Method, apparatus and device for identifying network assets
By acquiring login attribute information of network devices to identify associated network assets and constructing a topology graph, the inefficiency and inaccuracy caused by manual reporting are solved, and the network asset identification and perception capabilities are improved quickly and accurately.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANGHAI GUAN AN INFORMATION TECH
- Filing Date
- 2023-05-30
- Publication Date
- 2026-07-21
AI Technical Summary
In existing technologies, network asset identification relies on manual reporting, which results in low efficiency and poor accuracy, with issues of false alarms and missed alarms.
By acquiring the login attribute information of network devices, we can identify associated network assets using this information and store them in the network layer as tabular data. Through structured processing, we can convert the tabular data into asset information on different attribute dimensions, construct a topology diagram, and perform conflict identification.
It enables rapid and accurate identification of network assets without manual input, improving identification efficiency and accuracy, and enhancing the ability to perceive intranet computer assets.
Smart Images

Figure CN116719868B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a method, apparatus and device for identifying network assets. Background Technology
[0002] As business grows, the number of computer assets increases. Building a secure asset management platform to achieve visualized and secure management of the asset lifecycle and constructing a comprehensive and dynamic asset inventory database are the foundation of information security. Effective asset discovery and collection tools are a necessary condition for establishing a sound asset database.
[0003] In related technologies, asset collection largely relies on device users manually reporting network assets to the management unit. This includes reporting new network assets and updating existing ones. The management unit then organizes the reported asset information, establishes an asset database, and uses the information recorded in the database to identify network assets. However, manually reporting network assets requires manual input of currently running network assets, resulting in low identification efficiency. Furthermore, manual input can lead to misreporting or omissions, affecting the accuracy of network asset identification. Summary of the Invention
[0004] In view of this, this application provides a method, apparatus and device for identifying network assets, the main purpose of which is to solve the problem that the manual input of network assets in the prior art results in low identification efficiency and affects the accuracy of network asset identification.
[0005] According to a first aspect of this application, a method for identifying network assets is provided, comprising: Retrieve login attribute information of network devices within a specified network domain; The login attribute information is used to identify the associated network asset information of the network device, and the associated network asset information is stored in the network layer in the form of tabular data; The tabular data of associated network asset information is processed into asset information associated with network devices across different attribute dimensions through a structured processing method.
[0006] Furthermore, obtaining the login attribute information of the network device specifically includes: The system acquires network devices within a defined network domain and receives network device information provided by resource users. The network device information includes device identifiers and device login information. The device login information is configured using preset fields, and the device identifier is combined with the configured device login information to obtain the login attribute information of the network device.
[0007] Furthermore, the step of using the login attribute information to identify the associated network asset information of the network device and storing the associated network asset information in the network layer in the form of tabular data specifically includes: The device login service is enabled using the login attribute information of the network device, and a connection between the network resource and the network device is established using the login protocol supported by the device login service. Based on the connection between network resources and network devices, obtain at least one protocol table information for network device communication; Based on at least one protocol table information of the network device communication, the associated network asset information of the network device is determined, and the associated network asset information is stored in the network layer in the form of tabular data.
[0008] Furthermore, the step of obtaining at least one protocol table information for network device communication based on the connection between network resources and network devices specifically includes: Based on the connection between network resources and network devices, the version identifier of the network device is obtained by executing the device version collection command; Based on the version identifier of the network device, determine the acquisition instruction for the device resources that match the network device from the pre-configured instruction library; At least one protocol table information for network device communication is obtained by executing the device resource acquisition command.
[0009] Furthermore, obtaining at least one protocol table information for network device communication includes obtaining routing table information and link layer neighbor table information for network device communication; Accordingly, determining the associated network asset information of the network device based on at least one protocol table information of the network device communication, and storing the associated network asset information in the form of tabular data in the network layer, specifically includes: By parsing the routing table information and link-layer neighbor table information of the network devices, the original network asset information of the network device communication can be obtained; The associated network asset information of the network devices is filtered out from the original network asset information of the network device communication, and the associated network asset information is stored in the network layer in the form of tabular data.
