A Method, Device and Related Equipment for Identifying Risk Assets in the Intranet Based on Traffic

By obtaining response traffic data from network devices, eliminating data that does not meet the requirements, and finding target response traffic that matches the fingerprint information dictionary, the problem of long collection cycles of asset fingerprint information and untimely updates in the existing technology is solved, and efficient identification and positioning of risk assets is achieved.

CN115603954BActive Publication Date: 2025-06-24CHINA CONSTRUCTION BANK

Patent Information

Application Number
CN202211173578.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-26
Publication Date
2025-06-24
Estimated Expiration
2042-09-26

AI Technical Summary

Technical Problem

The active detection method for collecting asset fingerprint information in the prior art has the problem of long cycles and untimely updates, which affects the timely identification and positioning of risky assets.

Method used

By obtaining response traffic data from the physical interface of the network device, eliminating response traffic that does not meet the preset requirements, finding the target response traffic that matches the fingerprint information and the fingerprint information dictionary, obtaining the device IP address and associated with the fingerprint information dictionary, realizing the identification of risk assets.

Benefits of technology

This method improves the real-time collection and update efficiency of asset fingerprint information, reduces the impact on target hosts and network equipment, and enhances the ability to identify risk assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115603954B_ABST
    Figure CN115603954B_ABST
Patent Text Reader

Abstract

The present invention provides a method, device and related equipment for identifying risk assets in an intranet based on traffic. The method includes: obtaining at least response traffic containing address information and fingerprint information from the physical interface of a network device to obtain first response traffic data; removing the response traffic whose address information does not meet the preset requirements from the first response traffic data to obtain second response traffic data; finding target response traffic whose fingerprint information matches the fingerprint information dictionary from the second response traffic data; obtaining the device IP address of the target response traffic; and associating the device IP address and the fingerprint information dictionary according to the fingerprint information to obtain a risk asset identification result. The present invention performs identification based on intranet HTTP response traffic, which will not affect the target host and will not impose an additional burden on the network device; filtering the first response traffic data according to the preset requirements improves the matching efficiency between the response traffic and the fingerprint information dictionary.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet security technologies, and in particular, to a method, device, and related equipment for identifying internal network risk assets based on traffic. Background Art

[0002] With the continuous increase in the scale of enterprise internal network assets and network complexity, in asset security protection, it is required that operation personnel can timely locate the scope of assets affected by the enterprise when high-risk vulnerabilities break out in the network, and the establishment of an asset fingerprint library is indispensable for locating risk assets.

[0003] Currently, the active detection method for collecting asset fingerprint information has problems such as affecting scanning hosts and network devices, having a long interval between the collection periods of asset fingerprint information, and being updated untimely. Summary of the Invention

[0004] In view of this, embodiments of the present invention provide a method, device, and related equipment for identifying internal network risk assets based on traffic to solve the problem that the current collection period of asset fingerprint information is long and the update is untimely.

[0005] To achieve the above object, embodiments of the present invention provide the following technical solutions:

[0006] A first aspect of an embodiment of the present invention discloses a method for identifying internal network risk assets based on traffic, and the method includes:

[0007] Obtain first response traffic data from a physical interface of a network device, where the response traffic data is composed of response traffic at least including address information and fingerprint information;

[0008] Eliminate the response traffic whose address information does not meet the preset requirements from the first response traffic data to obtain second response traffic data;

[0009] Search for target response traffic whose fingerprint information matches a fingerprint information dictionary from the second response traffic data, where the fingerprint information dictionary is pre-generated based on vulnerability information;

[0010] Obtain the device IP address of the target response traffic;

[0011] Associate the device IP address and the fingerprint information dictionary according to the fingerprint information to obtain a risk asset identification result.

[0012] Preferably, the process of generating a fingerprint information dictionary based on vulnerability information includes:

[0013] Obtain first vulnerability information published by an information security vulnerability sharing platform;

[0014] Obtain second vulnerability information published by an information security vulnerability library;

[0015] The first vulnerability information and the second vulnerability information are summarized to generate a fingerprint information dictionary.

