WO2016078221A1 - 一种标识网内识别用户的方法及系统 - Google Patents

一种标识网内识别用户的方法及系统 Download PDF

Info

Publication number
WO2016078221A1
WO2016078221A1 PCT/CN2015/072131 CN2015072131W WO2016078221A1 WO 2016078221 A1 WO2016078221 A1 WO 2016078221A1 CN 2015072131 W CN2015072131 W CN 2015072131W WO 2016078221 A1 WO2016078221 A1 WO 2016078221A1
Authority
WO
WIPO (PCT)
Prior art keywords
user
request
identifier
packet
information
Prior art date
Application number
PCT/CN2015/072131
Other languages
English (en)
French (fr)
Inventor
关涛
汪绍飞
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2016078221A1 publication Critical patent/WO2016078221A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming

Definitions

  • the present invention relates to the field of communications and networking, and more particularly to a method and system for identifying users within a marking network.
  • the unit responsible for security often captures IP packets through network capture and analysis, and analyzes the contents of IP packets. If the content is found to be inconsistent with the regulations, it may be necessary to trace the users of the packets.
  • the IP information of the user changes every time, and the information captured in the network is changed. Does not contain user information. After the message is captured, only the content of the message can be analyzed, and the person who is using it cannot be located.
  • the means that the monitoring unit may often use is to record the message for storage, which is not needed at the time. Users who need to trace historical messages will be required in the future. For the current network situation, after a period of time, users who trace historical messages will be more difficult due to changes in data on the network and loss of various records.
  • the embodiment of the invention provides a method and a system for identifying a user in the identification network, so as to solve at least the problem that the message user is difficult to be quickly identified after the packet is captured on the network in the prior art.
  • a method for identifying a user within a identification network including:
  • the method further includes: determining whether the request for querying the user identity is legal; and if the request is illegal, rejecting the request;
  • the correspondence relationship information includes a correspondence establishment time of the user identifier and the packet identifier.
  • the correspondence relationship information includes a correspondence release time of the user identifier and the packet identifier.
  • the captured user message includes time and IP address information of the packet capture.
  • the associated system is an operator's account opening system or an enterprise network system.
  • the user identity information includes an account opening ID number, an address, an account opening time, or an account closing time.
  • the user identifier may be an international mobile subscriber identity.
  • a system for identifying a user within a logo network including:
  • the collecting module is configured to collect the correspondence information between the user identifier in the identification network and the packet identifier in the user packet, and obtain the user identity information from the associated system according to the user identifier;
  • a storage module configured to integrate the correspondence relationship information and the user identity information into a record, and store the record
  • the query module is configured to receive a request for querying the user identity by using the captured user message, and return, according to the record, user identity information corresponding to the request to the sender of the request.
  • the query module further includes:
  • the rights management unit is configured to determine whether the request for querying the user identity is legal after receiving the request for querying the user identity by using the captured user message; if the request is illegal, rejecting the request; if the request is legal, responding to the request .
  • the correspondence relationship information further includes a correspondence establishment time of the user identifier and the packet identifier.
  • the correspondence relationship information further includes a correspondence release time of the user identifier and the packet identifier.
  • the user packet includes time and IP address information of the packet capture.
  • the correspondence information between the user identifier in the identification network and the packet identifier in the user packet is collected, and the user identity information is obtained from the association system according to the user identifier; the correspondence relationship information and the user identity information are obtained. Synthesizing the record and storing the record; receiving a request for querying the user identity by using the captured user message, and returning the user identity information corresponding to the request to the sender of the request according to the record, and solving
  • the technology of the present invention can realize the positioning of the message user in real time and conveniently, and greatly improve the use of the positioning network message. The speed of the person.
  • FIG. 1 is a flow chart of a method for identifying a user in an identification network according to an embodiment of the present invention
  • FIG. 2 is a flow chart showing a preferred method for identifying a user in a logo network according to an embodiment of the present invention
  • FIG. 3 is a structural block diagram of a system for identifying a user in a logo network according to an embodiment of the present invention
  • FIG. 4 is a block diagram showing a preferred structure of a system for identifying a user in a logo network according to an embodiment of the present invention
  • FIG. 5 is a schematic diagram of a system for identifying a user within a identification network in accordance with a preferred embodiment of the present invention
  • FIG. 1 is a flowchart of a method for identifying a user in a network according to an embodiment of the present invention. As shown in FIG. 1 , the process includes the following steps. :
  • Step S102 Collect correspondence information between the user identifier in the identification network and the packet identifier in the user packet, and obtain user identity information from the association system according to the user identifier.
  • Step S104 integrating the correspondence relationship information and the user identity information into a record, and storing the record;
