Asset management method and system integrating NMAP active detection and AI
By combining NMAP active detection with AI technology and utilizing machine learning and anomaly detection algorithms, the problems of insufficient accuracy and lack of dynamic context awareness in traditional asset discovery and risk identification are resolved, enabling accurate identification and dynamic risk assessment of new assets, and improving security operation efficiency and decision-making quality.
Patent Information
- Application Number
- CN202510686159.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-09-19
AI Technical Summary
The existing NMAP-based asset discovery and risk identification solutions have problems such as insufficient asset identification accuracy, simple risk assessment models and lack of dynamic context awareness, inability to effectively process massive data and mine deep correlations and anomalies from them, and low intelligence.
Adopting machine learning technology, NMAP active detection combined with AI, asset identification and profiling are performed through machine learning classification models, asset status changes are continuously monitored, abnormal events are obtained using anomaly detection algorithms, and risk assessment and priority sorting are performed in combination with external CVE vulnerability library information, threat intelligence and asset importance.
It has achieved accurate identification of various types of assets, especially new and non-standard assets, dynamic risk assessment, proactive discovery of potential threats and anomalies, improved security operation efficiency and decision-making quality, and has self-learning capabilities to adapt to new asset types and attack methods.
Smart Images

Figure CN120675743A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of network security and artificial intelligence technology, and in particular to an asset management method and system integrating NMAP active detection and AI. Background Art
[0002] Accurate and real-time IT asset management is the cornerstone of enterprise network security. Although traditional scanning tools such as NMAP can discover some asset information, they face many challenges:
[0003] 1. Incomplete discovery and fingerprint recognition limitations: NMAP has limited ability to identify hidden devices and non-standard services. Traditional fingerprint databases are updated lagging behind, making it difficult to accurately identify new devices (such as IoT and cloud resources) and complex applications.
[0004] 2. Static risk assessment lacks context: Risk assessment based solely on port openness and service versions is too rough and cannot be accurately assessed based on the actual business importance of the asset, network exposure, actual exploitability, and dynamically changing threat intelligence, leading to misjudgment of risks and misplaced priorities.
[0005] 3. Low data processing and analysis efficiency: Large networks generate huge amounts of scan data, and manual analysis is inefficient, making it difficult to quickly extract valuable information and discover potential abnormal patterns. Summary of the Invention
[0006] The purpose of the embodiments of the present invention is to provide an asset management method and system that integrates NMAP active detection and AI, aiming to solve the problems existing in existing NMAP-based asset discovery and risk identification solutions, such as insufficient asset identification accuracy, simple risk assessment models and lack of dynamic context awareness, inability to effectively process massive data and mine deep correlations and anomalies from them, and low intelligence.
[0007] To achieve the above objectives, in a first aspect, an embodiment of the present invention provides an asset management method that integrates NMAP active detection and AI, including:
[0008] Using NMAP as the core detection engine, it detects the target network and collects raw asset information;
[0009] Using a machine learning classification model to perform asset identification and profiling on the original asset information to generate asset profiling information;
[0010] Continuously monitor asset status changes and use anomaly detection algorithms to capture abnormal events;
[0011] The asset portrait information, real-time associated external CVE vulnerability library information, threat intelligence information, asset importance and the abnormal events are collected, and a machine learning model is used to perform risk assessment and priority sorting on each asset to obtain risk assessment information.
[0012] As a preferred implementation of the present application, before detecting the target network, the method further includes:
[0013] Deploy system servers and configure scan targets, scan strategies, asset importance tags, and external data source interfaces;
[0014] The scanning targets include IP segments and domain names, the scanning strategies include scanning frequency, scanning intensity and NMAP parameter templates, and the external data source interfaces include CVE library APIs and threat intelligence subscription addresses.
