Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

73 results about "Deep packet inspection" patented technology

Deep packet inspection (DPI) is a type of data processing that inspects in detail the data being sent over a computer network, and usually takes action by blocking, re-routing, or logging it accordingly. Deep packet inspection is often used to ensure that data is in the correct format, to check for malicious code, eavesdropping and internet censorship among other purposes. There are multiple headers for IP packets; network equipment only needs to use the first of these (the IP header) for normal operation, but use of the second header (such as TCP or UDP) is normally considered to be shallow packet inspection (usually called stateful packet inspection) despite this definition.

Dynamic access blocking method based on zero trust

The invention relates to the technical field of network security, in particular to a dynamic access blocking method based on zero trust. Comprising the following steps: step 1, collecting whole network flow data in real time in a bypass monitoring mode through a flow mirroring function of a network switch, performing deep packet inspection analysis on the collected original flow data, and extracting network flow characteristic parameters; 2, maintaining a dynamic identity information base; 3, performing real-time behavior analysis on each network session; 4, according to the risk assessment result and the real-time security context, generating a dynamic access control strategy based on a minimum permission principle; 5, implementing access control at the network execution point; and 6, continuously monitoring the network flow and the strategy execution effect, collecting feedback data, optimizing the risk assessment model and the strategy generation algorithm based on the feedback data, and forming closed-loop control. By dynamically updating the identity and asset information, the system can identify new assets or changes in real time, so that the adaptability and response capability of a network environment are improved.
Owner:SHANDONG NETWORK SECURITY TECHNOLOGY CO LTD

Dynamic resource optimal configuration method for electric power communication network

The invention discloses a dynamic resource optimal configuration method for an electric power communication network, and belongs to the technical field of electric power system communication. The problems of low communication resource utilization rate and poor real-time response in the existing electric power communication are solved, the communication resources of physical network equipment are acquired through a network management system, and network operation state data and traffic flow characteristics are acquired in real time by utilizing a network probe or NETCONF / YANG; the method comprises the following steps: identifying service flows flowing into a communication network by adopting a deep packet inspection technology, classifying the service flows according to security partitions of power services, and mapping different types of service flows to different service levels; a quantitative QoS demand template is established for each type of services; and on the basis of the network operation state data, the service flow characteristics and the QoS demand template, constructing a multi-objective optimization model which takes guarantee of the service quality of key services as a highest priority objective, and solving by adopting an optimization algorithm to obtain an optimal resource allocation strategy. The method is suitable for optimal configuration of dynamic resources of the power communication network.
Owner:国网黑龙江省电力有限公司信息通信公司

Center position determination method and device and electronic equipment

The invention discloses a central position determination method and apparatus, and an electronic device. The method comprises the following steps: on the basis of deep packet inspection signaling data of an operator, determining feature data of a service cell, the deep packet inspection signaling data at least comprising a user identifier, a service cell identifier and service occurrence time, and the feature data at least comprising stay durations of different users in different service cells; based on the feature data, performing clustering processing on the service cells to obtain a plurality of first clustering results; performing clustering processing on the physical position of the service cell in each first clustering result to obtain a plurality of second clustering results; and determining the central point of the second clustering result according to the mean value of the second clustering result, and determining the position information of the central point. The technical problem that high-precision and low-cost data support cannot be provided for public services due to the fact that the center position of the area cannot be efficiently and accurately determined in the related technology is solved.
Owner:CHINA TELECOM CORP LTD

Lightweight encryption method and system for industrial real-time data stream

The invention relates to the technical field of industrial internet security communication, and discloses a lightweight encryption method and system for an industrial real-time data stream, and the method comprises the following steps: intercepting an original data packet, and carrying out the deep packet detection to extract a network layer quintuple and application layer metadata; matching an optimal strategy in a strategy rule set according to the feature vector and generating a scheduling instruction; in response to the instruction, calling a corresponding pre-compilation password operation pipeline to carry out differential encryption processing on the load; and constructing a fixed-length security policy head containing the algorithm template identifier, and packaging and sending the fixed-length security policy head. According to the invention, task fragmentation is carried out by using a consistent Hash technology so as to ensure processing order-preserving. By adopting a lightweight message structure without handshake negotiation and a multi-level strategy scheduling mechanism, content-based fine-grained security protection is realized, and the communication requirements of low delay and high certainty are met while the security of industrial control data is ensured.
Owner:MAINTENANCE & TEST CENTRE CSG EHV POWER TRANSMISSION CO

