Automatic identification method and device for asset network relationship
Automatically identifying asset network relationships through SNMP+ARP technology solves the difficulty of sorting out assets caused by the large scale of enterprise assets, achieves accurate network topology discovery and security management, improves asset management efficiency, and reduces network threats.
Patent Information
- Application Number
- CN202410384803.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-01
- Publication Date
- 2025-10-14
AI Technical Summary
The large scale of corporate assets makes it difficult to sort out assets. Manual addition is tedious and easy to miss, making it difficult to promptly detect violations such as computer modifications and unauthorized access. Network topology discovery is inaccurate, affecting security management and threat analysis.
Using SNMP+ARP technology, by obtaining the routing table and ARP table of network devices, identifying device types and drawing network connection relationships, generating topology maps, and updating device connection status in real time.
It achieves accurate identification of asset-network relationships, improves asset management efficiency, reduces network security threats, and enhances the monitoring and management capabilities of computer and network security.
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of network asset management, and particularly relates to a method and device for automatically identifying network relationship of assets. BACKGROUND
[0002] In practice, the asset scale of an enterprise or organization is increasingly large, and the sorting of company assets becomes increasingly difficult. Given the tediousness of manually adding assets and the easy omission of assets, automatic discovery of assets is particularly important.
[0003] In particular, for some units with high security requirements, how to timely discover the violation behaviors of users, such as arbitrary modification of internal computers, unauthorized access, information leakage, and the like, and track and collect evidence of related events is an important means to solve the security of computers and networks within an organization.
[0004] Therefore, enhancing the detection of product asset exposure and the automatic identification of network relationship of assets, and accurately and comprehensively discovering network topology are important prerequisites for effectively monitoring and managing network assets, and are also the basis for further network threat analysis. SUMMARY
[0005] In view of the above background, the present application aims to provide a method for automatically identifying network relationship of assets and a device for implementing the method. The specific technical solutions are as follows: On one hand, a method for automatically identifying network relationship of assets is provided, comprising: acquiring a routing table of a network device, If the routing type is direct connection, a subnet ARP table is scanned; a subnet is scanned according to the ARP table, a current node connection relationship is established, and scanning and detection of a subnet device are repeated for each subnet; If the routing type is indirect connection, a next-hop address of the interface is directly acquired, a current node connection relationship is established, and scanning and detection are repeated for the next-hop address.
[0006] The judgment of whether the current device is a network device comprises judgment of whether the device is a router or a switch: ① If IP forwarding (routing protocol) is present, it is determined that the routing function is enabled; ② If the number of ports is present, it is determined that a switch exists; Only ① is present, it is a router; only ② is present, it is a two-layer switch; and both ① and ② are present, it is a three-layer switch.
[0007] The connection relationship of the network device is drawn according to the IP network segment corresponding relationship by accessing the routing table of each network device through SNMP; and the subnet relationship is found through the IP and MAC corresponding relationship of the ARP table.
[0008] The topology graph is generated according to the found connection relationship and subnet relationship after the scanning or probing is completed, and the device connection condition and the front-end topology graph are updated in real time / timely.
[0009] It is judged whether the current scanned device is a network device, if yes, the device routing table is acquired, otherwise the process is ended.
[0010] On the other hand, an identification device of asset network relationship is provided, which comprises: An SNMP probing module for acquiring the routing table of the network device; An ARP probing module for finding the corresponding relationship between the device IP and MAC; A device identification module for judging whether the device is a router or switch of the network device; A network relationship drawing module for automatically generating and drawing the asset network relationship according to the detection result of the probing module.
[0011] The SNMP probing module acquires the routing table of the network device, if the routing type is direct connection, the subnet ARP table is scanned; if the routing type is non-direct connection, the next hop address of the interface is directly acquired, the current node connection relationship is established, and the scanning and probing are repeated for the next hop address.
[0012] The ARP probing module scans the subnet according to the ARP table, establishes the current node connection relationship, and repeatedly probes the subnet device for each subnet.
[0013] The device identification module judges whether the device is a network device, which comprises: ① If the device has IP forwarding (routing protocol), it is determined that the routing function is enabled; ② If the number of ports of the device is equal to the path value from the current node to the root bridge node, it is determined that the switch exists; If only ① is met, the device is a router; if only ② is met, the device is a two-layer switch; and if both ① and ② are met, the device is a three-layer switch.
[0014] The application has at least the following beneficial effects: the SNMP+ARP is used to access the routing table of each network device through the SNMP, the connection relationship of the network device is drawn according to the IP network segment corresponding relationship, and the subnet relationship is found through the IP and MAC corresponding relationship of the ARP table, so that the living assets are found and the connection relationship and asset information are identified, which is beneficial to improve the efficiency of asset security management and reduce network security threats. DETAILED DESCRIPTION
[0015] In order to make the object, technical scheme and advantages of the application clearer, the technical scheme of the application will be clearly and completely described below in combination with embodiments.
[0016] Embodiment one is an automatic identification method of asset network relationship, comprising: acquiring the routing table of a network device, If the routing type is direct connection, the subnet ARP table is scanned, the subnet is scanned according to the ARP table, the current node connection relationship is established, and the detection of the subnet device is repeated for each subnet; If the routing type is non-direct connection, the next hop address of the interface is directly acquired, the current node connection relationship is established, and the scanning detection is repeated for the next hop address.
[0017] The judgment of whether the current device is a network device comprises the judgment of whether the device is a router or a switch: ① If the device has IP forwarding (routing protocol), it is determined that the routing function is turned on; ② If the number of ports of the device is the path value from the current node to the root bridge node, that is, the number of ports from the current bridge node to the root bridge node, it is determined that the switch exists; Only ① is met, it is a router, only ② is met, it is a two-layer switch, and both ① and ② are met, it is a three-layer switch.