  • Step S106 Receive a request for querying a user identity by using the captured user message, and return, according to the record, user identity information corresponding to the request to the sender of the request.
  • the correspondence information between the user identifier in the network and the packet identifier in the user packet is collected, and the user identity information is obtained from the association system according to the user identifier, and the collected correspondence information and the user identity information are collected.
  • the records are integrated and stored. After the user packet is captured on the network, the stored record is queried according to the packet identifier in the captured packet, so as to obtain the identity information of the packet user.
  • the present invention implements the positioning of the message user according to the user message.
  • FIG. 2 is a flow chart of another method for identifying a user in the identification network according to an embodiment of the present invention.
  • the user identity is retrieved by the user message.
  • the step S207 is further configured to determine whether the request for querying the identity of the user is legal, and if not, the request is rejected; legally, in step S208, in response to the request, the stored record is queried, and the used message is used. The identity information of the person and return it.
  • the qualification of the querier can be limited, and the privacy of the message user can be protected.
  • the correspondence relationship information further includes a correspondence establishment time of the user identifier and the packet identifier.
  • the establishment time is used to confirm the correspondence between the user ID and the packet identifier in a certain period of time.
  • the correspondence information further includes a correspondence release time of the user identifier and the packet identifier.
  • the release time is used. If the corresponding relationship between the user ID and the message identifier is caused by the user's account cancellation, the change time will also be saved.
  • the user message includes time and IP address information of the packet capture.
  • time and IP address information of the packet capture By capturing the packet time and IP address information, you can analyze the user ID of the corresponding IP address in the above time.
  • the packet identifier can be only an IP address, but some application scenarios include other information, such as a port number.
  • the associated system is an operator's account opening system or an enterprise network system.
  • the user identity information queried according to the foregoing relationship system includes an account opening ID number, an address, an account opening time, or an account closing time.
  • the user identifier may be an International Mobile Subscriber Identification Number (IMSI) according to different application scenarios of the identification network.
  • IMSI International Mobile Subscriber Identification Number
  • Information such as account opening status, account opening point, etc. is obtained from the operator's account opening system through the IMSI.
  • a system for identifying a user in the network is also provided.
  • the system is configured to implement the foregoing embodiments and preferred embodiments, and details are not described herein.
  • the term "module” may implement a combination of software and/or hardware of a predetermined function.
  • the apparatus described in the following embodiments is preferably implemented in software, hardware, or a combination of software and hardware, is also possible and contemplated.
  • FIG. 3 is a structural block diagram of a system for identifying a user in a logo network according to an embodiment of the present invention. As shown in FIG. 3, the system includes an acquisition module 32, a storage module 34, and a query module 36. The system is described below. .
  • the collecting module 32 is configured to collect the correspondence information between the user identifier in the identification network and the packet identifier in the user packet, and obtain the user identity information from the association system according to the user identifier;
  • the storage module 34 is connected to the collection module 32. And arranging to integrate the corresponding relationship information and the user identity information into a record, and storing the record;
  • the query module 36 is connected to the storage module 34, and configured to receive the user message for fetching to query the user.
  • the request for identity returns, according to the record, user identity information corresponding to the request to the sender of the request.
  • the collected correspondence information and the user identity information are integrated into a record and stored. After the user packet is captured on the network, the stored record is queried according to the packet identifier in the captured packet, so as to obtain the identity information of the packet user.
  • the present invention implements the positioning of the message user according to the user message through the above system.
  • FIG. 4 is a block diagram showing a preferred structure of a system for identifying a user in a logo network according to an embodiment of the present invention.
  • the device includes a permission in addition to all modules shown in FIG.
  • the management unit 37 is configured to determine whether the request for querying the identity of the user is legal after sending a request for querying the identity of the user to the user identification database. If the request is not legal, the request is rejected; if the request is legal, the request is responded to.
  • the correspondence relationship information further includes a correspondence establishment time of the user identifier and the packet identifier.
  • the establishment time is used to confirm the correspondence between the user ID and the packet identifier in a certain period of time.
  • the correspondence relationship information further includes a correspondence cancellation time of the user identifier and the packet identifier.
  • the release time is used. If the corresponding relationship between the user ID and the message identifier is caused by the user's account cancellation, the change time will also be saved.
  • the user message to be queried includes packet capture time and address information.