Data leakage real-time blocking method fusing micro-isolation strategy and context awareness

The invention relates to the technical field of network security, and discloses a data leakage real-time blocking method fusing a micro-isolation strategy and context awareness. According to the method, a micro-isolation strategy engine based on a data sensitivity level is constructed, a logic security domain is defined, and an independent access control rule is configured; collecting a network data flow in real time, identifying sensitive data by using a deep packet detection technology, and extracting context information; dynamically analyzing and generating risk metadata, calculating a real-time risk index, and establishing a behavior baseline model to detect behavior deviation; in combination with behavior deviation, a risk index and a data operation type, an access control rule is adaptively decided and dynamically updated, a high-risk or unauthorized data transmission session is blocked in real time, and the data leakage protection capability is improved.
Owner:JIANGSU MR ZHI INFORMATION TECH CO LTD

Malicious message quarantine systems for enhanced security via deep packet inspection

Systems and methods receive, by an internet provider, a network traffic analysis subscription request to screen incoming network traffic using a DPI protocol, the network traffic including data messages from external parties to a plurality of recipient devices, the DPI protocol being configured to detect malicious code by examining contents of data packets as well as a packet header of the data packets and predict that a source of the data packets is likely a fraudulent source, the network traffic analysis subscription request identifying a plurality of subscribed devices. Incoming network traffic directed to the subscribed devices is monitored using the DPI protocol at a network gateway. Based on the monitoring, it is determined that a message that includes data packet(s) is coming from a source predicted to be fraudulent and a screening action is performed to quarantine the message.
Owner:TRUIST BANK

Abnormal traffic identification method, system and device based on deep packet inspection, and medium

The invention discloses an abnormal traffic identification method, system and device based on deep packet inspection, and a medium. The method comprises the following steps: collecting original traffic data in a network through a mirror image port or a probe, obtaining original message data, cleaning and labeling the original message data, and generating a structured data set; performing depth feature extraction on the structured data set to generate a feature vector; training a classification model by using the feature vectors, generating a detection model, analyzing the new flow data through the detection model, and outputting an abnormal probability and grading early warning; positioning an abnormal type according to the abnormal probability and graded early warning, generating a structured report, and linking the safety equipment to execute a blocking operation; and performing incremental training according to the detected feedback data, and updating the detection model. The invention provides an abnormal traffic identification method based on deep packet inspection according to the characteristics of diversified protocol levels and strong concealment and evolution of abnormal behaviors in network traffic.
Owner:YUNNAN POWER GRID CO LTD

Application assurance system having a method of offloading service from an edge device to the cloud

A cloud-based application assurance service system and method using Deep Packet Inspection (DPI) enables Network Elements (NE) to access the cloud-based application assurance service to search a rules / signature database, without impacting latency on network-firewall decisions. Additionally, the application assurance service system distributes the associated mapping of the NE cache's latest contents to neighboring NEs, where a given user might next access the network. The system can recognize applications associated with network traffic and apply firewall rules. Further, the system tracks applications and uses this data to update NE caches periodically, such that NE caches are more likely to store the relevant application signatures in advance. Moreover, a historical user usage matrix is generated to track application use per user, which is used to detect a highly probable user path and transfer mapping to an associated NE.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Systems and methods for hierarchical deep packet inspection for scalable network monitoring and cyber security functions

A system and method for hierarchical network monitoring functions are disclosed. An order of execution for layer functions of a network architecture is determined. The layer functions may be distributed across multiple layers. The layers may include a sensor layer, a federated application layer, and a data lake layer. A machine learning model may be executed at a first layer. The first layer may be the sensor layer.
Owner:NETSCOUT SYSTEMS INC

Tag-based selective packet duplication

Disclosed is technology for selectively determining whether to duplicate a packet based on factors beyond just the application it is associated with. For example, some methods determine a criticality of the packet by reading a tag stored in a header of the packet. The tag can represent a group to which the user is associated with, e.g., the financial department, and assign a criticality score based on that group and in some cases other factors. The criticality score can be measured against a threshold to determine whether duplication should occur in the next hop. The method therefore selectively determines whether to duplicate a packet, thereby avoiding costly overduplication, while also placing this tag in a header of the packet, which can be read easily and without deep packet inspection.
Owner:CISCO TECHNOLOGY INC

