An asset retrieval method and system

CN115952191BActive Publication Date: 2026-10-09BEIJING RUIFUXIN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310198880.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-03
Publication Date
2026-10-09
Estimated Expiration
2043-03-03

AI Technical Summary

Benefits of technology

[0017] The solution described in the foregoing embodiments supports custom search methods. Users can define search conditions to form custom statements. The backend can convert the custom statements to generate search statements that search for assets that meet the aforementioned search conditions, thus completing the custom search. Compared with related technologies, users do not need to know the specific table names or field names to complete the search, which greatly reduces the difficulty of the search. Furthermore, the search conditions can be customized, thereby enabling the rapid location of assets through a combination of multiple attributes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115952191B_ABST
    Figure CN115952191B_ABST
Patent Text Reader

Abstract

The application relates to the computer technical field, in particular to an asset retrieval method and system. The method can comprise the following steps: acquiring a retrieval request; the retrieval request comprises retrieval information used for retrieving assets; the retrieval information is a self-defined sentence; the self-defined sentence contains a plurality of set retrieval conditions; based on the retrieval request, a target retrieval type corresponding to the retrieval request is determined from preset retrieval types; in the case that the target retrieval type is self-defined retrieval, the self-defined sentence is converted to obtain a retrieval sentence; the retrieval sentence is used for retrieving assets meeting the plurality of retrieval conditions; and based on the retrieval sentence, asset retrieval is performed in a database. Thus, the retrieval difficulty can be greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, specifically to an asset retrieval method and system. Background Technology

[0002] With economic and technological development, enterprises and other organizations are growing larger, possessing more and more assets, and having more and more asset attributes. This increases the difficulty of asset management, and customers' search habits are also changing. They no longer simply search for assets using a single attribute (such as an IP address), but rather quickly locate assets through combinations of multiple attributes. These assets include hardware devices, software devices, and products combining hardware and software. For example, assets may include servers, PCs (personal computers), cameras, printers, firewalls, gateways, OA systems, antivirus software, etc.

[0003] The labor costs incurred by institutions in sorting out these assets are increasing, and there is an urgent need for a way to manage assets and to quickly locate assets through combinations of certain attributes. Summary of the Invention

[0004] In view of this, this application discloses an asset retrieval method. The method may include: obtaining a retrieval request; the retrieval request including retrieval information for retrieving assets; the retrieval information being a custom statement; the custom statement containing several set retrieval conditions; based on the retrieval request, determining a target retrieval type corresponding to the retrieval request from preset retrieval types; if the target retrieval type is a custom retrieval, converting the custom statement to obtain a retrieval statement; the retrieval statement being used to retrieve assets that satisfy the several retrieval conditions; and performing an asset retrieval in a database based on the retrieval statement.

[0005] In some embodiments, the database stores several asset information and associated descriptive information; the descriptive information corresponds to several search ranges; the custom statement includes several second search conditions set for several second descriptive information corresponding to at least one search range; the conversion of the custom statement to obtain a search statement includes: parsing the custom statement according to the statement generation rules corresponding to the target search type to obtain several second search conditions with logical relationships; generating a second initial search statement corresponding to each second search condition; and, for each of the several search ranges, combining the second initial search statements based on the logical relationships to obtain a second final search statement corresponding to each search range.

[0006] In some embodiments, parsing the custom statement to obtain a plurality of second search conditions with logical relationships includes: when the custom statement contains a second preset character, splitting the custom statement according to the second preset character to obtain a plurality of first statement fragments with a first logical relationship; for each first statement fragment, when the first statement fragment contains a logical character, splitting the first statement fragment based on the logical character to obtain a plurality of second statement fragments; performing the same operation as the first statement fragment on each second statement fragment until the statement fragments obtained after splitting do not contain the logical character; and determining each of the split statement fragments as a plurality of second search conditions.

[0007] In some embodiments, the preset search types include full-text search, custom search, and advanced search; determining the target search type corresponding to the search information among the preset search types based on the search request includes: determining the target search type as advanced search when the identifier bit included in the search request is a preset identifier; determining the target search type as custom search when the identifier bit included in the search request is not the preset identifier and the search information includes operators; and determining the target search type as full-text search when the identifier bit included in the search request is not the preset identifier and the search information does not include operators.

[0008] In some embodiments, the database stores several asset information items and descriptive information associated with the asset information; the descriptive information corresponds to several search ranges; the search information consists of keywords included in the descriptive information associated with the target asset information; the method further includes: when the target search type is full-text search, generating a search statement corresponding to each search range according to the statement generation rules corresponding to the full-text search; the search statement is used to retrieve target asset information under the corresponding search range; the descriptive information associated with the target asset information includes the keywords.

[0009] In some embodiments, the description information includes IP and / or MAC addresses; the word segmentation method for the IP and / or MAC addresses includes: traversing each character of the IP and / or MAC address from left to right, and forming a first word segment by a number of characters before the first preset character, forming a second word segment and a third word segment by a number of characters between two adjacent first preset characters, and forming a fourth word segment by a number of characters after the last first preset character; forming a fifth word segment by the first word segment and the first preset character; forming a sixth word segment by the fifth word segment and the second word segment; forming a seventh word segment by the sixth word segment and the middle first preset character; forming an eighth word segment by the seventh word segment and the third word segment; forming a ninth word segment by the eighth word segment and the last first preset character; and forming a tenth word segment by the ninth word segment and the fourth word segment.

[0010] In some embodiments, the database stores a plurality of asset information and descriptive information associated with the asset information; the descriptive information corresponds to a plurality of search ranges; the search information consists of a plurality of first search conditions set for a plurality of first descriptive information under a first search range; the plurality of first search conditions have a logical relationship with each other; the method further includes: When the target retrieval type is advanced retrieval, a first initial retrieval statement corresponding to each of the first retrieval conditions is generated according to the statement generation rules corresponding to the advanced retrieval; based on the logical relationship, the first initial retrieval statements are combined to obtain a first final retrieval statement; the first final retrieval statement is used to retrieve target asset information under the first retrieval scope, and the first description information contained in the target asset information satisfies the plurality of first retrieval conditions.

[0011] In some embodiments, the step of performing asset retrieval in the database based on the search statement includes: when there are multiple search statements, processing multiple search statements in parallel to complete the retrieval in the database; storing the target asset information retrieved for each search statement in a preset high-speed storage medium; the preset high-speed storage medium stores the target asset information retrieved under different search ranges; and retrieving the target asset information from the preset high-speed storage medium for display.

[0012] In some embodiments, the database is a graph-structured database; the graph-structured database stores the asset information and associated descriptive information in a graph structure; in response to retrieving target asset information that satisfies the search information in only one search scope, the method further includes: based on the graph structure, performing an association query to determine whether the target asset information has descriptive information in other search scopes besides the one search scope; in response to the descriptive information found in other search scopes, determining that the target asset information has been found in the other search scopes; and storing the search results of finding the target asset information in the other search scopes in the preset high-speed storage medium.

[0013] In some embodiments, before converting the custom statement, the method further includes: validating the custom statement; the validation dimensions include syntax validation and / or content validation; the syntax validation refers to checking whether the custom statement includes preset illegal characters, and determining that the syntax validation passes if no preset illegal characters are included; the content validation refers to determining whether the content of the custom statement is missing, and determining that the content validation passes if the content is not missing.

[0014] In some embodiments, the asset information storage method includes: acquiring asset information of the asset to be maintained; the asset information includes at least one type of information, such as asset attribute information, vulnerability information, port information, and weak password information; determining the primary key information for each type of asset information; using the descriptive information included in each type of asset information as nodes in a neo4j graph structure, and associating the asset information belonging to the asset to be maintained based on the primary key information, so as to complete the storage of asset information for the asset to be maintained.

[0015] In some embodiments, the method further includes: in response to completing the storage of asset information for the asset to be maintained, establishing a corresponding index for each type of asset information; the index includes at least a portion of the descriptive information of the asset information.

[0016] In some embodiments, the retrieval information consists of keywords included in the target asset information and / or target description information of the target asset to be retrieved; when the target retrieval type is full-text retrieval, the method for performing full-text retrieval based on the index includes: constructing a retrieval statement for each type of asset information based on the keywords; the retrieval statement is used to perform asset retrieval in the database, including: retrieving a first target node including the keywords and a second target node with a preset step size relative to the first target node based on the retrieval statement; the first target node and the second target node are nodes corresponding to the target asset information and the target description information; based on the first target node and the second target node, counting the number of nodes of each type and returning them as query results.

