A network space asset management method based on a knowledge graph

By constructing a knowledge graph-based cyberspace asset management method, the shortcomings of existing technologies in terms of diversified asset management needs and risk management are addressed. This enables flexible asset management and attack path analysis, meeting the management needs from multiple user perspectives.

CN116204658BActive Publication Date: 2026-08-25北京国御科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310252569.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-15
Publication Date
2026-08-25
Estimated Expiration
2043-03-15

AI Technical Summary

Technical Problem

Existing methods for managing cyberspace assets are insufficient to meet diverse management needs, particularly in terms of asset change management and business system management. Furthermore, CMDB technology is weak in risk management and has high maintenance costs.

Method used

A knowledge graph-based approach is used to construct a cyberspace asset ontology. By listing concepts, attributes and their relationships, a knowledge structure is built. Metadata is automatically updated by combining multiple information acquisition methods, and the possibility of attacks is analyzed through the shortest path algorithm to form an entity network reachable relationship network.

Benefits of technology

It enables flexible asset management from a multi-user perspective, monitors the dynamic changes of server and terminal assets in cyberspace, provides attack probability analysis, and guides vulnerability remediation efforts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116204658B_ABST
    Figure CN116204658B_ABST
Patent Text Reader

Abstract

The application discloses a network space asset management method based on a knowledge graph, relates to the technical field of network asset management, and comprises the following steps: S1, constructing a knowledge graph; S2, automatically updating metadata; collecting network space asset metadata in an asset initial construction stage, standardizing the metadata into an entity attribute graph according to a network space asset knowledge system, and then performing network space knowledge graph matching; and S3, constructing a network reachable relationship and analyzing attack possibility, wherein the construction of the network reachable relationship can include remote login modes, Agent collection modes, SNMP protocol modes and port scanning modes, the attack possibility is analyzed, the nodes in the relationship network are valued, a shortest path algorithm is used, and an attack path graph that can be used by an attacker is calculated. The application is aimed at actual network space asset management requirements, starts from application targets and ranges, considers applicability and simplicity, and realizes flexible asset management requirements in a multi-user perspective.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network asset management technology, and more specifically, to a knowledge graph-based method for managing cyberspace assets. Background Technology

[0002] The essence of cyberspace assets is information and resources. It includes not only hosts and servers as fixed assets, but also IP resources, web services running on hosts and servers, file servers, various systems, and personnel of organizations.

[0003] The management of cyberspace assets is the cornerstone of a security operations and maintenance system. With a structured asset database, various analyses, standards, and processes can be built on the foundation of cyberspace asset data, thereby achieving truly standardized, automated, and intelligent security operations and maintenance.

[0004] Cyberspace assets are diverse and complex, ranging from hardware to software, from standalone machines to clusters, and constantly giving rise to new products such as cloud computing, the Internet of Things, industrial control systems, mobile terminals, and big data systems. There are numerous asset managers with varying perspectives: system administrators focus on overall security risks and compliance, security administrators on various information vulnerabilities and security risks, operations and maintenance personnel on business continuity and operational status, network administrators on network policy configuration, and finance personnel on the asset's financial lifecycle. This complexity and diverse needs place extremely high demands on cyberspace asset management.

[0005] Currently, there are two main approaches to asset management: one is asset management centered on IP asset mapping, and the other is asset management centered on Configuration Management Database (CMDB) technology.

[0006] Asset mapping is an asset management method that primarily uses asset vulnerability scanning tools to scan IP assets and potential vulnerabilities in them. Its advantage lies in its simplicity and speed, enabling it to quickly identify surviving IP assets and their vulnerability risks within an organization.

[0007] Configuration Management Database (CMDB) asset management stores information about project configurations within an organization, including hardware, software, systems, facilities, and sometimes personnel. CMDB systems typically collect asset information through various channels, such as asset scanning tools, asset management forms, agents, and system APIs. The CMDB system cleans and integrates this information to ultimately form a manageable cyberspace asset database.

[0008] Assets managed using an IP asset mapping approach can only be considered IP assets. Even with the addition of fields such as business systems and responsible personnel, it is still insufficient to support other needs in cyberspace asset management, such as asset change management and asset business system management.

