A method, device, electronic device and storage medium for sensing abnormal opening of a network port

By acquiring network traffic and matching it with anomaly detection rules, network port anomalies are identified and real-time alarms are issued, solving the problem of traditional technologies being unable to detect abnormal openings in a timely manner and improving asset security and management efficiency.

CN116015808BActive Publication Date: 2025-09-05BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211620045.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-15
Publication Date
2025-09-05
Estimated Expiration
2042-12-15

AI Technical Summary

Technical Problem

Traditional network security defense technologies lack effective solutions for detecting abnormal network port openings and are unable to promptly perceive and respond to abnormal opening states, resulting in compromised asset security.

Method used

By obtaining the network traffic of the target network port and matching it with the anomaly detection rules, it is determined whether the port is abnormal and the alarm information is displayed in real time, including the port number, access source IP, abnormal access time and asset information.

Benefits of technology

It achieves timely perception and alarm of abnormal opening of network ports, improves the security of assets, and can accurately locate the source of abnormalities and take measures to prevent harm.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015808B_ABST
    Figure CN116015808B_ABST
Patent Text Reader

Abstract

Embodiments of the present invention disclose a method, device, electronic device, and storage medium for detecting abnormally open network ports, relating to the field of network security technology. The method facilitates timely and effective detection of abnormally open network ports, thereby improving asset security. The method comprises the following steps: obtaining network traffic collected by a target open network port; matching the network traffic with anomaly detection rules corresponding to the target open network port; and determining whether the target open network port is abnormal based on the matching results. The present invention is suitable for monitoring abnormal port opening in a network environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method, device, electronic device and storage medium for sensing abnormal opening of a network port. Background Art

[0002] With the rapid development of internet applications, asset information security has become increasingly important. Open ports on assets can be easily exploited by criminals, who can access computers and steal data, damaging users' business and data and causing irreparable financial losses. Some dangerous ports can be exploited by viruses and Trojans, which can infiltrate corporate intranets and steal corporate secrets.

[0003] Traditional network security defense technologies lack effective solutions for detecting anomalies in network port openings, making it impossible to effectively and timely detect abnormal opening status of network ports. Summary of the Invention

[0004] In view of this, embodiments of the present invention provide a method, device, electronic device, and storage medium for sensing abnormal opening of a network port, which facilitate timely and effective sensing of abnormal opening of a network port, thereby improving asset security.

[0005] In a first aspect, an embodiment of the present invention provides a method for perceiving abnormal opening of a network port, comprising the steps of: obtaining network traffic collected by a target open network port; matching the network traffic with an anomaly detection rule corresponding to the target open network port; and determining whether the target open network port is abnormal based on the matching result.

[0006] Optionally, after determining whether the target open network port is abnormal based on the matching result, the method further includes: displaying alarm information of the target open network port determined to be abnormal, the alarm information including: port number, abnormal access source IP, abnormal access time and / or asset information to which the port belongs.

[0007] Optionally, the target open network ports include multiple ones; the alarm information display of the target open network ports determined to be abnormal includes: determining the assets and / or corresponding anomaly detection rules to which the multiple target open network ports belong; and statistically merging and displaying the alarm information of the target open network ports with the same assets and / or the same anomaly detection rules according to the network traffic collection time or the alarm information generation time.

[0008] Optionally, the method further includes: pre-configuring anomaly detection rules for the target open network port.

[0009] Optionally, the pre-configured anomaly detection rules for the target open network port include: collecting network traffic data from a probe device; the network traffic data carries the identity information of the probe device, and the network traffic data is obtained based on monitoring the network port of the probe device; filtering and obtaining the network traffic data of the target asset based on the identity information of the probe device; identifying and registering the asset characteristics of the target asset based on at least the network traffic data of the target asset, the asset characteristics including: asset physical location, asset type, asset port, asset user and / or asset IP; configuring the anomaly detection rules for the target open network port based on the asset characteristics.

[0010] Optionally, configuring anomaly detection rules for the target open network port based on the asset characteristics includes: determining the importance of the target asset based on the asset characteristics; and configuring anomaly detection rules of a regulatory level corresponding to the importance based on the importance of the target asset.

[0011] Optionally, after filtering and obtaining the network traffic data of the target asset, the method further includes: storing the network traffic data of the target asset in a corresponding database according to a predetermined database data storage format; before performing asset feature identification and registration of the target asset based at least on the network traffic data of the target asset, the method further includes: obtaining the network traffic data of the target asset from the database.

