A method and system for managing custom private network asset fingerprints

By analyzing the multidimensional changes in network access behavior and dynamically adjusting the fingerprint permission categories of private network assets, the traditional private network asset fingerprint management method solves the problems of risk isolation and permission update in rapidly changing scenarios, realizes intelligent risk identification and management, and improves the flexibility of private network asset security management.

CN121283738BActive Publication Date: 2026-06-23GUANGZHOU TRUSTMO INFORMATION SYST CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GUANGZHOU TRUSTMO INFORMATION SYST CO LTD
Filing Date
2025-10-16
Publication Date
2026-06-23

Smart Images

  • Figure CN121283738B_ABST
    Figure CN121283738B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network security, in particular to a self-defined private network asset fingerprint management method and system, which comprises the following steps: based on network access events, analyzing behavior tracks and historical modes, identifying abnormal activity paths, judging abnormal relations between asset permission groups and access actions, screening risk assets and checking permission levels, adjusting fingerprint permissions, analyzing security event aggregation conditions to identify invalid states, and detecting fingerprint behavior deviation rates through operation time sequence analysis. The application identifies path deviation and traffic anomaly by analyzing the multidimensional changes of network access behavior, comprehensively judges operation risk and permission matching conditions by combining the time sequence correlation of permission allocation and access actions, dynamically adjusts fingerprint permission categories, further identifies the abnormal state of the fingerprint in real time through the aggregation analysis of security events and operation time sequences, and realizes behavior consistency verification in the use process of the asset fingerprint.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method and system for managing custom private network asset fingerprints. Background Technology

[0002] Cybersecurity primarily involves protecting networks and information systems from attacks, tampering, unauthorized access, and other potential threats. This field encompasses multiple sub-fields, including but not limited to data encryption, identity authentication, access control, vulnerability detection, intrusion prevention, and network security monitoring. Traditional private network asset fingerprint management methods refer to assigning a unique fingerprint identifier to each asset in a private network environment for unique identification and monitoring. This typically uses static identifiers such as MAC addresses and IP addresses, and asset fingerprint management is generally achieved through fixed hardware identifiers or system configurations.

[0003] Traditional methods use static fingerprints to uniquely identify private network assets, relying on fixed attributes for fingerprint allocation. This lacks responsiveness to changes in asset access behavior and dynamic adjustments to permissions. In actual management, when assets experience frequent behavior switching, abnormal access traffic, or short-term permission abuse, the existing fingerprint system struggles to reflect the risk status in a timely manner. This can easily lead to long-term permission stagnation, persistent validity of abnormal fingerprints, and risk exposure. Furthermore, it is difficult to promptly isolate risks and update permissions when encountering rapidly changing access scenarios, resulting in weakened asset security management capabilities in the private network environment. Summary of the Invention

[0004] The purpose of this invention is to address the shortcomings of existing technologies by proposing a management method and system for custom private network asset fingerprints.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: a method for managing custom private network asset fingerprints, comprising the following steps,

[0006] S1: Based on network access events, determine the target address switching path, compare the behavior trajectory of the same asset at each time point, examine each historical behavior pattern one by one, identify abnormal activity paths, and obtain behavior pattern deviation characteristics.

[0007] S2: Based on the deviation characteristics of the behavior pattern, analyze the actual access actions in the permission mapping control, combine the time nodes of abnormal behavior and high-privilege operation, determine the relationship between abnormality and permission distribution, and obtain the permission risk distribution index.

[0008] S3: Based on the aforementioned permission risk distribution index, filter assets that have been identified as risky, analyze the resource operation behavior of fingerprint items, compare permission categories with the current risk status, determine whether high-permission operations have exceeded the limits, automatically adjust fingerprint permission categories, and obtain fingerprint permission control parameters.

[0009] S4: Based on the fingerprint permission control parameters, determine the order of intrusion behavior, vulnerability interaction and repeated access operation events one by one, compare whether the events are clustered in the same fingerprint, mark it as an invalid state, and obtain the abnormal fingerprint marking result.

[0010] S5: Based on the abnormal fingerprint marking results, analyze the temporal correspondence between fingerprint operation time and login behavior time, determine whether the operation order and login time period are misaligned or separated, and if a deviation is detected, obtain the behavior fingerprint deviation rate.

[0011] The present invention is improved in that the behavioral pattern deviation features include path offset magnitude, abnormal access nodes, and traffic change features; the permission risk distribution indicators include risk level labels, sensitive operation types, and permission anomaly categories; the fingerprint permission control parameters include permission adjustment methods, fingerprint classification results, and permission matching status; the abnormal fingerprint marking results include fingerprint failure indicators, continuous risk alarms, and fingerprint anomaly indicators; and the behavioral fingerprint deviation rate includes time-series offset, behavioral consistency degree, and abnormal trigger frequency.

[0012] The present invention is improved in that the step of obtaining the behavioral pattern deviation feature is specifically as follows:

[0013] S111: Based on network access events, analyze the target address switching process, and by statistically analyzing the order of occurrence of each target address in a continuous time series, compare the changes in access frequency of the same asset, determine the correlation between target address switching and frequency increase or decrease, and obtain a path change trajectory record set;

[0014] S112: Based on the path change trajectory record set, analyze the data transmission volume associated with each path segment, determine the coupling mode between address switching and total data transmission volume, mark access segments that simultaneously have migration status and data fluctuations, adjust the data aggregation results, and obtain a node traffic mutation marker set.

[0015] S113: Based on the node traffic mutation marker set, compare the access segments with historical behavior trajectories, analyze the access patterns of assets in the continuous time sequence, determine the structural differences between access frequency and target switching characteristics in the trajectory distribution, identify abnormal performance of trajectory segments, and obtain behavioral pattern deviation characteristics.

[0016] The present invention is improved in that the steps for obtaining the permission risk distribution index are specifically as follows:

[0017] S211: Based on the behavioral pattern deviation characteristics, identify the fingerprint permission configuration of the corresponding asset, determine the access group distribution of the asset in the permission configuration, filter the fingerprint identifier and permission category of each access group, and integrate the correspondence between permission configuration and fingerprint information to obtain the permission grouping mapping table.

[0018] S212: Based on the permission grouping mapping table, analyze the actual access operations of each group of assets, retrieve resource acquisition failure events during the access process, determine the fingerprint identifier, resource path and response status involved in the failure events, aggregate failure records and distinguish various access anomalies to obtain a set of abnormal access events.

[0019] S213: Based on the set of abnormal access events, compare the failure events with the permission operation cycle, analyze the fingerprint permission category and operation time node of the failure events, determine whether the failure events are concentrated in the permission boundary area, adjust the correspondence structure between permission behavior and abnormal events, and obtain the permission risk distribution index.

[0020] The present invention is improved in that the step of obtaining the fingerprint permission control parameters is specifically as follows:

[0021] S311: Based on the aforementioned permission risk distribution index, filter assets whose risk status has been identified, determine the fingerprint item distribution of the corresponding asset under the access control unit, statistically analyze the resource operation behavior of each fingerprint item, classify the combination features of operation path and behavior type, and obtain a fingerprint behavior aggregation set.

[0022] S312: Based on the fingerprint behavior aggregation set, compare the fingerprint permission category with the current risk status, analyze the correspondence between permission configuration and risk identifier, determine the permission boundary associated with the resource operation scope and risk level, identify mismatched behavior segments under permission boundary conditions, and obtain permission conflict distribution items.