[0009] While asset management based on Configuration Management Database (CMDB) technology offers a relatively rich perspective on asset management, it also has its limitations. On the one hand, obtaining high-quality asset data requires very high maintenance and management costs. On the other hand, CMDB's ability to manage asset risks is relatively weak and insufficient to support the increasing demands for secure operations. Summary of the Invention

[0010] The purpose of this invention is to provide a knowledge graph-based cyberspace asset management method that addresses the actual needs of cyberspace asset management, taking into account the application objectives and scope, applicability, and simplicity, and constructs a cyberspace asset ontology manually.

[0011] To achieve the above objectives, a knowledge graph-based method for managing cyberspace assets includes the following steps:

[0012] Step 1: Construct a knowledge graph, which includes identifying the domain, listing concepts and attributes and their relationships, determining the knowledge structure, defining attributes and relationships, and defining constraints.

[0013] Step 2: Automated metadata update. During the initial asset construction phase, metadata of cyberspace assets is collected. The metadata is standardized into an entity attribute graph according to the cyberspace asset knowledge system, and then matched with the cyberspace knowledge graph.

[0014] Step 3: Network reachability construction and attack probability analysis. Building network reachability can include remote login, agent collection, SNMP protocol, and port scanning. Analyzing the attack probability involves assigning values ​​to nodes in the network and using the shortest path algorithm to calculate the attack path graph that attackers may exploit.

[0015] Optionally, the professional domains of cyberspace assets in the defined domain include physical equipment domains, software domains, spatial area domains, information system domains, organizational personnel domains, financial value domains, etc. The listing of concepts, attributes, and their relationships involves collecting and listing all the necessary concepts, attributes, and relationships within the defined domain, ensuring the comprehensiveness of the list of concepts, attributes, and relationships. The defined knowledge system structure is constructed using a top-down approach, first defining classes and then defining hierarchical structures. The definition of attributes and relationships, based on the listed concept attributes and relationships, clearly defines the cyberspace attributes contained in the concepts and the cyberspace relationships between concepts. The definition of constraints, based on the actual situation of the cyberspace asset concept attributes, defines the constraint conditions for each attribute.

[0016] Optionally, the process of matching the cyberspace knowledge graph is as follows:

[0017] 1) The scanned data is combined according to the pattern defined by the knowledge graph to form a subgraph relative to the complete network space knowledge graph;

[0018] 2) Set the subgraph similarity threshold;

[0019] 3) Match each subgraph with the complete network space knowledge graph using a subgraph similarity algorithm to obtain a similarity value;

[0020] 4) Compare the similarity value with the set threshold;

[0021] 5) Subgraphs exceeding the threshold are considered to belong to a certain asset knowledge graph based on the collected metadata;

[0022] 6) For subgraphs that do not exceed the threshold, their metadata is manually analyzed and judged, or new cyberspace knowledge graphs are automatically generated.

[0023] Based on the above technical features, it is possible to automatically update the metadata of cyberspace assets, thereby achieving the goal of monitoring the dynamic changes of server and terminal assets in cyberspace.

[0024] Optionally, the remote login method specifically involves the analysis platform collecting usernames and passwords from various devices, remotely logging in, and automatically analyzing the device's routing rules, firewall rules, port openness, and corresponding services through an analysis program. The Agent collection method specifically involves installing an Agent program on the device, obtaining the device's routing rules, firewall rules, port openness, and corresponding services through the program, and sending the results to the analysis platform. The SNMP protocol method specifically involves the analysis platform obtaining and analyzing the current configuration of devices with SNMP enabled through the SNMP protocol. The port scanning method specifically involves scanning the device through asset scanning to scan the open ports of the device and the corresponding services.

[0025] Based on the above technical features, by combining and using various acquisition methods, a clear network of reachable relationships between entities can be formed, leveraging the advantages of each method to adapt to suitable scenarios.