A data processing method, device, apparatus, and storage medium

ActiveCN116866066BData packOriginal data
The application discloses a data processing method and device, equipment and storage medium, relates to the technical field of deep packet inspection and data analysis, and comprises the following steps: defining a streaming label rule and a streaming index calculation rule based on an initialized anti-fraud identification model; filtering original data collected by using a deep packet inspection technology, and performing standardization processing on the filtered data; performing real-time index calculation on the standardized data according to the streaming index calculation rule; forwarding the standardized data to a risk calculation and analysis node, so that the risk calculation and analysis node performs real-time risk calculation by using index results corresponding to the standardized data to obtain risk information corresponding to user behaviors existing gambling and fraud risks, and outputs the risk information. The technical scheme of the application realizes second-level early warning of the user behaviors existing gambling and fraud risks, and improves the timeliness and accuracy of gambling and fraud data processing.
Owner:CHINA MOBILE(ZHEJIANG) RESEARCH & INNOVATION INSTITUTE

A power grid dispatching data dynamic perception and protection method based on a commercial secret algorithm

PendingCN122437681AData packData stream
The present application relates to the field of power grid dispatching data security, and more particularly to a power grid dispatching data dynamic perception and protection method based on a commercial secret algorithm. The method captures power grid dispatching network data streams in real time, obtains original service data containing dispatching instructions, measurement data and state information through protocol analysis and deep packet detection; then uses a dynamic data perception engine to identify sensitive data units, and dynamically generates data sensitivity labels according to the business type and the power grid operation state; dynamically matches commercial cryptographic algorithms from the commercial secret algorithm library according to the labels and distributes temporary session keys to generate an encryption strategy; encrypts the sensitive units, adds a security mark containing an algorithm identifier and a key index to the data packet header to form a protected data stream; sends the protected data stream to the target end, updates the session key state and uploads the execution log to the audit center. The present application realizes dynamic, accurate identification and differentiated encryption protection of power grid dispatching sensitive data.
Owner:HAINAN POWER GRID CO LTD

Data caching method and device and storage medium

The invention relates to the technical field of communication, and discloses a data caching method and device and a storage medium, the method comprises the following steps: copying a network flow which flows through a first electronic device and comprises a resource request and return data in real time, the resource request being a request sent by a user to an internet source station through a second electronic device via the first electronic device, the resource request is used for accessing a resource object of the Internet source station, and the return data is data of the resource object returned by the Internet source station to the second electronic equipment through the first electronic equipment based on the resource request; performing deep packet inspection (DPI) analysis on the network traffic to determine features of the network traffic; setting labels for the resource objects according to the features; determining a resource popularity value of the resource object according to the label and the weight corresponding to the label; determining a cache value score of the resource object according to the resource popularity value; and if the cache value score is greater than the current threshold, caching the resource object to a storage device. The utilization rate of the data cached by the storage device is improved.
Owner:BEIJING QIANHAI YANXIANG ELECTRONIC TECHNOLOGY CO LTD

Including packet processing data for deep packet inspection classification rules in a combined lookup table used for packet classification at a network device

Systems and methods for determining whether to perform deep packet inspection (DPI) on packets received at a network device based on shallow packet inspection data are disclosed. Embodiments may include DPI classification data in a combined lookup table that is utilized for shallow packet data based packet classification at a network device. Using the results of lookups in such a combined look table based on received packets, determinations can be made whether to perform DPI on such received packets, and those packets forwarded accordingly.
Owner:ARISTA NETWORKS INC

Modbus hold register process parameter dynamic extraction method and device based on deep packet inspection (DPI)