[0018] The SNMP+ARP is used to access the routing table of each network device through the SNMP, the connection relationship of the network device is drawn according to the IP network segment corresponding relationship, and the subnet relationship is found through the IP and MAC corresponding relationship of the ARP table.
[0019] After the scanning or detection is completed, the front-end structure is converted, and the topology graph is generated.
[0020] The device connection condition and the front-end topology graph are updated in real time / timely.
[0021] It is judged whether the scanned current device is a network device, if yes, the device routing table is acquired, otherwise, the process is ended.
[0022] Embodiment two is an identification device of asset network relationship, which comprises: SNMP detection module, for obtaining the routing table of the network device; ARP detection module, for discovering the correspondence between the device IP and MAC; Device identification module, for judging whether the device is a router or a switch; Network relationship drawing module, for automatically generating and drawing the asset network relationship according to the detection result of the detection module.
[0023] The SNMP detection module obtains the routing table of the network device, and if the routing type is direct connection, the ARP table of the subnet is scanned; if the routing type is indirect connection, the next hop address of the interface is directly obtained, the connection relationship of the current node is established, and the scanning and detection are repeated for the next hop address.
[0024] The ARP detection module scans the subnet according to the ARP table, establishes the connection relationship of the current node, and repeatedly detects the subnet device for each subnet.
[0025] The device identification module judges whether the device is a network device, including: ① If IP forwarding (routing protocol) is available, it is determined that the routing function is enabled; ② If the number of ports is available, the path value from the current node to the root bridge node is available, and the number of ports from the current bridge node to the root bridge node is available, it is determined that the switch exists; Only ① is met, it is a router; only ② is met, it is a two-layer switch; both ① and ② are met, it is a three-layer switch.
[0026] The technical scheme of the embodiment of the application described above is implemented by using SNMP+ARP, the routing table of each network device is accessed through SNMP, the connection relationship of the network device is drawn according to the IP network segment correspondence relationship; and the subnet relationship is discovered through the IP and MAC correspondence relationship of the ARP table. Thus, the living assets are found and the connection relationship and asset information are identified, which is beneficial to improve the efficiency of asset security management and reduce network security threats.
[0027] Those skilled in the art can understand that all or part of the steps in the above-mentioned embodiment method can be completed by programs instructing related hardware, and the programs can be stored in a computer readable storage medium, such as ROM / RAM, magnetic disc, optical disc, etc.
[0028] The foregoing description of the embodiments disclosed herein enables any person skilled in the art to make or use the present application. Modifications of these embodiments will occur to those skilled in the art, and all such modifications are within the scope of the present application as defined by the following claims. The claims are meant to cover all alternatives within the scope of the claims.
Claims
1. A method for automatically identifying asset network relationships, characterized in that: include: Get the routing table of the network device, If the routing type is direct connection, scan the subnet ARP table; scan the subnet according to the ARP table, establish the current node connection relationship, and repeat the detection of subnet devices for each subnet; If the route type is indirect connection, directly obtain the next hop address of the interface, establish the current node connection relationship, and repeat the scanning and detection for the next hop address.
2. The asset network relationship identification method according to claim 1, characterized in that: Determining whether the current device is a network device includes determining whether the device is a router or a switch: ① If there is IP forwarding, the routing function is determined to be enabled; ② If the number of ports minus the path value from the current node to the root bridge minus the number of ports from the current bridge node to the root bridge node equals the number of ports from the current bridge node to the root bridge node, then a switch is determined to exist. If only ① is met, it is a router; if only ② is met, it is a layer 2 switch; if both ① and ② are met, it is a layer 3 switch.
3. The asset network relationship identification method according to claim 1 or 2, characterized in that: It is implemented using SNMP+ARP. The routing table of each network device is accessed through SNMP, and the connection relationship of network devices is drawn according to the correspondence between IP segments; and the subnet relationship is discovered through the correspondence between IP and MAC in the ARP table.
4. The asset network relationship identification method according to claim 1, characterized in that: After scanning or detection is completed, it is converted into a front-end structure and a topology map is generated.
5. The asset network relationship identification method according to claim 4, characterized in that: Real-time / regular updates of device connection status and front-end topology.
6. The asset network relationship identification method according to claim 1, characterized in that: Determine whether the current device being scanned is a network device. If so, obtain the device routing table; otherwise, end.
7. An asset network relationship identification device, characterized in that: The device comprises: SNMP detection module, used to obtain the routing table of network devices; ARP detection module, used to discover the correspondence between device IP and MAC; A device identification module determines whether the device is a router or switch of a network device; The network relationship drawing module automatically generates and draws the asset network relationship according to the detection results of the detection module.
8. The asset network relationship identification device according to claim 7, characterized in that: The SNMP detection module obtains the routing table of the network device. If the routing type is direct connection, it scans the subnet ARP table; if the routing type is indirect connection, it directly obtains the next hop address of the interface, establishes the current node connection relationship, and repeats the scanning and detection for the next hop address.
9. The asset network relationship identification device according to claim 7, characterized in that: The ARP detection module scans the subnet according to the ARP table, establishes the current node connection relationship, and repeats the detection of subnet devices for each subnet.
10. The asset network relationship identification device according to claim 7, characterized in that: The device identification module determines whether the device is a network device, including: ① If there is IP forwarding (routing protocol), the routing function is enabled; ② The number of ports node - the path value from the current node to the root bridge node - the number of ports from the current bridge node to the root bridge node - determines whether a switch exists; If only ① is met, it is a router; if only ② is met, it is a layer 2 switch; if both ① and ② are met, it is a layer 3 switch.