[0017] The solution described in the foregoing embodiments supports custom search methods. Users can define search conditions to form custom statements. The backend can convert the custom statements to generate search statements that search for assets that meet the aforementioned search conditions, thus completing the custom search. Compared with related technologies, users do not need to know the specific table names or field names to complete the search, which greatly reduces the difficulty of the search. Furthermore, the search conditions can be customized, thereby enabling the rapid location of assets through a combination of multiple attributes. Attached Figure Description

[0018] The accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below.

[0019] Figure 1 This is a flowchart illustrating an asset retrieval method according to an embodiment of this application; Figure 2 This is a flowchart illustrating an asset retrieval method according to an embodiment of this application; Figure 3 This is a schematic diagram of the method for determining the retrieval type shown in this application; Figure 4 A schematic diagram of the method for generating search statements for the advanced search types shown in this application; Figure 5 This is a schematic diagram of the syntax structure shown in this application; Figure 6 This application illustrates a method for generating search statements based on a custom search type using Antlr4. Figure 7 This is a schematic diagram illustrating the method for parsing custom statements as shown in this application; Figure 8 This application illustrates a database retrieval process. Figure 9This is a schematic diagram of the association retrieval method shown in this application; Figure 10 This application illustrates the structure of an asset retrieval system. Figure 11 This is a schematic diagram of the method for determining the retrieval type shown in this application; Figure 12 This application illustrates a full-text search process diagram; Figure 13 This is a schematic diagram illustrating how a page unit in this application displays search results to a user; Figure 14 This is a schematic diagram of the advanced search process shown in this application; Figure 15 This is a schematic diagram of the advanced search window used in this application. Figure 16 This is a schematic diagram illustrating a custom search process as shown in this application. Detailed Implementation

[0020] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of devices and methods consistent with some aspects of this application as detailed in the appended claims.

[0021] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items. It should also be understood that the word “if” as used herein, depending on the context, can be interpreted as “when,” “in response to a determination,” or “when…”.

[0022] In some related technologies, assets are stored in traditional relational databases, such as MySQL, and the front end provides fixed search criteria templates for users to input for queries.

[0023] The previous approach relied on relatively fixed search criteria, requiring users to construct search information based on provided templates. For example, users needed to know specific table names and field names to build their search, and the resulting information was often difficult to read. Therefore, it placed high demands on users, potentially hindering the ability of average users to perform asset searches effectively and significantly increasing the difficulty of the search process.

[0024] In view of this, this application proposes an asset retrieval method. The method supports custom retrieval, allowing users to define several search conditions to form custom statements. The backend can then convert these custom statements to generate retrieval statements for searching assets that meet the defined search conditions, thus completing the custom retrieval. Compared to related technologies, users do not need to know the specific table names or field names to complete the retrieval, greatly reducing the difficulty of the retrieval process. Furthermore, the search conditions can be customized, enabling the rapid location of assets through combinations of multiple attributes.

[0025] The following description, in conjunction with the accompanying drawings, illustrates the embodiments. Please refer to the attached figures. Figure 1 , Figure 1 This is a flowchart illustrating an asset retrieval method according to an embodiment of this application.

[0026] Figure 1 The illustrated asset retrieval method can be applied to electronic devices. These electronic devices can execute the method by incorporating software logic corresponding to the asset retrieval method. The type of electronic device can be a laptop, computer, server, mobile phone, PDA, etc. This application does not specifically limit the type of electronic device. The electronic device can also be a client device or a server device.

[0027] like Figure 1 As shown, the method may include steps S102-S108. Unless otherwise specified, this application does not specifically limit the order in which these steps are performed.

[0028] S102, Obtain a search request; the search request includes search information for retrieving assets.

[0029] The search information is a custom statement; the custom statement contains several set search conditions.

[0030] Users can enter the custom statement on the display page as needed.

[0031] S104, Based on the search request, determine the target search type that corresponds to the search request among the preset search types.

[0032] This application provides users with multiple search types. The preset search types can be set according to needs.

[0033] In some embodiments, the preset search types include full-text search, custom search, and advanced search.

[0034] Full-text search refers to retrieving target assets containing keywords from a database.

[0035] In advanced search, the system can provide users with some search condition templates that they can select and fill in, as well as other search information. Then, the search information is translated into search statements to complete the search for the target asset.

[0036] Custom search can remove restrictions on user input and extract search criteria from user-defined statements to retrieve target assets.

[0037] There are many ways to determine the type of a target search. For example, a corresponding identifier can be preset for each search type. Users can select the appropriate search type on the front end so that the search request carries the corresponding identifier. The back end can identify the search type by recognizing the identifier carried in the search request. Subsequent embodiments will also propose a method for determining the search type, which can reduce the number of operations required for users to select and reduce search types, reduce the user's mastery of the search tool, and further reduce the difficulty of searching.

[0038] S106, when the target search type is a custom search, the custom statement is transformed to obtain a search statement. The search statement is used to retrieve assets that meet the aforementioned search conditions.

[0039] The conversion rules corresponding to the conversion can be pre-stored in the search engine. The conversion rules can be used to convert custom statements and obtain search statements.

[0040] S108, Based on the search query, perform an asset search in the database.

[0041] In this step, the generated search query is input into the database to complete the retrieval of the target asset.

[0042] The scheme described in S102-S108 supports custom search methods. Users can define search conditions to form custom statements. The backend can convert the custom statements to generate search statements that search for assets that meet the specified search conditions, thus completing the custom search. Compared with related technologies, users do not need to know the specific table names or field names to complete the search, which greatly reduces the difficulty of the search. Furthermore, the search conditions can be customized, thereby enabling the rapid location of assets through a combination of multiple attributes.

[0043] In view of this, this application also proposes an asset retrieval method. After obtaining a retrieval request, the method determines the target retrieval type corresponding to the current retrieval request from among several preset retrieval types. Then, it generates a retrieval statement corresponding to the retrieval information based on the statement generation rules corresponding to the target retrieval type to complete the retrieval. This supports multiple retrieval methods and can automatically adapt the retrieval method according to the retrieval information entered by the user, simplifying the user's operation of the retrieval tool, reducing the requirements for users, and enabling ordinary users to complete asset retrieval, greatly reducing the difficulty of retrieval.

[0044] The following description, in conjunction with the accompanying drawings, illustrates the embodiments. Please refer to the attached figures. Figure 2 , Figure 2 This is a flowchart illustrating an asset retrieval method according to an embodiment of this application.

[0045] Figure 2 The illustrated asset retrieval method can be applied to electronic devices. These electronic devices can execute the method by incorporating software logic corresponding to the asset retrieval method. The type of electronic device can be a laptop, computer, server, mobile phone, PDA, etc. This application does not specifically limit the type of electronic device. The electronic device can also be a client device or a server device.

[0046] like Figure 2 As shown, the method may include steps S202-S208. Unless otherwise specified, this application does not specifically limit the order in which these steps are performed.

[0047] S202, Obtain search request.

[0048] The search request includes search information for retrieving assets.

[0049] This application provides a front-end for user interaction. For example, the retrieval front-end could be a web page. This front-end can provide a window for users to input retrieval information. Users can construct retrieval information for the target asset based on this input, enabling the database to retrieve the target asset that meets the requirements.

[0050] After entering the search information, users can click a button such as "Search" provided on the front end to initiate a search request. The electronic device responsible for asset retrieval (such as a server) can then receive the search request.

[0051] S204, Based on the search request, determine the target search type that corresponds to the search information in the preset search types.

[0052] For an explanation of S204, please refer to S104; it will not be elaborated upon here.

[0053] In some embodiments, the preset search types include full-text search, custom search, and advanced search.

[0054] Full-text search refers to retrieving target assets containing keywords from a database.

[0055] In advanced search, the system can provide users with some search condition templates that they can select and fill in, as well as other search information. Then, the search information is translated into search statements to complete the search for the target asset.

[0056] Custom search can remove restrictions on user input and extract search criteria from user-defined statements to retrieve target assets.

[0057] There are many ways to determine the type of a target search. For example, a corresponding identifier can be preset for each search type. Users can select the appropriate search type on the front end so that the search request carries the corresponding identifier. The back end can identify the search type by recognizing the identifier carried in the search request. Subsequent embodiments will also propose a method for determining the search type, which can reduce the number of operations required for users to select and reduce search types, reduce the user's mastery of the search tool, and further reduce the difficulty of searching.