The invention discloses a modbus hold register process parameter dynamic extraction method and device based on deep packet inspection (DPI), and relates to the technical field of industrial automation communication, and the modbus hold register process parameter dynamic extraction device comprises a flow capture module, a message preprocessing module, a DPI deep analysis module, a parameter mapping and conversion module, an abnormity monitoring module, a data output module and a power supply module. The flow capturing module captures Modbus flow, the message preprocessing module achieves frame segmentation and CRC verification through an FPGA, the DPI deep analysis module filters key function codes and extracts original data, the parameter mapping and conversion module automatically converts the key function codes into actual parameters according to pre-configuration, the abnormity monitoring module achieves threshold and behavior warning, and the data output module supports multi-interface transmission. The device supports passive monitoring and active subscription modes, realizes non-intrusive, low-load and high-precision process parameter extraction, solves the problems that traditional acquisition depends on interfaces, polling is low in efficiency and conversion is easy to make mistakes, and is suitable for industrial automatic production scenes.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD

Data packet hierarchical detection method, system and electronic device

The application discloses a data packet hierarchical detection method, a system and an electronic device, wherein the hierarchical detection method is used when a data packet sent by a terminal or a data packet sent to the terminal is acquired; the current data packet detection level of the terminal is determined; when it is determined that the current data packet detection level of the terminal is a shallow layer detection, shallow layer detection is performed on the data packet; when it is determined that the current data packet detection level of the terminal is a middle layer detection, middle layer detection is performed on the data packet; and when it is determined that the current data packet detection level of the terminal is a deep layer detection, deep layer detection is performed on the data packet. The method can realize data packet detection with different depths according to the data packet detection levels corresponding to the terminals, effectively avoids the problems of high consumption and large delay caused by uniformly using deep packet detection, and is beneficial to improving network throughput, reducing operation and maintenance cost and reducing security policy configuration work.
Owner:SUZHOU MAXNET NETWORK SECURITY TECH CO LTD

Network security area boundary threat mimicry protection method and system

PendingCN121864349Atime-varyingBe differentiatedSecuring communicationNode clusteringPathPing
The invention provides a network security area boundary threat mimicry protection method and system, and relates to the technical field of network security, and the method comprises the steps: extracting a flow quintuple and load features through a deep packet inspection engine; inputting the quantity feature vector set into a graph neural network behavior pattern mining model, decoding to obtain an attacker target asset priority sequence and a potential attack path graph, and generating a dynamic service camouflage fingerprint matrix and a response bait sequence through parameter set mapping; configuration of a migration condition register is completed, and a programmable mimicry service node cluster is constructed; presetting a malicious request induction template in the response bait sequence, performing selective response delay and content tampering operation on an attacker request, and aggregating to generate an attacker tactical technology process feature chain; and driving the genetic algorithm population library to carry out iterative crossover variation to generate a new generation of protection strategy chromosomes. The attack residence time is obviously prolonged, the decoy success rate is improved, and the protection strategy can be automatically evolved according to the attack mode.
Owner:GUIZHOU POWER GRID CO LTD

Inference-based selective flow inspection

Techniques for augmenting deep packet inspection capabilities of a network security device provisioned in a networked computing environment with inference-based flow selection to focus processing resources on network traffic that is likely to be malicious. The network device(s) may receive decryption policies comprising one or more decrypt and / or do not decrypt rules for applying the decryption policy to the network traffic. The network device may receive network traffic associated with a given connection flow through the network between a client device and a workload application, and the network device may determine whether to decrypt or refrain from decrypting the network traffic associated with the network flow based on a risk score that is generated by the network device using connection fingerprints associated with the client device and the workload application, respectively, based on behavioral characteristics of the client device and the workload, respectively.
Owner:CISCO TECHNOLOGY INC

Systems and methods for wireless network management

Disclosed are computerized systems and methods for a decision intelligence (DI)-based framework that automatically and / or dynamically provides mechanisms for managing, optimizing and configuring a WiFi network at a location. The framework provides network management utilizing edge processing capabilities to bridge local WiFi and cloud systems. The framework implements comprehensive device typing through multi-layered analysis combining passive monitoring, deep packet inspection and hybrid deterministic-probabilistic classification methods. State synchronization between local and cloud networks can be achieved through hierarchical data modeling and differential synchronization algorithms. The framework can implement advanced features that include automated channel optimization, QoS management, and security monitoring. The framework incorporates self-healing capabilities using reinforcement learning techniques and maintains operational efficiency through intelligent resource management and workload distribution. The framework can operate autonomously while requiring minimal cloud connectivity, featuring extensible architecture through a plugin system that enables adaptation to evolving network requirements while maintaining stable operation of existing capabilities.
Owner:PLUME DESIGN INC