[0016] Preferably, removing the response traffic whose address information does not meet the preset requirements from the first response traffic data to obtain the second response traffic data includes:

[0017] Searching for a first response flow whose address information is a conversion address or a virtual address, or a second response flow whose status code is a preset value in the first response flow data, wherein the first response flow and the second response flow are any of the response flows;

[0018] The first response flow and the second response flow in the first response flow data are deleted to obtain second response flow data.

[0019] Preferably, searching the second response flow data for a target response flow whose fingerprint information matches a fingerprint information dictionary includes:

[0020] For each group of response traffic in the second response traffic data, determining whether fingerprint information included in the fingerprint information dictionary exists in the traffic log of the response traffic;

[0021] If the traffic log of the response traffic contains fingerprint information included in the fingerprint information dictionary, it is determined that the response traffic is the target response traffic.

[0022] A second aspect of an embodiment of the present invention discloses a flow-based intranet risk asset identification device, the device comprising:

[0023] A first acquisition unit, configured to acquire first response flow data from a physical interface of the network device, wherein the response flow data is composed of response flow including at least address information and fingerprint information;

[0024] a removing unit, configured to remove the response traffic whose address information does not meet the preset requirement from the first response traffic data, so as to obtain second response traffic data;

[0025] a searching unit, configured to search the second response flow data for a target response flow in which the fingerprint information matches a fingerprint information dictionary, the fingerprint information dictionary being pre-generated based on vulnerability information;

[0026] A second acquisition unit, used to acquire the device IP address of the target response flow;

[0027] An establishing unit is used to associate the device IP address with the fingerprint information dictionary based on the fingerprint information to obtain a risk asset identification result.

[0028] Preferably, the device further includes:

[0029] A third acquisition unit, configured to acquire first vulnerability information published by an information security vulnerability sharing platform;

[0030] A fourth acquisition unit, configured to acquire second vulnerability information published by an information security vulnerability library;

[0031] A summarization unit, configured to summarize the first vulnerability information and the second vulnerability information to generate a fingerprint information dictionary.

[0032] Preferably, the elimination unit includes:

[0033] A search module, configured to search for first response traffic in the first response traffic data whose address information is a converted address or a virtual address, or second response traffic whose status code is a preset value, where the first response traffic and the second response traffic are any of the response traffic;

[0034] A deletion module, configured to delete the first response traffic and the second response traffic in the first response traffic data to obtain second response traffic data.

[0035] Preferably, the search unit includes:

[0036] A judgment module, configured to, for each group of response traffic in the second response traffic data, judge whether fingerprint information included in the fingerprint information dictionary exists in the traffic log of the response traffic;

[0037] A determination module, configured to, if fingerprint information included in the fingerprint information dictionary exists in the traffic log of the response traffic, determine that the response traffic is target response traffic.

[0038] A third aspect of an embodiment of the present invention discloses an electronic device, including: a processor and a memory, where the processor and the memory are connected through a communication bus; wherein, the processor is configured to call and execute a program stored in the memory; the memory is configured to store a program, and the program is used to implement the traffic-based intranet risk asset identification method as described in any one of the above.

[0039] A fourth aspect of an embodiment of the present invention discloses a computer-readable storage medium, in which computer-executable instructions are stored, and the computer-executable instructions are used to implement the traffic-based intranet risk asset identification method as described in any one of the above.

[0040] Based on the method, device and related equipment for identifying internal network risk assets based on traffic provided by the embodiments of the present invention, at least response traffic including address information and fingerprint information is obtained from the physical interface of the network device to obtain first response traffic data; the response traffic with address information not meeting the preset requirements is removed from the first response traffic data to obtain second response traffic data; target response traffic with fingerprint information matching the fingerprint information dictionary is found from the second response traffic data; the device IP address of the target response traffic is obtained; and based on the fingerprint information, the device IP address and the fingerprint information dictionary are associated to obtain the risk asset identification result. The present invention performs identification based on the internal network HTTP response traffic, which will not affect the target host and will not impose an additional burden on the network device; filtering the first response traffic data based on the preset requirements improves the matching efficiency of the response traffic and the fingerprint information dictionary. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only the embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings according to the provided drawings without creative efforts.