[0058] S206, Generate a search statement corresponding to the search information according to the statement generation rule corresponding to the target search type.

[0059] In this step, statement generation rules can be pre-configured for each search type. After identifying the target search type corresponding to this search request through S204, the corresponding statement generation rules can be obtained to generate the corresponding search statement.

[0060] S208, Based on the search query, perform an asset search in the database.

[0061] In this step, the generated search query is input into the database to complete the retrieval of the target asset.

[0062] The schemes described in S202-S208 allow for the determination of the target search type among multiple preset search types after a search request is received. Then, based on the statement generation rules corresponding to the target search type, a search statement matching the search information can be generated to complete the search. This supports multiple search methods and automatically adapts the search method to the user's input, simplifying the user's operation of the search tool, reducing user requirements, and enabling even ordinary users to complete asset searches, significantly lowering the difficulty of the search.

[0063] In some embodiments, in S204, the search type can be determined by identifying the content of the search information, thereby reducing the number of operations that users need to perform to reduce the number of search types, reducing the user's mastery of the search tool, and further reducing the difficulty of the search.

[0064] Please see Figure 3 , Figure 3 This is a schematic diagram illustrating the method for determining the retrieval type as shown in this application. Figure 3 The illustrated steps are a detailed explanation of S204. For example... Figure 3 As shown, the method may include S302-S306.

[0065] S302, if the identifier bit included in the search request is a preset identifier, the target search type is determined to be advanced search.

[0066] The preset identifier can be set according to requirements.

[0067] In this step, advanced search options can be set for users on the front end. In response to the user selecting an advanced search option, the first identifier can be included in the search request. The back end can determine whether the search request is an advanced search by parsing whether the search request carries the first identifier.

[0068] S304, if the identifier bit included in the search request is not the preset identifier and the search information includes an operator, the target search type is determined to be a custom search.

[0069] If the identifier carried in the search request is not the first identifier, it indicates that this is not an advanced search. Then, it can be determined whether the search information includes operators. The operators refer to symbols such as equal to, greater than, less than, contain, and included, which can represent operational relationships.

[0070] If the search information entered by the user includes operators, it indicates that the user may have entered some search conditions. The user may know accurate information about the asset. The target search type can be determined as a custom search to accurately query the target asset based on the search conditions.

[0071] S306, if the identifier bit included in the search request is not the preset identifier and the search information does not include an operator, the target search type is determined to be full-text search.

[0072] If the search information entered by the user does not include operators, it means that the user has entered some keywords. The user may not know the accurate information of the asset. The target search type can be set to full-text search to search for the target asset that the user wants to search within the entire data range, thus exchanging search time for user ease of operation.

[0073] S302-S306 reduces the number of user operations required to choose between custom search and full-text search. The search type can be automatically determined based on the search information entered by the user, reducing the user's need to master the search tool and further reducing the difficulty of searching.

[0074] The following describes how to construct search statements for the three search methods.

[0075] This application's database stores several asset information items and associated descriptive information. These assets can be uploaded by users and obtained through asset detection modules or forwarding. The database stores a lot of descriptive information about the assets. The asset information may include attribute information such as the asset's name and IP address, while the descriptive information may include vulnerability information, open port information, weak password information, responsible person information, device type, etc.

[0076] The description information corresponds to several search ranges.

[0077] The search scopes can be set according to requirements. The correspondence between the search scopes and the descriptive information can also be set according to requirements.

[0078] In some embodiments, the search scope may include assets, vulnerabilities, ports, and weak passwords.

[0079] Assets can be associated with asset names, IP addresses, and other attribute information; vulnerabilities can be associated with asset vulnerability names, asset names, IP addresses, and other information; ports can be associated with asset ports, asset names, IP addresses, and other information; weak passwords can be associated with asset weak passwords, asset names, IP addresses, and other information.

[0080] In some embodiments, asset information retrieved within the search scope can be rendered and displayed on the front end for users to view.

[0081] This application constructs search statements using three search methods, which can be used to retrieve target asset information that meets the search criteria from a database. For example, to search for assets within the scope of vulnerability searches, the search statement can return information such as the vulnerability name, the name of the asset with the vulnerability, and its IP address. To search for assets within the scope of weak password searches, the search statement can return information such as the weak password, the name of the asset with the weak password, and its IP address.

[0082] I. Full-text search.

[0083] In a full-text search scenario, the search information refers to the keywords included in the descriptive information associated with the target asset information. For example, the search information could be 80. 80 can be understood as the target asset's port being 80, its IP address including 80, its name including 80, weak passwords including 80, vulnerabilities including 80, and so on.

[0084] In S206, a search statement corresponding to each of the plurality of search ranges can be generated according to the statement generation rules corresponding to the full-text search.

[0085] The search query is used to retrieve target asset information within the corresponding search scope; the descriptive information associated with the target asset information includes the keywords.

[0086] In a full-text search scenario, it is unknown which description information the user's search keywords are included in. Therefore, it is necessary to traverse all asset description information in the database to find the description information containing the keywords in order to find the target asset.

[0087] In some methods, an inverted index is created for a portion of the asset description information when storing the asset description information. By traversing the inverted index, the traversal of the asset description information can be completed, which helps to improve the efficiency of asset search.

[0088] In full-text search scenarios, it's necessary to collect target assets retrieved from each of several pre-defined search scopes. Therefore, search statements corresponding to each search scope can be constructed to retrieve target asset information for each scope from the database. For example, if the search scopes include assets, vulnerabilities, ports, and weak passwords, four search statements can be constructed for each scope. Each search statement for a specific scope can use the aforementioned keywords as search conditions. The construction method for search statements can refer to relevant technologies. For instance, Cypher statements can be constructed for graph databases. Cypher is the language for graph queries in Neo4j (a graph database), similar to SQL, and is also a declarative query language. This allows for more comprehensive search results, returning search results from multiple search dimensions in a single search, eliminating the need for users to search item by item and improving search accuracy.

[0089] In some embodiments, the method for storing asset information includes: Obtain asset information of the asset to be maintained; the asset information includes at least one of the following types of information: asset attribute information, vulnerability information, port information, and weak password information; For each type of asset information, determine its primary key information; Each type of asset information includes descriptive information as nodes in a Neo4j graph structure, and asset information belonging to the asset to be maintained is linked together based on the primary key information to complete the storage of asset information for the asset to be maintained. In response to completing the storage of asset information for the asset to be maintained, a corresponding inverted index is created for each type of asset information; the index includes at least a portion of the descriptive information of the asset information.

[0090] The asset attribute information may include, (1) Basic attributes of an asset (Ledger). Table 1 shows examples of descriptive information for the basic attributes of an asset.

[0091] Ip IP address of the asset 192.168.12.222 ips IP address word segmentation 192 168 12 222192.192.168192.168.192.168.12192.168.12. ledgerId Asset number is generated automatically. 19612 level The importance of assets 1 levelName The Importance of Assets (in Chinese) assets longIp The numerical form of an IP address 3232238814 name Name of the asset HP PC OS operating system Linux osVendor Operating system vendors Linux safeStatus safe status 1 safeStatusName Safety status in Chinese High-risk assets source Source of assets Ruifuxin (192.168.12.12) scanner status Online status 2 statusName Online status in Chinese Online upTime Launch time December 19, 2022, 15:53:45 epLevel Information security level 1 epLevel Information Security Level (Chinese) Level 1 Information Security Protection Table 1 (2) Basic attributes of hardware type. Table 2 shows examples of the descriptive information of the basic attributes of hardware type.

[0092] cn Chinese name PC devices name English name Pc typeId Hardware Type ID 27 parent Hardware type parent type ID 17 Table 2 (3) Basic attributes of the Manager. Table 3 shows examples of the descriptive information of the basic attributes of the Manager.

[0093] name name Cao XX sid Responsible Person ID 11 number Contact information of the person in charge 138xxxxxxxx mail Email address of the person in charge Xx@xxx.com Table 3 (4) Other basic information. For example, basic attributes such as asset group, machine room, equipment cabinet, address, security zone, asset label, port label, and operating system (the above table structures are the same). Table 4 shows an example of the descriptive information of the basic attributes of a machine room.