[0023] S313: Based on the permission conflict distribution item, analyze the allocation details corresponding to each fingerprint permission category, determine the correspondence between permission level adjustment conditions and risk status, verify the fingerprint permission field, update the permission category and fingerprint tag mapping, and obtain fingerprint permission control parameters.

[0024] The present invention is improved in that the step of obtaining the abnormal fingerprint marking result is specifically as follows:

[0025] S411: Based on the fingerprint permission control parameters, filter the security event logs of the assets with adjusted permissions, determine the time sequence of intrusion behavior, vulnerability interaction and repeated access operations in the logs, optimize the information sorting, and obtain the security event time sequence.

[0026] S412: Based on the security event time sequence, compare the concentrated distribution of various types of events, filter whether each type of event under the same fingerprint is continuous or overlapping in time period, determine the fingerprint identifier of the concentrated distribution, and obtain the fingerprint event aggregation index.

[0027] S413: Based on the fingerprint event aggregation index, analyze the degree of aggregation of each type of security event, calculate the event aggregation index, and filter out fingerprint identifiers that exceed the event aggregation benchmark reference range to obtain abnormal fingerprint marking results.

[0028] The present invention is improved in that the step of obtaining the behavioral fingerprint deviation rate is specifically as follows:

[0029] S511: Based on the abnormal fingerprint marking results, compare the temporal relationship between the fingerprint operation time and the login behavior time, determine whether the fingerprint operation occurred outside the login period or was misaligned, and filter the fingerprint data with temporal deviation between the operation and the login behavior according to the time period comparison to obtain the fingerprint operation time series.

[0030] S512: Based on the fingerprint operation time sequence, determine whether there is a deviation in fingerprint behavior, analyze the correspondence between operation time and login time, check whether the operation sequence matches the time period of login behavior, filter fingerprint data with cross-time period or separation phenomenon, and obtain fingerprint behavior time sequence deviation sequence.

[0031] S513: Based on the fingerprint behavior time sequence deviation, analyze the time deviation of each fingerprint behavior, calculate the difference between the fingerprint operation time and the login time period, and determine whether it conforms to the normal behavior pattern. If there is an abnormal deviation, obtain the behavior fingerprint deviation rate.

[0032] The present invention is improved in that the abnormal activity path refers to the access behavior flow path that is found to be different from the historical pattern after comparison, and the abnormal behavior refers to the access action that exceeds the historical behavior pattern or does not conform to the access control rules, including high-frequency access, unauthorized access and login during abnormal time periods.

[0033] A management system for custom private network asset fingerprints, the system comprising:

[0034] The behavior analysis module determines the target address switching path based on network access events, compares the behavior trajectory of the same asset at different time points, examines historical behavior patterns one by one, identifies abnormal activity paths, and obtains behavior pattern deviation characteristics.

[0035] Based on the behavioral pattern deviation characteristics, the permission determination module analyzes the actual access actions in permission mapping control, combines the time nodes of abnormal behavior and high-privilege operations to determine the relationship between anomalies and permission distribution, and obtains permission risk distribution indicators.

[0036] Based on the permission risk distribution index, the permission control module filters assets that have been identified as risky, analyzes the resource operation behavior of fingerprint items, compares the permission category with the current risk status, determines whether high-privilege operations have exceeded the boundaries, automatically adjusts the fingerprint permission category, and obtains fingerprint permission control parameters.

[0037] Based on the fingerprint permission control parameters, the event recognition module judges the order of intrusion behavior, vulnerability interaction and repeated access operation events one by one, compares whether the events are clustered in the same fingerprint, marks them as invalid, and obtains the abnormal fingerprint marking result.

[0038] Based on the abnormal fingerprint marking results, the timing discrimination module analyzes the temporal correspondence between the fingerprint operation time and the login behavior time, and determines whether the operation order and the login period are misaligned or separated. If a deviation is detected, the behavior fingerprint deviation rate is obtained.

[0039] Compared with the prior art, the advantages and positive effects of the present invention are as follows:

[0040] In this invention, by analyzing the multidimensional changes in network access behavior, path deviations and traffic anomalies are identified. By combining the temporal correlation between permission allocation and access actions, a comprehensive judgment is made on the operational risks and permission matching, and the fingerprint permission categories are dynamically adjusted. Furthermore, through the aggregation analysis of security events and operation sequences, abnormal fingerprint states are marked in real time, realizing the behavioral consistency verification during the use of asset fingerprints. This enables the linkage and adaptive control of fingerprints with actual asset behavior, permission distribution, and security events, supporting rapid identification and intelligent control of risky behaviors in complex access scenarios, and improving the flexibility and intelligence level of private network asset fingerprint management. Attached Figure Description

[0041] Figure 1 This is a flowchart of the main steps of the present invention;

[0042] Figure 2 This is a flowchart illustrating the process of obtaining behavioral pattern deviation features in this invention.

[0043] Figure 3 This is a flowchart illustrating the process of obtaining the permission risk distribution index in this invention.

[0044] Figure 4 This is a flowchart illustrating the process of obtaining fingerprint permission control parameters in this invention.

[0045] Figure 5 This is a flowchart illustrating the process of obtaining abnormal fingerprint marking results in this invention.

[0046] Figure 6 This is a flowchart illustrating the process of obtaining behavioral fingerprint deviation rate in this invention. Detailed Implementation

[0047] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0048] In the description of this invention, it should be understood that the terms "length," "width," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," and "outer," etc., indicating orientation or positional relationships, are based on the orientation or positional relationships shown in the accompanying drawings and are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, in the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0049] Example

[0050] Please see Figure 1 This invention provides a technical solution: a method for managing custom private network asset fingerprints, comprising the following steps:

[0051] S1: Based on network access events, analyze the continuous changes in access frequency, determine the path change trend presented by the target address switching, combine the correlation between the changes in data transmission volume, trace and compare the behavior trajectory of the same asset at each timestamp, identify abnormal activity paths and obtain the deviation characteristics of behavior patterns by comparing historical behavior patterns with current behavior trajectories one by one.

[0052] S2: Based on the deviation characteristics of the behavior pattern, determine the access group of the corresponding asset within the fingerprint permission allocation, analyze the actual access actions of each asset in the permission mapping control, and determine the relationship between abnormal events and permission distribution by analyzing the interaction between the time nodes of abnormal behavior and the time nodes of high-privilege operations based on each resource acquisition failure event during the access period, thereby obtaining the permission risk distribution index.

[0053] S3: Based on the permission risk distribution index, screen assets that have been identified as risky, analyze the resource operation behavior of fingerprint items under the access control unit, compare the fingerprint permission category with the current risk status, and check the permission level item by item in combination with the permission allocation rules to determine whether the high-permission operation exceeds the permission limit corresponding to the risk. If the permission does not match, the fingerprint permission category is automatically adjusted to obtain the fingerprint permission control parameters.

[0054] S4: Based on fingerprint permission control parameters, analyze the security event records of assets with adjusted permissions. By judging the order of occurrence of intrusion behavior, vulnerability interaction and repeated access operation events one by one, compare whether each event is concentrated in the same asset fingerprint. If multiple types of security events continue to gather in the fingerprint, it is marked as an invalid state, and the abnormal fingerprint marking result is obtained.