[0042] Figure 1 It is a flowchart of a method for identifying internal network risk assets based on traffic provided by an embodiment of the present invention;

[0043] FIG. 2(a) is a schematic diagram of traffic logs provided by an embodiment of the present invention;

[0044] FIG. 2(b) is a schematic diagram of an asset fingerprint database provided by an embodiment of the present invention;

[0045] Figure 3 It is a schematic diagram of a method for identifying internal network risk assets based on traffic provided by an embodiment of the present invention;

[0046] Figure 4 It is a structural block diagram of a device for identifying internal network risk assets based on traffic provided by an embodiment of the present invention;

[0047] Figure 5 It is a structural schematic diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0048] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0049] In this application, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

[0050] As can be seen from the background art, the current active detection method for collecting asset fingerprint information is likely to affect the normal operations of the scanned target host. At the same time, due to restricted network access relationships, it will also affect the scanning results. The probes deployed in the target host are difficult to update fingerprint information in a timely manner due to the long interval between upgrade cycles.

[0051] Therefore, the embodiments of the present invention provide a method, device and related equipment for identifying internal network risk assets based on traffic, which obtain first response traffic data, eliminate the response traffic that does not meet the preset requirements in the first response traffic data to obtain second response traffic data; search for target response traffic in the second response traffic data whose fingerprint information matches the fingerprint information dictionary, and obtain the device IP addresses in these target response traffic; based on the fingerprint information, associate the device IP addresses with the fingerprint information dictionary to obtain the risk asset identification result. Filtering the first response traffic data based on the preset requirements facilitates subsequent searching and extraction of target response traffic, and improves the matching efficiency between the response traffic and the fingerprint information dictionary.

[0052] Participate Figure 1 , which shows a flowchart of a method for identifying internal network risk assets based on traffic provided by an embodiment of the present invention. The method for identifying internal network risk assets based on traffic includes:

[0053] Step S101: Obtain first response traffic data from the physical interface of a network device.

[0054] In the specific implementation of step S101, obtain the first response traffic data of the network device from the physical interface of the internal network device, where the response traffic data is composed of response traffic at least including address information and fingerprint information.

[0055] It can be understood that the response traffic includes traffic logs. Refer to the schematic diagram of traffic logs shown in Fig. 2(a). The traffic logs record the address information and fingerprint information corresponding to the network device.

[0056] Step S102: Exclude the response traffic with address information not meeting the preset requirements from the first response traffic data to obtain the second response traffic data.

[0057] In the specific process of implementing step S102, search for the response traffic in the first response traffic data that does not meet the preset requirements, and delete the response traffic that does not meet the preset requirements to obtain the second response traffic data.

[0058] Specifically, search for the first response traffic in the first response traffic data whose address information is a translated address or a virtual address, or the second response traffic whose status code feedback by the security device is a preset value (such as 200), where the first response traffic and the second response traffic are any response traffic; delete the first response traffic and the second response traffic in the first response traffic data to obtain the second response traffic data.

[0059] It should be noted that searching for the translated address or the virtual address specifically means: searching for the translated address that does not belong to the network address planning and the dynamically allocated virtual address. Among them, the network planning means that the enterprise intranet divides the IP address segments according to different functions. For example, functional area 1 is 172.16.0.X / XX, functional area 2 is 172.17.0.X / XX, and functional area 3 is 172.18.0.X / XX.

