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

[0302] In a possible implementation, the first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by the manufacturers of the first device and the device to be detected.

[0303] In one possible implementation, the destination IP address of the first detection message is the destination IP address of the first message or each IP address included in the network segment; and / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

[0304] In one possible implementation, the sending module 903 is also used to send a second detection message to the network segment, and the port number, protocol type and payload of the second detection message are the same as the port number, protocol type and payload of the third message sent by the second device to the first device; the receiving module 901 is also used to receive a fourth message sent by the device to be detected; the processing module 902 is also used to parse the device information of the device to be detected from the fourth message.

[0305] In one possible implementation, the sending module 903 is also used to send a third detection message to the network segment, and the port number, protocol type and payload of the third detection message are the same as the port number, protocol type and payload of the fifth message sent by the third device to the fourth device; the receiving module 901 is also used for the sixth message sent by the device to be detected; the processing module 902 is also used to parse the device information of the device to be detected from the sixth message.

[0306] As another implementation example, the communication device 900 can implement the functions of the device to be detected in the method 200, and thus can also achieve the beneficial effects of the above-mentioned method 200.

[0307] Specifically, the receiving module 901 is used to receive a first detection message sent by a third device, and the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; the sending module 903 is used to send a first message to the third device, and the first message includes device information of the device to be detected.

[0308] FIG10 is a schematic diagram of the structure of a communication device 1000 provided in an embodiment of the present application. As shown in FIG10 , the communication device 1000 includes: a processor 1001 and a memory 1002 .

[0309] The memory 1002 is used to store computer-readable instructions; the processor 1001 is used to call the computer-readable instructions and execute all or part of the operations of the above-mentioned method 100 or method 200 according to the instructions of the computer-readable instructions.

[0310] In a specific embodiment, the communication device 1000 may include a communication interface, wherein the memory 1002, the processor 1001 and the communication interface are communicatively connected to each other. The communication interface is used to implement transceiver operations, and the processor 1001 is used to implement operations other than transceiver operations.

[0311] In an embodiment of the present application, the processor may be, for example, but not limited to, any one or more of the following combinations: a central processing unit (CPU), a network processor (NP), a tensor processing unit (TPU), a neural network processing unit (NPU), an application-specific integrated circuit (ASIC), a programmable logic device (PLD). The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof. The processor may refer to one processor or may include multiple processors. The processor may include one or more processing cores, and the processor executes various functional applications and data processing by running a computer program. The processor may be connected to the memory and the communication interface via a communication bus.

[0312] In an embodiment of the present application, the memory may include a volatile memory, such as a random access memory (RAM). The memory may also include a non-volatile memory, such as a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD). The memory may also include a combination of the above-mentioned types of memory. The memory may refer to one memory or may include multiple memories. In a specific embodiment, computer-readable instructions are stored in the memory, and the computer-readable instructions include multiple software modules, such as the receiving module 901, the processing module 902, and the sending module 903 described above. After executing each software module, the processor may perform corresponding operations according to the instructions of each software module. In this embodiment, the operation performed by a software module actually refers to the operation performed by the processor according to the instructions of the software module. After the processor executes the computer-readable instructions in the memory, it may perform all or part of the operations that the communication device can perform according to the instructions of the computer-readable instructions.

[0313] In an embodiment of the present application, there may be multiple communication interfaces, each used to communicate with other devices. The communication interface may include a wired communication interface, a wireless communication interface, or a combination thereof. The wired communication interface may be, for example, an Ethernet interface. The Ethernet interface may be an optical interface, an electrical interface, or a combination thereof. The wireless communication interface may be a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof.

[0314] In the above embodiments, all or part of the embodiments can be implemented by hardware, firmware, or any combination thereof. When software is involved in the specific implementation process, it can be embodied in the form of a computer program product in whole or in part. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital video disc (DVD)), or a semiconductor medium (eg, an SSD).

[0315] The following is an example of the system of the embodiment of the present application.

[0316] An embodiment of the present application further provides a communication system, including: multiple communication devices, which may include, for example, a communication device for implementing part or all of the operations of any of the above methods.

[0317] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.

[0318] In the embodiments of the present application, the terms “first”, “second” and “third” are used for descriptive purposes only and should not be understood as indicating or implying relative importance.

[0319] In this application, the term "and / or" simply describes an association between related objects, indicating that three possible relationships exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally indicates that the related objects are in an "or" relationship.