[0055] S5: Based on the abnormal fingerprint marking results, compare the asset fingerprint usage process that has met the judgment requirements, analyze the temporal correspondence between fingerprint operation time and login behavior time, and determine whether the operation order is misaligned or separated from the login period. If an abnormal deviation between fingerprint behavior and login behavior is detected, the behavior fingerprint deviation rate is obtained.

[0056] Behavioral pattern deviation characteristics include path offset magnitude, abnormal access nodes, and traffic change characteristics; permission risk distribution indicators include risk level labels, sensitive operation types, and permission anomaly categories; fingerprint permission control parameters include permission adjustment methods, fingerprint classification results, and permission matching status; abnormal fingerprint marking results include fingerprint failure indicators, continuous risk alarms, and fingerprint anomaly indicators; and behavioral fingerprint deviation rate includes temporal offset, behavioral consistency degree, and abnormal trigger frequency.

[0057] In S1, continuous change in access frequency refers to the number of network accesses, intervals, and trends of a certain asset (such as a server, terminal, or network device) within a unit of time in the private network. Dynamic monitoring of behavioral pattern changes is achieved through statistics on access events over a continuous period. Path change trend refers to the flow characteristics of access target addresses (such as IP, port, and URL) over time, focusing on trajectory analysis of switching from one target to another to detect abnormal changes in access destinations. Correlation refers to the relationship between parameters such as data transmission volume, target address, and access actions between access events at different times, reflecting the consistency or abrupt changes in behavior between consecutive events. Assets refer to all assets within the security management scope of the private network environment. Network physical devices, including but not limited to servers, switches, terminals, industrial control equipment, etc.; behavioral trajectory refers to the complete path record formed by arranging all network access events of the asset at different points in time in chronological order, used for subsequent behavior association and tracing; source comparison refers to comparing the current network access behavior trajectory with the previous historical behavior trajectory item by item at the event level to identify whether there are new patterns that do not conform to historical patterns; historical behavior pattern refers to the normal behavior patterns, templates or paradigms summarized from the access frequency, target flow, data characteristics, etc. of the asset in the past time period; abnormal activity path refers to the access behavior flow path that is found to be significantly different from the historical pattern after comparison (such as abnormal jump, abnormal traffic, etc.), reflecting suspicious or dangerous actions of the asset.

[0058] In S2, the access group within fingerprint permission allocation refers to the set of network access permissions assigned to different assets and accounts according to security policies in fingerprint management. Each group corresponds to a type of access capability. Permission mapping control refers to the control mechanism that manages the correspondence between permissions and asset behavior, ensuring that asset behavior matches its authorized operation scope. Actual access actions refer to every network operation behavior generated by the asset in actual operation, including quantifiable events such as login, reading, writing, and transmission. Resource acquisition failure events refer to events where the asset fails to complete the operation when attempting to access a network resource (such as authentication failure, unauthorized access, resource non-response, etc.). Abnormal behavior refers to access actions that exceed historical behavior patterns or do not conform to permission control rules, including high-frequency access, unauthorized access, and login during abnormal time periods. High-privilege operation time nodes refer to the specific time points when the high-level permissions assigned to the asset are actually used, used for cross-analysis to determine whether the abnormal behavior occurred during a high-privilege operation phase. The relationship between the abnormal event frequency and timing and the distribution characteristics of the permission groups held by the asset reflects the degree of matching or deviation between abnormal behavior and permission authorization.

[0059] In S3, risk-identified assets refer to private network assets detected in the previous process as exhibiting risky behavior characteristics, abnormal permission distribution, or security alarms; access control units refer to system functional units used to manage, restrict, and record asset network access permissions, operational scope, and security policies; fingerprint item resource operation behavior refers to all resource access, operation, and call records performed by a certain asset fingerprint (i.e., identity identifier, credential) in the private network; fingerprint permission category refers to the specific permission level assigned to the fingerprint by the system, such as read-only, read-write, administrator, etc., which determines the range of resources the fingerprint can access and the operational capabilities; current risk status refers to the asset's status as normal, warning, risk, dangerous, etc., marked in real time based on its recent behavior and security monitoring results; permission allocation details refer to the detailed rules and standards on how permissions are granted, adjusted, and revoked; item-by-item verification refers to reviewing and verifying each permission category actually held by the asset against the permission allocation details; the permission limit corresponding to risk refers to the maximum range of permissions that the asset is allowed to hold or operate under different risk states, which is the mapping boundary between permissions and risk levels.

[0060] In S4, security event logs refer to all event logs related to asset security that are automatically recorded by the system, including but not limited to intrusion, abnormal operations, and vulnerability exploitation; intrusion behavior refers to unauthorized access, attack attempts, malicious operations, and other illegal intrusion actions against assets; vulnerability interaction refers to the interaction records between assets or systems and external attackers through vulnerabilities, such as launching attacks or obtaining data by exploiting known vulnerabilities; repeated access operations refer to repeatedly launching the same or similar resource access requests within a short period of time, reflecting security risks such as automated attacks and abnormal scripts; concentration on the same asset fingerprint means that security events all occur on the asset corresponding to the same fingerprint (i.e., identity credential, unique asset identifier), focusing on event attribution; continuous clustering on the fingerprint means that multiple security events occur continuously and intensively on the asset fingerprint in time, reflecting that the fingerprint is continuously in an abnormal state; invalid state means that the system marks the fingerprint as invalid or dangerous, automatically triggering restrictions, disabling, or subsequent security measures.

[0061] In S5, the asset fingerprint usage process refers to the complete recording of all network behaviors performed by an asset using a specific fingerprint, including nodes such as login, operation, and logout; fingerprint operation time refers to the system recording time when the fingerprint is used for actual operation, used for behavior analysis and time sequence comparison; time sequence correspondence refers to the corresponding structure between the fingerprint operation time and the user login behavior time, such as sequence, overlap, and separation; operation order refers to the order in which the fingerprint operation and login behavior actually occur; misalignment or interval separation refers to abnormal sequence or long-term separation between the fingerprint operation time and the login behavior time; abnormal deviation refers to abnormal time sequence, usage patterns, etc., discovered through comparison, which differ from the normal behavior model.

[0062] Please see Figure 2 The specific steps for obtaining behavioral pattern deviation features are as follows:

[0063] S111: Based on network access events, analyze the target address switching process, and by statistically analyzing the order of occurrence of each target address in a continuous time series, compare the changes in access frequency of the same asset, determine the correlation between target address switching and frequency increase or decrease, and obtain a path change trajectory record set;

[0064] Extract the target address field corresponding to each access record in the log, and extract the access timestamp, source asset identification information, and access action type fields. Group the access events according to the asset identification field, and sort them in ascending order of timestamp within each group to form a sequence of access behaviors for that asset within a continuous time period. Compare the target address field of each record after sorting to see if it has changed. Whenever the target address of two consecutive records is inconsistent, it is determined as a target address switching event. Record the switching time, the preceding and following target addresses, and their order of occurrence. Then, count the total number of access behaviors for that asset within each time period to form an access frequency sequence. At the time point of each target switching event, extract the access frequency values ​​of the two time periods before and after it. By comparing the difference, determine whether the access frequency is increasing, decreasing, or remaining basically the same. For example, one The asset was accessed 12 times between 10:00 and 10:01, and 18 times between 10:01 and 10:02, with the frequency increasing by 6 times. This was recorded as a frequency increase segment. The frequency was then combined with whether an address change occurred. If so, it was recorded as "address change accompanied by frequency increase"; otherwise, it was recorded as "frequency fluctuation without address change". To facilitate the assessment of the significance of frequency changes, a defined range for access frequency changes was set. A change exceeding 5 times / minute was considered a significant change, and less than 3 times was considered a slight change. Throughout the entire behavior sequence of an asset, a continuously sliding window was used to determine the synchronicity between each segment of frequency fluctuation and the target address change. Related switching frequency segments were recorded as path change trajectory items. Finally, all trajectory change segments of the asset within the monitoring time were aggregated to form a path change trajectory record set.