[0010] Furthermore, the step of filtering out the associated network asset information of the network device from the original network asset information of the network device communication, and storing the associated network asset information in the network layer in the form of tabular data, specifically includes: Based on the original network asset information of the network communication device, a remote scanning tool is used to verify the device identifier recorded in the original network asset information to determine the communication status corresponding to the original network asset. If the communication status corresponding to the original network asset is connected, the original network asset information is used as the associated network asset information of the network device, and the associated network asset information is stored in the network layer in the form of tabular data.
[0011] Furthermore, after processing the tabular data of associated network asset information into asset information associated with network devices across different attribute dimensions using a structured processing method, the method further includes: A topology diagram of network devices within a defined network domain is constructed using the attribute information of the network assets in different dimensions. The topology diagram uses different dimensions to present the attribute information of the network assets associated with the network devices within the defined network domain. If there are conflicts between the associated network asset information of different network devices in the topology diagram, then the conflicting network asset information is identified and associated. Based on the association identification results, adjust the associated network asset information of conflicting network devices in the topology diagram.
[0012] According to a second aspect of this application, a network asset identification device is provided, comprising: The acquisition unit is used to acquire login attribute information of network devices within a specified network domain. The identification unit is used to identify the associated network asset information of the network device using the login attribute information, and store the associated network asset information in the form of tabular data in the network layer; The processing unit is used to process the tabular data of associated network asset information into asset information associated with network devices in different attribute dimensions through structured processing.
[0013] Furthermore, the acquisition unit is specifically used to acquire network devices within a set network domain, receive network device information provided by resource users, the network device information including device identifier and device login information; configure the device login information using preset fields, and combine the device identifier with the configured device login information to obtain the login attribute information of the network device.
[0014] Furthermore, the identification unit includes: A module is established to enable device login service using the login attribute information of the network device and to establish a connection between network resources and network devices using the login protocol supported by the device login service. The acquisition module is used to acquire at least one protocol table information of network device communication based on the connection between network resources and network devices; The determination module is used to determine the associated network asset information of the network device based on at least one protocol table information of the network device communication, and store the associated network asset information in the form of tabular data in the network layer.
[0015] Furthermore, the acquisition module is specifically used to, based on the connection between network resources and network devices, acquire the version identifier of the network device by executing a device version acquisition instruction; determine the acquisition instruction of the device resource matching the network device from a pre-configured instruction library according to the version identifier of the network device; and acquire at least one protocol table information of network device communication by executing the acquisition instruction of the device resource.
[0016] Furthermore, obtaining at least one protocol table information for network device communication includes obtaining routing table information and link layer neighbor table information for network device communication; The determining module is specifically used to obtain the original network asset information of the network device communication by parsing the routing table information and link layer neighbor table information of the network device; to filter out the associated network asset information of the network device from the original network asset information of the network device communication, and to store the associated network asset information in the form of tabular data in the network layer.
[0017] Furthermore, the determining module is specifically used to verify the device identifier recorded in the original network asset information using a remote scanning tool based on the original network asset information of the network communication device, and to determine the communication status corresponding to the original network asset. If the communication status corresponding to the original network asset is connected, the original network asset information is used as the associated network asset information of the network device, and the associated network asset information is stored in the network layer in the form of tabular data.
[0018] Furthermore, the device also includes: The construction unit is used to construct a topology diagram of network devices within a set network domain after the network asset information in tabular form is processed into asset information associated with network devices in different attribute dimensions through structured processing. The topology diagram uses different dimensions to present the attribute information of network assets associated with network devices within a set network domain. The identification unit is used to identify the conflicting network asset information if there is a conflict between the associated network asset information of different network devices in the topology diagram. The adjustment unit is used to adjust the associated network asset information of conflicting network devices in the topology diagram based on the association identification results.
[0019] According to a third aspect of this application, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described in the first aspect above.
[0020] According to a fourth aspect of this application, a readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in the first aspect above.