[0015] As a specific implementation of this application, the asset portrait information is generated as follows:
[0016] Extract features from the original asset information to obtain features to be identified, including port, service banner, and TCP / IP;
[0017] Using a machine learning classification model to classify and identify the features to be identified, obtaining identification results, including highly reliable asset types, OS tags, service tags, and application tags;
[0018] The identification results are integrated to generate asset portrait information, and the asset portrait information is stored in the asset database; the asset portrait information includes detailed software and hardware information and inferred business attribute information.
[0019] As a specific implementation of this application, the abnormal events are obtained by using an abnormality detection algorithm as follows:
[0020] Continuously monitor changes in asset status and obtain the latest asset status;
[0021] The latest asset status is compared with the normal baseline, identified using an anomaly detection algorithm, and abnormal events are output; the normal baseline is formed by learning the stable characteristics of a specified asset or asset group within a preset time period as the normal baseline.
[0022] As a preferred implementation of the present application, after obtaining the risk assessment information, the method further includes:
[0023] Associating the risk assessment information with the assets and storing them in an asset database;
[0024] Reading assets and risk assessment information from the asset database for visual display;
[0025] Use AI to conduct asset cluster analysis, risk trend prediction, and utilize NLG technology to provide analysis reports and disposal recommendations.
[0026] Secondly, embodiments of the present application also provide an asset management system that integrates NMAP active detection and AI, including:
[0027] The intelligent scanning and data collection module is used to deploy system servers, configure scanning information, and execute scanning tasks. The scanning tasks use NMAP as the core detection engine to detect the target network and collect raw asset information.
[0028] An asset identification and profiling module, configured to perform asset identification and profiling on the original asset information using a machine learning classification model to generate asset profiling information;
[0029] The asset behavior baseline and anomaly detection module is used to continuously monitor asset status changes and use anomaly detection algorithms to detect abnormal events;
[0030] The risk assessment and prioritization module is used to collect the asset portrait information, real-time associated external CVE vulnerability library information, threat intelligence information, asset importance and the abnormal events, and use the machine learning model to perform risk assessment and priority sorting on each asset to obtain risk assessment information.
[0031] As a specific implementation of this application, the asset identification and profiling module includes:
[0032] A feature extraction unit is used to extract features from the original asset information to obtain features to be identified, including ports, service banners, and TCP / IP;
[0033] An AI classification / recognition model unit is used to classify and identify the features to be identified using a machine learning classification model to obtain identification results, including highly reliable asset types, OS tags, service tags, and application tags;
[0034] The asset portrait generation unit is used to integrate the identification results, generate asset portrait information, and store the asset portrait information in the asset database; the asset portrait information includes detailed software and hardware information and inferred business attribute information.
[0035] As a specific implementation of this application, the asset behavior baseline and anomaly detection module includes:
[0036] The baseline learning unit is used to learn the stable characteristics of a specified asset or asset group within a preset time period as a normal baseline;
[0037] The anomaly detection unit is used to periodically compare the asset status discovered by the current scan with the normal baseline, use an anomaly detection algorithm to identify significant deviations, and output an abnormal event.
[0038] As a specific implementation of this application, the risk assessment and prioritization module includes:
[0039] A multi-source information fusion unit, used to integrate the asset portrait information, real-time associated external CVE vulnerability library information, threat intelligence information, asset importance and the abnormal events;
[0040] The AI risk scoring / ranking model unit is used to extract features from the integrated information to obtain multi-dimensional features, input the multi-dimensional features into the AI risk model, and output risk scores and priorities.
[0041] As a specific implementation of this application, the asset management system further includes:
[0042] Intelligent visualization and reporting module, used to visualize assets and their risk assessment information, conduct asset cluster analysis and risk trend prediction through AI, and provide analysis reports and disposal recommendations using NLG technology;
[0043] The external interface data module is used to connect to the external CVE vulnerability library, threat intelligence platform and CMDB.
[0044] The advantages of implementing the embodiments of the present invention are as follows:
[0045] 1. More accurate and comprehensive asset identification: Utilizing AI classification models, the accuracy and granularity of identifying various types of assets, especially new and non-standard assets and specific application versions, are significantly improved.