  • packet capture time and address information By capturing the packet time and IP address information, you can analyze the user ID of the corresponding IP address in the above time.
  • the packet identifier can be only an IP address, but some application scenarios include other information, such as a port number.
  • the embodiment of the present invention further provides a system structure diagram for identifying a user in the identification network.
  • the user identification data center system in the box includes a data collection module 32, a user identification data history library (ie, the storage module 34), And a query module 36.
  • the data collection module 32 is configured to collect the correspondence between the user identifier and the packet identifier IP, and access the system such as the operator and the enterprise network to collect the user identity information.
  • the user identification data history library is responsible for storing user identification data and user identity data.
  • the query module 36 is responsible for processing the query of the user identity, receiving the query request, analyzing the request data, querying the identifier data history database, and encapsulating the qualified user identity data into a response and forwarding to the queryer.
  • the query module may add an authorization and rights management module to control access to the user identity information.
  • the identification network system completes the control and generation of the user identification, and the operator or enterprise network system provides the user identity data.
  • the querier can be a security unit, such as a network monitoring department, and is a system that needs to query the identity of the user.
  • step S501 the user identification data center system of the present invention is connected to the identification network, and the collection module 32 is responsible for collecting and receiving the correspondence between the International Mobile Subscriber Identification Number (IMS) and the packet identification IP.
  • IMS International Mobile Subscriber Identification Number
  • the relationship, as well as the time at which this correspondence was established, is recorded and stored into the user identification data history library 34.
  • this change will also be stored into the user identification data history library 34.
  • the stored information may include the user identifier IMSI, the message identifier IP, and the time and type of change of the relationship, such as creation, release, and the like.
  • Step S502 The user identification data center system acquires user identity information from the associated system according to the user identifier, that is, obtains data information such as account opening identity, account opening time, location, and number from the operator's account opening system according to the user identifier IMSI.
  • step S503 the user identification data history database 34 integrates the information of the above correspondence relationship and the user identity information into a record and stores it.
  • step S504 the security department system continuously monitors a website and crawls the website accessing the website. It is now necessary to identify the user of a message that was crawled a month ago. Obtain the IP address and packet capture time of the packet from the captured packet capture record.
  • Step S505 Send the captured user message to the user identification data center system to send a request for querying the user identity, and the query module 36 analyzes the query request to determine its legality, and ensures that the query function is only open to the trusted system. If it is legal, the data identification history library 34 is queried according to the request information, and the user identity information is extracted therefrom.
  • the IP address information and time determine a unique user identity record, and the record contains the user identity information acquired by the collection module. Look for the record of this IP, the creation time should be earlier than the packet capture time. If there is a release time, the release time should be later than the capture time. After searching, extract the information such as the user ID number in the record. Other information, such as the time and place of opening an account, number, etc., can also be provided as needed.
  • Step S506 the user identification data center system returns the user information to the querying party, such as identity information, account opening information, and number.
  • the identification network is a system attached to the existing network. After the identification network is deployed, the information such as the IP address and the user identifier of the network are related to each other, and the user identification information is recorded in the packet indirectly. When the identification network is deployed, the user sends and receives to the external network. For example, the Internet packet contains more fixed IP information. After the packet is captured on the network, the corresponding user identifier can be retrieved through the IP packet information. Therefore, other steps may be used to obtain user information corresponding to the user identifier, such as the user's true identity, geographic location, and the like.
  • the present invention provides a method and apparatus for identifying a user in an identification network, and using the method for quickly locating a message user on the network according to the present invention, compared with the existing network tracking message user, the speed Fast, real-time effects can be achieved. Simply connect to the user ID data center system and be authorized to use. At the same time, the historical message is still valid, and the message captured from the system construction time can be queried.
  • the method and system for identifying a user in the identification network have the following beneficial effects: compared with the existing network tracking message user, the speed is fast, and the real-time effect can be achieved. Simply connect to the user ID data center system and be authorized to use. At the same time, the historical message is still valid, and the message captured from the system construction time can be queried.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明提供一种标识网内识别用户的方法及系统,该方法包括:采集标识网中用户标识和用户报文中报文标识的对应关系信息,并根据所述用户标识从关联系统内获取用户身份信息;将所述对应关系信息和所述用户身份信息整合成记录,并存储所述记录;接收用抓取的用户报文去查询用户身份的请求,根据所述记录,返回与所述请求对应的用户身份信息至所述请求的发送方。本发明解决了现有技术中在网络上抓取报文后,难以快速识别报文使用者的问题,能够实时便捷地实现对报文使用者的定位,极大地提高了定位网络报文使用者的速度。