[0094] name name Beijing Data Center sid serial number 1 Table 4 The storage of asset attribute information includes the following steps: The system organizes asset data based on the received data; stores assets in a MySQL database, generating a ledgerId using the auto-incrementing primary key attribute; organizes the data into nodes in Neo4j and stores them in Neo4j; matches asset nodes with port nodes based on the asset's ledgerId and port node's SID; matches asset nodes with hardware type nodes based on the asset's ledgerId and hardware type type ID; matches asset nodes with responsible person nodes based on the asset's ledgerId and responsible person's SID; matches asset nodes with responsible person nodes based on the asset's ledgerId and asset group, data center, rack, area location, security domain, and asset tag SID; once the system detects that the asset data entry is complete (which may be a scan task, a file upload, etc.), it begins issuing commands to Neo4j to build an inverted index.

[0095] By following the steps above, the asset's attribute information can be stored in the neo4j database, and an inverted index can be created to facilitate subsequent asset retrieval.

[0096] Port information may include: (1) Basic attributes of the LedgerPort node. Table 5 shows examples of the descriptive information of the basic attributes of the LedgerPort node.

[0097] port port 80 portString port string form 80 This field stores the port number as a string to resolve the issue that Neo4j cannot create indexes for numeric fields. product Components PostgreSQL DB protocol protocol TCP serviceName Service Name PostgreSQL sid Port number 13734 version Component version 9.6.0 or later Table 5 (2) Basic attributes of the software node. Table 6 shows examples of the descriptive information of the basic attributes of the software node.

[0098] category Classification Service company Manufacturers Microsoft HTTPAPI level hierarchy 5 product Components Microsoft HTTPAPI version Version 2.0 Table 6 The storage of port attribute information includes the following steps: The organization's port data is encapsulated into a MySQL storage format and stored, and the sid is generated using MySQL's auto-incrementing primary key function; After obtaining the SID, it is organized into the storage format in Neo4j and stored. The relationship between assets and ports is established by matching the SID of the port node with the LedgerId of the asset node. Match the port node's product with the software node's product and establish the relationship between the port and the software.

[0099] The above steps allow you to store port information in the neo4j database and create an inverted index for easy asset retrieval later.

[0100] Vulnerability information may include: (1) Basic attributes of the vulnerability node. Table 7 shows examples of the descriptive information of the basic attributes of the vulnerability node.

[0101] createBy Creator ID 1 cve Cve number CVE-2017-15906 cvss Cvss 5.0 IP IP address 192.168.12.222 ips IP address word segmentation 192 168 12 222192.192.168192.168.192.168.12192.168.12. level Vulnerability level in numerical form 1 levelName Vulnerability Level (in Chinese characters) Medium risk longIp IP address in numerical form 3232238771 name Vulnerability Name OpenSSH 'sftp-server' security bypass vulnerability port port 22 cncve cncve CNCVE-201715906 cnnvd cnnvd CNNVD-201710-1230 cnvd cnvd CNVD-2017-36017 vuId Vulnerability ID 4052 vulnGroup Vulnerability Group 0 Remark Vulnerability hit points Opening high-risk ports Table 7 (2) Basic attributes of the VulnType node. Table 8 shows examples of the descriptive information of the basic attributes of the VulnType node.

[0102] name Vulnerability type name Other types of system vulnerabilities Table 8 (3) Basic attributes of the RiskStatus node. Table 9 shows examples of the descriptive information of the basic attributes of the RiskStatus node.

[0103] name Status of handling Pending disposal value Disposal status numerical representation 1 Table 9 The storage of vulnerability attribute information includes the following steps: Organize the data and store it in MySQL, then use its auto-incrementing primary key function to obtain the vuId; The data was organized into a Neo4J storage format and stored in Neo4J. Match and establish a connection based on the vuId of the vulnerability node and the name of the vulnerability type node; Match and establish a connection based on the vuId of the vulnerable node and the name of the handling status node; The relationship between weak passwords is matched and established based on the IP of the vulnerable node and the IP of the asset node. Match and establish a relationship based on the port of the vulnerable node and the port of the port node; Once all vulnerability information has been stored (through a single scan or file upload), an inverted index is created for the vulnerability information.

[0104] By following the steps above, vulnerability information can be stored in the neo4j database, and an inverted index can be created to facilitate subsequent asset retrieval.

[0105] Weak password information may include: (1) Basic attributes of the weak password node. Table 10 shows examples of the descriptive information of the basic attributes of the weak password node.

[0106] createBy Creator ID 1 IP Weak password IP 192.168.12.222 level Weak password level 1 levelName Weak password level Chinese Low risk password Weak password 4e0b5d95f92e3f2dec9ebc650bf73b16 port Weak password port 22 serviceName Service Name SSH username Weak password username Root weakId Weak password number 2 Ips IP address word segmentation 192 168 12 222192.192.168192.168.192.168.12192.168.12. Table 10 (2) Basic attributes of the weak password type node. Table 11 shows an example of the descriptive information of the basic attributes of the weak password type node.

[0107] name Type Name SSH Table 11 (3) Basic attributes of the RiskStatus node. Table 12 shows examples of the descriptive information of the basic attributes of the RiskStatus node.

[0108] name Status of handling Pending disposal value Disposal status numerical representation 1 Table 12 The storage of weak password attribute information includes the following steps: The organization stores the data in MySQL and obtains the weakId; Organize it into a Neo4j storage format and store it in Neo4j; Match and establish relationships based on the weak password node's weakId and the weak password type node's name; Match and establish a relationship based on the weak password node's weakId and the handling status node's name; The relationship between weak password nodes and asset nodes is matched and established based on the IP address of the weak password node. Match and establish a relationship based on the port of the weak password node and the port of the port node; Once all weak passwords have been stored (after a scan or file upload), an inverted index will be created for the weak passwords.

[0109] The above steps can store weak password information in the neo4j database and create an inverted index, which facilitates subsequent asset retrieval.

[0110] Once the asset information storage task is completed, an index can be created. The index creation step can involve creating a corresponding inverted index for each type of asset information in response to the completion of asset information storage for the asset to be maintained; the index includes at least a portion of the descriptive information of the asset information.

[0111] For each type of asset information (including vulnerabilities, weak passwords, basic attributes and port information), at least part of the descriptive information can be added to the corresponding index through statements, and an inverted index can be built for it using the CJK tokenizer.

[0112] When the target retrieval type is full-text retrieval, the retrieval information consists of keywords included in the target asset information and / or target description information of the target asset to be retrieved; the method for performing full-text retrieval based on the index includes: Based on the keywords, construct search statements for each type of asset information; The search query is used to perform asset retrieval in the database, including: Based on the search query, a first target node including the keyword is retrieved, and a second target node with a preset stride is retrieved from the first target node; the first target node and the second target node are nodes corresponding to the target asset information and the target description information; Based on the first target node and the second target node, count the number of nodes of each type and return them as query results.

[0113] The preset step size can be set according to requirements. This allows all first and second target nodes associated with the target asset to be retrieved, completing asset retrieval and statistical analysis of asset information.

[0114] To facilitate keyword matching based on IP and / or MAC addresses, IP and / or MAC addresses need to be segmented into words. Segmentation methods for IP and / or MAC addresses may include: Iterate through each character of the IP and / or MAC address from left to right, and form a first word segment by taking the characters before the first preset character, form a second word segment and a third word segment by taking the characters between two adjacent first preset characters, and form a fourth word segment by taking the characters after the last preset character. The first word segment and the first preset character are combined to form the fifth word segment; Combine the fifth and second segmentation words to form the sixth segmentation word; The sixth word segment and the first preset character in the middle are combined to form the seventh word segment; Combine the seventh and third segment words to form the eighth segment word; The eighth word and the last first preset character are combined to form the ninth word; The ninth and fourth segment words are combined to form the tenth segment word.

[0115] The first to the tenth word segmentation results are for IP and / or MAC addresses.

[0116] For example, "192.168.12.21" will be segmented into ten words: "192", "168", "12", "21", "192.", "192.168", "192.168.", "192.168.12", "192.168.12.", and "192.168.12.12". Users can directly search for any part of the IP range to find the asset.

[0117] In some embodiments, deduplication is performed in the first to fourth word segmentation, reducing the number of index matching operations and simplifying the user experience. For example, "192.168.12.12" will be segmented into nine words: "192", "168", "12", "192.", "192.168", "192.168.", "192.168.12", "192.168.12.", and "192.168.12.12". Users can directly search for any part of the IP address to find the asset.

[0118] II. Advanced Search.

[0119] In advanced search scenarios, the search information consists of several first search conditions set for several first descriptive information within a first search scope. These first search conditions are logically related.