[0046] 2. Risk assessment is more dynamic and accurate: AI models can integrate multi-dimensional dynamic information (vulnerabilities, exploit intelligence, asset context, behavioral anomalies) to achieve accurate assessment and prioritization based on real risks rather than static rules, effectively reducing false positives and missed alerts.
[0047] 3. Proactively discover potential threats and anomalies: Through asset behavior baseline learning and anomaly detection, it can detect abnormal conditions that may indicate intrusion or configuration risks that traditional signature-based scanning cannot identify.
[0048] 4. Improve security operations efficiency and decision-making quality: AI-driven risk prioritization, automated report generation (including intelligent interpretation), and intelligent asset grouping greatly reduce the burden of manual analysis, allowing security teams to focus on the highest-value risk management tasks.
[0049] 5. The system has the ability to self-learn and evolve: risk assessment models, fingerprint recognition models, etc. can be continuously optimized through continuous learning to adapt to new asset types and attack methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the specific implementation of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the specific implementation or the description of the prior art.
[0051] Figure 1 This is a structural diagram of an asset management system that integrates NMAP active detection and AI, provided by an embodiment of the present invention;
[0052] Figure 2 yes Figure 1 The structure diagram of the asset identification and profiling module shown;
[0053] Figure 3 yes Figure 1 The structure diagram of the asset behavior baseline and anomaly detection module is shown;
[0054] Figure 4 yes Figure 1 The structure diagram of the risk assessment and prioritization module is shown;
[0055] Figure 5 yes Figure 1 The structure diagram of the visualization and reporting module is shown;
[0056] Figure 6 This is a flowchart of an asset management method that integrates NMAP active detection and AI, provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0057] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0058] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0059] The inventive concept of the embodiment of the present invention is:
[0060] This paper proposes an enterprise IT asset discovery and risk assessment solution that integrates NMAP active detection and AI intelligent analysis. The solution aims to address the problems of existing NMAP-based asset discovery and risk identification solutions, such as insufficient asset identification accuracy, simple risk assessment models that lack dynamic context awareness, inability to effectively process massive data and mine deep correlations and anomalies, and low intelligence. The specific goals are:
[0061] 1. Use AI technology to enhance asset fingerprint recognition capabilities and improve the accuracy and granularity of identifying various types of assets (especially new and non-standard assets).
[0062] 2. Build an AI-driven dynamic risk assessment model that integrates multi-dimensional information (vulnerabilities, threat intelligence, asset context, behavioral baselines, etc.) to perform accurate and real-time risk quantification and prioritization.
[0063] 3. Implement asset behavior baseline learning and anomaly detection to proactively identify changes in asset status or behavior that may indicate risks.
[0064] 4. Improve the system's automated analysis and decision-making support capabilities to provide smarter and more insightful support for security operations.
[0065] The core of this invention is to introduce multiple key modules that use artificial intelligence technology to perform enhanced processing. The working principle is as follows:
[0066] The system first uses the intelligent scanning and data collection module (with NMAP as the core detection engine and the ability to integrate other data sources) to detect the target network and collect raw asset information. The collected data (such as open ports, service banners, operating system guesses, etc.) is fed into the AI-enhanced asset fingerprint recognition and profiling module, which uses machine learning classification models (such as SVM, random forest, or deep learning models) to more accurately classify and identify assets (such as device type, precise operating system version, running applications / middleware, and even business attribute inferences) to generate detailed asset portraits. At the same time, the asset behavior baseline and anomaly detection module establishes a baseline model of normal operating characteristics (such as stable open ports and service combinations) for key assets, and uses anomaly detection algorithms (such as isolation forests and autoencoders) to continuously monitor state changes and detect abnormal behaviors that deviate from the baseline. The AI-driven risk assessment and prioritization engine is the core of risk analysis. It integrates asset profile information, services / versions discovered by NMAP, real-time associated external CVE vulnerability library information, threat intelligence (such as the exploitation of related vulnerabilities in the wild), asset importance (configurable or AI-inferred), and the output of the anomaly detection module. It calculates the dynamic risk score and disposal priority for each asset and specific risk item (such as vulnerability) through machine learning models (such as regression models to predict risk scores, or ranking learning models for prioritization). Finally, the intelligent visualization and reporting module not only displays asset lists and risk lists, but also performs asset cluster analysis and risk trend prediction through AI, and uses natural language generation (NLG) technology to provide report summaries and disposal recommendations with intelligent analytical insights.