[0065] S112: Based on the path change trajectory record set, analyze the data transmission volume associated with each path segment, determine the coupling mode between address switching and total data transmission volume, mark access segments that simultaneously have migration status and data fluctuations, adjust the data aggregation results, and obtain the node traffic mutation marker set.

[0066] Iterate through the start and end times of each trajectory segment, summarizing the total upload and download data volume of all access events within that time period. Calculate the total data transmission volume generated during the change period for each path segment, and record the number of times the target address changed within that segment. When a trajectory segment experiences a significant increase or decrease in total data transmission volume while the target address changes, mark that segment as a sudden access segment. To determine whether a data change constitutes a sudden change, set a data fluctuation judgment interval; for example, a data change exceeding 500KB is considered a significant change. Compare the data volume in a path segment with the preceding and following time periods. If the current segment's data increases by 600KB and two addresses are switched, it indicates that the path change is accompanied by an increase in traffic, satisfying the sudden change condition. If only the address is switched and the data changes by 150KB, it does not constitute a mutation. Such segments are filtered out. Segments that show both drastic data changes and target address switching are retained as node traffic mutation items. To avoid misidentification, segments with fluctuations below 200KB and fewer than one target switch are uniformly removed. In the updated record set, only those trajectory behaviors that are accompanied by drastic changes in data volume during target address migration are retained. For example, if an asset switches from address A to address B between 11:00 AM and 11:05 AM, and the data upload volume surges from 300KB to 1100KB, with one switch and a fluctuation of 800KB, this segment is marked as a node traffic mutation segment and added to the node traffic mutation marker set.

[0067] S113: Based on the node traffic mutation marker set, compare access segments with historical behavior trajectories, analyze the access patterns of assets in the continuous time sequence, determine the structural differences between access frequency and target switching characteristics in the trajectory distribution, identify abnormal performance of trajectory segments, and obtain behavioral pattern deviation characteristics.

[0068] For each mutation segment, matching is performed based on time period, access target, and asset ID. Access trajectory data for the corresponding time period of the asset is retrieved from the historical behavior database. A regular behavior template for the asset within the same time window is established on a daily or weekly basis. The number of common target addresses, average access frequency, and average data transmission rate from past accesses are extracted to construct a reference trajectory for comparison. For example, in the same time period over the past 7 working days, asset X had an average access frequency of 11 times / minute, an average of 1 target address switching, and an average data transmission volume of 900KB. In the current mutation segment, if the access frequency is 17 times / minute and 3 target addresses are switched... The total transmission volume is 1450KB. The frequency increased by 6 times, the target switching increased by 2 times, and the data increased by 550KB. It is determined that this behavior deviates significantly from the historical data. Based on the set reference standard deviation range, if the frequency changes more than 3 times, the number of addresses increases by more than 1 time, and the data fluctuation exceeds 500KB, it constitutes an abnormal trajectory segment, which is marked as a behavior pattern deviation segment. The specific dimensions of the deviation are recorded. In the entire behavior sequence, if the asset has 3 trajectory deviation items within a certain continuous time period, they are integrated and recorded in the behavior pattern deviation feature to form an identification mark that the current asset has an abnormal trajectory within the specified time range, and is included in the behavior pattern deviation feature record set.

[0069] Please see Figure 3 The specific steps for obtaining the permission risk distribution indicator are as follows:

[0070] S211: Based on behavioral pattern deviation features, identify the fingerprint permission configuration of the corresponding asset, determine the distribution of the access group of the asset in the permission configuration, filter the fingerprint identifier and permission category of each access group, and integrate the correspondence between permission configuration and fingerprint information to obtain the permission grouping mapping table.

[0071] The system reads recorded abnormal behavior trajectories, locates the unique asset identifier corresponding to each abnormal record, and then retrieves the fingerprint configuration record for that asset from the permission configuration database. It extracts the permission type field, fingerprint category label, and permission allocation time period parameter for that fingerprint. In the access group configuration data table, it determines the access group number to which the fingerprint belongs by matching the fingerprint identifier field. It then extracts the permission boundary setting value and permission level definition value corresponding to that access group. If a fingerprint exists in multiple access groups simultaneously, it is matched first according to the permission coverage priority from high to low, and the access group with the highest priority is taken as the current permission group for that fingerprint. Within the assigned group, it further filters out currently valid fingerprint identifiers, discarding fingerprints with the status of "expired," "cancelled," or "frozen." Only fingerprint records with a status of "active" or "enabled" are retained. At the same time, fingerprints are classified and labeled according to the permission type field of the access group. For example, if an asset fingerprint has a permission type of "read-write control" in the "production network management group" and a permission type of "read-only audit" in the "data audit group", the former is given priority and its permission level is recorded as "medium+". Then, all valid fingerprint identifiers in each access group are mapped one by one with their corresponding permission types. This mapping relationship is archived according to the asset number to form an integrated record of permission configuration to fingerprint identifier. The fingerprint and permission configuration correspondence results of all assets in each access group are summarized and formatted according to the access group number, fingerprint ID, permission level, and enabled status, etc., to build a permission group mapping table.

[0072] S212: Based on the permission grouping mapping table, analyze the actual access operations of each group of assets, retrieve resource acquisition failure events during the access process, determine the fingerprint identifier, resource path and response status involved in the failure events, aggregate failure records and distinguish various access anomalies to obtain a set of abnormal access events.

[0073] The fingerprint assets within each access group are processed sequentially. Access behavior logs for the specified time period are read, all access action records are extracted, and access response field values ​​are retrieved one by one. It is determined whether the response field indicates a failure status. Common failure statuses include authentication failure, insufficient permissions, resource unreachable, and access denied. By comparing access result fields, records with status codes between 400-499 or 500-599 are selected as resource acquisition failure events. Simultaneously, the fingerprint identifier, the attempted resource path field, the resource type field, and the request time information corresponding to this failure event are extracted. When aggregating multiple failure events, the fingerprint identifier is used as the primary key for classification and statistics. The number of failures for each fingerprint is counted, and the resource path and resource type categories where failure events are concentrated are recorded. For example... An asset with fingerprint ID FA001 recorded 16 authentication failure events between May 1, 2024 and May 5, 2024. Twelve of these failures occurred under the access path " / data / sensitive / ", with the resource type being database forms. The primary failure type was "no permission to read," and the remaining four were "access timeouts." This fingerprint's abnormal access records are aggregated as "high-frequency failures," and the primary anomaly type is marked as "insufficient permissions." If a fingerprint experiences failure events under multiple resource paths, the failure reasons are further categorized and labeled by resource path. Each type of access failure record is divided into three main categories: permission errors, target errors, and system errors. Detailed information such as the time, frequency, resource path, resource type, and response status code of each type of failure event is recorded to form an abnormal access event set.

