A multi-mode adaptive computer terminal asset intelligent detection and identification method

By combining the network asset intelligent detection system with the terminal security monitoring system and deep detection technology, the problems of insufficient information and high false alarm rate in traditional network asset detection have been solved. This has enabled accurate identification and monitoring of unknown terminals in enterprise networks and private networks, thereby improving network security supervision capabilities.

CN116684162BActive Publication Date: 2025-11-04NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310717408.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-16
Publication Date
2025-11-04
Estimated Expiration
2043-06-16

AI Technical Summary

Technical Problem

Traditional network asset detection mechanisms suffer from limited detection information, high false alarm rates, and low accuracy in enterprise and private networks. They are unable to effectively identify and monitor unknown and hidden terminals in complex network environments, leading to network security risks.

Method used

A multi-mode adaptive intelligent detection method for computer terminal assets is adopted. Through the intelligent collaborative linkage between the network asset intelligent detection system and the terminal security monitoring system, combined with terminal identification and deep detection technology, the method identifies monitored and non-monitored terminals and performs data compilation to achieve accurate asset information collection.

Benefits of technology

It enables accurate identification and monitoring of unknown terminals in the network, improves network security supervision capabilities, reduces false alarm rate, and solves the problem of inaccurate detection data caused by multiple address configurations of the same terminal.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116684162B_ABST
    Figure CN116684162B_ABST
Patent Text Reader

Abstract

The application provides a kind of multi-mode adaptive computer terminal asset intelligent detection identification method, comprising: part computer terminal is deployed terminal security monitoring system, and the cloud end background of terminal security monitoring system builds complete security monitoring terminal information base;With the terminal security monitoring system, the network asset intelligent detection system with computer terminal asset adaptive detection function is realized intelligent cooperation, to form computer terminal asset adaptive detection model;Through the computer terminal asset adaptive detection model, with the aid of terminal security monitoring and terminal identity identification, monitor and non-monitoring computer terminal are identified.The application realizes intelligent cooperation linkage between network asset intelligent detection system and terminal security monitoring system, and relies on the security monitoring terminal information base of terminal security monitoring system cloud end background, and can intelligently and accurately identify monitoring terminal and non-monitoring terminal.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network asset detection, in particular to a multi-mode adaptive computer terminal asset intelligent detection and identification method. BACKGROUND

[0002] With the development of electronic information systems towards networking, scaling and complexification, computer terminals in enterprise networks and private networks present phenomena such as large quantity, scattered deployment and complex connection mode, and the problems of illegal access terminals, unknown terminals and hidden terminals in the network are increasingly prominent. The above problems may lead to potential security risks in the network and may become a way of implementing network threats. Traditional network asset detection mechanisms directly applied in enterprise networks and private networks have problems such as less detection information, high false positive rate and low accuracy, and cannot effectively solve the above terminal problems. How to accurately and comprehensively master the "bottom number" of terminal assets in the network and how to quickly find terminal assets outside the security monitoring system are the key and difficult problems in the current network security field construction and operation.

[0003] In order to comprehensively and accurately master the "bottom number" of terminal assets in the target network area, and comprehensively improve the security supervision capability of the internal network area, it is urgently needed to provide a multi-mode adaptive computer terminal asset intelligent detection and identification method. On the basis of the conventional network asset detection system and the terminal security monitoring system, intelligent collaborative linkage is realized, the monitored terminals and the non-monitored terminals are accurately and effectively identified, and the corresponding asset information detection and asset data compilation capabilities can be provided. SUMMARY

[0004] The present application aims to provide a multi-mode adaptive computer terminal asset intelligent detection and identification method to solve the above problems.

[0005] The present application provides a multi-mode adaptive computer terminal asset intelligent detection and identification method, comprising:

[0006] Part of the computer terminals are deployed with terminal security monitoring systems, and the cloud backend of the terminal security monitoring system builds a complete security monitoring terminal information database;

[0007] The network asset intelligent detection system with computer terminal asset adaptive detection function is intelligently cooperated with the terminal security monitoring system, thereby forming a computer terminal asset adaptive detection model;

[0008] The computer terminal asset adaptive detection model identifies the monitored and non-monitored computer terminals by means of terminal security monitoring and terminal identity identification.