[0120] In advanced search scenarios, the front-end can provide users with a search condition construction window corresponding to several search scopes. The first search scope is any one of the search scopes selected by the user. For example, the search scopes include assets, vulnerabilities, ports, and weak passwords. If the user selects the assets search scope, the front-end can provide a search condition construction window for that scope. The user can select several descriptive information corresponding to the assets search scope in the window and then construct the corresponding first search conditions. These first search conditions directly possess logical relationships. These logical relationships refer to AND, OR, etc.

[0121] In advanced search scenarios, users clearly know the information of the target asset they need to search for, thus enabling precise retrieval.

[0122] Please see Figure 4 , Figure 4 A flowchart illustrating the method for generating search statements for the advanced search types shown in this application. Figure 4 The illustrated steps are supplementary explanations to S206. For example... Figure 4 As shown, the method may include S402-S404.

[0123] S402, generate a first initial search statement corresponding to each of the first search conditions according to the statement generation rules corresponding to the advanced search.

[0124] The first search condition can contain several characters, with operators between them. The escape module converts these characters and operators into characters and operators recognizable by the search query, thus generating the initial search query. The escape module contains character mappings, ensuring that even if the first search condition is in Chinese, the corresponding characters can still be mapped out.

[0125] S404, based on the logical relationship, the first initial search statement is combined to obtain a first final search statement; the first final search statement is used to retrieve target asset information under the first search scope, and the first description information contained in the target asset information satisfies the several first search conditions.

[0126] The logical relationship can indicate the AND / OR relationship between several first search conditions. Based on this logical relationship, the first initial search statement can be combined so that the resulting first final search statement can reflect the logical relationship.

[0127] By using S402-S404, a search statement can be constructed for the first search scope to obtain the target asset information under the first search scope.

[0128] III. Custom Search.

[0129] It's easy to see that advanced search criteria can only be constructed for a single search scope, limiting the search scenarios. To address this issue, custom search is proposed, which can parse user-inputted custom statements. Custom statements can be used to construct search criteria for different search scopes, thereby expanding the search scenarios and facilitating asset retrieval.

[0130] In a custom search scenario, the search information is a custom statement. The custom statement conforms to a certain syntax.

[0131] Please see Figure 5 , Figure 5 This is a schematic diagram illustrating the syntax structure of this application.

[0132] like Figure 5 As shown, the syntax may include six units: search scope, delimiter, description field, operator, query target, and logical operator.

[0133] The search scope refers to the different types of objects that can be searched in this system, namely: assets, ports, vulnerabilities, and weak passwords.

[0134] Separator: Used here to distinguish between ranges and fields.

[0135] Description field: This field contains the attribute information of the target asset to be retrieved, such as the asset's IP address, port, name, responsible person, etc.

[0136] Operators: Available operators include equal to: "=", not equal to: "!=", "<>", fuzzy search: "like", greater than: ">", greater than or equal to: ">=", less than: "<", less than or equal to: "<=", start with: "STARTS WITH", end with: "ENDSWITH", contain: "CONTAINS", and parentheses "()".

[0137] Query Target: Information about the target asset that the user wants to retrieve. This information may include asset attribute information, port information, vulnerability information, weak passwords, etc.

[0138] Asset attributes can include importance, security, IP address, asset name, online status, operating system, system vendor, system version, security compliance level, online time, offline time, expiration time, source, port, responsible person, asset group, hardware type, regional location, data center, server rack, security domain, application system, asset tag, hardware type, and validity period.

[0139] Port information can include importance, security, IP address, asset name, online status, operating system, system vendor, system version, security compliance level, online time, offline time, expiration time, source, port, responsible person, asset group, hardware type, regional location, data center, cabinet, security domain, application system, asset tag, hardware type, validity period, protocol, service, component, version, etc.

[0140] Vulnerability information can include the vulnerable IP address, vulnerable port, protocol, vulnerability name, vulnerability source, vulnerability level, CVE, CNVD, CNCVE, CVSS, CWE, CNNVD, vulnerability status, etc.

[0141] Weak passwords can include IP address, port, service, username, password, weak password level, and weak password status.

[0142] Logical operators: and, or. These indicate the AND or OR relationship between different search criteria.

[0143] Users can enter custom statements that conform to this syntax.

[0144] The custom statement contains several second search conditions set for several second descriptive information corresponding to at least one search scope. That is, the user-edited statement can cover search conditions for multiple search scopes. For example, several search scopes include assets, vulnerabilities, ports, and weak passwords. A custom statement could be asset.IP=192.168.1.1 and vulnerability.port=80. This statement includes two second search conditions corresponding to the asset search scope and the vulnerability search scope, respectively. The first second search condition restricts the IP to 192.168.1.1, and the second search condition restricts the port to 80. The two second search conditions are related by AND.

[0145] In a custom search scenario, the user clearly knows the information of the target asset they need to search for, thus enabling precise retrieval. This scenario also requires collecting the target assets retrieved from each of several preset search ranges. Therefore, search statements corresponding to each search range can be constructed, allowing the retrieval of target asset information for each search range from the database.

[0146] Please see Figure 6 , Figure 6 This application illustrates a flowchart of a method for generating search statements based on a custom search type in Antlr4. Figure 6 The illustrated steps are supplementary explanations to S106 and / or S206. For example... Figure 6 As shown, the method may include S602-S606.

[0147] Antlr4, another tool for language recognition, is a parser generator based on the LL(*) algorithm. It is written in Java and uses a top-down recursive descent LL parser method.

[0148] In this application, based on the Antlr4 framework, a segmentation module (VisitBarRelation module), a first escaping module (EqRelation module), a logical relationship processing module (AndRelation module), and a second escaping module (FieldRelation) can be set.

[0149] The VisitBarRelation() method retrieves the condition in parentheses and then performs recursive operations on the retrieved condition.

[0150] The EqRelation() method escapes all operators, converting the user-entered operators into operators supported by the Cypher language. The resulting value is "range.field + operator + query value". The left side of each operator is recursively processed.

[0151] The AndRelation() method processes predicate relations by converting conditions into the form "(condition 1 and condition 2)" to ensure that Cypher can parse them correctly.

[0152] The FieldRelation() method is responsible for parsing fields. First, we determine whether the obtained data is in the format of "range.field". If the format is correct, we use the dic module to obtain the information of the fields within that range and escape it into Cypher syntax.

[0153] The four modules work together to achieve accurate parsing of custom statements.

[0154] S602, according to the statement generation rules corresponding to the target retrieval type, the custom statement is parsed to obtain several second retrieval conditions with logical relationships.

[0155] Custom statements may include many secondary search conditions. The logical relationships between these search conditions affect the execution order of the search conditions, thus affecting the search results. Therefore, it is necessary to accurately parse the secondary search conditions and their logical relationships to avoid search errors.

[0156] Please see Figure 7 , Figure 7 This is a schematic diagram illustrating the method flow for parsing custom statements as shown in this application. Figure 7 This is a detailed explanation of S602. For example... Figure 7 As shown, the method may include steps S702-S706. Unless otherwise specified, this application does not limit the order in which these steps are performed.

[0157] S702, when the custom statement contains a second preset character, the custom statement is split according to the second preset character to obtain a number of first statement fragments with a first logical relationship.

[0158] The search criteria within the second preset character have the highest priority. For example, the second preset character is "parentheses". This step can use the segmentation module to traverse the custom statement and identify the statement fragments inside and outside the second preset character, i.e., the first statement fragments. These first statement fragments have the first logical relationship.

[0159] S704, for each first statement segment, if the first statement segment contains a logical character, the first statement segment is split based on the logical character to obtain several second statement segments. The same operation as the first statement segment is performed on each second statement segment until the statement segments obtained after splitting do not contain the logical character.

[0160] This step can recursively split each first statement fragment using the segmentation module until the resulting statement fragments do not contain the logical symbols. In S702-S704, the logical relationship processing module can record the logical relationships between each statement fragment, facilitating subsequent assembly of the retrieval statement.

[0161] S706, each of the obtained sentence fragments is determined as several of the second search conditions.

[0162] These second search criteria are logically related.

[0163] By using S702-S706 to accurately parse each second search condition and its logical relationship, the correctness of the search results is ensured.

[0164] S604, Generate a second initial search statement corresponding to each of the second search conditions.

[0165] In this step, the first escaping module can be used to escape operators (e.g., equal sign, greater than, less than, etc.) in each statement segment that does not contain logical characters, so as to obtain operators that the database can recognize. The second escaping module can be used to convert characters in the search conditions, so as to obtain characters that the database can recognize.