[0060] In some embodiments, through the probe set in the network device, collect the component information of the network device, so as to construct an asset fingerprint database. Specifically, refer to the schematic diagram of the asset fingerprint database shown in Fig. 2(b). According to the asset fingerprint database, extract the fingerprint information of the network device from the traffic logs of each group of response traffic in the second response traffic data. For example, the traffic log records user_agent:Apache-HttpClient / 4.5.3(Java / 1.8.0_171), and match the specific fingerprint information based on the asset fingerprint database, that is, the network device uses the Apache-http component. Thus, based on the asset fingerprint database to analyze the traffic logs of each group of response traffic, the content shown in Table 1 can be obtained. For example, the network device 172.X.X.1 uses components such as ActiveMQ, Apache APISIX, and Dubbo.

[0061] Table 1

[0062] IP Fingerprint information 172.X.X.1 ActiveMQ, Apache APISIX, Dubbo 172.X.X.2 Docker, ECMall 172.X.X.3 Jetty, Harbor

[0063] Step S103: Find the target response traffic in the second response traffic data whose fingerprint information matches the fingerprint information dictionary.

[0064] In the specific process of implementing step S103, for each group of response traffic in the second response traffic data, it is judged whether the fingerprint information contained in the fingerprint information dictionary exists in the traffic log of the response traffic; if the fingerprint information contained in the fingerprint information dictionary exists in the traffic log of the response traffic, the response traffic is determined to be the target response traffic.

[0065] For example: the fingerprint dictionary contains the Apache vulnerability component, and the traffic log of the response traffic contains user_agent:Apache-HttpClient / 4.5.3(Java / 1.8.0_171). Then, through fuzzy matching, the fingerprint information Apache-HttpClient in the user_agent field is obtained, and the response traffic is determined to be the target response traffic.

[0066] In the specific implementation, the traffic log of the response traffic is analyzed through the asset fingerprint library to obtain the fingerprint information of the response traffic as shown in Table 1, and the fingerprint information is matched with the fingerprint information dictionary. If the fingerprint information of a certain response traffic in the second response traffic data matches the fingerprint information dictionary (that is, the fingerprint information matches the specific vulnerability in the fingerprint information dictionary), then the response traffic is recorded as the target response traffic.

[0067] It should be noted that the fingerprint information dictionary is pre-generated based on vulnerability information; obtain the first vulnerability information released daily by the information security vulnerability sharing platform (such as CNVD), for example, there is a command execution vulnerability in Apache CouchDB; obtain the second vulnerability information released daily by the information security vulnerability library (such as CNNVD), for example, there is a buffer error vulnerability in Apache HttpServer; input validation error vulnerability in Apache HttpServer, etc.; summarize the first vulnerability information and the second vulnerability information to generate the fingerprint information dictionary.

[0068] Step S104: Obtain the device IP address of the target response traffic.

[0069] In the specific process of implementing step S104, obtain the traffic log of the target response traffic, and extract the device IP address from the traffic log.

[0070] For example, extract the device IP address from the src_address field of the traffic log: src_address:10.X.X.166, and after processing, the device IP address can be obtained as 10.X.X.166.

[0071] Step S105: Based on the fingerprint information, associate the device IP address with the fingerprint information dictionary to obtain the risk asset identification result.

[0072] In the specific process of implementing step S105, based on the fingerprint information in the target response traffic, associate the device IP address in the target response traffic with the fingerprint information dictionary to obtain the risk asset identification result as shown in Table 2 for example.

[0073] Table 2

[0074]

[0075]

[0076] In the embodiment of the present invention, the first response traffic data is filtered according to preset requirements, excluding the useless response traffic, which can reduce the workload of fingerprint information identification when searching for the target response traffic later and improve the identification efficiency. Associating the device IP address in the target response traffic with the fingerprint information dictionary to obtain the risk asset identification result improves the efficiency of asset sorting and is conducive to quickly locating the risk assets.

[0077] For better explanation of Figure 1 the content, see Figure 3 , which shows a schematic diagram of a method for identifying internal network risk assets based on traffic provided by an embodiment of the present invention.