Description

一种标识网内识别用户的方法及系统 技术领域
本发明涉及通信和网络领域,特别是一种标识网内识别用户的方法及系统。
背景技术
互联网通信在人类生活中的用户越来越广泛,带来无数的便利。但同时也出现了一些借用网络实施具有危害性的活动,例如不法分子在互联网上利用网络实施诈骗,甚至通过网络散布暴恐思想,组织危害社会安全的活动等等。这对人们的生活造成了负面影响。
为应对这些情况,负责安全的单位往往通过网络抓包等方式捕获IP报文,分析IP报文的内容,如果发现内容不符合法规,则可能需要追溯报文的使用人员。
目前,仅凭抓包方式去定位报文的使用者是非常困难的,以现在使用量与日俱增的移动网络来说,用户每次上网的IP等信息是变化的,在网络上抓获的报文内不包含用户信息。在抓到报文后,只能分析报文内容,无法定位到使用的人员。
另一方面,监控单位常常可能采用的手段是记录报文进行存储,当时不需要使用。在以后有情况时才需要追查历史报文的使用者。对目前的网络情况而言,过一段时间后,由于网络上数据的变化和各种记录的遗失,追查历史报文的使用者将更加困难。
针对相关技术中存在的在网络上抓取报文后,难以快速识别报文使用者的问题,目前尚未提出有效解决的方案。
发明内容
本发明实施例提供了一种标识网内识别用户的方法及系统,以至少解决现有技术中存在的在网络上抓取报文后,难以快速识别报文使用者的问题。
根据本发明的一个方面,提供一种标识网内识别用户的方法,包括:
采集标识网中用户标识和用户报文中报文标识的对应关系信息,并根据所述用户标识从关联系统内获取用户身份信息;
将所述对应关系信息和所述用户身份信息整合成记录,并存储所述记录;
接收用抓取的用户报文去查询用户身份的请求,根据所述记录,返回与所述请求对应的用户身份信息至所述请求的发送方。
优选地,在接收用抓取的用户报文去查询用户身份的请求之后,还包括:判断所述查询用户身份的请求是否合法;如请求不合法,则驳回所述请求;
如请求合法,则响应所述请求。
优选地,所述对应关系信息包括所述用户标识和所述报文标识的对应关系建立时间。
优选地,所述对应关系信息包括所述用户标识和所述报文标识的对应关系解除时间。
优选地,所述抓取的用户报文包括抓包的时间和IP地址信息。
优选地,所述的关联系统为运营商的开户系统或企业网系统。
优选地,所述用户身份信息包括开户身份证号、地址、开户时间或销户时间。
优选地,所述用户标识可为国际移动用户识别码。
根据本发明的另一个方面,提供了一种报标识网内识别用户的系统,包括:
采集模块,设置为采集标识网中用户标识和用户报文中报文标识的对应关系信息,并根据所述用户标识从关联系统内获取用户身份信息;
存储模块,设置为将所述对应关系信息和所述的用户身份信息整合成记录,并存储所述记录;
查询模块,设置为接收用抓取的用户报文去查询用户身份的请求,根据所述记录,返回与所述请求对应的用户身份信息至所述请求的发送方。
优选地,所述查询模块还包括:
权限管理单元,设置为在接收用抓取的用户报文去查询用户身份的请求之后,判断查询用户身份的请求是否合法;如请求不合法,则驳回请求;如请求合法,则响应所述请求。
优选地,所述对应关系信息还包括所述用户标识和所述报文标识的对应关系建立时间。
优选地,所述对应关系信息还包括所述用户标识和所述报文标识的对应关系解除时间。
优选地,所述用户报文包括抓包的时间和IP地址信息。
通过本发明,采集标识网中用户标识和用户报文中报文标识的对应关系信息,并根据所述用户标识从关联系统内获取用户身份信息;将所述对应关系信息和所述用户身份信息整合成记录,并存储所述记录;接收用抓取的用户报文去查询用户身份的请求,根据所述记录,返回与所述请求对应的用户身份信息至所述请求的发送方,解决了现有技术中在网络上抓取报文后,难以快速识别报文使用者的问题,使用本发明的技术能够实时便捷地实现对报文使用者的定位,极大地提高了定位网络报文使用者的速度。
附图说明
此处所说明的附图用来提供对本发明的进一步理解,构成本申请的一部分,
本发明的示意性实施例及其说明用于解释本发明,并不构成对本发明的不当限定。在附图中:
图1是根据本发明实施例的一种标识网内识别用户的方法流程图;
图2是根据本发明实施例的一种标识网内识别用户的方法优选流程图;
图3是根据本发明实施例的一种标识网内识别用户的系统的结构框图;
图4是根据本发明实施例的一种标识网内识别用户的系统的优选结构框图;
图5是根据本发明其优选实施例的一种标识网内识别用户的系统的示意图;
具体实施方式
下文中将参考附图并结合实施例来详细说明本发明。需要说明的是,在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互组合。