[0009] Further, the running mechanism of the computer terminal asset adaptive detection model is as follows:

[0010] Step 1, the computer terminal deployed with the terminal security monitoring system generates a unified detection password CC(n) at time n, and pushes the detection password to the network asset intelligent detection system;

[0011] Step 2, the network asset intelligent detection system conducts comprehensive detection towards the detection target network area, and feeds back the network detection message to the feedback network asset intelligent detection system, and carries the password detection message after the network detection message; thereafter:

[0012] The computer terminal deployed with the terminal security monitoring system receives the network detection message, and feeds back the detection response message to the network asset intelligent detection system, and carries the detection password CC(n) after the detection response message;

[0013] The computer terminal without deployment of the terminal security monitoring system only feeds back the detection response message;

[0014] Step 3, the network asset intelligent detection system selects the corresponding terminal asset detection mode based on the feedback of the computer terminal a i :

[0015] For the computer terminal a i that only feeds back the detection response message and does not feed back the detection password CC(n), the conventional detection mode NoCol_Ter_Detect(a i ) is adopted, the computer terminal asset information is obtained based on the network detection message, and the computer terminal a i without feedback of the detection password CC(n) ends the network detection operation;

[0016] For the computer terminal a i that feeds back the detection response message and feeds back the detection password CC(n), the computer terminal a i uses its own public and private key pair (a i -ID, Keya i ) to conduct identity authentication and terminal identification towards the network asset intelligent detection system, and simultaneously adopts the collaborative computer terminal asset deep detection mode Col_Ter_Detect(a i ) to deeply detect more and more accurate computer terminal asset information;

[0017] Step 4, for the computer terminal a i that feeds back the detection password CC(n), the network asset intelligent detection system reports the obtained computer terminal asset information Ter_Detect_Info(a i ) to the terminal security monitoring system;

[0018] Step 5, the terminal security monitoring system will transfer the computer terminal asset information Ter_Detect_Info(a i ) and locally stored terminal monitoring information Ter_Monitor_Info(a i Perform fusion analysis, if terminal public a i - Same ID and terminal attribute Ter_Att_Info(a i The terminal attribute Ter_Att_Info(a) is the same. i This includes the terminal operating system, terminal service port, etc. If the same computer terminal is configured with multiple network addresses, then a multi-address merging and reorganization operation will be performed, and the computer terminal's running status information will be updated; otherwise, no operation will be performed.

[0019] Furthermore, in step 1, the computer terminal with the endpoint security monitoring system deployed will periodically generate a probe password CC(n).

[0020] Furthermore, in step 3, the collaborative computer terminal asset depth detection mode Col_Ter_Detect(a i The operating mechanism is as follows:

[0021] Step 31, Network Asset Intelligent Detection System A j For computer terminal a i Select the Collaborative Computer Terminal Asset Deep Detection mode (Col_Ter_Detect(a)). i ), to computer terminal a i Send a directional depth probe request;

[0022] Step 32, computer terminal a i Upon receiving a directional depth probing request, obtain the monitoring version information Monitor_Ver(a i ), System configuration information Sys_Con(a i ), running status information Opera_State(a i ) and timestamp Time_Stamp;

[0023] Step 33, computer terminal a i The identity identifier Key_a(a) encrypted with its private key i -ID) and the obtained monitoring version information Monitor_Ver(a i ), System configuration information Sys_Con(a i ), running status information Opera_State(a i The key and timestamp (Time_Stamp) are integrated into the probe feedback information M = (Key_a(a)).i -ID), Monitor_Ver(a i ), Sys_Con(a i ), Ope_State(a i ), Time_Stamp), and sends to the network asset intelligent detection system A j ;

[0024] Step 34, the network asset intelligent detection system A j decrypts the identity a i -ID in the detection feedback information by the private key Key_a() of the computer terminal a i , and if the identity a i -ID is the same as the locally stored identity, it is judged that the detection feedback information is correct.

[0025] Step 35, the network asset intelligent detection system A j compares the time stamp Time_Stamp accepted this time with the locally stored time stamp Time_Stamp, and if the time stamp Time_Stamp accepted this time is greater than the locally stored time stamp Time_Stamp, the computer terminal asset information locally stored is updated based on the detection feedback information M.

[0026] Further, the system configuration information Sys_Con(a i ) includes the operating system, open port and security policy of the computer terminal a i .

[0027] Further, the running state information Oper_State(a i ) includes the operating system running information and application service running information of the computer terminal a i .