[0074] S213: Based on the set of abnormal access events, compare the failure events with the permission operation cycle, analyze the fingerprint permission category and operation time node of the failure events, determine whether the failure events are concentrated in the permission boundary area, adjust the correspondence structure between permission behavior and abnormal events, and obtain the permission risk distribution index.

[0075] The system sequentially reads the permission operation records corresponding to each failure event, extracting the permission allocation time, permission activation time, and the time point of the failure event to construct a permission operation cycle timeline. If the time interval between the fingerprint activation time and the failure event is less than 24 hours, it is marked as "new permission failure"; if the interval exceeds 72 hours, it is marked as "persistent permission anomaly". The system then compares the fingerprint's permission level with the sensitivity level of the accessed resource. If the permission level is lower than the resource sensitivity level, it is determined as a permission overreach attempt, and this behavior type is recorded as "insufficient permission failure". Subsequently, the failure times are clustered by hour. If failure events are concentrated in the time period of the permission level edge value, i.e., within 24 hours before and after the permission configuration is adjusted, the clustering is considered successful. Within this framework, the failed behavior is recorded as a "boundary concentration event." For example, if a fingerprint obtains "read and write" permissions on May 3rd and experiences 7 failed access attempts between 0:00 and 6:00 on May 4th, 5 of which are write operations with no response, it indicates that the fingerprint highly overlaps with the permission boundary and is marked as a "boundary segment risk event." After archiving all such events, the proportion of boundary concentration failure events to all failure events is calculated. If the proportion exceeds 30%, the access group corresponding to the fingerprint is set as "high risk of permission boundary." If the proportion is less than 10%, it is "low risk distribution." Based on this classification principle, the fingerprint permission category, failure event type, time concentration, and other dimensions are structurally combined to obtain the permission risk distribution index.

[0076] Please see Figure 4 The specific steps for obtaining fingerprint permission control parameters are as follows:

[0077] S311: Based on the permission risk distribution index, filter assets with identified risk status, determine the fingerprint item distribution of the corresponding asset under the access control unit, count the resource operation behavior of each fingerprint item, classify the combination features of operation path and behavior type, and obtain fingerprint behavior aggregation set.

[0078] Retrieve the list of assets marked as risky, filter out all assets currently in the "Warning," "Risk," or "Danger" status, and their corresponding fingerprint identifiers. Locate all fingerprint entries for each asset in the access control unit, and obtain the activation status, most recent access time, assigned permission type, and resource operation log index for each fingerprint entry. Search the resource operation log for each fingerprint's network access behavior, extracting the operation action field and access path field. Count the total number and type of operations performed by each fingerprint under different resource paths. For example, fingerprint IDA01 performed 32 operations on the path " / confidential / data," including 14 write operations and 18 read operations. Combine this type of resource path and operation behavior into "read / write / confidential / data". The "al / data" operation feature is used. If this feature appears repeatedly on other fingerprints, its frequency is counted and combinations appearing more than 20 times are marked as "high-frequency features". All operation path and behavior type combinations are categorized and processed. All path-behavior combinations are aggregated according to fingerprint ID to form the behavior feature set of the fingerprint. At the same time, a frequency label is added to each combination to divide it into high-frequency, medium-frequency, and low-frequency operation segments. The frequency is greater than 30 times, which is high-frequency, 10 to 30 times is medium-frequency, and less than 10 times is low-frequency. In this way, a complete description of the access behavior of each fingerprint is formed. For example, fingerprint B35 accessed 7 resource paths and involved 5 types of operation within three days. After aggregation, a total of 21 path-behavior combination entries are obtained. The fingerprint behavior sets of all risk assets are integrated to construct the fingerprint behavior aggregation set.

[0079] S312: Based on the fingerprint behavior aggregation set, compare the fingerprint permission category with the current risk status, analyze the correspondence between permission configuration and risk identifier, determine the permission boundary associated with the resource operation scope and risk level, identify mismatched behavior fragments under permission boundary conditions, and obtain permission conflict distribution items.

[0080] The system reads the permission category information for each fingerprint, determining whether its current permission level is read-only, read-write, control, or management. It then compares this with the path-operation characteristics in the behavior aggregation set, comparing the fingerprint's execution scope with its permission category. For example, if a fingerprint with a "read-only" permission category performs "write" or "delete" operations, it is immediately marked as having incompatible permissions. Simultaneously, it reads the fingerprint's current risk status label, determining whether it is "medium risk" or "high risk." If the current risk status is high risk but the permission category is still management, the fingerprint is marked as "risk exceeding authority." The system then performs a joint match between the permission category field and the risk level field to construct a permission-risk matching structure table and sets permission boundary thresholds. For example, the maximum permission in the "high-risk" state is restricted to "read and write". If the fingerprint's current permission is "control" or "management", it is considered an out-of-bounds permission. The sensitivity level of the resource path is analyzed item by item during the comparison. For example, resources with fields such as " / secure", " / admin", and " / root" are defined as high-sensitivity paths. Behaviors of low-to-medium permissions accessing high-sensitivity paths are recorded. Then, such behaviors are grouped together and identified as permission conflict behavior segments. For example, if the fingerprint IDC07's current permission category is "read and write", but six configuration change operations have been performed on the " / admin / settings" path, then this segment is marked as permission out-of-bounds access. All the identified abnormal permission accesses are grouped and organized into the permission conflict distribution item.

[0081] S313: Based on the permission conflict distribution item, analyze the allocation details corresponding to each fingerprint permission category, determine the correspondence between permission level adjustment conditions and risk status, verify the fingerprint permission field, update the permission category and fingerprint tag mapping, and obtain the fingerprint permission control parameters.

[0082] The system reads the current permission category for each fingerprint and compares it with the preset permission allocation rules in the permission configuration table. For example, rules might specify that "read-only permissions cannot be written to sensitive paths" or "management permissions are only assigned to zero-risk assets." When reviewing each fingerprint's permission, the system checks whether its corresponding risk level field violates the rules. If not, it determines that the permission level and risk status do not match. All mismatched records are extracted, and the upper and lower limit control parameters in the permission adjustment condition field are analyzed. For example, if a fingerprint's risk level is "high" but its permission is "control," then according to the permission adjustment rules, it should be downgraded to "read-only." This adjustment relationship is written to the list to be updated, and then the fingerprint tag configuration table is read again. Update the current fingerprint's permission fields to the adjusted permission category, and modify the "permission level" field value in its label. Record the time, reason, original permissions, and new permission content of this adjustment. If a fingerprint has multiple permission overreach behaviors, perform cumulative calculation. Each permission conflict is counted as a risk behavior. If the cumulative number of conflicts exceeds 5, it will be forcibly updated to the lowest permission level. The threshold of 5 times is set as the upper limit of risk behavior based on the default configuration and can be adjusted according to the asset level. For example, the threshold is set to 3 times for level 1 core assets and 7 times for level 3 peripheral assets. Integrate the updated permission categories, label fields, and adjustment records of all fingerprints to form fingerprint permission control parameters.

