A network asset discovery method, device and storage medium

By monitoring network traffic data, analyzing asset information, and classifying it, the problem of time-consuming full IP and port scanning was solved, achieving efficient network asset discovery and detection.

CN116684329BActive Publication Date: 2025-12-19BEIJING LANYUN TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310737368.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-20
Publication Date
2025-12-19
Estimated Expiration
2043-06-20

AI Technical Summary

Technical Problem

In existing technologies, full IP and port scanning are time-consuming and easily blocked by firewalls in network asset discovery, resulting in low efficiency.

Method used

By monitoring network traffic data, analyzing and classifying basic asset information, and using asset types to probe network assets, only basic information obtained from scanning traffic is obtained, and a small-scale scanning task is specified.

Benefits of technology

Significantly reduce the number of scans, improve the efficiency of network asset discovery, avoid firewall blocking and alerts, and improve the efficiency and accuracy of detection tools.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116684329B_ABST
    Figure CN116684329B_ABST
Patent Text Reader

Abstract

A network asset discovery method, device and storage medium, the method comprising: listening to network traffic data, parsing the network traffic data to obtain asset basic information; classifying network assets according to the asset basic information; and detecting the network assets according to the type of the network assets. Through the method, on the one hand, when the network assets are detected, the detection tool only needs to scan the asset basic information obtained from the traffic, which can exponentially reduce the asset basic information that needs to be scanned; on the other hand, a small range of scanning tasks can be specified based on the classified asset types, which greatly reduces the number of scans and greatly improves the efficiency of network asset discovery.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to, but is not limited to, the technical field of network security, and in particular to a network asset discovery method, device and storage medium. BACKGROUND

[0002] Users pay more and more attention to assets (including servers, terminals, network devices, etc.) in a network environment, and therefore, we need to discover and identify assets and asset types in a user network to help the user find assets that need to be focused on, so as to quickly respond and dispose after a security risk or vulnerability occurs in the monitored key assets, and protect asset security.

[0003] Most of the prior art is to perform full IP and port scanning on a specified network segment by using Nmap, Masscann and other port scanning tools to discover asset information on the network, including: IP, port, provided service, service version, hardware, operating system and other information. However, full IP and port scanning has problems such as too long scanning time, scanning requests may be intercepted by security devices such as firewalls, and alarms are generated. SUMMARY

[0004] The following is a summary of the subject matter detailed herein. This summary is not intended to limit the scope of the claims.

[0005] An embodiment of the present disclosure provides a network asset discovery method, which comprises:

[0006] listening to network traffic data, and analyzing the network traffic data to obtain asset basic information;

[0007] classifying network assets according to the asset basic information;

[0008] detecting the network assets according to the types of the network assets.

[0009] An embodiment of the present disclosure also provides a network asset discovery device, which comprises a processor and a memory storing a computer program, wherein the processor can implement the network asset discovery method according to any embodiment of the present disclosure when executing the computer program.

[0010] An embodiment of the present disclosure also provides a non-transitory computer readable storage medium storing a computer program, wherein the computer program can implement the network asset discovery method according to any embodiment of the present disclosure when executed by a processor.

[0011] The network asset discovery method, device and storage medium of the present disclosure can realize the following effects. The network asset discovery method, device and storage medium of the present disclosure can monitor network traffic data, and preliminarily classify network assets according to asset basic information obtained by analyzing the network traffic data. On the one hand, when the network assets are probed, the probing tool only needs to scan the asset basic information obtained from the traffic, which can exponentially reduce the asset basic information that needs to be scanned. On the other hand, the small-range scanning task can be specified based on the classified asset types, which can greatly reduce the scanning times and greatly improve the efficiency of network asset discovery.

[0012] Other aspects can become apparent from a review of the drawings and detailed description. BRIEF DESCRIPTION OF DRAWINGS

[0013] Figure 1 A flowchart of a network asset discovery method according to an embodiment of the present disclosure is shown in FIG. 1.

[0014] Figure 2 A specific flowchart of a network asset discovery method according to an embodiment of the present disclosure is shown in FIG. 2.