[0067] Please refer to Figure 1 , is an asset management system that integrates NMAP active detection and AI, provided by an embodiment of the present invention, and includes:
[0068] Intelligent scanning and data collection module, used to deploy system servers, configure scanning information and execute scanning tasks;
[0069] An asset identification and profiling module, configured to perform asset identification and profiling on the original asset information using a machine learning classification model to generate asset profiling information;
[0070] The asset behavior baseline and anomaly detection module is used to continuously monitor asset status changes and use anomaly detection algorithms to detect abnormal events;
[0071] A risk assessment and prioritization module is used to collect the asset profile information, real-time associated external CVE vulnerability library information, threat intelligence information, asset importance and the abnormal events, and use a machine learning model to perform risk assessment and priority sorting on each asset to obtain risk assessment information;
[0072] Intelligent visualization and reporting module, used to visualize assets and their risk assessment information, conduct asset cluster analysis and risk trend prediction through AI, and provide analysis reports and disposal recommendations using NLG technology;
[0073] The external interface data module is used to connect to the external CVE vulnerability library, threat intelligence platform and CMDB.
[0074] Among them, the intelligent scanning and data acquisition module is specifically used for:
[0075] Responsible for deploying system servers: installing software including the NMAP engine and AI-related libraries (such as Scikit-learn, TensorFlow / PyTorch, and NLP libraries);
[0076] Configure scanning information: This includes configuring scanning targets (IP segments, domain names), scanning policies (frequency, intensity, NMAP parameter templates), asset importance tags, and external data source interfaces (CVE library API keys, threat intelligence subscription addresses, etc.). It should be noted that AI can be used to optimize scanning policies (e.g., dynamically adjusting scanning parameters based on network feedback and intelligently selecting NSE scripts).
[0077] Execute scanning tasks: The core uses NMAP for host discovery, port scanning, service detection, and OS detection, and can call the NMAP Scripting Engine (NSE) for deep detection through configuration.
[0078] In addition, the intelligent scanning and data collection module can also inherit other data sources, such as passive traffic analysis, cloud platform API, CMDB interface, etc.
[0079] Furthermore, if Figure 2 As shown, the asset identification and profiling module includes:
[0080] Feature extraction unit, which receives raw scan data from the intelligent scanning and data acquisition module and extracts feature vectors for machine learning from NMAP output (banner, port combination, response characteristics, etc.);
[0081] The AI classification / recognition model unit uses machine learning classification models to classify and identify extracted features and obtain recognition results. This unit has built-in multiple pre-trained or online learning ML / DL models to perform high-precision identification of asset types (servers, PCs, printers, IoT devices, etc.), operating systems (accurate to versions), and services / applications (specific versions of Nginx, Tomcat, database types, etc.). It can also use NLP technology to analyze service banners to obtain richer information.
[0082] The asset portrait generation unit is used to integrate the identification results to form a structured asset portrait containing detailed software and hardware information and inferred business attributes (if any), and store it in the asset database.
[0083] Furthermore, if Figure 3 As shown, the asset behavior baseline and anomaly detection module includes:
[0084] The baseline learning unit is used to learn the stable characteristics of a specified asset or asset group over a period of time (such as the set of open ports and the signature of running services) as a normal baseline;
[0085] The anomaly detection unit is used to periodically compare the asset status discovered by the current scan with the normal baseline, use the anomaly detection algorithm to identify significant deviations (such as newly opened unknown ports, service version mutations, etc.), and output abnormal events.