[0012] In a second aspect, an embodiment of the present invention also provides a network port abnormal opening perception device, including: an acquisition program module for acquiring network traffic collected by a target open network port; a matching program module for matching the network traffic with anomaly detection rules corresponding to the target open network port; and a determination program module for determining whether the target open network port is abnormal based on the matching result.

[0013] In a third aspect, an embodiment of the present invention also provides an electronic device, comprising: a housing, a processor, a memory, a circuit board and a power supply circuit, wherein the circuit board is placed inside the space enclosed by the housing, and the processor and the memory are arranged on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, and is used to execute any of the network port abnormal opening perception methods described in the first aspect above.

[0014] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, which stores one or more programs, and the one or more programs can be executed by one or more processors to implement the network port abnormal open perception method described in any one of the first aspects.

[0015] The embodiments of the present invention provide a method, device, electronic device, and storage medium for sensing abnormal opening of a network port, which include the following steps: obtaining network traffic collected by a target open network port; matching the network traffic with anomaly detection rules corresponding to the target open network port; and determining whether the target open network port is abnormal based on the matching result; thereby facilitating timely and effective sensing of abnormal opening of a network port, thereby improving asset security. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0017] Figure 1 This is a flow chart of a method for detecting abnormal opening of a network port according to an embodiment of the present invention;

[0018] Figure 2 This is a flow chart of a method for sensing abnormal opening of a network port according to another embodiment of the present invention;

[0019] Figure 3 This is a schematic diagram of the architecture of an embodiment of a device for sensing abnormally open network ports according to the present invention;

[0020] Figure 4 The figure is a schematic block diagram of the architecture of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0021] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0022] It should be understood that the embodiments described are only a portion of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without creative work are within the scope of protection of the present invention.

[0023] Example 1

[0024] Figure 1 This is a flow chart of a method for sensing abnormal opening of a network port according to an embodiment of the present invention. Figure 1As shown, an embodiment of the present invention provides a method for sensing abnormal opening of a network port, comprising the steps of:

[0025] S110, obtaining network traffic collected by the target open network port;

[0026] Specifically, the network traffic collected from the target open network ports must first be obtained, wherein the network traffic collected from these target open network ports includes: port number, access source IP, access time and / or asset information to which the port belongs.

[0027] S120, matching the network traffic with anomaly detection rules corresponding to the target open network port;

[0028] Specifically, after obtaining the network traffic collected by the target open network port, the network traffic is matched with the anomaly detection rule corresponding to the target open network port to obtain a matching result.

[0029] S130: Determine whether the target open network port is abnormal according to the matching result.

[0030] Specifically, the matching results are used to determine whether the target open network port is abnormal, so as to timely and effectively detect the abnormal opening of the network port and improve the security of assets.

[0031] In some embodiments, in step S130, after determining whether the target open network port is abnormal based on the matching result, the method further includes: displaying alarm information of the target open network port determined to be abnormal, the alarm information including: port number, abnormal access source IP, abnormal access time and / or asset information to which the port belongs.

[0032] Specifically, after determining that a target open network port is abnormal based on the matching results, the system displays alarm information for the identified abnormal target open network port in real time in the form of lists, charts, data statistical analysis, etc. The alarm information includes: port number, abnormal access source IP address, abnormal access time, and / or asset information to which the port belongs. For example, alarm information for abnormal port opening is displayed in a list format, with alarm details including alarm occurrence time, alarm level, alarm tag, and other information. The alarm details display detailed information about the asset where the alarm occurred, allowing accurate location of the asset user and asset IP address.

[0033] In some embodiments, the target open network ports include multiple ones; the alarm information display of the target open network ports determined to be abnormal includes: determining the assets and / or corresponding anomaly detection rules to which the multiple target open network ports belong; and statistically merging and displaying the alarm information of the target open network ports with the same assets and / or the same anomaly detection rules according to the network traffic collection time or the alarm information generation time.