[0320] The above description is merely an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the concepts and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A method for online learning detection messages, characterized in that: The method comprises: Acquire information of a first message sent by the second device to the first device, wherein the information of the first message includes a first port number, a first protocol type, and a first payload; A first detection message is sent to the first device, where the first detection message includes the first port number, the first protocol type, and the first payload.

2. The method for online learning detection message according to claim 1, characterized in that: The method further comprises: Acquire information of a second message sent by the first device to the second device, where the information of the second message includes a second payload; The first detection message is a valid message when the following conditions are met, and the conditions include: after sending the first detection message, a third message sent by the first device is received, and the third message includes the second payload.

3. The method for online learning detection message according to claim 1 or 2, characterized in that: The destination IP address of the first detection message is the destination IP address of the first message or the IP address of the device to be detected; And / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

4. The method for online learning detection message according to any one of claims 1 to 3, characterized in that: The method further comprises: Acquire information of a fourth message sent by the second device to the first device, wherein the information of the fourth message includes a second port number, a second protocol type, and a third payload; A second detection message is sent to the first device, where the second detection message includes the second port number, the second protocol type, and the third payload.

5. The method for online learning detection message according to any one of claims 1 to 4, characterized in that: The method further comprises: Acquire information of a fifth message sent by the fourth device to the third device, wherein the information of the fifth message includes a third port number, a third protocol type, and a fourth payload; Send a third detection message to the third device, where the third detection message includes the third port number, the third protocol type, and the fourth payload.

6. The method for online learning detection message according to any one of claims 1 to 5, characterized in that: The destination IP address of the first message is a multicast or broadcast IP address or an IP address of the first device; And / or the destination MAC address of the first message is a multicast or broadcast MAC address or the MAC address of the first device.

7. The method for online learning detection messages according to any one of claims 1 to 6, characterized in that: The first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

8. The method for online learning detection messages according to any one of claims 1 to 6, characterized in that: The first detection message is the first protocol message, the first message is the second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

9. The method for online learning detection message according to claim 7 or 8, characterized in that: The first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by the manufacturers of the first device and the device to be detected.

10. The method for online learning detection message according to any one of claims 1 to 9, characterized in that: The obtaining information of the first message sent by the second device to the first device includes: mirroring the first message from a fifth device, where the fifth device is an intermediate device between the first device and the second device; The information of the first message is obtained according to the first message.

11. The method for online learning detection message according to any one of claims 1 to 10, characterized in that: The acquiring information of the second message sent by the first device to the second device includes: Receive information of the second message sent by the fifth device.

12. The method for online learning detection message according to any one of claims 1 to 11, characterized in that: The acquiring information of the second message sent by the first device to the second device includes: Acquire multiple messages sent by the first device to the second device; Matching a key field of each message in the plurality of messages with a field library; The information of the second message is obtained according to the message that successfully matches the field library among the multiple messages.

13. The method for online learning detection message according to claim 12, characterized in that: The field library includes one or more of the following fields: a name field of a device brand, a name field of a device model, a device category field, or a serial number of a device.

14. The method for online learning detection message according to any one of claims 2 to 13, characterized in that: Before sending the first detection message, the method further includes: In response to the second payload including the device information of the first device, acquiring the information of the first message according to the information of the second message; Generate the first detection message according to the information of the first message.

15. The method for online learning detection message according to claim 14, characterized in that: The acquiring the information of the first message according to the information of the second message includes: acquiring information of the first message according to the source IP address of the second message and the destination IP address of the second message, wherein the information of the second message includes: the source IP address of the second message and the destination IP address of the second message, the source IP address of the second message is the IP address of the first device, and the destination IP address of the second message is the IP address of the second device; and / or The information of the first message is obtained according to the source MAC address of the second message and the destination MAC address of the second message, wherein the information of the second message includes: the source MAC address of the second message and the destination MAC address of the second message, the source MAC address of the second message is the MAC address of the first device, and the destination MAC address of the second message is the MAC address of the second device.

16. The method for online learning detection message according to any one of claims 1 to 15, characterized in that: After sending the first detection message to the first device, the method further includes: Sending the first detection message to the device to be detected; Receiving a sixth message sent by the device to be detected; The device information of the device to be detected is parsed from the sixth message.

17. The method for online learning detection message according to any one of claims 4 to 16, characterized in that: After sending the second detection message to the first device, the method further includes: Sending the second detection message to the device to be detected; Receiving a seventh message sent by the device to be detected; The device information of the device to be detected is parsed from the seventh message.

18. The method for online learning detection message according to any one of claims 5 to 17, characterized in that: After sending the third detection message to the third device, the method further includes: Sending the third detection message to the device to be detected; Receiving an eighth message sent by the device to be detected; The device information of the device to be detected is parsed from the eighth message.