[0166] S606, for each of the plurality of search ranges, based on the logical relationship, the second initial search statement is combined to obtain the second final search statement corresponding to each search range.

[0167] In this step, for each search range, based on the logical relationships recorded by the logical relationship processing module, the second initial search statement can be combined to obtain the second final search statement corresponding to each search range.

[0168] S602-S606 can accurately parse custom statements to obtain corresponding search statements and target asset information under each search scope, thereby providing more comprehensive search results. In a single search process, search results from multiple search dimensions are returned, eliminating the need for users to search item by item and improving search accuracy.

[0169] The syntax for constructing search statements proposed in this application has the following advantages: Related technologies require the use of either 'English table name + "." + English field name + operator + target value' or 'English field name + operator + target value'. Such search conditions require professional expertise and are difficult for ordinary users. Asset information often involves dozens or even hundreds of tables, and the use of English naming increases the learning cost for users, making the generated search conditions difficult to read. While the format of English field name + operator + target value avoids specifying the table name, it can easily lead to ambiguity when there are many fields, and users may find it difficult to remember the meaning of each English field. The syntax proposed in this application integrates the table name into the corresponding search scope. Users only need to enter "search scope.description field" (e.g., "asset.ip") to perform a search, without needing to know which table is being searched at the underlying level. Furthermore, specifying the search scope avoids ambiguity. Since the syntax uses Chinese characters for the scope and fields, it greatly reduces the learning cost for users. Users only need a basic understanding of the supported fields and operators to write search information, greatly facilitating user comprehension and reducing the difficulty of searching.

[0170] In some embodiments, custom statements can be validated to verify the legality of the search information entered by the user, and parsing is performed if the search information is legal to ensure that correct search results can be obtained.

[0171] Validation dimensions can include syntax validation and / or content validation.

[0172] The syntax validation refers to checking whether the custom statement contains preset illegal characters, and determining that the syntax validation passes if no preset illegal characters are included.

[0173] The preset illegal characters can be maintained as needed. For example, if a custom statement includes preset illegal characters such as remove, delete, set, and update, it indicates SQL injection. SQL injection is an aggressive behavior, and syntax validation can intercept this behavior to prevent data corruption.

[0174] The content validation refers to determining whether the content of the custom statement is missing, and determining that the content validation passes if the content is not missing.

[0175] For example, the content validation can determine whether parentheses appear in pairs, whether logical operators include search conditions on both sides, whether operators include characters on both sides, etc., and determine that the validation passes if no content is missing.

[0176] After constructing the search query, you can input it into the database to perform the search.

[0177] In some embodiments, multi-threaded parallel processing of search statements can be initiated, and search results can be stored in a high-speed storage medium, thereby improving the search speed and the speed of obtaining search results.

[0178] Please see Figure 8 , Figure 8 This is a schematic diagram illustrating a database retrieval process as shown in this application. Figure 8 The illustrated steps are a detailed explanation of S108 and / or S208. For example... Figure 8 As shown, the method may include S802-S806.

[0179] S802, if there are multiple search statements, the multiple search statements are processed in parallel to complete the search in the database.

[0180] In full-text search and custom search scenarios, search statements are generated for each search scope, meaning there are multiple search statements. Multiple threads can be started to execute the search statements in parallel to complete the search.

[0181] During each search, the number of assets that meet the criteria within each search range can be determined first using the search query. Then, the asset information of the target asset can be retrieved from the search ranges where the number is not zero.

[0182] S804 stores the target asset information retrieved for each search query in a preset high-speed storage medium.

[0183] The preset high-speed storage medium may include memory, cache, etc. For example, the preset high-speed storage medium may be Redis. The preset high-speed storage medium stores target asset information retrieved under different search scopes.

[0184] S806, Obtain the target asset information from the preset high-speed storage medium and display it.

[0185] The S802-S806 architecture enables multi-threaded parallel processing of search statements and stores search results on high-speed storage media, thereby improving search speed and the speed of obtaining and displaying search results.

[0186] In some embodiments, several search scopes are arranged in a preset order. For example, the search scopes include assets, vulnerabilities, ports, and weak passwords, and the preset order is assets, vulnerabilities, ports, and weak passwords. In S806, target asset information queried under the first-order search scope can be obtained from the preset high-speed storage medium based on the preset order and displayed.

[0187] For example, if the target asset is found in the asset, vulnerability, port, and weak password search scopes, the target asset found in the asset search scope will be displayed first.

[0188] In response to the selection operation for other search ranges, the target asset information queried from the other search ranges is obtained from the preset high-speed storage medium and displayed.

[0189] For example, if a user selects a vulnerability, the target assets retrieved from the vulnerability scope can be displayed from a preset high-speed storage medium.

[0190] In some embodiments, the database is a graph-structured database. For example, the graph-structured database is Neo4j.

[0191] Neo4j is a high-performance NoSQL graph database that stores structured data on a network instead of tables. It's an embedded, disk-based Java persistence engine with full transaction capabilities, but it stores structured data on a network (mathematically called a graph) instead of tables. Neo4j can also be seen as a high-performance graph engine with all the features of a mature database. Programmers work within an object-oriented, flexible network structure, rather than strict, static tables. However, they can enjoy all the benefits of a fully transactional, enterprise-grade database. Neo4j is gaining increasing attention due to its embedded, high-performance, and lightweight advantages.

[0192] The graph-structured database stores the asset information and associated descriptive information in a graph structure.

[0193] In these embodiments, asset retrieval also includes an associated retrieval function.

[0194] Please see Figure 9 , Figure 9 This is a schematic diagram of the association retrieval method shown in this application. Figure 9 The illustrated method is a supplement in response to situations where only one search scope yields target asset information that satisfies the search criteria. For example... Figure 9 As shown, the method may include S902-S906.

[0195] S902, based on the graph structure, perform an association query to determine whether the target asset information has descriptive information in other search ranges besides the one search range.

[0196] In this step, the graph structure can be used to traverse and query the description information stored in other nodes that have connecting edges with the target asset information, and to determine whether the description information stored in other nodes is related to other search scopes.

[0197] For example, retrieve asset A within the asset scope. Then, iterate through the descriptions of other nodes connected to asset A to see if they relate to at least one of the following: vulnerability, weak password, or port.

[0198] S904, in response to the description information of other search scopes found, it is determined that the target asset information was found in the other search scopes.

[0199] In this step, if the description information stored by other nodes is related to other search scopes, it is determined that the target asset information was found in the other search scopes.

[0200] For example, if the description information of other nodes connected to asset A is related to vulnerabilities, weak passwords, and ports, it can be determined that asset A can be retrieved under the dimensions of vulnerabilities, weak passwords, and ports.

[0201] S906, the search results for the target asset information found in other search ranges are stored in the preset high-speed storage medium.

[0202] For example, the search structure that retrieves asset A under the dimensions of vulnerability, weak password, and port can be stored in the preset high-speed storage medium.

[0203] Related searches can be completed through S902-S906, and more comprehensive search results are provided through graph structure. Search results from multiple search dimensions are returned in a single search process, eliminating the need for users to search item by item and improving search accuracy.

[0204] This application also proposes an asset retrieval system. The system offers several advantages: First, it simplifies retrieval; second, it reduces the learning curve by supporting full-text search, allowing users to retrieve assets without needing to understand their specific attributes; third, it allows users to write search criteria in Chinese, including table and field names, eliminating the need to understand the underlying table and field names and reducing the learning curve; fourth, it aggregates search results across different dimensions, facilitating asset statistics; fifth, it provides a Chinese-supported search syntax for users to organize their search criteria; and sixth, it offers more comprehensive search results, simultaneously returning information such as assets, ports, weak passwords, and vulnerabilities during subsequent searches, eliminating the need for users to search item by item.

[0205] Please see Figure 10 , Figure 10 This is a schematic diagram illustrating the structure of an asset retrieval system as shown in this application. Figure 10 As shown, the system comprises five units: asset source, asset source handle, database, web interface, and web handle.

[0206] The asset source includes three sub-units. The first is the asset scanning sub-unit (Scanner). This unit provides asset detection functionality and inputs the detection results into the system. The second is the upload sub-unit (Upload). Through this unit, users can upload assets to the system. The third is the system log sub-unit (Syslog), which can retrieve assets from syslog or message queues through third-party services.

[0207] The asset information acquired by the first three asset source sub-units will flow into the asset source processing unit for processing. After processing by this unit, the asset information will be stored in a database. The database is Neo4j. This database includes several nodes, and the nodes are linked together via edges. Different nodes can store different information. For example, some nodes can store asset information, some can store vulnerability information, and some can store weak password information.