[0021] By utilizing the above technical solutions, this application provides a method, apparatus, and device for identifying network assets. Compared with the existing technology of manually reporting network assets, this application identifies network assets by obtaining the login attribute information of network devices within a defined network domain, using the login attribute information to identify the associated network asset information of the network devices, storing the associated network asset information in the form of tabular data in the network layer, and processing the tabular data of associated network asset information into asset information associated with network devices in different attribute dimensions through structured processing. The entire process can directly use the login attribute information to automatically identify the network asset information associated with network devices without manual input of network assets, ensuring the accuracy of network asset identification. After the network device logs in, it can quickly and accurately discover and identify unknown and known network assets in the computer network, improving the perception capability of computer assets in the intranet and improving the efficiency of network asset identification.
[0022] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0023] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1 This is a flowchart illustrating a method for identifying network assets in one embodiment of this application; Figure 2 yes Figure 1 A flowchart illustrating a specific implementation method of step 101; Figure 3 yes Figure 1 A flowchart illustrating a specific implementation method for step 102; Figure 4 This is a flowchart illustrating a method for identifying network assets in another embodiment of this application; Figure 5This is a schematic diagram of the structure of a network asset identification device in one embodiment of this application; Figure 6 This is a schematic diagram of the device structure of a computer device provided in an embodiment of the present invention. Detailed Implementation
[0024] The invention will now be discussed with reference to several exemplary embodiments. It should be understood that these embodiments are described merely to enable those skilled in the art to better understand and thus implement the invention, and are not intended to imply any limitation on the scope of the invention.
[0025] As used herein, the term "comprising" and its variations are to be interpreted as open-ended terms meaning "including but not limited to". The term "based on" is to be interpreted as "at least partially based on". The terms "one embodiment" and "an embodiment" are to be interpreted as "at least one embodiment". The term "another embodiment" is to be interpreted as "at least one other embodiment".
[0026] In related technologies, asset collection largely relies on device users manually reporting network assets to the management unit. This includes reporting new network assets and updating existing ones. The management unit then organizes the reported asset information, establishes an asset database, and uses the information recorded in the database to identify network assets. However, manually reporting network assets requires manual input of currently running network assets, resulting in low identification efficiency. Furthermore, manual input can lead to misreporting or omissions, affecting the accuracy of network asset identification.
[0027] To address this problem, this embodiment provides a method for identifying network assets, such as... Figure 1 As shown, this method is applied to the server side of the network asset identification system and includes the following steps: 101. Obtain login attribute information of network devices within the specified network domain.
[0028] The network domain can be a network range within a defined area, such as a room or a plaza. It can also be a network range within a defined distance; for example, with a router as the network center, the network range could be a circular area within a defined radius. The specific method for obtaining this information is by collecting and recording the login attribute information of network devices within the defined network domain.
[0029] Typically, network devices operate within a network environment, functioning as physical entities connected to the network. These can be computer hosts, switches, routers, firewalls, network printers, etc. In a network environment, each network device can connect to the network in a specific way, either wired or wireless. Different types of network devices can choose different connection methods, ultimately forming an interconnected network. As one implementation method, wired connections can utilize Ethernet networking, assembling a local area network (LAN) using hubs, switches, and routers to form a network, and connecting network devices to the host via fiber optic cables. Wireless connections can use Wi-Fi. In smaller spaces, a wireless router can connect all networked devices; in larger spaces, wireless controllers and access point controllers can be used to create a wireless local area network (WLAN) to connect network devices to the host.
[0030] In this embodiment, the login attribute information of a network device includes the network device's IP address and login information. The network device's IP address is a protocol for interconnecting networks and serves as a unique identifier for the network device within the network environment. Each network device can be identified through its IP address. The login information is authentication for the network device user, protecting the user's account security and forming the user's identity, proving that the user's operation was initiated by the user. One method for obtaining network device login attribute information is to receive network device information provided by users within a defined network range. This information records the network device's IP address and login information. The network device's IP address and login information are maintained in a database through configuration, and then combined to obtain the login attribute information for each network device. Another method for obtaining network device login attribute information is to use device identification information provided by the user. This device identification information can be an IP address, port, username, etc. The core of a network device is a switch or router. If the network device is a switch or router, discovering the network device within the defined network range allows obtaining other network devices connected to the switch or router in the network environment. If the network device is not a switch or router, it cannot be obtained through discovery.