[0026] Optionally, the node assignment includes node weight allocation, edge weight allocation, and specifying the starting node and target node. The node weight allocation assigns a weight w to each node in the reachable relationship network of the entity network, and subtracts the maximum CVSS score of the node with vulnerabilities from 10, i.e., w = 10 - Max(vulnerability score). CVSS In the edge weight allocation, the edges between nodes are directed edges. There may be no edge between two nodes, there may be one directed edge, or there may be two directed edges in different directions. The weight of the edge is set as the weight of the target node. The specified starting node and target node are usually nodes representing the external Internet. Users can also choose their own starting node. The target node is usually a node selected by the user.

[0027] Optionally, the shortest path algorithm uses Dijkstra's algorithm. Let G = (V, E), which is the reachable relational network of the entity network, and is a weighted directed graph. The vertex set V in the graph is divided into two groups. The first group is the set of vertices for which the shortest path has been found (denoted by S; initially, S contains only one source vertex, and each time a shortest path is found, it is added to set S until all vertices are added to S, at which point the algorithm ends). The second group is the set of vertices for which the shortest path has not yet been determined (denoted by U). Vertices in the second group are added to S in ascending order of shortest path length. During this process, the shortest path length from the source vertex v to any vertex in S is always maintained at no greater than the shortest path length from the source vertex v to any vertex in U. Furthermore, each vertex corresponds to a distance. The distance between vertices in S is the shortest path length from v to that vertex, and the distance between vertices in U is the current shortest path length from v to that vertex, including only vertices in S as intermediate vertices.

[0028] Optionally, the steps of the shortest path algorithm are as follows:

[0029] 1) Initially, S contains only the source vertex, i.e., S = {v}, and the distance to v is 0. U contains all vertices except v, i.e., U = {the remaining vertices}. If v has an edge with vertex u in U, then...<u,v> Normally, if u is not an outgoing edge adjacent to v, then...<u,v> The weight is ∞;

[0030] 2) Select a vertex k from U that has the smallest distance to v, and add k to S (the selected distance is the shortest path length from v to k);

[0031] 3) Using k as the new intermediate point, modify the distances of each vertex in U; ​​if the distance from the source point v to vertex u (passing through vertex k) is shorter than the original distance (not passing through vertex k), then modify the distance value of vertex u, and add the weight of the edge to the distance value of vertex k after modification.

[0032] 4) Repeat steps 2) and 3) until all vertices are contained in S.

[0033] The present invention provides a knowledge graph-based method for managing cyberspace assets, which has the following advantages compared with the prior art:

[0034] 1. This invention, based on practical management needs, identifies the various domains to which cyberspace assets belong, and then constructs a cyberspace asset knowledge graph by listing and organizing concepts, attributes, and relationships. Cyberspace assets are composed of entities and relationships from various domains, and can extend outward from each endpoint of the graph, thereby realizing flexible asset management needs from multiple user perspectives;

[0035] 2. This invention, based on a cyberspace asset knowledge graph and utilizing various information acquisition methods, can initially construct a complete list of asset entities, attributes, and relationships within an organization. During automated network security operations, it can form a cyberspace asset subgraph using limited information, and through a subgraph approximation matching algorithm, match the complete asset graph corresponding to the subgraph, thereby achieving the goal of monitoring the dynamic changes of server and terminal assets in cyberspace.

[0036] 3. This invention proposes four complementary methods to obtain and construct network reachability relationships between entities. Combined with vulnerability scoring and using the shortest path algorithm, it can calculate the attack path graph that attackers may exploit, thereby realizing attack probability analysis and effectively guiding vulnerability remediation work.

[0037] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0038] To more clearly illustrate the technical solutions in the specific embodiments or related technologies of the present invention, the drawings used in the description of the specific embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0039] Figure 1 This is a flowchart of the network space knowledge graph matching process in an embodiment of the present invention. Detailed Implementation

[0040] To enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in the embodiments of this application will be clearly and completely described below. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0041] The following describes specific embodiments; please refer to the appendix for details. Figure 1 The present invention will be further described in detail below.

[0042] This invention proposes a method for managing cyberspace assets based on knowledge graphs. The first step is to construct a knowledge graph, which involves ontology modeling. The steps involved in constructing a knowledge graph are as follows:

[0043] 1) Defining the domain: The professional domains of cyberspace assets constructed by this invention include physical equipment domain, software domain, spatial area domain, information system domain, organizational personnel domain, financial value domain, etc.