[0034] Specifically, the target open network port has multiple targets, including: file sharing service ports, remote connection service ports, Web application service ports, database service ports, and mail service ports, etc. When displaying the alarm information of the target open network port determined to be abnormal, determine the assets and / or corresponding anomaly detection rules to which the multiple target open network ports belong; according to the network traffic collection time or the alarm information generation time, perform statistical aggregation and display on the data of the same rule, the same asset, and the same day to reduce the amount of data displayed by the data application; when the asset to which the target open network port belongs corresponds to the anomaly detection rule, display the alarm information in real time using list and chart data statistical analysis. Display the alarm information of abnormal port opening in the form of a list, and the alarm details, including the alarm occurrence time, alarm level, alarm label and other information, display the detailed information of the asset where the alarm occurred in the 5 alarm details, and accurately locate the user and IP. At the same time,

[0035] The trend of abnormal port opening within a period of time can be displayed in the form of a chart, and the location of the top (important) assets with abnormal port opening, asset users and other information can be intuitively identified.

[0036] In some embodiments, the method further includes: pre-configuring anomaly detection rules for the target open network port.

[0037] Furthermore, the pre-configured abnormality detection rules for the target open network port include: collecting network flow data from the probe device; the network flow data carries the identity information of the probe device, and the network flow data is obtained based on monitoring the network port of the probe device; filtering the network flow data of the target asset according to the identity information of the probe device; at least according to the target asset

[0038] The network traffic data generated is used to identify and register the asset characteristics of the target asset, where the asset characteristics 5 include: asset physical location, asset type, asset port, asset user and / or asset IP; according to the asset characteristics, anomaly detection rules for the target open network port are configured.

[0039] Specifically, before matching the network traffic with the anomaly detection rules corresponding to the target open network port, the anomaly detection rules of the target open network port must be pre-configured; specifically, in the network traffic data

[0040] It carries the identification information of the probe device. The network traffic information reported by the probe device is obtained based on the network port monitoring of the probe 0 device. Among them, the probe devices include: network probes, WiFi probes and network traffic hyper-convergence probes. The network probe is a component used to capture and analyze network data packets, such as Yaf, bro, packetbeat, etc. The core of these components is traffic collection; WiFi probe technology refers to the use of WiFi detection technology to identify the WiFi-enabled smart devices near the AP (wireless access point).

[0041] The WiFi Probe 5 can identify user information without the need for the user to access WiFi through a mobile phone or WiFi terminal (laptop, tablet, etc.); the network traffic hyper-converged probe adopts a combination of feature detection technology, abnormal behavior detection technology, threat intelligence technology, black and white list technology, baseline technology, static APT technology and other methods. Through deep packet analysis and flow analysis of network traffic, it realizes comprehensive and effective detection of various network threats.

[0042] Furthermore, through data source configuration, data from multiple probe devices are accessed, and network traffic data of the target assets are filtered out based on the identity information of the probe devices. The network traffic data of the filtered-out valid assets are automatically identified as target assets, and asset feature identification and registration are performed on the target assets. Invalid asset data is discarded, and the data is stored in the database after governance. Asset characteristics include: asset physical location, asset type, asset port, asset user and / or asset IP; asset data is enriched through manual entry of asset attributes and asset types, including: printing devices, computing devices, network devices, storage devices, security devices, and other devices; asset attributes include: IP address (Internet Protocol Address), MAC address (MAC, Media Access Control, also known as hardware address), asset source, asset user, asset region, asset group, asset department, asset physical location, asset logical partition, etc.; some asset inherent information is automatically identified, and the asset discovery process is completed automatically. Manual maintenance of asset attributes, asset type and other information can ensure the accuracy of asset information; asset registration and identification are only performed when the asset is first discovered on the network. Asset information may change during actual asset use, and asset management is mainly used to respond to changes in asset information; when asset information such as asset attributes and asset type changes, asset information can be edited through asset management to ensure the accuracy of asset information.

[0043] Based on asset characteristics, for example, by configuring asset types, such as asset types include: printing devices, computing devices, network devices, storage devices, security devices, other devices, etc.; asset attributes, such as asset attributes include: IP address, MAC address, asset source, asset user, asset area, asset group, asset department, asset physical location, asset logical partition, etc.; ports or port ranges that need to be detected, set rule black / white lists; control the opening and closing of rules through rule switches, edit the rules when they need to be adjusted, and configure anomaly detection rules for the target open network ports that need to be monitored.

[0044] In some embodiments, configuring anomaly detection rules for the target open network port based on the asset characteristics includes: determining the importance of the target asset based on the asset characteristics; and configuring anomaly detection rules with a regulatory level corresponding to the importance based on the importance of the target asset.