在本实施例中提供了一种标识网内识别用户的方法,图1是根据本发明实施例的一种标识网内识别用户的方法的流程图,如图1所示,该流程包括如下步骤:
步骤S102,采集标识网中用户标识和用户报文中报文标识的对应关系信息,并根据所述用户标识从关联系统内获取用户身份信息;
步骤S104,将所述对应关系信息和所述用户身份信息整合成记录,并存储所述记录;
步骤S106,接收用抓取的用户报文去查询用户身份的请求,根据所述记录,返回与所述请求对应的用户身份信息至所述请求的发送方。
通过上述步骤,集标识网中用户标识和用户报文中报文标识的对应关系信息,并根据用户标识从关联系统内获取用户身份信息,将采集到的对应关系信息和所述的用户身份信息整合成记录,并存储所述记录。在网络上抓取用户报文后,根据抓取报文中的报文标识查询存储的记录,从而获取报文使用者的身份信息。
相对于现有技术中,报文使用者难以定位识别的问题,本发明通过上述步骤实现了根据用户报文实现了对报文使用者的定位。
在一个优选的实施例中,图2是根据本发明实施例的另一种标识网内识别用户的方法优选流程图,如图2所示,在接收用抓取的用户报文去查询用户身份的请求S206之后,还设有步骤S207,用于判断查询用户身份的请求是否合法,如果不合法,则驳回请求;合法,步骤S208,响应所述请求,查询存储的记录,将获取报文使用者的身份信息并返回出去。通过上述过程,可以限定对查询者的限定,能够保护报文使用者的隐私。
在一个优选的实施例中,所述对应关系信息还包括用户标识和报文标识的对应关系建立时间。建立时间用于确认某一时间内用户标识和报文标识的对应关系。
在一个优选的实施例中,所述对应关系信息还包括用户标识和报文标识的对应关系解除时间。解除时间用于,如因用户销户引发用户标识和报文标识的对应关系的解除,此变化时间也将记录保存。
在一个优选的实施例中,所述用户报文包括抓包的时间和IP地址信息。通过抓包的时间和IP地址信息,可以分析上述时间内对应IP地址的用户标识。报文标识可以仅是IP地址,但有些应用场景会包含其它信息,如端口号等。
在一个优选的实施例中,所述的关联系统为运营商的开户系统或企业网系统。
在一个优选的实施例中,根据上述关系系统查询到的所述用户身份信息包括开户身份证号、地址、开户时间或销户时间。
在一个优选的实施例中,用户标识依据标识网不同应用场景有差异,可以是国际移动用户识别码(International Mobile Subscriber Identification Number,简称IMSI)。通过IMSI从运营商的开户系统中获取开户身份、开户点等信息。
在本实施例中还提供了一种标识网内识别用户的系统,该系统设置为实现上述实施例及优选实施方式,已经进行过说明的不再赘述。如以下所使用的,术语“模块”可以实现预定功能的软件和/或硬件的组合。尽管以下实施例所描述的装置较佳地以软件来实现,但是硬件,或者软件和硬件的组合的实现也是可能并被构想的。
图3是根据本发明实施例的一种标识网内识别用户的系统的结构框图,如图3所示,该系统包括采集模块32、存储模块34和查询模块36,下面对该系统进行说明。
采集模块32,设置为采集标识网中用户标识和用户报文中报文标识的对应关系信息,并根据所述用户标识从关联系统内获取用户身份信息;存储模块34,连接至上述采集模块32,设置为将所述对应关系信息和所述的用户身份信息整合成记录,并存储所述记录;查询模块36,连接至上述存储模块34,设置为接收用抓取的用户报文去查询用户身份的请求,根据所述记录,返回与所述请求对应的用户身份信息至所述请求的发送方。
通过上述模块,将采集到的对应关系信息和所述的用户身份信息整合成记录,并存储。在网络上抓取用户报文后,根据抓取报文中的报文标识查询存储的记录,从而获取报文使用者的身份信息。
相对于现有技术中,报文使用者难以定位的问题,本发明通过上述系统实现了根据用户报文实现了对报文使用者的定位。
图4是根据本发明实施例的一种标识网内识别用户的系统的优选结构框图,如图4所示,该装置除包括图3所示的所有模块外,其中查询模块36还包括一个权限管理单元37,设置为在向所述用户标识数据库发送查询用户身份的请求之后,判断查询用户身份的请求是否合法。如请求不合法,则驳回请求;如请求合法,则响应所述请求。
在一个优选的实施例中,所述采集模块中,所述对应关系信息还包括用户标识和报文标识的对应关系建立时间。建立时间用于确认某一时间内用户标识和报文标识的对应关系。
在一个优选的实施例中,所述采集模块中,所述对应关系信息还包括用户标识和报文标识的对应关系解除时间。解除时间用于,如因用户销户引发用户标识和报文标识的对应关系的解除,此变化时间也将记录保存。