[0028] In summary, due to the adoption of the above technical solutions, the beneficial effects of the present application are:

[0029] 1. The present application realizes intelligent collaborative linkage between the network asset intelligent detection system with computer terminal asset adaptive detection function and the terminal security monitoring system, can intelligently and accurately identify the monitoring terminal and the non-monitoring terminal, and can accurately find the unknown terminal outside the terminal monitoring system, relying on the security monitoring terminal information database of the terminal security monitoring system cloud end background.

[0030] 2、the application proposes a cooperative computer terminal asset deep detection mode, a cooperative terminal security monitoring system, and a special deep detection mechanism to provide comprehensive and accurate terminal asset information, and better solve the problems of less information, high false alarm rate and low accuracy in the conventional network detection mode.

[0031] 3、the application proposes a data compilation method combining terminal monitoring data and terminal detection data, taking terminal address as the main line, merging and compiling multiple different IP addresses, and better solving the problem of inaccurate detection data caused by the same computer terminal configuring multiple IP addresses. BRIEF DESCRIPTION OF DRAWINGS

[0032] In order to more clearly illustrate the technical solutions of the embodiments of the application, the drawings in the embodiments will be briefly introduced as follows, and it should be understood that the following drawings only show some embodiments of the application, and therefore should not be regarded as a limitation on the scope, and other related drawings can be obtained by those skilled in the art without creative labor on the premise of not paying.

[0033] Figure 1 The running mechanism flow chart of the computer terminal asset adaptive detection model in the embodiments of the application.

[0034] Figure 2 The running mechanism flow chart of the cooperative computer terminal asset deep detection mode in the embodiments of the application. DETAILED DESCRIPTION

[0035] In order to make the purpose, technical solutions and advantages of the embodiments of the application more clear, the technical solutions in the embodiments of the application will be described clearly and completely in combination with the drawings in the embodiments of the application, and obviously, the described embodiments are part of the embodiments of the application, but not all the embodiments. The components of the embodiments of the application described and shown in the drawings herein can be arranged and designed in various different configurations.

[0036] Therefore, the following detailed description of the embodiments of the application provided in the drawings is not intended to limit the scope of the claimed application, but only represents selected embodiments of the application. All other embodiments obtained by those skilled in the art without creative labor based on the embodiments in the application are within the scope of the protection of the application.

[0037] EMBODIMENTS

[0038] The embodiment provides a multi-mode adaptive computer terminal asset intelligent detection and identification method, which comprises the following steps: partial computer terminals are provided with a terminal security monitoring system, and a complete security monitoring terminal information base is constructed in a cloud end background of the terminal security monitoring system; a network asset intelligent detection system with a computer terminal asset adaptive detection function is intelligently cooperated with the terminal security monitoring system, so that a computer terminal asset adaptive detection model is formed; and monitored and unmonitored computer terminals are identified by means of the terminal security monitoring and terminal identity through the computer terminal asset adaptive detection model. Therefore, the network asset intelligent detection system cooperates with the terminal security monitoring system to adopt a special detection mechanism and a deep detection method, and accurate and complete asset detection information is provided.

[0039] The specific implementation is as follows:

[0040] It is assumed that a security monitoring terminal information base has been formed in the cloud end background of the terminal security monitoring system (generally generated by combining system presetting and online monitoring), and the security monitoring terminal information base comprises terminal IP addresses, terminal operating systems, terminal service ports, terminal public keys and terminal running states and the like. The computer terminals a j j -ID, Keya j ) are provided with the terminal security monitoring system. j The cloud end background can obtain the public keys of the computer terminals a n j -ID} of the computer terminals provided with the terminal security monitoring system, wherein j≤s, and s represents the number of computer terminals provided with the terminal security monitoring system.

[0041] As shown in the computer terminal asset adaptive detection model, the operation mechanism of the computer terminal asset adaptive detection model is as follows: Figure 1

[0042] Step 1: The computer terminals provided with the terminal security monitoring system generate a unified detection password CC(n) periodically, and the detection password is pushed to the network asset intelligent detection system with the computer terminal asset adaptive detection function; wherein the detection password CC(n) represents the detection password of the security monitoring system generated at the n time.

[0043] Step 2: The network asset intelligent detection system performs comprehensive detection on the detection target network area, and feeds back the network detection message to the feedback network asset intelligent detection system, and carries the password detection message after the network detection message; and then:

[0044] ​​​The computer terminal deployed with the terminal security monitoring system receives the network probe message, and then feeds back a probe response message to the network asset intelligent probe system, and carries the probe password CC(n) after the probe response message;

[0045] The computer terminal not deployed with the terminal security monitoring system only feeds back the probe response message.