[0045] Specifically, when configuring anomaly detection rules that need to monitor the target open network ports, due to the excessive number of terminal assets in the network environment, the excessive number of available ports, and the excessive number of open deployment services in the environment, in order to manage key assets and key abnormal ports, the importance of the assets can be determined based on classification information such as the asset's location, asset user, asset type, and asset department, and rules that focus on the assets can be configured. Alternatively, an asset whitelist can be configured to exclude assets that do not require attention, and by associating them with asset types and asset attributes in the configuration, the assets that cause abnormal port openings can be accurately located. At the same time, alarm labels can be set to display information and alarm levels, and the opening and closing of rules can be flexibly controlled through switches, and multiple rules can be created as needed.

[0046] In some embodiments, after filtering and obtaining the network traffic data of the target asset, the method further comprises: storing the network traffic data of the target asset in a corresponding database according to a predetermined database data storage format;

[0047] Before performing asset feature identification and registration on the target asset at least based on the network traffic data of the target asset, the method further includes: acquiring the network traffic data of the target asset from the database.

[0048] Specifically, first, data logs are collected for the network traffic data entering the port. After that, the network traffic data is transmitted through the Kafka message service cluster (Kafka is a high-throughput distributed publish-subscribe message system that can process all action flow data of consumers on the website). The Kafka message queue is mainly used for real-time data collection, and the probe device in the data is used to determine whether it is asset data; data collection is performed based on the identity information of the probe device. The device identifier is used to determine the asset source and classification of the device, and the network traffic data of the target asset is filtered and stored in the corresponding database according to the predetermined database data storage format; the data storage layer includes: HFDFS distributed file system, Postgresql application relational database and Hbase columnar database; the data storage layer mainly provides data services for the data analysis layer. Among them, Hbase is established based on the HFDFS file. The data storage format of Hbase is based on the initial log columnar data storage, the HDFS data storage format is stored in the form of files, and the PostgreSql application relational database is mainly used for system business data storage.

[0049] Furthermore, before the target asset is identified and registered based on its network traffic data, the network traffic data of the current target asset is obtained from the database to identify and register the asset. Some of the inherent information of the asset is automatically identified, and the asset's physical location, asset user, asset type, asset IP and other information can be improved according to actual conditions.

[0050] Example 2

[0051] Please see Figure 2 As shown, according to the above-mentioned method for sensing abnormal opening of a network port, the method for sensing abnormal opening of a network port provided by the embodiment of the present invention includes the following steps:

[0052] S21. Data Collection: Collect network traffic from the target's open network port and collect network traffic data from the probe device. The network traffic data carries the identity information of the probe device. Based on the identity information of the probe device, the network traffic data of the target asset is filtered and obtained.

[0053] S22. Network traffic data passes through the Kafka message server cluster: Kafka message queues are mainly used for real-time data collection, and the device in the data is used to determine whether it is asset data;

[0054] S23. The data storage layer stores network traffic data: The data storage layer includes: HFDFS distributed file system, Postgresq l application relational database and Hbase column database; the collected data is processed, and different data are uniformly processed according to their formats and stored in the data storage layer;

[0055] S24. Data analysis layer analyzes data: The data analysis layer mainly includes: asset registration and identification, exception rule configuration, and data statistical analysis; Asset registration and identification: After obtaining asset data from the database, identify and register the assets, deploy corresponding equipment based on the business needs of the network environment, and passively discover assets through the data reported by the equipment. After passive discovery, supplement asset attributes, asset types and other information. Abnormal rule configuration: Based on asset information such as asset attributes and asset types, as well as network port information that requires attention, configure abnormal port opening rules, and associate and map ports with assets. Data statistical analysis: In order to achieve timely discovery of abnormal port opening, the amount of data in the network environment is often large. Even if special attention is paid through the exception rule configuration, a large amount of data will still be generated. Therefore, certain statistical analysis methods are used to analyze the huge amount of collected data, extract useful information, and aggregate and summarize the information for display.

[0056] S25. Data Application Layer Displays Data: The data application layer includes asset management, alarm management, and situation monitoring. It obtains data from the data analysis service layer and displays it visually. Asset Management: Asset management is primarily used to respond to changes in asset information. When asset information such as asset attributes and asset types changes, the asset information can be edited through asset management to ensure the accuracy of the asset information; Alarm management: Real-time data is obtained from the message queue, and matched and associated through asset management and exception rule configuration. Once an abnormal port is found to be open on an asset, alarm data is generated, and the alarm information is displayed in real time through list and chart data statistical analysis. The asset information can be located in time through the alarm information, and the assets with abnormal port openings can be processed in time, and certain measures can be taken to prevent harm; Situation monitoring: The trend of abnormal port openings over a period of time is displayed in the form of a chart, and the location of the top assets with abnormal port openings, the users of the assets and other information can be intuitively identified. Through situation monitoring, historical data can be effectively analyzed to provide decision-making analysis for preventing the occurrence of harm. It can be analyzed that a certain department or a certain asset has too many abnormal ports open, and the asset ports can be effectively managed. After confirming that there is no threat, the detection rules can be adjusted to provide a basis for subsequent analysis and judgment.