在一个优选的实施例中,所要查询的用户报文包括抓包时间和地址信息。通过抓包的时间和IP地址信息,可以分析上述时间内对应IP地址的用户标识。报文标识可以仅是IP地址,但有些应用场景会包含其它信息,如端口号等。
本发明实施例还提供一种标识网内识别用户的系统结构图,针对相关技术中所存在的上述问题,下面结合优选实施例进行说明,本优选实施例结合了上述实施例及其优选实施方式。
图5是根据本发明其优选实施方式的标识网内识别用户的系统的示意图,其中方框内用户标识数据中心系统,包含数据采集模块32,用户标识数据历史库(即上述存储模块34),以及查询模块36。数据采集模块32负责收集用户标识和报文标识IP的对应关系,并访问运营商、企业网等系统,采集用户身份信息。用户标识数据历史库负责将用户标识数据、用户身份数据的存储。查询模块36负责处理对用户身份的查询,接收查询请求,分析请求数据,查询标识数据历史库,并将符合要求的用户身份数据封装为响应,转发到查询者。其中,查询模块可增加授权及权限管理模块,以控制对用户身份信息的访问。
方框外是和用户标识数据中心系统相关的几个部分。标识网系统完成用户标识的控制和产生,运营商或企业网系统提供用户身份数据。查询者可以是安全单位,如网络监控部门等,是需要查询用户身份的系统。
下面以运营商场景为例,介绍本发明的实施流程。本例中,假设国家安全部门一个月前抓取了访问某网站的某个报文,现在欲获取此报文的使用者。当然,也可以是当前刚抓取的报文。
步骤S501,本发明所述的用户标识数据中心系统与标识网对接,其中采集模块32负责采集接收其用户标识国际移动用户识别码(International Mobile Subscriber Identification Number,简称IMS)和报文标识IP的对应关系,以及此对应关系建立的时间,进行记录并存储进入用户标识数据历史库34。
如果对应关系有变化,此变化也将将存储进入用户标识数据历史库34。例如,因销户引发此对应关系的解除。存储的信息可以包含用户标识IMSI、报文标识IP,以及关系变化的时间、变化类型,例如创建、解除等。
步骤S502,用户标识数据中心系统依据用户标识从关联系统内获取用户身份信息,即依据用户标识IMSI从运营商的开户系统中获取开户身份、开户时间、地点和号码等数据信息。
步骤S503,用户标识数据历史库34将上述对应关系的信息和所述的用户身份信息整合成记录,并存储。
步骤S504,安全部门系统持续监控某网站,对访问此网站报文进行抓取。现需要确定一个月之前抓取的某个报文的使用者。从存储的抓包记录中获取此报文的IP地址、抓包时间。
步骤S505,将抓取的用户报文向用户标识数据中心系统发送查询用户身份的请求,查询模块36分析查询请求,判断其合法性,确保此查询功能只对可信的系统开放。如合法,则根据请求信息查询数据标识历史库34,从中提取用户身份信息。
用户标识数据历史库34中,IP地址信息和时间确定了唯一的用户身份记录,记录包含采集模块获取的用户身份信息。寻找此IP的记录,创建时间应早于报文抓取时间,如果存在解除时间,则解除时间应晚于抓包时间。寻找到后,提取记录内的用户身份证号等信息。其它信息,如开户时间地点、号码等也可根据需要一并提供。
步骤S506,用户标识数据中心系统将使用者信息返回给查询方,如身份信息、开户信息和号码等。
标识网是附加在现有网络之上的一个系统,部署标识网后,可实现IP地址等信息和网络的用户标识有一定的关联性,间接的在报文内记录了用户标识信息。在部署了标识网的情况下,用户收发到外部网络,如互联网的报文内包含较固定的IP等信息。在网络上抓获报文后,可通过IP包信息来检索对应的用户标识。因此可通过其它步骤获取用户标识对应的用户信息,如用户的真实身份,地理位置等等。
综上所述,本发明提供了一种标识网中识别用户的方法和装置,采用本发明所述标识网上快速定位报文使用者的方法,与现有网络追踪报文使用者相比,速度快,可达到实时的效果。只需和用户标识数据中心系统对接,获得授权即可使用。同时,对历史报文仍然有效,可查询从系统建设时间起抓获的报文。
以上所述仅为本发明的优选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。
工业实用性
如上所述,本发明实施例提供的一种标识网内识别用户的方法及系统具有以下有益效果:与现有网络追踪报文使用者相比,速度快,可达到实时的效果。只需和用户标识数据中心系统对接,获得授权即可使用。同时,对历史报文仍然有效,可查询从系统建设时间起抓获的报文。