[0015] Figure 3 A structure diagram of a network asset discovery device according to an embodiment of the present disclosure is shown in FIG. 3. DETAILED DESCRIPTION

[0016] The present disclosure describes a plurality of embodiments, but the description is exemplary rather than limiting, and it is obvious to those skilled in the art that there can be more embodiments and implementation schemes within the scope of the embodiments described in the present disclosure. Although many possible combinations of features are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are also possible. Unless specifically limited, any feature or element of any embodiment can be used with any other feature or element of any other embodiment, or can replace any other feature or element of any other embodiment.

[0017] The present disclosure includes and contemplates combinations of features and elements known to those skilled in the art. The embodiments, features and elements disclosed in the present disclosure can also be combined with any conventional features or elements to form a unique inventive scheme defined by the claims. Any feature or element of any embodiment can also be combined with features or elements from other inventive schemes to form another unique inventive scheme defined by the claims. Therefore, it should be understood that any feature shown and / or discussed in the present disclosure can be implemented alone or in any appropriate combination. Therefore, the embodiments are not limited other than as set forth in the claims and their equivalents. In addition, various modifications and changes can be made within the scope of protection of the appended claims.

[0018] Moreover, in describing representative embodiments, the specification can have presented the method and / or process as a particular sequence of steps. However, to the extent that the method or process depends on the performance of certain steps, the method or process is not limited to the order of steps presented nor to performing some specific steps before other specific steps, unless the description clearly indicates otherwise. Other steps can be utilized, and not all of the steps that are utilized can be presented in this specification. Furthermore, a person of ordinary skill in the art would understand that the steps in the processes recited in this specification are not to be construed as necessarily requiring their performance in the order presented, unless explicitly so stated. Additionally, the steps in the claims are not to be construed as requiring their performance in a time order unless explicitly so stated. Furthermore, the claims are not to be construed as requiring their performance in a time order unless explicitly so stated.

[0019] An embodiment of the present disclosure provides a network asset discovery method, which can be executed in the following steps as shown in the figure: Figure 1 An embodiment of the present disclosure provides a network asset discovery method, which can be executed in the following steps as shown in the figure:

[0020] In step S110, network traffic data is monitored, and asset basic information is parsed from the network traffic data; the asset basic information includes IP address, port, application protocol information, etc.

[0021] In step S120, network assets are classified according to the asset basic information.

[0022] In step S130, the network assets are detected according to the network asset type.

[0023] In the step of monitoring network traffic data, the network traffic data can be monitored by installing traffic monitoring software on the core switch of the user, analyzing the network topology of the user, and obtaining the traffic mirror in the network concerned by the user, so that the original network packet can be obtained from the mirror. In addition, the monitoring of network traffic data can be set to monitor the network traffic within a preset time, such as one day (24h).

[0024] The network asset discovery method of the embodiment can monitor network traffic data, and classify the network assets according to the asset basic information parsed from the network traffic data, which can reduce the asset basic information to be scanned by an exponential order when the network assets are detected by a detection tool, and can also greatly reduce the number of scans and improve the efficiency of network asset discovery by assigning a small range of scan tasks based on the classified asset type.

[0025] In an exemplary embodiment of the present disclosure, the parsing of the network traffic data to obtain asset basic information includes parsing target network packets to obtain IP addresses in the packets.

[0026] The classification of network assets according to the asset basic information includes:

[0027] For each IP address obtained by analysis, the proportion of the packet whose destination IP address is the IP address in all packets containing the IP address is counted, and when the proportion is greater than or equal to a set first proportion threshold, it is determined that the type of the network asset corresponding to the IP address is a server; wherein the first proportion threshold can be 80%.

[0028] For each IP address obtained by analysis, the proportion of the packet whose source IP address is the IP address in all packets containing the IP address is counted, and when the proportion is greater than or equal to a set second proportion threshold, it is determined that the type of the network asset corresponding to the IP address is a terminal; wherein the second proportion threshold can be 80%.

[0029] In an example of the embodiment, the target network packet can refer to all packets monitored; or the target network packet can also refer to the packet whose port in the packet is a designated well-known server port; wherein the well-known server port can include a web server port, a database server port, and a file server port; the web server port can include 80, 443, 8080 and 8443, the database server port can include 1521 and 3306, and the file server port can include 139 and 445. The above ports are only examples, and the well-known server port is not limited thereto.

[0030] The network asset discovery method of the embodiment can quickly identify assets of the server type by judging whether the asset contains a well-known server port, thereby improving the performance of network asset discovery. For example, in the case where the user only needs to detect assets of the server type, if the asset does not contain a well-known server port, it can be directly identified as an asset of other types, thereby avoiding further network asset type judgment and saving a lot of time, thereby improving the efficiency of network asset discovery.