[0046] Step 3, the network asset intelligent probe system selects the corresponding terminal asset probe mode based on the feedback of the computer terminal a i ;

[0047] For the computer terminal a i that only feeds back the probe response message and does not feed back the probe password CC(n), a conventional probe mode NoCol_Ter_Detect(a i ) is adopted to obtain the computer terminal asset information based on the network probe message, and the computer terminal a i that does not feed back the probe password CC(n) ends the network probe operation.

[0048] For the computer terminal a i that feeds back the probe response message and feeds back the probe password CC(n), the computer terminal a i uses its own public and private key pair (a i -ID, Keya i ) to perform identity authentication and terminal identification to the network asset intelligent probe system, and uses a collaborative computer terminal asset deep probe mode Col_Ter_Detect(a i ) to deeply probe more and more accurate computer terminal asset information.

[0049] Step 4, for the computer terminal a i that feeds back the probe password CC(n), the network asset intelligent probe system reports the obtained computer terminal asset information Ter_Detect_Info(a i ) to the terminal security monitoring system.

[0050] Step 5, the terminal security monitoring system fuses and analyzes the computer terminal asset information Ter_Detect_Info(a i ) and the locally stored terminal monitoring information Ter_Monitor_Info(a i ), if the terminal public key a i -ID is the same and the terminal attribute Ter_Att_Info(a i ) is the same, the terminal attribute Ter_Att_Info(a i) including terminal operating system, terminal service port, etc. If the same computer terminal is configured with multiple network addresses, then multi-address merging and reorganization operations are performed, and the running state information of the computer terminal is updated; otherwise, no operation is performed.

[0051] Further, in step 3 above, if the collaborative computer terminal asset deep detection mode Col_Ter_Detect(a i ) is adopted, i uses its own public and private key pair (a i -ID, Keya i ) to perform identity authentication and terminal identification to the network asset intelligent detection system, and at the same time, integrates the monitoring version information Monitor_Ver(a i ), system configuration information Sys_Con(a i ), running state information Oper_State(a i ) and time stamp Time_Stamp to form detection feedback information, and uses the public key information of the network asset intelligent detection system for secure transmission and interaction. As shown in Figure 2 , the specific steps are as follows:

[0052] Step 31, the network asset intelligent detection system A j selects the collaborative computer terminal asset deep detection mode Col_Ter_Detect(a i ) for the computer terminal a i , and sends a directional deep detection request to the computer terminal a i .

[0053] Step 32, after receiving the directional deep detection request, the computer terminal a i acquires the monitoring version information Monitor_Ver(a i ), integrates the operating system, open port and security policy information to form the system configuration information Sys_Con(a i ); and acquires the operating system running information and application service running information of the computer terminal a i at the current time, and the running state information Oper_State(a i ), and records the time stamp information Time_Stamp.

[0054] Step 33, the computer terminal a i encrypts its private key identity Key_a(a i -ID) and the acquired monitoring version information Monitor_Ver(a i ), system configuration information Sys_Con(a i), operating state information Oper_State(a i ) and a time stamp Time_Stamp into probe feedback information M=(Key_a(a i -ID), Monitor_Ver(a i ), Sys_Con(a i ), Ope_State(a i ), Time_Stamp) and sends the probe feedback information to the network asset intelligent probe system A j .

[0055] In step 34, the network asset intelligent probe system A j decrypts the identity a i -ID in the probe feedback information by using the private key Key_a() of the computer terminal a i , and if the identity a i -ID is the same as the locally stored identity, it is determined that the probe feedback information is correct.

[0056] In step 35, the network asset intelligent probe system A j compares the time stamp Time_Stamp accepted this time with the locally stored time stamp Time_Stamp, and if the time stamp Time_Stamp accepted this time is greater than the locally stored time stamp Time_Stamp, the locally stored computer terminal asset information is updated based on the probe feedback information M.