[0031] In this embodiment, the executing entity can be a network asset identification device or equipment, which can be configured on the server corresponding to the network asset identification system. By obtaining the login attribute information of network devices within a set network domain, logging in using the login attribute information, and after logging in to the network device, collecting the device resources associated with the network device, and identifying network assets based on the collected device resources, there is no need for manual input of network assets, thereby more accurately identifying the asset information associated with the network device and improving the efficiency of network asset identification.
[0032] 102. Use the login attribute information to identify the associated network asset information of the network device, and store the associated network asset information in the network layer in the form of tabular data.
[0033] In this embodiment, login attribute information can be used to enable the login service of the network device. After logging in, the network device can forward data packets with other network devices on the communication path through the switching device, and then query the associated network asset information of the network device through the communication data resources recorded in the switching device. Here, the network asset information includes at least the manufacturer, model and version information of the network device.
[0034] In practical applications, network devices in a network environment can forward data packets flowing through their own nodes along a communication path. Common network devices are mainly switches and routers. During actual operation, network devices maintain some table structures to help complete the correct addressing and forwarding of data packets. Since two network devices are usually located in different positions in the network topology, they are mostly not directly physically connected. A communication path determined by routing protocols is required between them. Network layer protocols are responsible for ensuring that data packets are ultimately sent to the destination network device. Logical communication between different network devices can be achieved through network layer protocols.
[0035] Specifically, in identifying the associated network assets of network devices, we can obtain the table structure data related to the network data packet forwarding function during communication. Further parsing of this table structure data reveals the relationships between network devices, and based on these relationships, we can identify the associated network asset information of each device. This table structure data mainly includes a forwarding table, an ARP table, and a routing table. Specifically, the forwarding table stores MAC addresses (Media Access Control Addresses), used to identify the location of network devices. The ARP table stores the address resolution protocol used by each network device to map IP addresses to MAC addresses. The routing table stores the IP addresses of network devices, which are assigned to various network devices on the network and used to record communication path information between different network segments.
[0036] In practical applications, network devices can be logged into using network login attribute information, the devices can be identified, routing table and link-layer neighbor collection commands can be executed, and the collection results of the collection commands can be parsed to collect associated network asset information, such as the IP, MAC and switch port information of network assets.
[0037] In the forwarding table, each network device has a unique MAC address. After receiving a communication data frame, the network device records the source MAC address and the corresponding destination port in the communication data frame into the MAC table. Then, the network device checks its own MAC table to see if there is a matching entry for the destination MAC address in the data frame. If there is, it will forward the communication data frame according to the corresponding port recorded in the MAC table. If not, it will send the communication data frame out from all other ports other than the destination port. By parsing the forwarding table, the MAC address of the network device and the communication device resource can be determined.
[0038] In the ARP table, the IP addresses and MAC addresses of network devices are stored in a cached manner. Before a network device performs communication, it checks the ARP table to see if the mapping between the target network device's IP address and MAC address is recorded. If it is, the target network device's MAC address is encapsulated into the data frame as the destination MAC address. No further processing is required to obtain all the information needed for data frame encapsulation, and the data frame is sent to the destination MAC address. If not, the network device sends an ARP request message. The destination IP address in the request is the target network device's IP address, the destination MAC address is the MAC layer broadcast address, and the source IP address and MAC address are the network device's IP address and MAC address, respectively. By resolving the ARP table, the mapping between the IP address and MAC address of the network device and the resources it is communicating with can be determined.
[0039] The routing table records information about different network segments. Some information needs to be added manually, while others are automatically obtained through routing protocols. The routing table is continuously updated and maintained by periodically exchanging routing information with neighboring routers. By resolving the routing table, the IP addresses of network devices and the resources they communicate with can be determined.
[0040] 103. The tabular data of associated network asset information is processed into asset information of network devices associated with different attribute dimensions through structured processing.
[0041] Understandably, the associated network asset information in tabular form can be identified through probing, which can obtain the asset information of the target device communicating with the network device. Specifically, the table records the device attribute information and application attribute information of the target device, such as IP liveness, port / service, operating system, traffic collection, alias resolution, and application type. However, the associated asset information in tabular form does not have a complete attribute mapping relationship. It is still necessary to use asset comparison to standardize the associated network asset information to obtain the asset information associated with the network device in different attribute dimensions.