[0044] 2) Listing concepts, attributes and their relationships: This invention, in combination with actual needs, collects and lists all the concepts, attributes and relationships required in the above-mentioned fields, ensuring the comprehensiveness of the list of concepts, attributes and relationships;

[0045] 3) Determine the knowledge system structure, which means defining concepts and their hierarchical structure. This design adopts a top-down approach, first defining classes, then defining the hierarchical structure;

[0046] 4) Define attributes and relationships. Based on the listed conceptual attributes and relationships, clearly define the network space attributes contained in the concepts and the network space relationships between the concepts. The attributes of network space concepts can be defined by referring to the existing attributes of the CMDB system. At the same time, asset attributes in the security and business domains should be added.

[0047] 5) Define constraints: Based on the actual situation of the conceptual attributes of cyberspace assets, define the constraints for these attributes.

[0048] The cyberspace asset knowledge graph has now been completed. Furthermore, a server, in the traditional sense, will no longer be just a single entity, but rather a complex network of interconnected entities from multiple domains. By showcasing these interconnected entity assets from multiple perspectives, it meets the cyberspace asset management needs of various roles, including system administrators, security administrators, network administrators, and financial personnel.

[0049] Next, it's necessary to automate metadata updates. During the initial asset construction phase, cyberspace asset metadata is collected through various methods, including manual addition, file import, remote login, agent-based collection, SNMP protocol transmission, and port scanning. After automated data cleaning, standardization, and manual review, a complete cyberspace asset map is formed. Traditionally, servers and terminals are no longer single entities, but rather an asset map composed of interconnected entities from multiple domains. This represents the perspective presented to the user regarding servers and terminals.

[0050] In reality, most servers and terminals cannot be directly logged into remotely or have agent-based data collection clients installed, resulting in very limited information acquisition. Furthermore, due to the complexity of the network environment, certain hardware information, such as MAC addresses, cannot be easily obtained. Through port service scanning and network traffic detection, a small amount of metadata can be acquired. This metadata can be standardized into an entity attribute graph based on the cyberspace asset knowledge system. The next step is cyberspace knowledge graph matching, the process of which is as follows (refer to the attached diagram in the instruction manual). Figure 1 ):

[0051] 1) The scanned data is combined according to the pattern defined by the knowledge graph to form a subgraph relative to the complete network space knowledge graph;

[0052] 2) Set the subgraph similarity threshold;

[0053] 3) Match each subgraph with the complete network space knowledge graph using a subgraph similarity algorithm to obtain a similarity value;

[0054] 4) Compare the similarity value with the set threshold;

[0055] 5) Subgraphs exceeding the threshold are considered to belong to a certain asset knowledge graph based on the collected metadata;

[0056] 6) For subgraphs that do not exceed the threshold, their metadata is manually analyzed and judged, or new cyberspace knowledge graphs are automatically generated.

[0057] The above process enables automated updates of cyberspace asset metadata, thereby achieving the goal of monitoring the dynamic changes of server and terminal assets in cyberspace.

[0058] Finally, network reachability relationship construction and attack probability analysis are required. This involves obtaining and constructing network reachability relationships between entities using four methods, as follows:

[0059] 1) Remote login method: The analysis platform collects usernames and passwords of various devices for remote login. The analysis program automatically analyzes the device's routing rules, firewall rules, port open status, and the services corresponding to the ports.

[0060] 2) Agent-based data collection method: Install an Agent program on the device to obtain the device's routing rules, firewall rules, port open status, and services corresponding to the ports, and send the results to the analysis platform.

[0061] 3) SNMP protocol method: For devices with SNMP enabled, the analysis platform can obtain and analyze the current configuration of the device through the SNMP protocol;

[0062] 4) Port scanning method: Using asset scanning equipment, scan the open ports of the equipment and the services corresponding to those ports.

[0063] Port scanning is generally used when the other three methods are not applicable. By combining multiple acquisition methods, the advantages of each method can be used to adapt to different scenarios, ultimately forming a clear network of reachable entity relationships.