[0031] In an example of the embodiment, the analysis of the network traffic data to obtain asset basic information further includes:

[0032] The port in the monitored packet is analyzed to obtain the port in the packet;

[0033] When the target network packet refers to the packet whose port is a designated well-known server port, the packet whose port is the designated well-known server port is divided into the target network packet.

[0034] In an example of the embodiment, the analysis of the network traffic data to obtain asset basic information further includes:

[0035] The other packets except the target network packet in the monitored packet are analyzed to obtain asset basic information;

[0036] The classifying the network assets according to the asset basic information further comprises:

[0037] The type of the network asset corresponding to the asset basic information obtained by analyzing the other message is determined as an other type, i.e., a type of neither server nor terminal.

[0038] In an example of the embodiment, before determining that the type of the network asset corresponding to the IP address is server, the method further comprises:

[0039] counting the number of messages with the IP address as the destination IP address; and / or counting the number of source IP addresses of the messages with the IP address as the destination IP address;

[0040] In a case where the number of messages with the IP address as the destination IP address is greater than a first preset number, and / or the number of source IP addresses of the messages with the IP address as the destination IP address is greater than a second preset number, it is determined that the type of the network asset corresponding to the IP address is server.

[0041] The first preset number and the second preset number are positive integers, the first preset number can be set to 10, and the second preset number can be set to 100. The first preset number and the second preset number can be customized, so that the user can set the numbers according to the number of users using the business system in the unit, thereby improving the accuracy of classification.

[0042] In an example embodiment of the disclosure, the detecting the network assets according to the types of the network assets comprises:

[0043] According to the classification result, the network assets of different types are divided into different detection task sets; and

[0044] According to the type of the network asset to be detected, a corresponding detection task set is selected, and the network assets in the selected detection task set are detected. For example, if the user focuses on server assets, the assets preliminarily classified as server type can be added to the detection task set as a server task set for detection; if the user focuses on terminal assets, the assets preliminarily classified as terminal type can be added to the detection task set as a terminal task set for detection. The assets focused on by the user are only exemplary, and the user can detect any type of asset or any combination of assets as a detection task set.

[0045] In an example of the embodiment, the dividing the network assets of different types into different sets of probing tasks comprises: dividing the network assets of the terminal type into a set of terminal tasks, and dividing the network assets of the server type into a set of server tasks; and the selected set of probing tasks comprises the set of terminal tasks and / or the set of server tasks.

[0046] The probing the network assets in the selected set of probing tasks comprises: probing the network assets in the selected set of probing tasks by the asset probing tool, and obtaining detailed information of the target asset when the target asset is detected in the selected set of probing tasks.

[0047] The asset probing tool can be the asset probing tool of the embodiment, or can be a port scanning tool such as Nmap or Masscan; and the detailed information of the network asset comprises software, hardware, operating system, and the like.

[0048] The network asset discovery method of the embodiment can probe a corresponding set of probing tasks according to the type of the network asset concerned by the user, so as to probe only the assets concerned by the user, save the probing of other types of assets, greatly reduce the number of scans, and greatly improve the probing efficiency.

[0049] In an example of the embodiment, the dividing the network assets of different types into different sets of probing tasks further comprises: dividing the network assets of other types into a set of other tasks.

[0050] After the probing the network assets in the selected set of probing tasks, the method further comprises: probing the network assets in the set of other tasks when the target asset is not detected in the selected set of probing tasks.

[0051] In the embodiment, the target asset can be a certain type of asset, or can be a certain asset. If the target asset is a server type asset, but the set of server tasks composed of the server type assets classified initially is probed, and the server type asset is not matched according to the preset identification rule of the server type asset, the set of other tasks composed of other types of assets needs to be probed continuously. Similarly, if the target asset is a terminal type asset, but the set of terminal tasks composed of the terminal type assets classified initially is probed, and the terminal type asset is not matched according to the preset identification rule of the terminal type asset, the set of other tasks composed of other types of assets needs to be probed continuously. If the target asset is a certain server type asset, but the set of server tasks composed of the server type assets classified initially is probed, and the asset is not found in the set of server tasks, the set of other tasks composed of other types of assets needs to be probed continuously to find the target asset.