[0083] Please see Figure 5 The specific steps for obtaining abnormal fingerprint marking results are as follows:

[0084] S411: Based on fingerprint permission control parameters, filter security event logs of assets with adjusted permissions, determine the time sequence of intrusion behavior, vulnerability interaction and repeated access operations in the logs, optimize information sorting, and obtain a security event time sequence.

[0085] Filter out all assets whose permission levels have been adjusted within the past 24 hours or a specified period. Read the security event logs for these assets within 48 hours before and after the adjustment. Extract the fingerprint ID, event type, target resource path, operation timestamp, and response result fields for each event in the logs. Categorize and summarize the event types according to "Intrusion Behavior," "Vulnerability Interaction," and "Repeated Access Operations." Sort each type of event by time field to construct an initial event time list. During the sorting process, compare the time difference between any two events with second-level precision. If the time difference is less than 10 seconds, it is classified as an adjacent event segment; if the difference is between 10 and 60 seconds, it is considered a short-term continuous event segment; if the difference exceeds 60 seconds, it is defined as an independent event segment. Intrusion behaviors are analyzed to extract keywords such as "illegal login," "port scanning," and "session hijacking." Vulnerability interactions are analyzed to extract keywords such as "remote code execution," "privilege escalation exploitation," and "database injection attempt." Repeated operation behaviors are analyzed to determine whether the same target resource is accessed more than 3 times consecutively within 5 minutes. If so, it is marked as a repeated behavior event. All events are then sorted in ascending order by timestamp to generate a full security event sequence list corresponding to the asset's fingerprint. After sorting, each record is labeled with an event type, original log ID, source address, and resource path. The output view includes both event type and timestamp fields to construct a security event time sequence for subsequent analysis to determine continuity and aggregation.

[0086] S412: Based on the time sequence of security events, compare the concentrated distribution of various types of events, filter whether each type of event under the same fingerprint is continuous or overlapping in time period, determine the fingerprint identifier of the concentrated distribution, and obtain the fingerprint event aggregation index.

[0087] Read all types of security event records corresponding to each fingerprint, and perform sliding window processing on the event timestamps. Set the window size to 15 minutes, and judge the occurrence frequency of each type of event within the window one by one. Calculate the distribution density of each type of event within the time period. For example, if fingerprint IDD44 has 4 intrusion behaviors, 3 vulnerability interactions, and 5 repeated access behaviors between 13:00 and 13:15, this segment is marked as a "high-density cluster segment". Set the density judgment threshold as ≥3 occurrences of each type of event within the window to be high density. If only one type meets the condition, it is marked as "single-type cluster". If two or more types meet the condition, it is marked as "multi-type cluster". Then, determine whether the events are generated by the same fingerprint. If so, record that fingerprint as a concentrated distribution fingerprint. When judging continuous or overlapping cluster segments, if the time difference between the occurrence of events in two adjacent windows is less than 1 minute, they are merged into a continuous cluster segment. Then, it is judged whether the total duration of the cluster segment is greater than 30 minutes. If it is, the degree of clustering of the fingerprint event is marked as "continuous clustering". If it is only clustered within one time window, it is marked as "short-term clustering". At the same time, for each fingerprint identifier, the corresponding event type number, clustering duration, maximum single-type event density and other indicator fields are recorded. If the same fingerprint has more than 3 cluster segments in 6 hours, the fingerprint is marked as "clustered fingerprint". All fingerprint identifiers judged as clustered distribution are output to construct fingerprint event aggregation index, which serves as the key judgment basis for subsequent abnormal fingerprint identification.

[0088] S413: Based on fingerprint event aggregation metrics, analyze the degree of aggregation for each type of security event, using the following formula:

[0089] ;

[0090] Calculate the event clustering index And filter out fingerprint identifiers that exceed the event aggregation baseline reference range to obtain abnormal fingerprint marking results, among which, Representing the first under the same fingerprint The ratio of the time interval between two adjacent security events to the average time interval of all events in the fingerprint. This represents the total number of times each type of security event occurred under this fingerprint. This represents the frequency of the fingerprint's access in the security event sequence;

[0091] The event clustering metric measures the degree to which three types of security events (such as intrusion behavior, vulnerability interaction, and repeated access operations) occur in a security event sequence within the same asset fingerprint. This metric calculates the clustering of events in a time series under a specific fingerprint, i.e., the degree and frequency of deviation in the time interval between events, aiming to reflect the event concentration of the fingerprint. A high value indicates high event concentration and a greater likelihood of fingerprint anomalies. The event clustering baseline reference range is a standard range used to determine whether event clustering is abnormal. The baseline reference range, defined through historical data or security policy settings, specifies the range within which the event clustering of a fingerprint should fall under normal circumstances. If the calculated event clustering... If the event count exceeds this range, it indicates an abnormally high level of event clustering in the fingerprint, suggesting potential risky or malicious behavior. This baseline range helps the system identify fingerprints with excessively dense event activity, prompting further security review or automatic labeling as anomalous fingerprints.

[0092] If there are 3 different types of security events for the fingerprint "X", the original time interval and event frequency are as follows:

[0093] Event 1 (Intrusion) had an initial time interval of 30 seconds;

[0094] The original time interval for Event 2 (vulnerability interaction) was 20 seconds;

[0095] Event 3 (Repeated Operation) The original time interval was 25 seconds;

[0096] The total number of occurrences of the three types of events under this fingerprint. ;

[0097] Fingerprint call frequency ;

[0098] First, convert the time interval to dimensionless by dividing the time interval of each event by the average time interval of all events. If the average time interval of the events is 25 seconds, the calculation is as follows:

[0099] Event 1: ;

[0100] Event 2: ;

[0101] Event 3: ;

[0102] Substitute the normalized time interval values ​​into the formula to calculate the event clustering index, and calculate the weighted time interval component:

[0103] ;

[0104] Take the square root:

[0105] ;

[0106] Frequency calculation part:

[0107] ;

[0108] Obtain the event clustering index:

[0109] ;

[0110] Event clustering index Set the following interval range:

[0111] Low aggregation: This range indicates that security events under fingerprints exhibit a low degree of clustering, suggesting that the events are relatively dispersed and generally do not pose a serious risk;

[0112] Moderate aggregation: When the event clustering index If the fingerprint falls within this range, it indicates that the security incidents are somewhat concentrated and there are some security risks, but they have not yet reached a high-risk level.

[0113] High aggregation: When the fingerprint clustering index is within this range, it indicates that the event concentration under this fingerprint is high, multiple abnormal events have occurred, and the potential security risk is relatively large.

[0114] Extremely high aggregation: When the clustering index exceeds 1, it indicates that the density of security events under the fingerprint is extremely high, which means serious security problems or potential attacks, and further security review and response must be carried out immediately.

[0115] The obtained event clustering degree Falling into the high-cluster range indicates that the fingerprint "X" has a high degree of security event clustering, meaning that the density of security events occurring under this fingerprint is high and related to potential attacks or unauthorized operations. Therefore, further security review and monitoring of this fingerprint are required.