[0064] Attack probability analysis involves assigning values ​​to nodes in the relationship network based on vulnerability scores, and using a shortest path algorithm to calculate the attack path graph that attackers might exploit. This process analyzes the attack probability and guides vulnerability remediation efforts. The specific process is as follows:

[0065] 1) Node weight allocation

[0066] Each node in the reachable relationship network of the entity network is assigned a weight w. The maximum CVSS score for a node with vulnerabilities is subtracted from 10; that is, if a node has no vulnerabilities, its CVSS score is 0. The formula is as follows:

[0067] w = 10 - Max(vul) CVSS )

[0068] 2) Edge weight allocation

[0069] The edges between nodes are directed edges. There may be no edge between two nodes, there may be one directed edge, or there may be two directed edges in different directions. The weight of the edge is set to the weight of the target node.

[0070] 3) Specify the starting node and the target node

[0071] The starting node is usually a node representing the external internet, but users can also choose their own starting node. The target node is usually a node selected by the user.

[0072] 4) Calculate the shortest path using Dijkstra's algorithm.

[0073] Specifically, let G = (V, E), which is the reachability network of entities, and is a weighted directed graph. Divide the vertex set V in the graph into two groups. The first group is the set of vertices for which shortest paths have been found (denoted by S; initially, S contains only one source vertex, and each time a shortest path is found, it is added to set S until all vertices are added to S, at which point the algorithm ends). The second group is the set of vertices for which shortest paths have not yet been determined (denoted by U). Vertices in the second group are added to S in ascending order of shortest path length. During this process, the shortest path length from the source vertex v to any vertex in S is always maintained at no greater than the shortest path length from the source vertex v to any vertex in U. Furthermore, each vertex corresponds to a distance. The distance to a vertex in S is the shortest path length from v to that vertex, and the distance to a vertex in U is the current shortest path length from v to that vertex, including vertices in S as intermediate vertices.

[0074] The algorithm steps are as follows:

[0075] 1) Initially, S contains only the source vertex, i.e., S = {v}, and the distance to v is 0. U contains all vertices except v, i.e., U = {the remaining vertices}. If v has an edge with vertex u in U, then...<u,v> Normally, if u is not an outgoing edge adjacent to v, then...<u,v> The weight is ∞.

[0076] 2) Select a vertex k from U that has the smallest distance from v, and add k to S (the selected distance is the shortest path length from v to k).

[0077] 3) Using k as the new intermediate point, modify the distances of each vertex in U; ​​if the distance from the source point v to vertex u (passing through vertex k) is shorter than the original distance (not passing through vertex k), then modify the distance value of vertex u, and add the weight of the edge to the distance of vertex k after modification.

[0078] 4) Repeat steps 2) and 3) until all vertices are contained in S.

[0079] The above specific embodiments further illustrate the technical solution of the present invention. The examples given are merely application examples and should not be construed as limiting the scope of protection of the claims of the present invention.

Claims

1. A knowledge graph-based method for managing cyberspace assets, characterized in that, Includes the following steps: Step 1: Construct a knowledge graph, which includes identifying the domain, listing concepts and attributes and their relationships, determining the knowledge structure, defining attributes and relationships, and defining constraints. Step 2: Automated metadata update. In the initial asset component stage, metadata of cyberspace assets is collected. The metadata is standardized into entity attribute graphs according to the cyberspace asset knowledge system, and then matched with the cyberspace knowledge graph. The process of matching the cyberspace knowledge graph is as follows. 1) Combine the scanned data according to the patterns defined in the knowledge graph to form a subgraph relative to the complete network space knowledge graph; 2) Set the subgraph similarity threshold; 3) Match each subgraph with the complete network space knowledge graph using a subgraph similarity algorithm to obtain a similarity value; 4) Compare the similarity value with the set threshold; 5) Subgraphs exceeding the threshold are considered to belong to a certain asset knowledge graph based on the collected metadata; 6) For subgraphs that do not exceed the threshold, their metadata is manually analyzed and judged, or new cyberspace knowledge graphs are automatically generated; Step 3: Network reachability construction and attack probability analysis. The construction of network reachability includes remote login, Agent collection, SNMP protocol and port scanning. The attack probability is analyzed by assigning values ​​to the nodes in the network and using the shortest path algorithm to calculate the attack path graph that attackers may use. The node assignment includes node weight allocation, edge weight allocation, and specifying the starting and target nodes. The node weight allocation assigns a weight w to each node in the reachable relationship network of the entity network, calculated by subtracting the maximum CVSS score of a node with vulnerabilities from 10. In the edge weight allocation, the edges between nodes are directed edges. There may be no edge between two nodes, or there may be one directed edge, or there may be two directed edges in different directions. The weight of the edge is set as the weight of the target node. In the specified starting node and target node, the starting node is a node representing the external Internet, or a starting node selected by the user, and the target node is a node selected by the user.