Claims (13)

  1. 一种标识网内识别用户的方法,包括:
    采集标识网中用户标识和用户报文中报文标识的对应关系信息,并根据所述用户标识从关联系统内获取用户身份信息;
    将所述对应关系信息和所述用户身份信息整合成记录,并存储所述记录;
    接收用抓取的用户报文去查询用户身份的请求,根据所述记录,返回与所述请求对应的用户身份信息至所述请求的发送方。
  2. 根据权利要求1所述的方法,其中,在接收用抓取的用户报文去查询用户身份的请求之后,还包括:判断所述查询用户身份的请求是否合法;
    如请求不合法,则驳回所述请求;
    如请求合法,则响应所述请求。
  3. 根据权利要求2所述的方法,其中,所述对应关系信息包括所述用户标识和所述报文标识的对应关系建立时间。
  4. 根据权利要求3所述的方法,其中,所述对应关系信息包括所述用户标识和所述报文标识的对应关系解除时间。
  5. 根据权利要求4所述的方法,其中,所述抓取的用户报文包括抓包的时间和IP地址信息。
  6. 根据权利要求5所述的方法,其中,所述的关联系统为运营商的开户系统或企业网系统。
  7. 根据权利要求6所述的方法,其中,所述用户身份信息包括开户身份证号、地址、开户时间或销户时间。
  8. 根据权利要求7所述的方法,其中,所述用户标识可为国际移动用户识别码。
  9. 一种标识网内识别用户的系统,包括:
    采集模块,设置为采集标识网中用户标识和用户报文中报文标识的对应关系信息,并根据所述用户标识从关联系统内获取用户身份信息;
    存储模块,设置为将所述对应关系信息和所述的用户身份信息整合成记录,并存储所述记录;
    查询模块,设置为接收用抓取的用户报文去查询用户身份的请求,根据所述记录,返回与所述请求对应的用户身份信息至所述请求的发送方。
  10. 根据权利要求9所述的系统,其中,所述查询模块还包括:
    权限管理单元,设置为在接收用抓取的用户报文去查询用户身份的请求之后,判断查询用户身份的请求是否合法;
    如请求不合法,则驳回请求;
    如请求合法,则响应所述请求。
  11. 根据权利要求10所述的系统,其中,所述对应关系信息还包括所述用户标识和所述报文标识的对应关系建立时间。
  12. 根据权利要求11所述的系统,其中,所述对应关系信息还包括所述用户标识和所述报文标识的对应关系解除时间。
  13. 根据权利要求12所述的方法,其中,所述抓取的用户报文包括抓包的时间和IP地址信息。
PCT/CN2015/072131 2014-11-18 2015-02-03 一种标识网内识别用户的方法及系统 WO2016078221A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410658613.4 2014-11-18
CN201410658613.4A CN105681183B (zh) 2014-11-18 2014-11-18 一种标识网内识别用户的方法及系统