19. A method for identifying a communication device, characterized in that: The method comprises: Receive the network segment to which the IP address of the device to be detected belongs; Sending a first detection message to the network segment, wherein the port number, protocol type, and payload of the first detection message are the same as the port number, protocol type, and payload of the first message sent by the second device to the first device; Receiving a second message sent by the device to be detected; The device information of the device to be detected is parsed from the second message.

20. The communication device identification method according to claim 19, characterized in that: The first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

21. The communication device identification method according to claim 19, characterized in that: The first detection message is the first protocol message, the first message is the second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

22. The communication device identification method according to claim 20 or 21, characterized in that: The first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by the manufacturers of the first device and the device to be detected.

23. The communication device identification method according to any one of claims 19 to 22, characterized in that: The destination IP address of the first detection message is the destination IP address of the first message or each IP address included in the network segment; And / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

24. The communication device identification method according to any one of claims 19 to 23, characterized in that: The method further comprises: Sending the second detection message to the network segment, the port number, protocol type and payload of the second detection message being the same as the port number, protocol type and payload of the third message sent by the second device to the first device; Receiving a fourth message sent by the device to be detected; The device information of the device to be detected is parsed from the fourth message.

25. The communication device identification method according to any one of claims 19 to 24, characterized in that: The method further comprises: Sending the third detection message to the network segment, the port number, protocol type and payload of the third detection message being the same as the port number, protocol type and payload of the fifth message sent by the third device to the fourth device; Receiving a sixth message sent by the device to be detected; The device information of the device to be detected is parsed from the sixth message.

26. A message sending method, characterized in that: The method comprises: Receive a first detection message sent by a third device, where the port number, protocol type, and payload of the first detection message are the same as the port number, protocol type, and payload of the first message sent by the second device to the first device; A first message is sent to the third device, where the first message includes device information of the device to be detected.

27. A communication device, characterized in that: include: Communication interfaces and processors; The communication interface and the processor perform the method of any one of claims 1 to 18.

28. A communication device, characterized in that: include: Communication interfaces and processors; The communication interface and the processor perform the method of any one of claims 19 to 25.

29. A communication device, characterized in that: include: Communication interfaces and processors; The communication interface and the processor perform the method of claim 26.

30. A communication device, characterized in that: include: A processing unit, configured to obtain information of a first message sent by a second device to a first device, wherein the information of the first message includes a first port number, a first protocol type, and a first payload; A transceiver unit is used to send a first detection message to the first device, where the first detection message includes the first port number, the first protocol type and the first payload.

31. The device according to claim 30, characterized in that The processing unit is further configured to obtain information of a second message sent by the first device to the second device, where the information of the second message includes a second payload; The first detection message is a valid message when the following conditions are met, and the conditions include: after the transceiver unit sends the first detection message, a third message sent by the first device is received, and the third message includes the second payload.

32. The device according to claim 30 or 31, characterized in that The destination IP address of the first detection message is the destination IP address of the first message or the IP address of the device to be detected; And / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

33. The device according to any one of claims 30 to 32, characterized in that The processing unit is further configured to obtain information of a fourth message sent by the second device to the first device, wherein the information of the fourth message includes a second port number, a second protocol type, and a third payload; The transceiver unit is further configured to send a second detection message to the first device, where the second detection message includes the second port number, the second protocol type and the third payload.

34. The device according to any one of claims 30 to 33, characterized in that The processing unit is further configured to obtain information of a fifth message sent by the fourth device to the third device, wherein the information of the fifth message includes a third port number, a third protocol type, and a fourth payload; The transceiver unit is further configured to send a third detection message to the third device, wherein the third detection message includes the third port number. The third protocol type and the fourth payload.

35. The device according to any one of claims 30 to 34, characterized in that The destination IP address of the first message is a multicast or broadcast IP address or the IP address of the first device; and / or the destination MAC address of the first message is a multicast or broadcast MAC address or the MAC address of the first device.

36. The device according to any one of claims 30 to 35, characterized in that The first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

37. The device according to any one of claims 30 to 35, characterized in that The first detection message is the first protocol message, the first message is the second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

38. The device according to claim 36 or 37, characterized in that The first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by the manufacturers of the first device and the device to be detected.

39. The device according to any one of claims 30 to 38, characterized in that The processing unit is further configured to mirror the first message from a fifth device, where the fifth device is an intermediate device between the first device and the second device; The information of the first message is obtained according to the first message.