2. The method for managing cyberspace assets based on knowledge graphs according to claim 1, characterized in that: The defined domain of cyberspace assets includes physical equipment domain, software domain, spatial area domain, information system domain, organizational personnel domain, financial value domain, etc. Listing concepts, attributes, and their relationships involves collecting and listing all necessary concepts, attributes, and relationships within the defined domain, ensuring the comprehensiveness of the list. The defined knowledge structure is constructed using a top-down approach, first defining classes, then defining hierarchical structures. Defining attributes and relationships, based on the listed concepts, attributes, and relationships, clearly defines the cyberspace attributes contained in the concepts and the cyberspace relationships between concepts. Defining constraints, based on the actual situation of the cyberspace asset concept attributes, defines the constraints for each attribute.

3. The method for managing cyberspace assets based on knowledge graphs according to claim 1, characterized in that: The remote login method specifically involves the analysis platform collecting usernames and passwords from various devices for remote login. The analysis program automatically analyzes the device's routing rules, firewall rules, port openness, and corresponding services. The agent collection method specifically involves installing an agent program on the device to obtain the device's routing rules, firewall rules, port openness, and corresponding services, and sending the results to the analysis platform. The SNMP protocol method specifically involves the analysis platform acquiring and analyzing the current configuration of devices with SNMP enabled. The port scanning method specifically involves scanning the device through asset scanning to scan the open ports and corresponding services of the devices.

4. The method for managing cyberspace assets based on knowledge graphs according to claim 1, characterized in that: The shortest path algorithm uses Dijkstra's algorithm. Let G = (V, E), which is the reachable relational network of the entity network, and it is a weighted directed graph. The vertex set V in the graph is divided into two groups. The first group is the set of vertices whose shortest paths have been found (denoted by S). Initially, S contains only one source vertex. Each time a shortest path is found, it is added to set S until all vertices are added to S, at which point the algorithm ends. The second group is the set of vertices whose shortest paths have not been determined (denoted by U). Vertices in the second group are added to S in ascending order of shortest path length. During the addition process, the shortest path length from the source vertex v to any vertex in S is always kept no greater than the shortest path length from the source vertex v to any vertex in U. In addition, each vertex corresponds to a distance. The distance of a vertex in S is the shortest path length from v to that vertex. The distance of a vertex in U is the current shortest path length from v to that vertex, including vertices in S as intermediate vertices.

5. The knowledge graph-based cyberspace asset management method according to claim 4, characterized in that: The steps of the shortest path algorithm are as follows: 1) Initially, S contains only the source vertex, i.e., S = {v}, and the distance from v is 0; U contains all vertices except v, i.e., U = {the remaining vertices}. If v has an edge with vertex u in U, then<u,v> Normally, if u is not an outgoing edge adjacent to v, then...<u,v> The weight is ∞; 2) Select a vertex k from U that has the smallest distance to v, and add k to S (the distance of vertex k is the shortest path length from source point v to vertex k). 3) Using k as the new intermediate point, modify the distances of each vertex in U; ​​if the distance from the source point v to vertex u (passing through vertex k) is shorter than the original distance (not passing through vertex k), then modify the distance value of vertex u, and add the weight of the edge to the distance value of vertex k after modification. 4) Repeat steps 2) and 3) until all vertices are contained in S.

Citation Information

Patent Citations

  • Network attack prediction method and device based on knowledge graph

    CN115296924A

  • Network security threat assessment method, apparatus and device, and readable storage medium

    CN115733646A