Publications (1)

Publication Number Publication Date
WO2016078221A1 true WO2016078221A1 (zh) 2016-05-26

Family

ID=56013140

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/072131 WO2016078221A1 (zh) 2014-11-18 2015-02-03 一种标识网内识别用户的方法及系统

Country Status (2)

Country Link
CN (1) CN105681183B (zh)
WO (1) WO2016078221A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108984767A (zh) * 2018-07-20 2018-12-11 珠海宏桥高科技有限公司 一种虚拟身份核实的方法
CN110716941B (zh) * 2019-10-18 2023-06-27 网络通信与安全紫金山实验室 一种handle标识解析系统及数据查询方法

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101399853A (zh) * 2007-09-24 2009-04-01 中国移动通信集团公司 用户标识服务器、数据业务处理系统及方法
CN101674587A (zh) * 2009-10-14 2010-03-17 成都市华为赛门铁克科技有限公司 实现业务监控的方法和系统及认证代理服务器
CN102790812A (zh) * 2012-07-31 2012-11-21 中国联合网络通信集团有限公司 基于移动终端的ip地址溯源方法、设备和系统
CN103179188A (zh) * 2013-01-17 2013-06-26 北京亿赞普网络技术有限公司 用户识别方法和装置
CN103532947A (zh) * 2013-10-10 2014-01-22 北京首信科技股份有限公司 移动互联网络在线用户标识的管理装置和管理方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101399853A (zh) * 2007-09-24 2009-04-01 中国移动通信集团公司 用户标识服务器、数据业务处理系统及方法
CN101674587A (zh) * 2009-10-14 2010-03-17 成都市华为赛门铁克科技有限公司 实现业务监控的方法和系统及认证代理服务器
CN102790812A (zh) * 2012-07-31 2012-11-21 中国联合网络通信集团有限公司 基于移动终端的ip地址溯源方法、设备和系统
CN103179188A (zh) * 2013-01-17 2013-06-26 北京亿赞普网络技术有限公司 用户识别方法和装置
CN103532947A (zh) * 2013-10-10 2014-01-22 北京首信科技股份有限公司 移动互联网络在线用户标识的管理装置和管理方法

Also Published As

Publication number Publication date
CN105681183A (zh) 2016-06-15
CN105681183B (zh) 2020-11-06

Similar Documents

Publication Publication Date Title
US9767279B2 (en) Systems and methods for combined physical and cyber data security
Sathwara et al. IoT Forensic A digital investigation framework for IoT systems
US20080159146A1 (en) Network monitoring
CN107046543A (zh) 一种面向攻击溯源的威胁情报分析系统
US20160191549A1 (en) Rich metadata-based network security monitoring and analysis
CN111277421B (zh) 一种网络摄像机接入安全防护的系统和方法
US8577680B2 (en) Monitoring and logging voice traffic on data network
CN105024977A (zh) 基于数字水印和蜜罐技术的网络追踪系统
CN108600154A (zh) 一种政务远程认证系统及方法
CN103888459A (zh) 网络内网入侵的检测方法及装置
EP2993607B1 (en) Privacy compliant event analysis
US20190356571A1 (en) Determining attributes using captured network probe data in a wireless communications system
CN103944788B (zh) 基于网络通信行为的未知木马检测方法
CN107733858A (zh) 一种智能保护摄像头信息的监控设备及方法
Sudozai et al. Forensics study of IMO call and chat app
CN105447385B (zh) 一种多层次检测的应用型数据库蜜罐实现系统及方法
CN104486320A (zh) 基于蜜网技术的内网敏感信息泄露取证系统及方法
CN106790073B (zh) 一种Web服务器恶意攻击的阻断方法、装置及防火墙
Mrdovic IoT forensics
WO2016078221A1 (zh) 一种标识网内识别用户的方法及系统
CN107222330A (zh) 一种智能识别系统请求和应答敏感内容的方法
CN107315974A (zh) 一种基于物联网的图像成型介质保护装置
Bedi The fourth amendment disclosure doctrines
Alshalawi et al. Forensic tool for wireless surveillance camera
US20160189160A1 (en) System and method for deanonymization of digital currency users

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15861150

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15861150

Country of ref document: EP

Kind code of ref document: A1