[0042] Considering that the identified associated network assets are different types of network devices, asset texture comparison can be used to determine asset attributes. In practical application scenarios, the identified associated network asset information mainly includes device components, application components, and service type inferences. Network assets differ in protocol implementation, network applications, etc., such as open port / service information, banner information, and web page data. Feature extraction of these differences can obtain the feature fingerprint of the network asset. The feature fingerprint database of network assets has accumulated a large number of network asset fingerprints. By comparing asset fingerprints, the attribute information of the identified associated network assets can be determined.
[0043] The network asset identification method provided in this application, compared with the existing technology of manually reporting network assets, obtains the login attribute information of network devices within a set network domain, uses the login attribute information to identify the associated network asset information of the network devices, stores the associated network asset information in the form of tabular data in the network layer, and processes the tabular data of associated network asset information into asset information associated with network devices in different attribute dimensions through structured processing. The entire process can directly use the login attribute information to automatically identify the network asset information associated with network devices without manual input of network assets, ensuring the accuracy of network asset identification. After the network device logs in, it can quickly and accurately discover and identify unknown and known network assets in the computer network, improve the perception capability of computer assets in the intranet, and improve the efficiency of network asset identification.
[0044] Specifically, in the above embodiments, such as Figure 2 As shown, step 101 includes the following steps: 201. Obtain network devices within the specified network domain and receive network device information provided by resource users.
[0045] 202. Configure the device login information using preset fields, and combine the device identifier with the configured device login information to obtain the login attribute information of the network device.
[0046] In this embodiment, network devices within the network domain can be network devices communicating within the network segment where the local area network (LAN) is located. Within the LAN, resource users can connect network devices to the LAN by logging in with their accounts. To more accurately identify the asset information associated with network devices within the LAN, the server corresponding to the network asset identification system can initiate an information retrieval request to the resource user, who will then provide the corresponding network device information. This network device information includes device identifiers and device login information. Device identifiers can include the network device's IP address, MAC address, login username, etc., while device login information can include the network device's login account, login password, and login usage agreement, etc.
[0047] The preset fields can be at least one field in the device login information, such as one or more of the login account, login protocol, and login key. The preset fields configure the information in the device login information that has the function of login connection as login connection fields. Each login connection field can realize the login service of the network device through the login program. The device identifier and the login connection fields are further combined to obtain the login attribute information of the network device.
[0048] It should be noted that, considering the possibility of missing information in device login data, preset fields can be used to configure default values for missing items in the device login data. The device identifier can then be combined with the configured device login information to obtain the login attribute information of the network device. For example, the login attribute information of a network device may include the following attribute fields, as shown in Table 1 below: Table 1. Login Attribute Information of Network Devices It is understandable that, considering that different types of network devices support different connection methods, some network devices support the SSH protocol to implement login services, while others support the Telnet protocol to implement login services. For different types of network devices, the connection method corresponding to the login connection field is different, and the specific configuration can be made according to the actual situation.
[0049] Furthermore, by writing a program to use the login information of the network devices that have been entered and managed as described above, and by connecting to the terminal interaction environment of the network devices through the login protocol supported by the network device terminals, the program reads the echo data of the devices and determines the start and end instruction flags for executing each instruction.
[0050] Specifically, in the above embodiments, such as Figure 3 As shown, step 102 includes the following steps: 301. Use the login attribute information of the network device to enable the device login service, and use the login protocol supported by the device login service to establish a connection between the network resource and the network device.
[0051] 302. Based on the connection between network resources and network devices, obtain at least one protocol table information for network device communication.
[0052] 303. Based on at least one protocol table information of the network device communication, determine the associated network asset information of the network device, and store the associated network asset information in the network layer in the form of tabular data.
[0053] Typically, for ease of management, network devices are configured with device login services. Depending on the connection methods supported by different network devices, the login protocol used varies. Common login protocols include SSH and Telnet. Users can further select the login protocol supported by the network device to establish a connection between the network resource and the device. For example, if the network device supports remote login, the Telnet protocol can be used to establish a connection. While this device login service supports remote login, all information in Telnet is transmitted in plaintext, posing a security risk. For a more secure remote login method, the SSH protocol can be used. SSH encrypts the sent account passwords and data, significantly reducing the risk of leakage.