[0057] The above only describes the preferred embodiments of the present application and is not used to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A multi-mode adaptive computer terminal asset intelligent probing identification method, characterized in that, The application relates to a computer terminal asset adaptive detection model. The computer terminal asset adaptive detection model comprises the following steps: Step 1, a computer terminal to which a terminal security monitoring system is deployed generates a unified detection password CC(n) at an n moment, and pushes the detection password to a network asset intelligent detection system; Step 2, the network asset intelligent detection system comprehensively detects a detection target network area, feeds back a network detection message to the network asset intelligent detection system, and carries a password detection message after the network detection message; Afterwards: If the computer terminal to which the terminal security monitoring system is deployed receives the network detection message, the computer terminal feeds back a detection response message to the network asset intelligent detection system, and carries the detection password CC(n) after the detection response message; If the computer terminal to which the terminal security monitoring system is not deployed only feeds back the detection response message; Otherwise, no operation is performed. In step 1, the computer terminal to which the terminal security monitoring system is deployed generates the detection password CC(n) regularly. ​ Step 3, the network asset intelligent detection system selects the corresponding terminal asset detection mode based on the feedback of the computer terminal a i : For computer terminal a that only feedbacks the probe response packet and does not feedback the probe password CC(n) i , the conventional probe mode NoCol_Ter_Detect(a i ) is adopted, the computer terminal asset information is acquired based on the network probe packet, and the computer terminal a that does not feedback the probe password CC(n) i The network probe operation ends here; For the computer terminal a that feedbacks the probe response packet and feedbacks the probe password CC(n) i , the computer terminal a i uses its own public and private key pair (a i -ID, Keya i ) to conduct identity authentication and terminal identification with the network asset intelligent probe system, and uses the collaborative computer terminal asset deep probe mode Col_Ter_Detect(a i ) to conduct in-depth probe on the computer terminal asset information; Step 4, for the computer terminal a that feedbacks the probe password CC(n) i , the network asset intelligent detection system reports the acquired computer terminal asset information Ter_Detect_Info(a i ) to the terminal security monitoring system; Step 5, the terminal security monitoring system fuses and analyzes the computer terminal asset information Ter_Detect_Info(a i ) and the locally stored terminal monitoring information Ter_Monitor_Info(a i ), if the terminal public ID a i -ID is same and the terminal attribute Ter_Att_Info(a i ) is same, the terminal attribute Ter_Att_Info(a i ) includes the terminal operating system and the terminal service port, it is explained that multiple network addresses are configured for the same computer terminal, then the multiple address merging and collating operation is executed, and the running state information of the computer terminal is updated; ​ 2. The multi-modal adaptive computer terminal asset intelligence probe and identification method of claim 1, wherein, ​ 3. The multi-modal adaptive computer terminal asset intelligence probe and identification method of claim 1, wherein, In step 3, the operation mechanism of the cooperative computer terminal asset deep detection mode Col_Ter_Detect(a i ) is as follows: Step 31, Network asset intelligent probing system A j For computer terminal a i Select collaborative computer terminal asset deep probing mode Col_Ter_Detect(a i ), send a targeted deep probing request to computer terminal a i ; Step 32, computer terminal a i Upon receiving a directional depth probing request, obtain the monitoring version information Monitor_Ver(a i ), System configuration information Sys_Con(a i ), running status information Opera_State(a i ) and timestamp Time_Stamp; Step 33, computer terminal a i encrypts its private key, the identity Key_a(a i -ID), and the obtained monitoring version information Monitor_Ver(a i ), system configuration information Sys_Con(a i ), running state information Oper_State(a i ), and time stamp Time_Stamp into probe feedback information M = (Key_a(a i -ID), Monitor_Ver(a i ), Sys_Con(a i ), Ope_State(a i ), Time_Stamp), and sends it to the network asset intelligent probe system A j ; Step 34, network asset intelligent detection system A j Through computer terminal a i Private key Keya i Decrypt the identity a in the detection feedback information i -ID, if the same as the locally stored identity, it is judged that it is from computer terminal a i Correct detection feedback information; Step 35, network asset intelligent detection system A j The received time stamp Time_Stamp is compared with the locally stored time stamp Time_Stamp. If the received time stamp Time_Stamp is greater than the locally stored time stamp Time_Stamp, the locally stored computer terminal asset information is updated based on the detection feedback information M.

4. The multi-modal adaptive computer terminal asset intelligence probe and identification method of claim 3, wherein, The system configuration information Sys_Con(a i ) includes the operating system, open ports, and security policy of the computer terminal a i .

5. The multi-modal adaptive computer terminal asset intelligence probe and identification method of claim 3, wherein, The operation state information Oper_State(a i ) includes the operating system running information and the application service running information of the computer terminal a i at the current time.

Citation Information

Patent Citations

  • Distributed network asset detection method

    CN109660401A

  • Network asset information monitoring method and device and storage device

    CN116225829A