[0052] The network asset discovery method of the embodiment can improve the accuracy of detection by detecting other task sets when the corresponding detection task set according to the network asset type concerned by the user does not find the asset concerned.

[0053] In an example embodiment of the present disclosure, after obtaining the asset basic information, the asset basic information can be saved to a designated database, thereby facilitating direct query in the future.

[0054] After obtaining the detailed information of the asset, the detailed information of the asset can also be saved to a designated database, thereby facilitating direct query in the future.

[0055] In an example embodiment of the present disclosure, after obtaining the detailed information of the network asset, the asset can be classified in detail according to the detailed information of the network asset, such as subdividing the server type into a web server type, a database server type, a file server type, and the like; subdividing the terminal type into a desktop computer, a notebook computer, a mobile phone, and the like; and subdividing other types into network equipment, and the network equipment includes a router and a switch.

[0056] In an example embodiment of the present disclosure, the application protocol information includes asset open services, service versions, URL information, and the like.

[0057] The network asset discovery method of the above embodiment can avoid full IP and port scanning on a designated network segment by only scanning the IP and port obtained from network traffic, and can also reduce the number of IP and port to be scanned exponentially by preliminary classification of assets and designation of a small range of scanning tasks. Thus, the network connection establishment and packet transmission can be greatly reduced, and the detection efficiency can be greatly improved. Meanwhile, the firewall interception and alarm can also be avoided.

[0058] The following is a specific process of the network asset discovery method of the present disclosure, as shown in Figure 2 The network asset discovery can be performed according to the following steps:

[0059] In step S210, network traffic data is listened to, and network protocol restoration is performed.

[0060] In step S220, the basic information of the asset is obtained, including IP address, port, application protocol information, and the like.

[0061] In step S230, the network asset is preliminarily classified according to the asset basic information, which can include the following steps:

[0062] In step S231, if the port contains a designated well-known server port, the asset is preliminarily classified as a server or a terminal; if the port does not contain a well-known server port, the asset is classified as other types.

[0063] Step S232, further determining whether it is a server, and the determination rule is as follows: for each IP address obtained by parsing, the proportion of the packet whose destination IP address is the IP address in all packets containing the IP address is counted, and when the proportion is greater than or equal to a set first proportion threshold, it is determined that the type of the network asset corresponding to the IP address is a server; wherein the first proportion threshold can be 80%;

[0064] Step S233, further determining whether it is a terminal, and the determination rule is as follows: for each IP address obtained by parsing, the proportion of the packet whose source IP address is the IP address in all packets containing the IP address is counted, and when the proportion is greater than or equal to a set second proportion threshold, it is determined that the type of the network asset corresponding to the IP address is a terminal; wherein the second proportion threshold can be 80%;

[0065] Step S233, if the determination of step S232 and step S233 is not met, it is determined that the network asset corresponding to the IP address is of other types.

[0066] Step S240, different sets of detection tasks are performed according to the type of the network asset;

[0067] Step S250, obtaining detailed information of the asset, including operating system, software, hardware information, etc.

[0068] The present disclosure also provides a network asset discovery device, as shown in Figure 3 The processor executes the computer program to implement the network asset discovery method according to any one of the embodiments of the present disclosure.

[0069] The network asset discovery method and device of the present disclosure can identify the assets and asset types in the user network, help the user find the assets that need to be focused on, so as to quickly respond and dispose after the security risks or vulnerabilities of the monitored key assets occur.

[0070] The processor of the above-mentioned embodiments of the present disclosure can be a general processor, including a central processing unit (CPU), a network processor (NP), a microprocessor, etc., and can also be other conventional processors, etc. The processor can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), discrete logic or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, or other equivalent integrated or discrete logic circuit, and can also be a combination of the above devices. That is, the processor of the above-mentioned embodiments can be any processing device or combination of devices that implements the methods, steps, and logic block diagrams disclosed in the embodiments of the present disclosure. If the embodiments of the present disclosure are implemented partially in software, instructions for the software can be stored in a suitable non-transitory computer-readable storage medium, and the instructions can be executed in hardware using one or more processors to implement the methods of the embodiments of the present disclosure. The term "processor" used herein can refer to the above structures or any other structure suitable for implementing the techniques described herein.