[0078] The host collection 100, based on the host security product, acquires the first vulnerability information published daily by the information security vulnerability sharing platform (such as CNVD) through CNVD and the second vulnerability information published daily by the information security vulnerability database (such as CNNVD) through CNNVD; aggregates the first vulnerability information and the second vulnerability information to generate the fingerprint information dictionary 400.

[0079] It should be noted that the information security vulnerability sharing platform (such as CNVD) and the information security vulnerability database (such as CNNVD) update the vulnerability information daily, so the fingerprint information dictionary 400 is updated daily according to the information security vulnerability sharing platform and the information security vulnerability database.

[0080] The HTTP response traffic collection 500 collects the response traffic containing at least the address information and fingerprint information from the physical interface of the network device to obtain the first response traffic data.

[0081] The HTTP response traffic determination 600 filters the first response traffic data according to preset requirements to obtain the second response traffic data.

[0082] The asset fingerprint database 700 is constructed by probes set in various network devices to collect component information of the network devices; by combining multiple pieces of component information included in the asset fingerprint database 700, fingerprint information recognition 800 performs fingerprint information recognition on the response traffic in the second response traffic data to obtain the fingerprint information of each group of response traffic.

[0083] Risky asset identification 900 combines the fingerprint information recognized by fingerprint information recognition 800 and the fingerprint information dictionary 400 to determine the target response traffic in the second response traffic data, obtain the device IP address in the target response traffic, and based on the fingerprint information, associate the device IP address with the vulnerability component information in the fingerprint information dictionary 400 to obtain the risky asset identification result.

[0084] It can be understood that the asset fingerprint database 800 is affected by the vulnerability information recorded in the fingerprint information dictionary, and the positioning of risky assets is also affected accordingly.

[0085] Corresponding to the method for identifying internal network risky assets based on traffic provided in the above embodiment of the present invention, refer to Figure 4 which shows a structural block diagram of a device for identifying internal network risky assets based on traffic provided in an embodiment of the present invention. The device for identifying internal network risky assets based on traffic includes a first acquisition unit 401, a rejection unit 402, a search unit 403, a second acquisition unit 404, and a establishment unit 405:

[0086] The first acquisition unit 401 is configured to acquire first response traffic data from the physical interface of a network device, and the response traffic data is composed of response traffic at least including address information and fingerprint information.

[0087] The rejection unit 402 is configured to reject the response traffic whose address information does not meet the preset requirements from the first response traffic data to obtain second response traffic data.

[0088] The search unit 403 is configured to search for target response traffic in the second response traffic data whose fingerprint information matches the fingerprint information dictionary, and the fingerprint information dictionary is pre-generated based on vulnerability information.

[0089] The second acquisition unit 404 is configured to acquire the device IP address of the target response traffic.

[0090] The establishment unit 405 is configured to associate the device IP address with the fingerprint information dictionary based on the fingerprint information to obtain the risky asset identification result.

[0091] In an embodiment of the present invention, the response traffic of the intranet network device is acquired to obtain the first response traffic data, and the response traffic that does not meet the preset requirements in the first response traffic data is eliminated to obtain the second response traffic data, reducing the workload of subsequent searching for the target response traffic and improving the matching efficiency of the response traffic and the fingerprint information dictionary.

[0092] Preferably, in combination with Figure 4 the content shown, the establishing device further includes a third acquisition unit, a fourth acquisition unit, and a summarizing unit:

[0093] The third acquisition unit is configured to acquire the first vulnerability information published by the information security vulnerability sharing platform.

[0094] The fourth acquisition unit is configured to acquire the second vulnerability information published by the information security vulnerability library.

[0095] The summarizing unit is configured to summarize the first vulnerability information and the second vulnerability information to generate a fingerprint information dictionary.

[0096] Preferably, in combination with Figure 4 the content shown, the elimination unit 402 includes a searching module and a deleting module, and the implementation principles of each module are as follows:

[0097] The searching module is configured to search for the first response traffic in the first response traffic data whose address information is a converted address or a virtual address, or the second response traffic whose status code is a preset value, and the first response traffic and the second response traffic are any response traffic.