Network interface card testing method and apparatus

The application discloses a network interface card testing method and device, and relates to the technical field of computer network testing, and comprises the following steps: generating mixed traffic simulating a real network environment dynamically through an intelligent traffic generation engine; performing all-around performance measurement from a physical layer to an application layer by using a full-stack performance analysis framework, and dynamically generating and optimizing test cases; constructing a virtualized test environment, and inputting the test cases into the virtualized test environment for parallel testing; and automatically generating a test report containing problem diagnosis suggestions, so that the technical problems in the prior art, such as low test efficiency and automation degree of network card testing technology, great limitation of test scenes, difficulty in effectively analyzing data packet contents, serious waste of hardware resources and difficulty in fully verifying compatibility, are solved, and the technical effect that the performance, stability and reliability of a network card are comprehensively tested through intelligent traffic generation and deep packet inspection technology is achieved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Anomaly detection method, anomaly detection device, and recording medium

An anomaly detection method is performed by a higher electronic control unit in an in-vehicle network having a hierarchical structure including a higher network including the higher electronic control unit(s) and a lower network including lower electronic control unit(s). The method includes: collecting flow information including statistical information, for each flow, classified based on header information of each message received at a predetermined observation point in the in-vehicle network; performing anomaly detection based on the flow information; and performing generating, adding, deleting, changing, enabling, or disabling of a DPI rule based on the anomaly detection result. The DPI rule is used in message monitoring by the lower electronic control unit(s). The DPI rule indicates (i) a condition for header information and payload information included in a message, and (ii) processing to be performed when a message satisfying the condition is received.
Owner:PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD

User behavior classification method, device, equipment and storage medium

The application discloses a user behavior classification method and device, equipment and storage medium, the method comprises the following steps: obtaining deep packet inspection data and user behavior traffic data from the terminal equipment of a target user, and obtaining user portrait features and corresponding environment features of the target user; vectorizing the deep packet inspection data and the user behavior traffic data to obtain an access sequence embedding vector and a simulated access feature embedding vector; adaptively discretizing and vectorizing the user portrait features and the environment features to obtain a user portrait feature vector and an environment feature vector; and determining a behavior category of the target user according to the access sequence embedding vector, the simulated access feature embedding vector, the user portrait feature vector and the environment feature vector. The behavior category of the target user can be determined according to the vector obtained after the vectorization of the multi-source features, and the accuracy of the user behavior classification is improved.
Owner:CHINA MOBILE GROUP ZHEJIANG +2

Call bill synthesis method and device, equipment, storage medium and program product

The invention discloses a ticket synthesis method and device, equipment, a storage medium and a program product. The method comprises the following steps: gathering ticket data of all machine rooms in a target area to obtain gathered data; associating messages belonging to the same ticket in the aggregated data according to a preset address rule to obtain asymmetric associated ticket data; and for each hypertext transfer security protocol ticket, backfilling the associated domain name system resolution domain name and alias record field into the hypertext transfer security protocol ticket to obtain a deep packet inspection ticket synthesis result. According to the embodiment of the invention, by integrating the dispersed and one-way network flow data into the complete and two-way associated ticket, and performing association backfilling on the domain name system ticket and the hypertext transfer security protocol ticket to obtain the DPI ticket, network transmission resources can be effectively saved, data packet loss is reduced, the two-way integrity and recognition degree of the ticket are improved, and the success rate of data transmission is improved. And powerful big data basic support is provided for internet content resource operation and the like.
Owner:CHINA MOBILE GRP GUANGDONG CO LTD +1

Deep packet inspection on network devices

Load balancing operations between network devices to perform DPI operations are provided herein. Network devices of a virtualized network device arrangement may load balance network traffic by employing a network link between the network devices to exchange data packets for DPI operations. Further, the network devices may employ dedicated CPUs to offload DPI operations. In this manner, the current techniques may enable preservation of pre-existing networking routing or deterministic routing to be performed on-the-fly by enabling DPI to be performed without constraining network traffic flows to a specified route.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Method and device for detecting and warning fake account, electronic equipment and storage medium