[0116] Please see Figure 6 The specific steps for obtaining the behavioral fingerprint deviation rate are as follows:

[0117] S511: Based on the abnormal fingerprint marking results, compare the temporal relationship between the fingerprint operation time and the login behavior time to determine whether the fingerprint operation occurred outside the login period or was misaligned. Based on the time period comparison, filter the fingerprint data with temporal deviation between the operation and the login behavior to obtain the fingerprint operation time series.

[0118] Retrieve all fingerprint IDs marked as abnormal and search their operation and login logs within a specified period. Extract the timestamp, resource path, and operation type fields from each operation record in the operation logs. Extract the login and logout times of the user credentials from the login logs. Perform time comparison processing on each fingerprint operation record, matching the operation time with the corresponding login time period. If the operation time is more than 10 minutes earlier than the login start time or later than the logout time, it is marked as "time sequence misalignment." If the operation time falls entirely within a time period with no login records, it is marked as "no session operation." To avoid misjudgment, cross-day logins are handled differently. For example, if a user logs in at 23:50 and performs an operation at 00:10 the next day, the operation is considered legitimate. If more than three consecutive operations occur within a period without login records, it is considered a serious misalignment. All fingerprint data exhibiting the above two types of time-series anomalies are filtered out, and their fingerprint ID, operation time, corresponding invalid login segment, resource path, and operation type are recorded. Then, these records are sorted by operation time to construct a time-series view, and grouped by fingerprint ID to output the fingerprint operation time series for subsequent deviation behavior detection.

[0119] S512: Based on the fingerprint operation time series, determine whether there is a deviation in fingerprint behavior, analyze the correspondence between operation time and login time, check whether the operation sequence matches the time period of login behavior, filter fingerprint data with cross-time period or separation phenomenon, and obtain fingerprint behavior time series deviation sequence.

[0120] The system sequentially reads all operation records of each fingerprint within a specific time period. Each operation time is matched against its closest login time period to determine if a match exists. If the operation time and login time completely overlap, it is considered normal. If there is a time difference that is outside the preset tolerance range, it is recorded as a "deviation behavior." The tolerance range is set to ±5 minutes, meaning an operation time more than 5 minutes earlier than the login start time or more than 5 minutes later than the logout time is considered a mismatch. All mismatched operation records are aggregated, and the cumulative number and duration of mismatched operations for each fingerprint within 24 consecutive hours are analyzed. For example, if fingerprint IDE78 has 5 operation times more than 40 minutes later than the login time within a day, with a cumulative deviation duration of 190 minutes, this fingerprint is marked as "cross-time period deviation." The system then counts whether the fingerprint continuously performs operations during periods without login records. If continuous operations exceed 2 hours or the number of operations exceeds 8, it is judged as "time sequence separation." All fingerprints exhibiting the above behaviors are output together to form a fingerprint behavior time sequence deviation sequence. The output records the start and end times of each deviation behavior, the deviation in minutes, the associated resource path, and the corresponding fingerprint ID.

[0121] S513: Based on the fingerprint behavior time-series deviation sequence, analyze the time-series deviation of each fingerprint behavior, calculate the difference between the fingerprint operation time and the login time period, determine whether it conforms to the normal behavior pattern, and if there is an abnormal deviation, obtain the behavior fingerprint deviation rate.

[0122] For each deviation record, the difference between the operation time and the login time period is read. If the difference is within ±5 minutes, it is defined as normal; if the difference is between ±6 and ±30 minutes, it is marked as "minor deviation"; and if the difference exceeds 30 minutes, it is defined as "major deviation". All operations of each fingerprint are divided into these ranges. The number of deviations for each type is counted and summed. The cumulative duration and frequency of minor and major deviations are calculated. Then, the normal behavior pattern records of the asset to which the fingerprint belongs are retrieved from the historical behavior database. The distribution of its operation and login times over the past 7 days is read, and its historical average deviation is calculated. The deviation time and standard offset are calculated. If the deviation between the current deviation record and the historical average is greater than twice the historical standard offset, it is judged as an "abnormal behavior pattern". For example, if the average deviation of a fingerprint is 4 minutes and the standard offset is 3 minutes, and the current deviation is 18 minutes, it is classified as an abnormal deviation item. Then, the deviation behavior ratio of each fingerprint is calculated in turn, and a deviation rate range standard is set. Among them, the deviation behavior ratio exceeding 30% is "moderate deviation" and exceeding 60% is "severe deviation". The fingerprint ID, deviation number, cumulative deviation duration and deviation level label are output to obtain the behavioral fingerprint deviation rate.

[0123] A management system for custom private network asset fingerprints, the system comprising:

[0124] The behavior analysis module determines the target address switching path based on network access events, compares the behavior trajectory of the same asset at different time points, examines historical behavior patterns one by one, identifies abnormal activity paths, and obtains behavior pattern deviation characteristics.

[0125] The permission determination module analyzes the actual access actions in permission mapping control based on behavioral pattern deviation characteristics, and determines the relationship between anomalies and permission distribution by combining the time nodes of abnormal behavior and high-privilege operations, thereby obtaining permission risk distribution indicators.

[0126] The access control module uses access risk distribution indicators to filter assets with identified risks, analyzes the resource operation behavior of fingerprint items, compares the access category with the current risk status, determines whether high-access operations have exceeded the limits, automatically adjusts the fingerprint access category, and obtains fingerprint access control parameters.

[0127] The event recognition module, based on fingerprint permission control parameters, judges the order of intrusion behavior, vulnerability interaction and repeated access operation events one by one, compares whether the events are clustered in the same fingerprint, marks them as invalid, and obtains the abnormal fingerprint marking result.

[0128] The timing discrimination module analyzes the temporal correspondence between fingerprint operation time and login behavior time based on the abnormal fingerprint marking results, and determines whether the operation order and login time period are misaligned or separated. If a deviation is detected, the behavior fingerprint deviation rate is obtained.

[0129] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention in any other way. Any person skilled in the art may make changes or modifications to the above-disclosed technical content to create equivalent embodiments that can be applied to other fields. However, any simple modifications, equivalent changes, and modifications made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the protection scope of the present invention.

Claims

1. A method for managing custom private network asset fingerprints, characterized in that, Includes the following steps: S1: Based on network access events, determine the target address switching path, compare the behavior trajectory of the same asset at each time point, examine each historical behavior pattern one by one, identify abnormal activity paths, and obtain behavior pattern deviation characteristics. S2: Based on the deviation characteristics of the behavior pattern, analyze the actual access actions in the permission mapping control, combine the time nodes of abnormal behavior and high-privilege operation, determine the relationship between abnormality and permission distribution, and obtain the permission risk distribution index. S3: Based on the aforementioned permission risk distribution index, filter assets that have been identified as risky, analyze the resource operation behavior of fingerprint items, compare permission categories with the current risk status, determine whether high-permission operations have exceeded the limits, automatically adjust fingerprint permission categories, and obtain fingerprint permission control parameters. S4: Based on the fingerprint permission control parameters, determine the order of intrusion behavior, vulnerability interaction and repeated access operation events one by one, compare whether the events are clustered in the same fingerprint, mark it as an invalid state, and obtain the abnormal fingerprint marking result. S5: Based on the abnormal fingerprint marking results, analyze the temporal correspondence between fingerprint operation time and login behavior time, determine whether the operation order and login time period are misaligned or separated, and if a deviation is detected, obtain the behavior fingerprint deviation rate.