[0057] The method for sensing abnormal opening of a network port provided by an embodiment of the present invention obtains network traffic collected from a target open network port, matches the network traffic with anomaly detection rules corresponding to the target open network port, determines whether the target open network port is abnormal based on the matching result, and generates and displays alarm information for the abnormal network port in real time, so as to facilitate timely and effective sensing of abnormal opening of the network port, thereby improving the security of assets.

[0058] Example 3

[0059] Based on the same technical concept as the above embodiment 1, the present invention also provides a network port abnormal opening sensing device, such as Figure 3 As shown, the network port abnormal opening sensing device includes: an acquisition program module 31, which is used to obtain the network traffic collected by the target open network port;

[0060] a matching program module 32 for matching the network traffic with anomaly detection rules corresponding to the target open network port;

[0061] The determination program module 33 is configured to determine whether the target open network port is abnormal according to the matching result.

[0062] The implementation principle and technical effects of the device of this embodiment are similar to those of the corresponding embodiment of the method for sensing abnormal opening of a network port in the aforementioned embodiment 1. For details not described in detail, please refer to each other and will not be repeated here.

[0063] Example 4

[0064] Figure 4 This is a schematic block diagram of the architecture of an embodiment of an electronic device of the present invention; based on the technical concept basically the same as that of the aforementioned embodiment 1, the electronic device provided by the embodiment of the present invention, as shown in Figure 4, can implement the step flow of the embodiment method described in any one of the embodiments 1 and 2 of the present invention.

[0065] The above-mentioned electronic device may include: a shell 41, a processor 42, a memory 43, a circuit board 44 and a power supply circuit 45, wherein the circuit board 44 is placed inside the space enclosed by the shell 41, and the processor 42 and the memory 43 are set on the circuit board 44; the power supply circuit 45 is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory 43 is used to store executable program code; the processor 42 runs the program corresponding to the executable program code by reading the executable program code stored in the memory 43, and is used to execute the network port abnormal open perception method described in any of the above-mentioned embodiments.

[0066] The specific execution process of the above steps by the processor 42 and the steps further executed by the processor 42 by running the executable program code can be found in the description of the first embodiment of the present invention, and will not be repeated here.

[0067] The electronic devices exist in various forms, including but not limited to:

[0068] (1) Mobile communication devices: These devices are characterized by their mobile communication capabilities and are primarily designed to provide voice and data communications. These terminals include smartphones (e.g., iPhones), multimedia phones, feature phones, and low-end phones.

[0069] (2) Ultra-mobile personal computer devices: These devices fall under the category of personal computers, have computing and processing capabilities, and generally also have mobile Internet access. These terminals include PDAs, MIDs, and UMPCs, such as the iPad.

[0070] (3) Portable entertainment devices: These devices can display and play multimedia content. These devices include audio and video players (such as iPods), handheld game consoles, e-books, smart toys, and portable car navigation devices.

[0071] (4) Server: A device that provides computing services. The server consists of a processor, hard disk, memory, system bus, etc. The server is similar to a general computer architecture, but because it needs to provide highly reliable services, it has higher requirements in terms of processing power, stability, reliability, security, scalability, and manageability.

[0072] (5) Other electronic devices with data interaction functions.

[0073] Example 5

[0074] An embodiment of the present invention also provides a computer-readable storage medium, which stores one or more programs. The one or more programs can be executed by one or more processors to implement the network port abnormal openness perception method described in any of the above-mentioned embodiments, thereby also achieving the corresponding technical effects. The above has been described in detail and will not be repeated here.

[0075] In summary, the embodiments of the present invention provide a method, device, electronic device and storage medium for sensing abnormal opening of network ports. Based on a variety of detection technologies, the method can obtain data from different probe devices from network ports according to different asset sources and network environment requirements, identify target assets, process and store information such as the regional location, personnel information, and basic information of the assets, configure abnormal rules based on the stored data such as the regional location of the assets, asset IP, asset users, and asset groups that need to be paid attention to, rely on big data and data statistical analysis capabilities to perform real-time calculations, offline analysis and mining, and asset analysis, so as to accurately locate the abnormal port opening of the assets and perform aggregated alarm display for the abnormal port opening of the assets, so as to facilitate timely and effective perception of the abnormal opening of the network ports, thereby improving the security of the assets.