[0086] Furthermore, the risk assessment and prioritization module can be understood as an AI-driven risk assessment and prioritization engine, e.g. Figure 4 Shown, including:
[0087] A multi-source information fusion unit is used to integrate asset profiles, abnormal events, externally connected real-time CVE vulnerability libraries, externally connected threat intelligence (such as vulnerability exploitation information), and configured asset importance levels;
[0088] The AI risk scoring / ranking model unit is used to extract features from the integrated information above, obtain multi-dimensional features, input them into the core AI risk model, and output the following information: a) the overall risk score of the asset; b) the exploitability and potential impact assessment of specific vulnerabilities / risk items; c) the ranking of risk items / assets that need to be handled first.
[0089] Furthermore, if Figure 5 As shown, the intelligent visualization and reporting module includes:
[0090] Data visualization unit, used to provide dashboards, asset lists, risk lists, network topology (optional), and can also use AI clustering algorithms to automatically group assets for display;
[0091] The intelligent analysis and reporting unit is used to display risk trends, predict potential high-risk areas, and use NLG technology to generate automated report summaries containing key findings, risk interpretation, and priority recommendations.
[0092] Based on the same inventive concept, the embodiment of the present invention also provides an asset management method that integrates NMAP active detection and AI, such as Figure 6 As shown, the following steps are included:
[0093] S1, Deployment and Configuration: Deploy system servers, configure scan information, and execute scan tasks.
[0094] To implement this, deploy a system server and install software including the NMAP engine and AI-related libraries (such as Scikit-learn, TensorFlow / PyTorch, and NLP libraries). Configure scan targets (IP segments, domain names), scan policies (frequency, intensity, and NMAP parameter templates), asset importance tags, and external data source interfaces (CVE library API keys, threat intelligence subscription addresses, etc.).
[0095] S2, model training and initialization: load pre-trained asset identification model and risk assessment model.
[0096] In specific implementations, the system can load pre-trained asset fingerprint recognition and risk assessment models. For specific environments, the models can be fine-tuned or incrementally trained using local historical scan data and security event feedback. The behavioral baseline module automatically learns the normal state of each asset during initial operation.
[0097] S3, perform scanning and discovery: perform NMAP scanning and collect scan data such as raw asset information.
[0098] In practice, the Intelligent Scanning and Data Collection module executes NMAP scans according to policy. AI can recommend optimized parameters based on historical data before scanning, or adjust subsequent scanning behavior based on initial responses during scanning. For example, upon discovering a specific open port, it can automatically activate a targeted NSE script.
[0099] S4, AI asset identification and profiling: Based on scanning data, use the asset identification model to perform asset identification and profiling to generate asset profiling information.
[0100] In practice, the raw scan results (in XML or other formats) are fed into the asset identification and profiling module. The feature extraction unit parses the data, extracting features such as ports, service banners, and TCP / IP fingerprints. An AI classification model (e.g., one for IoT devices or one for web application frameworks) processes these features and outputs highly reliable labels such as asset type, operating system, service, and application. These labels are then integrated and stored in the asset database by the profiling unit.
[0101] S5, behavioral baseline comparison and anomaly detection: Continuously monitor asset status changes, obtain the latest asset status, compare it with the learned normal baseline, and output abnormal events.
[0102] In practice, the asset behavior baseline and anomaly detection module periodically obtains the latest asset status and compares it with the learned baseline model. For example, if a server's baseline indicates open ports {80, 443, 22}, and a scan reveals open ports {80, 443, 22, 6666}, the anomaly detection unit (e.g., based on statistical probability or reconstruction error) identifies the anomaly event "unexpected opening of port 6666."