[0208] The page unit primarily interacts with the user during the search process, helping the user construct search criteria. These criteria are then processed by the page processing unit to generate corresponding Cypher syntax. The Cypher syntax is then passed to the database for data querying. The database query returns the results to the page processing unit for encapsulation before being returned to the front-end page.

[0209] The following describes the process of using the system to complete asset retrieval.

[0210] The page unit provides a search window for users to input search information. The search window includes two options: advanced search and search.

[0211] Users can enter their search information in the search window and select advanced search or regular search. Selecting advanced search will include a preset identifier in the search request.

[0212] After receiving a search request, the page processing unit can use the search sub-unit to determine the search type. See also... Figure 11 , Figure 11 This is a schematic diagram illustrating the method for determining the retrieval type as shown in this application. Figure 11 As shown, the method may include S1101-S1108.

[0213] S1101, Obtain a search request. The search request includes search information entered by the user.

[0214] S1102, Verify legality. Legality verification can include checking whether the condition is a malicious attack statement. If not, the verification passes, and S1104 is executed. If it is, S1103 is executed.

[0215] S1103, the abnormal content is directly returned to the front end, prompting the user that there is a problem with the search query.

[0216] S1104, Determine if it is an advanced search. If yes, proceed to S1105. If not, proceed to S1106.

[0217] In S1104, it can be determined whether the search request is an advanced search by judging whether the search request carries a preset identifier. For specific methods, please refer to the relevant description in S204 above.

[0218] S1105, proceed to advanced retrieval sub-unit (advance) processing.

[0219] S1106, Determine if it is a full-text search? If yes, proceed to S1107; otherwise, proceed to S1108.

[0220] In S1106, it can be determined whether the search is a full-text search by checking whether the search information includes operators. For specific methods, please refer to the relevant explanation in S204 above.

[0221] S1107 is processed through the full-text search sub-unit (full).

[0222] S1108, proceed to the custom retrieval sub-unit (analyzer) for processing.

[0223] S1101-S1108 supports multiple search methods and can automatically adapt the search method according to the search information entered by the user, simplifying the operation of the search tool for the user, reducing the requirements for the user, and enabling ordinary users to complete asset search, greatly reducing the difficulty of the search.

[0224] The following sections describe the working logic of the full-text search sub-unit, the advanced search sub-unit, and the custom search sub-unit.

[0225] I. Full-text search sub-unit.

[0226] Please see Figure 12 , Figure 12 This application illustrates a full-text search process. For example... Figure 12 As shown, the method may include S1201-S1207.

[0227] S1201, Obtain search information.

[0228] S1202, determine whether the search information is compliant. If not compliant, end the search. If compliant, proceed to S1203.

[0229] S1203, Generate a search statement corresponding to each of the plurality of search ranges.

[0230] S1204, Parallel query of target assets.

[0231] S1205, determine whether the target asset was found; if not, end the search. If yes, proceed to S1206.

[0232] S1206, Analyze target assets according to preset dimensions. These preset dimensions can be set according to requirements. For example, the preset dimensions may include responsible persons, equipment types, etc.

[0233] S1207, Encapsulate statistical results. Statistical results can be stored in Redis. In this step, the result output module can process the search results returned by the three search methods, encapsulating the different content returned by the three searches into a unified format, so that the front end does not need to perform different processing based on different searches.

[0234] Full-text search can be completed through S1201-S1207.

[0235] Taking four preset search scopes—assets, ports, vulnerabilities, and weak passwords—as an example, if a user enters "80," in the system, "80" could be a port number, part of an IP address, or a weak password for a device. The full-text search subunit will insert "80" into the organized search statement and search for the target asset within each of the four scopes: assets, ports, vulnerabilities, and weak passwords. If no target asset is found in any of the four scopes, the system will inform the user that the relevant asset does not exist. If a target asset is found, data will be constructed within the first search scope that retrieves multiple target assets. Simultaneously, the statistics subunit (count) will perform statistics on dimensions such as hardware type and responsible person within this scope, storing the quantity for each of the four scopes. Users can freely switch between the displayed content. Please refer to [link to relevant documentation]. Figure 13 , Figure 13 This is a schematic diagram illustrating how a page unit in this application displays search results to a user. For example... Figure 13 You can prioritize displaying target assets within the specified asset range. If you click on the vulnerability range, you can then display target assets within that range to the user.

[0236] II. Advanced Search Sub-units.

[0237] Please see Figure 14 , Figure 14 This is a schematic diagram illustrating the advanced search process described in this application. Figure 14 As shown, the method may include S1401-S1407.

[0238] S1401, Obtain search information.

[0239] S1402, escape the retrieved information to obtain the escaped result.

[0240] S1403, Generate a Cypher search statement based on the escaped result.

[0241] S1404, submit the search criteria to the database for query.

[0242] S1405, Encapsulate the statistical results. The statistical results can be stored in Redis. In this step, the retrieval results returned by the three retrieval methods can be processed through the result encapsulation subunit (result), encapsulating the different content returned by the three retrieval methods into a unified format, so that the front end does not have to perform different processing according to different retrievals.

[0243] S1406, Record retrieval information. This is for the user's convenience in future searches.

[0244] Advanced searches can be performed using S1401-S1406.

[0245] Taking four preset search categories—assets, ports, vulnerabilities, and weak passwords—as an example, please refer to [link / reference]. Figure 15 , Figure 15 This is a schematic diagram illustrating the advanced search window used in this application. Figure 15 As shown, the user selected the newspaper publication level and rack description fields within the asset scope to construct search criteria. After the user constructs the search criteria, the advanced search sub-unit can translate these criteria into corresponding Cypher search statements to retrieve target assets that meet the criteria within the asset search scope. Since the advanced search only needs to search within the user-selected search scope, the search speed is relatively fast.

[0246] III. Custom search sub-units.

[0247] Users can base on Figure 5 The example statement demonstrates how to construct a custom statement to complete the input of retrieved information.

[0248] Please see Figure 16 , Figure 16 This is a schematic diagram illustrating a custom search process as shown in this application. Figure 16 As shown, the method may include S1601-S1610.

[0249] S1601, retrieve custom statements.

[0250] S1602, Determine legality. The method for determining legality can be referred to in the previous embodiments, and will not be described in detail here.

[0251] S1603, the user-defined statement is parsed using the syntax parsing subunit (anltr) to obtain the search criteria. The search criteria include information such as the search scope, description fields, description targets, operators, and logical operators.

[0252] The syntax parsing subunit is based on the Antlr4 framework and can be configured with a segmentation module (VisitBarRelation module), a first escaping module (EqRelation module), a logical relation processing module (AndRelation module), and a second escaping module (FieldRelation). The combination of these four modules enables precise parsing of custom statements.

[0253] During the parsing of custom statements, dictionary sub-units (dic) can be used to map the search scope and description fields to nodes in Neo4j. These dictionary sub-units include the mapping relationship between the Chinese characters of the search scope and description fields and the English names of Neo4j nodes. This mapping is completed through these sub-units, converting user-input characters into characters recognizable by the database.

[0254] S1604, construct the search statement corresponding to each search range.

[0255] For explanations of S1603 and S1604, please refer to the relevant explanations of S602-S606 and S702-S706.

[0256] S1605, Parallel query of the number of target assets that meet the criteria within four different search ranges.

[0257] S1606, Obtain the target search range where the number of the target assets is not 0.

[0258] S1607, query the asset information of the target asset within the target retrieval range.

[0259] S1608 performs statistics based on preset dimensions, obtains the statistical results, and caches them in Redis.

[0260] S1609 performs permission checks on the user who initiates the asset retrieval, retaining the description fields that are visible to the user in the asset information of the retrieved target asset, and setting or hiding the description fields that are not visible to the user.

[0261] S1610 returns the final result to the front end.

[0262] Custom searches can be performed using S1601-S1610.

[0263] The aforementioned system offers several advantages: First, it simplifies retrieval; second, it reduces the learning curve for asset searches by supporting full-text search, eliminating the need to understand the specific attributes of assets; third, it allows users to write search criteria in Chinese, including table and field names, reducing the learning curve by eliminating the need to understand the underlying table and field names; fourth, it adds aggregations of different dimensions to search results, facilitating asset statistics for users; fifth, it provides a search syntax that supports Chinese, allowing users to organize their own search criteria; and sixth, it provides more comprehensive search results, returning information such as assets, ports, weak passwords, and vulnerabilities in subsequent searches, eliminating the need for users to search item by item.