[0076] Furthermore, by acquiring network traffic data in real time and matching it with anomaly detection rules, alarm data is generated in real time when the asset type, asset attributes, and abnormal port meet the configured rules. The alarm information can be used to promptly locate the asset that caused the abnormal port to be opened. At the same time, historical alarm data can be analyzed through situation monitoring to improve asset security.

[0077] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0078] Each embodiment in this specification is described in a related manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments.

[0079] For the convenience of description, when referring to a system, server, etc., it may be described separately by dividing the functions into various units / modules. Of course, when implementing the present invention, the functions of each unit / module can be implemented in the same or multiple software and / or hardware.

[0080] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware through a computer program. The program can be stored in a computer-readable storage medium, and when executed, the program can include the processes in the above-described method embodiments. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).

[0081] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A method for sensing abnormal opening of a network port, characterized in that: Including steps: Collecting network traffic data from a probe device; the network traffic data carries identification information of the probe device, and the network traffic data is obtained based on monitoring the network port of the probe device; Filtering and obtaining network traffic data of the target asset based on the identification information of the probe device; Identify and register asset characteristics of the target asset based at least on the network traffic data of the target asset, where the asset characteristics include: asset physical location, asset type, asset port, asset user, and / or asset IP address; Based on the asset characteristics, configure anomaly detection rules for the target open network ports; Get the network traffic collected from the target open network port: Matching the network traffic with anomaly detection rules corresponding to the target open network port; Determine whether the target open network port is abnormal based on the matching result.

2. The method for sensing abnormal opening of a network port according to claim 1, wherein: After determining whether the target open network port is abnormal based on the matching result, the method further includes: displaying alarm information of the target open network port determined to be abnormal, the alarm information including: port number, abnormal access source IP, abnormal access time and / or asset information to which the port belongs.

3. The method for sensing abnormal opening of a network port according to claim 2, wherein: The target open network ports include multiple; The display of alarm information of the target open network port determined to be abnormal includes: determining the assets to which the target open network ports belong and / or corresponding abnormality detection rules; Alarm information for target open network ports with the same assets and / or the same anomaly detection rules is aggregated and displayed based on the network traffic collection time or alarm information generation time.

4. The method for sensing abnormal opening of a network port according to claim 1, wherein: Configuring anomaly detection rules for a target open network port based on the asset characteristics includes: determining the importance of the target asset based on the asset characteristics; and configuring anomaly detection rules with a supervision level corresponding to the importance based on the importance of the target asset.

5. The method for sensing abnormal opening of a network port according to claim 4, wherein: After obtaining the network traffic data of the target asset through screening, the method further includes: storing the network traffic data of the target asset in a corresponding database according to a predetermined database data storage format; Before performing asset feature identification and registration on the target asset at least based on the network traffic data of the target asset, the method further includes: acquiring the network traffic data of the target asset from the database.

6. A network port abnormal opening sensing device, characterized in that: include: A rule configuration program module for collecting network traffic data from probe devices; The network flow data carries the identification information of the probe device, and the network flow data is obtained based on monitoring the network port of the probe device; Filtering and obtaining network traffic data of the target asset based on the identification information of the probe device; Identify and register asset characteristics of the target asset based at least on the network traffic data of the target asset, where the asset characteristics include: asset physical location, asset type, asset port, asset user, and / or asset IP address; Based on the asset characteristics, configure anomaly detection rules for the target open network ports; An acquisition program module is used to obtain network traffic collected by the target open network port; a matching program module, configured to match the network traffic with anomaly detection rules corresponding to the target open network port; The determination program module is used to determine whether the target open network port is abnormal according to the matching result.

7. An electronic device, characterized in that: The electronic device includes: a housing, a processor, a memory, a circuit board and a power supply circuit, wherein the circuit board is placed inside the space enclosed by the housing, and the processor and memory are arranged on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, and is used to execute the network port abnormal opening perception method described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the method for sensing abnormal opening of a network port according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Network asset identification method and device, storage medium and electronic equipment

    CN113949748A

  • Abnormality detection method and device, computer equipment and storage medium

    CN114465741A