2. The method for managing custom private network asset fingerprints according to claim 1, characterized in that, The behavioral pattern deviation features include path offset magnitude, abnormal access nodes, and traffic change features. The permission risk distribution indicators include risk level labels, sensitive operation types, and permission anomaly categories. The fingerprint permission control parameters include permission adjustment methods, fingerprint classification results, and permission matching status. The abnormal fingerprint marking results include fingerprint failure identifiers, continuous risk alarms, and fingerprint anomaly identifiers. The behavioral fingerprint deviation rate includes time-series offset, behavioral consistency degree, and abnormal trigger frequency.

3. The method for managing custom private network asset fingerprints according to claim 1, characterized in that, The specific steps for obtaining the behavioral pattern deviation features are as follows: S111: Based on network access events, analyze the target address switching process, and by statistically analyzing the order of occurrence of each target address in a continuous time series, compare the changes in access frequency of the same asset, determine the correlation between target address switching and frequency increase or decrease, and obtain a path change trajectory record set; S112: Based on the path change trajectory record set, analyze the data transmission volume associated with each path segment, determine the coupling mode between address switching and total data transmission volume, mark access segments that simultaneously have migration status and data fluctuations, adjust the data aggregation results, and obtain a node traffic mutation marker set. S113: Based on the node traffic mutation marker set, compare the access segments with historical behavior trajectories, analyze the access patterns of assets in the continuous time sequence, determine the structural differences between access frequency and target switching characteristics in the trajectory distribution, identify abnormal performance of trajectory segments, and obtain behavioral pattern deviation characteristics.

4. The method for managing custom private network asset fingerprints according to claim 1, characterized in that, The specific steps for obtaining the permission risk distribution index are as follows: S211: Based on the behavioral pattern deviation characteristics, identify the fingerprint permission configuration of the corresponding asset, determine the access group distribution of the asset in the permission configuration, filter the fingerprint identifier and permission category of each access group, and integrate the correspondence between permission configuration and fingerprint information to obtain the permission grouping mapping table. S212: Based on the permission grouping mapping table, analyze the actual access operations of each group of assets, retrieve resource acquisition failure events during the access process, determine the fingerprint identifier, resource path and response status involved in the failure events, aggregate failure records and distinguish various access anomalies to obtain a set of abnormal access events. S213: Based on the set of abnormal access events, compare the failure events with the permission operation cycle, analyze the fingerprint permission category and operation time node of the failure events, determine whether the failure events are concentrated in the permission boundary area, adjust the correspondence structure between permission behavior and abnormal events, and obtain the permission risk distribution index.

5. The method for managing custom private network asset fingerprints according to claim 1, characterized in that, The specific steps for obtaining the fingerprint permission control parameters are as follows: S311: Based on the aforementioned permission risk distribution index, filter assets whose risk status has been identified, determine the fingerprint item distribution of the corresponding asset under the access control unit, statistically analyze the resource operation behavior of each fingerprint item, classify the combination features of operation path and behavior type, and obtain a fingerprint behavior aggregation set. S312: Based on the fingerprint behavior aggregation set, compare the fingerprint permission category with the current risk status, analyze the correspondence between permission configuration and risk identifier, determine the permission boundary associated with the resource operation scope and risk level, identify mismatched behavior segments under permission boundary conditions, and obtain permission conflict distribution items. S313: Based on the permission conflict distribution item, analyze the allocation details corresponding to each fingerprint permission category, determine the correspondence between permission level adjustment conditions and risk status, verify the fingerprint permission field, update the permission category and fingerprint tag mapping, and obtain fingerprint permission control parameters.

6. The method for managing custom private network asset fingerprints according to claim 1, characterized in that, The specific steps for obtaining the abnormal fingerprint marking results are as follows: S411: Based on the fingerprint permission control parameters, filter the security event logs of the assets with adjusted permissions, determine the time sequence of intrusion behavior, vulnerability interaction and repeated access operations in the logs, optimize the information sorting, and obtain the security event time sequence. S412: Based on the security event time sequence, compare the concentrated distribution of various types of events, filter whether each type of event under the same fingerprint is continuous or overlapping in time period, determine the fingerprint identifier of the concentrated distribution, and obtain the fingerprint event aggregation index. S413: Based on the fingerprint event aggregation index, analyze the degree of aggregation of each type of security event, calculate the event aggregation index, and filter out fingerprint identifiers that exceed the event aggregation benchmark reference range to obtain abnormal fingerprint marking results.

7. The method for managing custom private network asset fingerprints according to claim 1, characterized in that, The steps for obtaining the behavioral fingerprint deviation rate are as follows: S511: Based on the abnormal fingerprint marking results, compare the temporal relationship between the fingerprint operation time and the login behavior time, determine whether the fingerprint operation occurred outside the login period or was misaligned, and filter the fingerprint data with temporal deviation between the operation and the login behavior according to the time period comparison to obtain the fingerprint operation time series. S512: Based on the fingerprint operation time sequence, determine whether there is a deviation in fingerprint behavior, analyze the correspondence between operation time and login time, check whether the operation sequence matches the time period of login behavior, filter fingerprint data with cross-time period or separation phenomenon, and obtain fingerprint behavior time sequence deviation sequence. S513: Based on the fingerprint behavior time sequence deviation, analyze the time deviation of each fingerprint behavior, calculate the difference between the fingerprint operation time and the login time period, and determine whether it conforms to the normal behavior pattern. If there is an abnormal deviation, obtain the behavior fingerprint deviation rate.

8. The method for managing custom private network asset fingerprints according to claim 1, characterized in that, The abnormal activity path refers to the access behavior flow path that differs from the historical pattern after comparison. The abnormal behavior refers to access actions that exceed the historical behavior pattern or do not conform to the access control rules, including high-frequency access, unauthorized access, and login during abnormal time periods.

9. A management system for custom private network asset fingerprints, characterized in that, The system is used to implement the management method for custom private network asset fingerprints as described in any one of claims 1-8, and the system includes: The behavior analysis module determines the target address switching path based on network access events, compares the behavior trajectory of the same asset at different time points, examines historical behavior patterns one by one, identifies abnormal activity paths, and obtains behavior pattern deviation characteristics. Based on the behavioral pattern deviation characteristics, the permission determination module analyzes the actual access actions in permission mapping control, combines the time nodes of abnormal behavior and high-privilege operations to determine the relationship between anomalies and permission distribution, and obtains permission risk distribution indicators. Based on the permission risk distribution index, the permission control module filters assets that have been identified as risky, analyzes the resource operation behavior of fingerprint items, compares the permission category with the current risk status, determines whether high-privilege operations have exceeded the boundaries, automatically adjusts the fingerprint permission category, and obtains fingerprint permission control parameters. Based on the fingerprint permission control parameters, the event recognition module judges the order of intrusion behavior, vulnerability interaction and repeated access operation events one by one, compares whether the events are clustered in the same fingerprint, marks them as invalid, and obtains the abnormal fingerprint marking result. Based on the abnormal fingerprint marking results, the timing discrimination module analyzes the temporal correspondence between the fingerprint operation time and the login behavior time, and determines whether the operation order and the login period are misaligned or separated. If a deviation is detected, the behavior fingerprint deviation rate is obtained.

Citation Information

Patent Citations

  • CN120200839A

  • CN120281550A