40. The device according to any one of claims 30 to 39, characterized in that The transceiver unit is further used to receive information of the second message sent by the fifth device.

41. The device according to any one of claims 30 to 40, characterized in that The processing unit is further used to obtain multiple messages sent by the first device to the second device; Matching a key field of each message in the plurality of messages with a field library; The information of the second message is obtained according to the message that successfully matches the field library among the multiple messages.

42. The device according to claim 41, characterized in that The field library includes one or more of the following fields: a name field of a device brand, a name field of a device model, a device category field, or a serial number of a device.

43. The device according to any one of claims 31 to 42, characterized in that The processing unit is further configured to, in response to the second payload including the device information of the first device, acquire the information of the first message according to the information of the second message; Generate the first detection message according to the information of the first message.

44. The device according to claim 43, characterized in that The processing unit is further used to obtain information of the first message according to the source IP address of the second message and the destination IP address of the second message, wherein the information of the second message includes: the source IP address of the second message and the destination IP address of the second message, the source IP address of the second message is the IP address of the first device, and the destination IP address of the second message is the IP address of the second device; and / or The information of the first message is obtained according to the source MAC address of the second message and the destination MAC address of the second message, wherein the information of the second message includes: the source MAC address of the second message and the destination MAC address of the second message, the source MAC address of the second message is the MAC address of the first device, and the destination MAC address of the second message is the MAC address of the second device.

45. The device according to any one of claims 30 to 44, characterized in that The transceiver unit is further configured to send the first detection message to the device to be detected; Receiving a sixth message sent by the device to be detected; The processing unit is further configured to parse the device information of the device to be detected from the sixth message.

46. ​​The device according to any one of claims 33 to 45, characterized in that The transceiver unit is further configured to send the second detection message to the device to be detected; Receiving a seventh message sent by the device to be detected; The processing unit is further configured to parse the device information of the device to be detected from the seventh message.

47. The device according to any one of claims 34 to 46, characterized in that The transceiver unit is further configured to send the third detection message to the device to be detected; Receiving an eighth message sent by the device to be detected; The processing unit is further configured to parse the device information of the device to be detected from the eighth message.

48. A communication device, characterized in that: include: A transceiver unit, used for receiving the network segment to which the IP address of the device to be detected belongs; Sending a first detection message to the network segment, wherein the port number, protocol type, and payload of the first detection message are the same as the port number, protocol type, and payload of the first message sent by the second device to the first device; Receiving a second message sent by the device to be detected; A processing unit is used to parse the device information of the device to be detected from the second message.

49. The device according to claim 48, characterized in that The first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

50. The device according to claim 48, characterized in that The first detection message is the first protocol message, the first message is the second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

51. The device according to claim 49 or 50, characterized in that The first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by the manufacturers of the first device and the device to be detected.

52. The device according to any one of claims 48 to 51, characterized in that The destination IP address of the first detection message is the destination IP address of the first message or each IP address included in the network segment; And / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

53. The device according to any one of claims 48 to 52, characterized in that The transceiver unit is further used to send the second detection message to the network segment, the port number, protocol type and payload of the second detection message are the same as the port number, protocol type and payload of the third message sent by the second device to the first device; Receiving a fourth message sent by the device to be detected; The processing unit is further configured to parse the device information of the device to be detected from the fourth message.

54. The device according to any one of claims 48 to 53, characterized in that The processing unit is further configured to send the third detection message to the network segment, wherein the port number, protocol type and payload of the third detection message are the same as the port number, protocol type and payload of the fifth message sent by the third device to the fourth device; Receiving a sixth message sent by the device to be detected; The device information of the device to be detected is parsed from the sixth message.

55. A communication device, characterized in that: include: A transceiver unit, configured to receive a first detection message sent by a third device, wherein the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; A first message is sent to the third device, where the first message includes device information of the device to be detected.

56. A computer program product comprising instructions, characterized in that When a computer runs the computer program product, the computer is caused to perform the method according to any one of claims 1 to 26.

57. A communication system, characterized in that: The system comprises the communication device of any one of claims 27 or 30 to 47, the communication device of any one of claims 28 or 48 to 54, and the communication device of claim 29 or 55.

Citation Information

Patent Citations

  • Identification method of communication device and related device

    CN120034469A

  • Terminal asset identification method and device, and computer readable storage medium

    CN111447089A

  • Equipment identification method and device, equipment and storage medium

    CN112787875A

  • Industrial asset detection method, equipment and device

    CN113240258A

  • Network asset detection method and device, electronic equipment and storage medium

    CN114422387A