[0264] Those skilled in the art will understand that one or more embodiments of this application can be provided as a method, system, or computer program product. Therefore, one or more embodiments of this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this application can take the form of a computer program product implemented on one or more computer-usable storage media (which may include, but are not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0265] In this application, "and / or" means having at least one of the two. The various embodiments in this application are described in a progressive manner, and similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the data processing device embodiments are basically similar to the method embodiments, so the description is relatively simple, and relevant parts can be referred to the description of the method embodiments.

[0266] While this application contains numerous specific implementation details, these should not be construed as limiting the scope of any disclosure or the scope of the claims, but rather are primarily used to describe the features of specific embodiments of a particular disclosure. Certain features described in the multiple embodiments of this application may also be implemented in combination in a single embodiment. Conversely, various features described in a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination. Furthermore, while features may function in certain combinations as described and even initially claimed in this way, one or more features from a claimed combination may be removed from that combination in some cases, and a claimed combination may refer to a sub-combination or a variation of a sub-combination.

[0267] Similarly, although operations are depicted in a specific order in the accompanying drawings, this should not be construed as requiring these operations to be performed in the specific order shown or sequentially, or requiring all illustrated operations to be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Furthermore, the separation of various system modules and components in the described embodiments should not be construed as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.

[0268] The above are merely preferred embodiments of one or more embodiments of this application and are not intended to limit the scope of one or more embodiments of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of one or more embodiments of this application should be included within the scope of protection of one or more embodiments of this application.

Claims

1. An asset retrieval method, characterized in that, The method includes: Obtain a search request; the search request includes search information for retrieving assets; the search information is a custom statement; the custom statement contains several set search conditions; the custom statement conforms to a certain syntax; the syntax includes six units: search scope, separator, description field, operator, query target, and logical operator; the search scope includes assets, vulnerabilities, ports, and weak passwords; the description field is the attribute information of the target asset to be searched. Based on the search request, determine the target search type that corresponds to the search request from the preset search types; When the target retrieval type is a custom retrieval, the custom statement is converted to obtain a retrieval statement. Specifically, fields are parsed to determine if the obtained data is in the format "range.field". If the format is correct, the information of the fields within that range is obtained using the dic module and escaped into Cypher syntax. The retrieval statement is used to retrieve assets that meet the aforementioned retrieval conditions. The asset information storage method includes: obtaining the asset information of the asset to be maintained; the asset information includes the following types of information: asset attribute information, vulnerability information, port information, and weak password information; for each type of asset information, its primary key information is determined; the descriptive information included in each type of asset information is used as a node in the neo4j graph structure, and the asset information belonging to the asset to be maintained is associated based on the primary key information to complete the storage of the asset information for the asset to be maintained. Based on the search query, asset retrieval is performed in the database; In response to retrieving target asset information that satisfies the search information within only one search scope, the method further includes: Based on the graph structure, the system performs a correlation query to determine whether descriptive information exists in other search ranges besides the first search range for the target asset information. In response to the descriptive information of other search scopes found, it is determined that the target asset information was found in the other search scopes; The search results for the target asset information found in other search categories will be stored in a preset high-speed storage medium.

2. The asset retrieval method according to claim 1, characterized in that, The database stores several asset information items and associated descriptive information; the descriptive information corresponds to several search ranges. The custom statement includes several second search conditions set for several second descriptive information corresponding to at least one search range; The process of converting the custom statement to obtain the search statement includes: Based on the statement generation rules corresponding to the target retrieval type, the custom statement is parsed to obtain several second retrieval conditions with logical relationships; Generate a second initial search statement corresponding to each of the second search conditions; For each of the plurality of search ranges, based on the logical relationship, the second initial search statement is combined to obtain the second final search statement corresponding to each search range.

3. The asset retrieval method according to claim 2, characterized in that, The process of parsing the custom statement yields several second search conditions with logical relationships, including: When the custom statement contains a second preset character, the custom statement is split according to the second preset character to obtain several first statement fragments with a first logical relationship; For each first statement segment, if the first statement segment contains a logical character, the first statement segment is split based on the logical character to obtain several second statement segments. The same operation as the first statement segment is performed on each second statement segment until the statement segments obtained after splitting do not contain the logical character. Each of the resulting sentence fragments is then identified as several of the second search criteria.

4. The asset retrieval method according to claim 1, characterized in that, The preset search types include full-text search, custom search, and advanced search; The step of determining the target search type corresponding to the search request from the preset search types includes: If the identifier bit included in the search request is a preset identifier, the target search type is determined to be advanced search; If the identifier bit included in the search request is not the preset identifier and the search information includes an operator, the target search type is determined to be a custom search. If the identifier bit included in the search request is not the preset identifier and the search information does not include an operator, the target search type is determined to be full-text search.

5. The asset retrieval method according to claim 1, characterized in that, The database stores several asset information items and associated descriptive information; the descriptive information corresponds to several search ranges. The search information consists of keywords included in the descriptive information associated with the target asset information; The method further includes: When the target retrieval type is full-text retrieval, a retrieval statement corresponding to each retrieval scope is generated according to the statement generation rules corresponding to the full-text retrieval; the retrieval statement is used to retrieve target asset information under the corresponding retrieval scope; the descriptive information associated with the target asset information includes the keywords.

6. The asset retrieval method according to claim 5, characterized in that, The description information includes IP and / or MAC addresses; the word segmentation method for the IP and / or MAC addresses includes: Traverse each character of the IP and / or MAC address from left to right, and form a first word segment by the characters before the first preset character, form a second word segment and a third word segment by the characters between two adjacent first preset characters, and form a fourth word segment by the characters after the last preset character. The first word segment and the first preset character are combined to form the fifth word segment; Combine the fifth and second segmentation words to form the sixth segmentation word; The sixth word segment and the first preset character in the middle are combined to form the seventh word segment; Combine the seventh and third segment words to form the eighth segment word; The eighth word and the last first preset character are combined to form the ninth word; The ninth and fourth segment words are combined to form the tenth segment word.

7. The asset retrieval method according to claim 1, characterized in that, The database stores several asset information items and associated descriptive information; the descriptive information corresponds to several search ranges. The search information consists of several first search conditions set for several first descriptive information under a first search scope; the several first search conditions have a logical relationship with each other; The method further includes: When the target search type is advanced search, Based on the statement generation rules corresponding to the advanced search, a first initial search statement corresponding to each of the first search conditions is generated. Based on the logical relationship, the first initial search statement is combined to obtain the first final search statement; the first final search statement is used to retrieve target asset information under the first search scope, and the first description information contained in the target asset information satisfies the several first search conditions.

8. The asset retrieval method according to any one of claims 1 to 7, characterized in that, The asset retrieval in the database based on the search query includes: In the case of multiple search statements, the multiple search statements are processed in parallel to complete the search in the database; The target asset information retrieved for each search query is stored in a preset high-speed storage medium; the preset high-speed storage medium stores the target asset information retrieved under different search ranges; The target asset information is obtained from the preset high-speed storage medium and displayed.

9. The asset retrieval method according to any one of claims 1 to 3, characterized in that, Before converting the custom statement, the method further includes: The custom statement is validated; the validation dimensions include syntax validation and / or content validation. The syntax validation refers to checking whether the custom statement contains preset illegal characters, and determining that the syntax validation passes if no preset illegal characters are included. The content validation refers to determining whether the content of the custom statement is missing, and determining that the content validation passes if the content is not missing.

10. The asset retrieval method according to claim 1, characterized in that, The method further includes: In response to the completion of storing asset information for the asset to be maintained, an index is established for each type of asset information; the index includes at least a portion of the descriptive information of the asset information.

11. The asset retrieval method according to claim 10, characterized in that, The search information consists of keywords included in the target asset information and / or target description information of the target asset to be searched; when the target search type is full-text search, the method for performing full-text search based on the index includes: Based on the keywords, construct search statements for each type of asset information; The search query is used to perform asset retrieval in the database, including: Based on the search query, a first target node including the keyword is retrieved, and a second target node with a preset stride is retrieved from the first target node; the first target node and the second target node are nodes corresponding to the target asset information and the target description information; Based on the first target node and the second target node, count the number of nodes of each type and return them as query results.

Citation Information

Patent Citations

  • DSL statement conversion and query method and device for asset retrieval

    CN110647667A

  • Data retrieval analysis method and device, electronic equipment and storage medium

    CN113934430A