[0098] The deleting module is configured to delete the first response traffic and the second response traffic in the first response traffic data to obtain the second response traffic data.

[0099] Preferably, in combination with Figure 4 the content shown, the searching unit 403 includes a judging module and a determining module, and the implementation principles of each module are as follows:

[0100] The judging module is configured to judge, for each group of response traffic in the second response traffic data, whether there is fingerprint information included in the fingerprint information dictionary in the traffic log of the response traffic.

[0101] The determining module is configured to, if there is fingerprint information included in the fingerprint information dictionary in the traffic log of the response traffic, determine the response traffic as the target response traffic.

[0102] An embodiment of the present invention further provides an electronic device, which includes: a processor and a memory, and the processor and the memory are connected through a communication bus; wherein, the processor is configured to call and execute a program stored in the memory; the memory is configured to store a program, and the program is used to implement the method for identifying intranet risk assets based on traffic.

[0103] Reference is made below to Figure 5 , which shows a schematic structural diagram of an electronic device suitable for implementing the embodiments of the present disclosure. The electronic devices in the embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The electronic device shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0104] As Figure 5 shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 501, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage device 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the electronic device are also stored. The processing device 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0105] Generally, the following devices may be connected to the I / O interface 505: an input device 506 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 507 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 508 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 509. The communication device 509 may allow the electronic device to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 5 an electronic device with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.

[0106] Specifically, according to the embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, the embodiments of the present disclosure include a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program may be downloaded and installed from a network through the communication device 509, or installed from the storage device 508, or installed from the ROM 502. When the computer program is executed by the processing device 501, the above-mentioned functions defined in the methods of the embodiments of the present disclosure are executed.

[0107] Furthermore, an embodiment of the present invention also provides a computer-readable storage medium, in which computer-executable instructions are stored, and the computer-executable instructions are used to execute a flow-based intranet risk asset identification method.

[0108] The above-mentioned computer-readable medium carries one or more programs. When the above-mentioned one or more programs are executed by the electronic device, the electronic device: obtains first response flow data from the physical interface of the network device; eliminates the response flow whose address information does not meet the preset requirements from the first response flow data to obtain second response flow data; searches for the target response flow whose fingerprint information matches the fingerprint information dictionary from the second response flow data; obtains the device IP address of the target response flow; and associates the device IP address with the fingerprint information dictionary based on the fingerprint information to obtain the risk asset identification result.

[0109] It should be noted that the computer-readable medium disclosed above may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that may be used by or in combination with an instruction execution system, device or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried. This propagated data signal may take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The computer readable signal medium may also be any computer readable medium other than a computer readable storage medium, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer readable medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0110] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.

[0111] In summary, the embodiments of the present invention provide a method, device and related equipment for identifying risk assets in an intranet based on traffic. The first response traffic data is obtained, and the response traffic that does not meet the preset requirements in the first response traffic data is removed to obtain the second response traffic data, which improves the matching efficiency of the response traffic and the fingerprint information dictionary. The target response traffic whose fingerprint information matches the fingerprint information dictionary is found in the second response traffic data, and the device IP addresses in these target response traffic are obtained; according to the fingerprint information, the device IP addresses and the fingerprint information dictionary are associated to obtain the risk asset identification result, which improves the efficiency of asset sorting and is conducive to quickly locating risk assets.

[0112] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the system or system embodiment, since it is basically similar to the method embodiment, it is described relatively simply, and the relevant parts can refer to the partial description of the method embodiment. The systems and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative work.