The application relates to a method and device for detecting and warning fake accounts, electronic equipment and a storage medium. The method comprises the following steps: S1, obtaining feature information related to a user account; S2, generating a whitelist of normal website or application access of a user; S3, DPI (Deep Packet Inspection) is used to extract user behavior logs of domain names in the blacklist and the whitelist, wherein user behaviors meeting the feature information of the user account generate risk behavior records and trusted behavior records; S4, cosine similarity algorithm analysis, the cosine similarity algorithm is used to calculate the cosine value of the included angle of two vectors, and a fake account risk threshold is set for the cosine value; and S5, risk warning, implementing warning according to the information of a risk warning table. According to the method, more targeted and effective detection of fake user account behaviors can be initiated actively in the whole Internet range.
Owner:SHANDONG BRANCH OF BEST TONE INFORMATION

Gateway service comprehensive management method and system based on fttr demand

The application relates to the technical field of data processing, and discloses a gateway service comprehensive management method and system based on FTTR demand. The method comprises the following steps: obtaining a room-level FTTR topology mapping table through topology scanning of an optical time domain reflectometer test signal, extracting features of service traffic of each room based on deep packet detection to obtain a room function identification label library, compensating attenuation of corresponding room optical ports by using an optical power meter to obtain an FTTR link quality evaluation matrix, performing bandwidth allocation by using a reinforcement learning algorithm to obtain a room-level QoS strategy configuration set, and obtaining an FTTR gateway service comprehensive management scheme based on MQTT protocol building data interaction. The application improves the intelligent level and resource allocation efficiency of room-level management of the FTTR network. The application improves the real-time performance of optical fiber link quality monitoring and the collaboration of building network management.
Owner:JIAXING HUASHU TV COMM CO LTD

Traffic monitoring method, device, equipment, storage medium and program product

The application provides a traffic monitoring method and device, equipment, storage medium and program product, and relates to the field of communication. The method comprises the following steps: obtaining a plurality of network traffic data samples of a plurality of time periods; the plurality of time periods correspond to the plurality of network traffic data samples one by one; extracting semantic features of the plurality of network traffic data samples by using a first model; extracting time sequence features of the plurality of network traffic data samples by using a second model; clustering the plurality of network traffic data samples according to the semantic features and the time sequence features to obtain network traffic data samples of different categories; and determining abnormal network traffic data samples from the network traffic data samples of different categories. The method is suitable for the network traffic monitoring process. The method is used for solving the problem that the deep packet detection monitoring precision is not high.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Systems and methods for wireless network management

Disclosed are computerized systems and methods for a decision intelligence (DI)-based framework that automatically and / or dynamically provides mechanisms for managing, optimizing and configuring a WiFi network at a location. The framework provides network management utilizing edge processing capabilities to bridge local WiFi and cloud systems. The framework implements comprehensive device typing through multi-layered analysis combining passive monitoring, deep packet inspection and hybrid deterministic-probabilistic classification methods. State synchronization between local and cloud networks can be achieved through hierarchical data modeling and differential synchronization algorithms. The framework can implement advanced features that include automated channel optimization, QoS management, and security monitoring. The framework incorporates self-healing capabilities using reinforcement learning techniques and maintains operational efficiency through intelligent resource management and workload distribution. The framework can operate autonomously while requiring minimal cloud connectivity, featuring extensible architecture through a plugin system that enables adaptation to evolving network requirements while maintaining stable operation of existing capabilities.
Owner:PLUME DESIGN INC

Equipment information identification method based on deep packet inspection

The invention provides an equipment information identification method based on deep packet inspection, and the method comprises the steps: S1, carrying out the deep packet inspection, identification and filtering of an input network data packet based on a preset trusted application rule base through a network intrusion detection engine, and obtaining trusted application traffic; s2, filtering user agent information based on a primary filtering rule in the trusted application traffic, and outputting candidate traffic; s3, for the candidate traffic, performing accurate extraction of equipment information from the whole HTTP protocol message to obtain structured equipment information; and S4, associating the structured equipment information with the corresponding network quintuple information, and outputting a value log file. According to the scheme, double screening is performed through combination of trusted application filtering and UA primary filtering, interference of forged UA and non-standard applications is eliminated from the source, and the accuracy of equipment detection is improved.
Owner:XIAN XINLU NETWORK TECH CO LTD