[0103] S6, AI risk assessment and prioritization: Collect asset profile information, external CVE vulnerability library information, threat intelligence information, asset importance and abnormal events, etc., extract features and input them into the reputation assessment model to output risk scores and priorities.
[0104] In practice, the risk assessment and prioritization module collects asset profile information (e.g., OS: Ubuntu 20.04, Running: Apache 2.4.41), associated CVEs (obtained from external repositories, such as CVE-2021-XXXX affecting Apache 2.4.41), threat intelligence (this CVE has a public exploit), asset importance (configured to "High"), and abnormal events (none). This information is converted into a feature vector and input into the AI risk model. The model outputs a risk score (e.g., 8.5 / 10) and a priority (e.g., "High"), which is then stored in association with the asset.
[0105] S7, Visualization and Reporting: Read assets and their risk assessment information from the asset database for visual display, use AI to perform asset cluster analysis and risk trend prediction, and use NLG technology to provide analysis reports and disposal recommendations.
[0106] In practice, the intelligent visualization and reporting module reads asset and risk information from a database. On the visualization interface, administrators can see not only a list but also asset groups automatically clustered by AI (e.g., "unpatched web servers"). Clicking on a risk item reveals the AI-generated scoring criteria (e.g., "High-risk vulnerability CVE-XXXX, exploited in the wild, impacting core assets"). Administrators can generate a report with an NLG-generated summary: "This scan discovered 15 high-risk assets, primarily concentrated in the web application server cluster. We recommend prioritizing vulnerabilities CVE-XXXX and CVE-YYYY..."
[0107] Implementing the asset management solution that integrates NMAP active detection and AI provided by the embodiment of the present invention has the following advantages:
[0108] 1. More accurate and comprehensive asset identification: Utilizing AI classification models, the accuracy and granularity of identifying various types of assets, especially new and non-standard assets and specific application versions, are significantly improved.
[0109] 2. Risk assessment is more dynamic and accurate: AI models can integrate multi-dimensional dynamic information (vulnerabilities, exploit intelligence, asset context, behavioral anomalies) to achieve accurate assessment and prioritization based on real risks rather than static rules, effectively reducing false positives and missed alerts.
[0110] 3. Proactively discover potential threats and anomalies: Through asset behavior baseline learning and anomaly detection, it can detect abnormal conditions that may indicate intrusion or configuration risks that traditional signature-based scanning cannot identify.
[0111] 4. Improve security operations efficiency and decision-making quality: AI-driven risk prioritization, automated report generation (including intelligent interpretation), and intelligent asset grouping greatly reduce the burden of manual analysis, allowing security teams to focus on the highest-value risk management tasks.
[0112] 5. The system has the ability to self-learn and evolve: risk assessment models, fingerprint recognition models, etc. can be continuously optimized through continuous learning to adapt to new asset types and attack methods.
[0113] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the composition and steps of each example according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0114] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, or can be electrical, mechanical or other forms of connection.
[0115] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the objectives of the embodiments of the present invention.
[0116] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0117] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and such modifications or substitutions are intended to be within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.
Claims
1. An asset management method integrating NMAP active detection and AI, characterized in that: include: Using NMAP as the core detection engine, it detects the target network and collects raw asset information; Using a machine learning classification model to perform asset identification and profiling on the original asset information to generate asset profiling information; Continuously monitor asset status changes and use anomaly detection algorithms to capture abnormal events; The asset portrait information, real-time associated external CVE vulnerability library information, threat intelligence information, asset importance and the abnormal events are collected, and a machine learning model is used to perform risk assessment and priority sorting on each asset to obtain risk assessment information.
2. The asset management method according to claim 1, wherein: Before detecting the target network, the method further includes: Deploy system servers and configure scan targets, scan strategies, asset importance tags, and external data source interfaces; The scanning targets include IP segments and domain names, the scanning strategies include scanning frequency, scanning intensity and NMAP parameter templates, and the external data source interfaces include CVE library APIs and threat intelligence subscription addresses.