[0071] An embodiment of the present disclosure further provides a non-transitory computer-readable storage medium, which stores a computer program, wherein the computer program is capable of implementing the network asset discovery method of any embodiment of the present disclosure when executed by a processor.

[0072] In one or more exemplary embodiments described above, the functions described can be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions can be stored or transmitted over as one or more instructions or code on a computer-readable medium and executed by a hardware-based processing unit. Computer-readable media can include computer-readable storage media, which corresponds to a tangible medium such as data storage media, or communication media including any medium that facilitates transfer of a computer program from one place to another, e.g., according to a communication protocol. In this manner, computer-readable media generally can correspond to non-transitory computer- readable storage media or communication media. Data storage media can be any available media that can be accessed by one or more computers or one or more processors to retrieve instructions, code and / or data structures for implementation of the techniques described in this disclosure. A computer program product can include a computer-readable medium.

[0073] By way of example, and not limitation, such computer-readable storage media can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage, or other magnetic storage devices, flash memory, or any other storage medium that can be used to store desired program codes in the form of instructions or data structures and that can be accessed by a computer. Also, any connection is properly termed a computer-readable medium. For example, if the instructions are transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. It should be understood, however, that computer-readable storage media and data storage media do not include connections, carrier waves, signals, or other transient media, but are instead directed to non-transient, tangible storage media. Disk and disc, as used herein, includes compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk and Blu-ray disc where disks usually reproduce data magnetically, while discs reproduce data optically with lasers. Combinations of the above should also be included within the scope of computer-readable media. While the disclosed embodiments have been described above, it should be understood that they have been presented by way of example only, and not limitation. Any modification and variation of the disclosed embodiments, which come within the scope of the disclosed embodiments, are intended to be included. The various embodiments described above are intended to be covered by the following claims in their full scope.

Claims

1. A network asset discovery method, the method comprising: listening to network traffic data, and parsing the network traffic data to obtain asset basic information, including: parsing target network packets to obtain IP addresses in the packets; classifying network assets according to the asset basic information, including: for each IP address obtained by parsing, counting a proportion of packets with a destination IP address being the IP address among all packets containing the IP address, and determining a type of a network asset corresponding to the IP address as a server when the proportion is greater than or equal to a set first proportion threshold; and for each IP address obtained by parsing, counting a proportion of packets with a source IP address being the IP address among all packets containing the IP address, and determining the type of the network asset corresponding to the IP address as a terminal when the proportion is greater than or equal to a set second proportion threshold; detecting the network assets according to the types of the network assets. 2.The method of claim 1, wherein: the detecting the network assets according to the types of the network assets comprises: dividing network assets of different types into different detection task sets according to the classification results; and selecting a corresponding detection task set according to a type of a network asset to be detected, and detecting the network asset in the selected detection task set. 3.The method of claim 2, wherein: the target network packets refer to all packets listened to, or the target network packets refer to packets with a port being a designated well-known service port. 4.The method of claim 3, wherein: the parsing the network traffic data to obtain asset basic information further comprises: parsing other packets than the target network packets in the listened packets to obtain asset basic information; the classifying network assets according to the asset basic information further comprises: determining a type of a network asset corresponding to the asset basic information obtained by parsing the other packets as another type. 5.The method of claim 4, wherein: the dividing network assets of different types into different detection task sets comprises: dividing network assets of the terminal type into a terminal task set, and dividing network assets of the server type into a server task set; and the selected detection task set comprises the terminal task set and / or the server task set; the detecting the network asset in the selected detection task set comprises: detecting the network asset in the selected detection task set by an asset detection tool, and obtaining detailed information of a target asset when the target asset is detected in the selected detection task set. 6.The method of claim 5, wherein: the dividing network assets of different types into different detection task sets further comprises: dividing network assets of the other type into an other task set; after the detecting the network asset in the selected detection task set, the method further comprises: detecting the network asset in the other task set when the target asset is not detected in the selected detection task set.

7. A network asset discovery apparatus comprising a processor and a memory having a computer program stored therein, wherein, The computer program, when executed by the processor, is capable of implementing the network asset discovery method as claimed in any one of claims 1 to 6.

8. A non-transitory computer-readable storage medium storing a computer program, wherein, The computer program, when executed by the processor, is capable of implementing the network asset discovery method as claimed in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Network asset information generation method and apparatus, and electronic device

    CN115333951A