[0113] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0114] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for identifying risk assets in an intranet based on traffic, characterized in that, The method includes: Obtaining first response traffic data from a physical interface of a network device, where the response traffic data consists of response traffic containing at least address information and fingerprint information; Removing from the first response traffic data the response traffic whose address information does not meet the preset requirements to obtain second response traffic data; Searching in the second response traffic data for target response traffic whose fingerprint information matches a fingerprint information dictionary, where the fingerprint information dictionary is pre-generated based on vulnerability information; Obtaining the device IP address of the target response traffic; Associating the device IP address and the fingerprint information dictionary according to the fingerprint information to obtain a risk asset identification result; The removing from the first response traffic data the response traffic whose address information does not meet the preset requirements to obtain second response traffic data includes: Searching for first response traffic in the first response traffic data whose address information is a translated address or a virtual address, or second response traffic whose status code is a preset value, where the first response traffic and the second response traffic are any of the response traffic; Deleting the first response traffic and the second response traffic in the first response traffic data to obtain second response traffic data.

2. The method according to claim 1, wherein The process of generating a fingerprint information dictionary based on vulnerability information includes: Obtaining first vulnerability information published by an information security vulnerability sharing platform; Obtaining second vulnerability information published by an information security vulnerability database; Summarizing the first vulnerability information and the second vulnerability information to generate a fingerprint information dictionary.

3. The method according to claim 1, characterized in that, The searching in the second response traffic data for target response traffic whose fingerprint information matches a fingerprint information dictionary includes: For each group of response traffic in the second response traffic data, determining whether fingerprint information included in the fingerprint information dictionary exists in the traffic log of the response traffic; If fingerprint information included in the fingerprint information dictionary exists in the traffic log of the response traffic, determining the response traffic as target response traffic.

4. An intranet risk asset identification device based on traffic, characterized in that, The apparatus includes: A first obtaining unit, configured to obtain first response traffic data from a physical interface of a network device, where the response traffic data consists of response traffic containing at least address information and fingerprint information; A removing unit, configured to remove from the first response traffic data the response traffic whose address information does not meet the preset requirements to obtain second response traffic data; A searching unit, configured to search in the second response traffic data for target response traffic whose fingerprint information matches a fingerprint information dictionary, where the fingerprint information dictionary is pre-generated based on vulnerability information; A second obtaining unit, configured to obtain the device IP address of the target response traffic; A establishing unit, configured to associate the device IP address and the fingerprint information dictionary according to the fingerprint information to obtain a risk asset identification result; The removing unit includes: A searching module, configured to search for first response traffic in the first response traffic data whose address information is a translated address or a virtual address, or second response traffic whose status code is a preset value, where the first response traffic and the second response traffic are any of the response traffic; A deletion module, configured to delete the first response traffic and the second response traffic in the first response traffic data to obtain second response traffic data.

5. The device according to claim 4, characterized in that, The device further includes: A third acquisition unit, configured to acquire first vulnerability information published by an information security vulnerability sharing platform; A fourth acquisition unit, configured to acquire second vulnerability information published by an information security vulnerability library; A summarization unit, configured to summarize the first vulnerability information and the second vulnerability information to generate a fingerprint information dictionary.

6. The device according to claim 4, characterized in that The search unit includes: A judgment module, configured to judge, for each group of response traffic in the second response traffic data, whether fingerprint information included in the fingerprint information dictionary exists in the traffic log of the response traffic; A determination module, configured to determine that the response traffic is target response traffic if fingerprint information included in the fingerprint information dictionary exists in the traffic log of the response traffic.

7. An electronic device, characterized in that, It includes: A processor and a memory, the processor and the memory are connected through a communication bus; wherein, the processor is configured to call and execute a program stored in the memory; The memory is configured to store a program, and the program is used to implement a method for identifying internal network risk assets based on traffic according to any one of claims 1-3.

8. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and the computer-executable instructions are used to execute a method for identifying internal network risk assets based on traffic according to any one of claims 1-3.

Citation Information

Patent Citations

  • Vulnerability detection method and device

    CN113849820A

  • Network asset processing method and device, equipment and storage medium

    CN114301757A

Cited By

  • Data processing method for bank investment business risk monitoring

    CN121458444A