3. The asset management method according to claim 1, wherein: The asset portrait information generated is as follows: Extract features from the original asset information to obtain features to be identified, including port, service banner, and TCP / IP; Using a machine learning classification model to classify and identify the features to be identified, obtaining identification results, including highly reliable asset types, OS tags, service tags, and application tags; Integrating the identification results to generate asset portrait information, and storing the asset portrait information in an asset database; The asset profile information includes detailed software and hardware information and inferred business attribute information.
4. The asset management method according to claim 1, wherein: The specific methods of using anomaly detection algorithms to obtain abnormal events are as follows: Continuously monitor changes in asset status and obtain the latest asset status; The latest asset status is compared with the normal baseline, identified using an anomaly detection algorithm, and abnormal events are output; the normal baseline is formed by learning the stable characteristics of a specified asset or asset group within a preset time period as the normal baseline.
5. The asset management method according to any one of claims 1 to 4, characterized in that: After obtaining the risk assessment information, the method further includes: Associating the risk assessment information with the assets and storing them in an asset database; Reading assets and risk assessment information from the asset database for visual display; Use AI to conduct asset cluster analysis, risk trend prediction, and utilize NLG technology to provide analysis reports and disposal recommendations.
6. An asset management system integrating NMAP active detection and AI, characterized in that: include: The intelligent scanning and data collection module is used to deploy system servers, configure scanning information, and execute scanning tasks. The scanning tasks use NMAP as the core detection engine to detect the target network and collect raw asset information. An asset identification and profiling module, configured to perform asset identification and profiling on the original asset information using a machine learning classification model to generate asset profiling information; The asset behavior baseline and anomaly detection module is used to continuously monitor asset status changes and use anomaly detection algorithms to detect abnormal events; The risk assessment and prioritization module is used to collect the asset portrait information, real-time associated external CVE vulnerability library information, threat intelligence information, asset importance and the abnormal events, and use the machine learning model to perform risk assessment and priority sorting on each asset to obtain risk assessment information.
7. The asset management system according to claim 6, wherein: The asset identification and profiling module includes: A feature extraction unit is used to extract features from the original asset information to obtain features to be identified, including ports, service banners, and TCP / IP; An AI classification / recognition model unit is used to classify and identify the features to be identified using a machine learning classification model to obtain identification results, including highly reliable asset types, OS tags, service tags, and application tags; The asset portrait generation unit is used to integrate the identification results, generate asset portrait information, and store the asset portrait information in the asset database; the asset portrait information includes detailed software and hardware information and inferred business attribute information.
8. The asset management system according to claim 6, wherein: The asset behavior baseline and anomaly detection module includes: The baseline learning unit is used to learn the stable characteristics of a specified asset or asset group within a preset time period as a normal baseline; The anomaly detection unit is used to periodically compare the asset status discovered by the current scan with the normal baseline, use an anomaly detection algorithm to identify significant deviations, and output an abnormal event.
9. The asset management system according to claim 6, wherein: The risk assessment and prioritization module includes: A multi-source information fusion unit, used to integrate the asset portrait information, real-time associated external CVE vulnerability library information, threat intelligence information, asset importance and the abnormal events; The AI risk scoring / ranking model unit is used to extract features from the integrated information to obtain multi-dimensional features, input the multi-dimensional features into the AI risk model, and output risk scores and priorities.
10. The asset management system according to any one of claims 6 to 9, characterized in that: The asset management system further includes: Intelligent visualization and reporting module, used to visualize assets and their risk assessment information, conduct asset cluster analysis and risk trend prediction through AI, and provide analysis reports and disposal recommendations using NLG technology; The external interface data module is used to connect to the external CVE vulnerability library, threat intelligence platform and CMDB.
Citation Information
Cited By
Novel data outbound abnormal behavior analysis system and method
CN121486039A
Network space asset management method based on big data analysis
CN121567580A