[0054] Furthermore, considering that, based on the connection between network resources and network devices, the version identifier of the network device is obtained by executing the device version collection command, and then the collection command of the device resource matching the network device is determined from the pre-configured command library according to the version identifier of the network device, and at least one protocol table information of network device communication is obtained by executing the device resource collection command.
[0055] As one feasible approach, obtaining at least one protocol table information of network device communication includes obtaining routing table information and link-layer neighbor table information of network device communication. Accordingly, the original network asset information of network device communication can be obtained by parsing the routing table information and link-layer neighbor table information of network device communication, the associated network asset information of network device can be filtered out from the original network asset information of network device communication, and the associated network asset information can be stored in the network layer in the form of tabular data.
[0056] In one possible implementation, the device version's collection instructions mainly include routing table collection instructions and link-layer neighbor collection instructions. After executing the instructions, the collection results of the routing table and the link-layer neighbor are obtained respectively. For each row in the routing table collection result, the IP address, MAC address, and device port name are extracted by regular table matching. Each row in the routing table is parsed and identified as a live network asset. For the link-layer neighbor collection results, all management IP addresses are extracted first. Then, the results are segmented according to the management IP addresses, and each segment is identified as a device asset. Then, the manufacturer, MAC address, and model are parsed and extracted for each segment. Finally, the routing table collection results and the link-layer neighbor collection results are merged to obtain the network asset information as the original network asset information.
[0057] Specifically, you can first execute the device routing table collection command, such as `show arp` for Cisco devices, then read the command results and parse the routing table, identifying each IP address extracted as an associated asset. During the parsing process, the MAC address, communication switch port information, and VLAN information of the associated asset are also extracted, ultimately collecting the associated network asset information from the routing table. Next, execute the device link-layer neighbor collection command, such as `show lldp` or `showcdp` for Cisco devices, then read the link-layer neighbor collection results and parse the link-layer neighbor list, identifying each IP address extracted as an associated asset. During the parsing process, the MAC address of the associated asset is also extracted, ultimately collecting the associated network asset information from the link-layer neighbors.
[0058] Furthermore, to enhance the identification of the identified associated network asset information, as a possible method to filter associated network asset information of network devices from the original network asset information of network device communication, a remote scanning tool can be used to verify the device identifier recorded in the original network asset information to determine the communication status corresponding to the original network asset. If the communication status corresponding to the original network asset is connected, the original network asset information is used as the associated network asset information of the network device, and the associated network asset information is stored in the network layer in the form of tabular data. Here, the communication status can be represented by whether the network device is connected, which can determine whether the IP address of the associated network device is alive. If the communication status is connected, it means that the IP address of the associated network device is alive; otherwise, it means that the IP address of the associated network device has been disconnected and is not alive.
[0059] In one possible implementation, the asset IP obtained by executing the link table and link layer neighbor collection instructions is remotely scanned and identified using remote scanning tools such as nmap to improve the asset attribute information, including obtaining the asset's survival status, asset manufacturer, model, operating system version number, etc.
[0060] Understandably, remote scanning tools can be used to scan raw network asset information with probes. The purpose is to detect the open ports, services, operating systems, and other information of online network devices within the target range. By scanning and identifying the coarse-grained raw network asset information obtained through login collection via remote scanning, information such as asset liveness status, manufacturer, and operating system can be further supplemented and improved. Here, data packets can be actively sent for scanning to obtain the network address, open system ports, and service types of network assets. Based on the system's built-in fingerprint database, the type, operating system, and manufacturer information of each network asset can be determined, thereby obtaining the associated network asset information of the network devices.
[0061] Furthermore, in the above embodiments, such as Figure 4 As shown, after step 103, the following steps are also included: 401. Construct a topology diagram of network devices within a defined network domain using the attribute information of the network assets in different dimensions.
[0062] 402. If there is a conflict between the associated network asset information of different network devices in the topology diagram, the conflicting network asset information shall be identified and associated.
[0063] 403. Adjust the associated network asset information of conflicting network devices in the topology diagram based on the association identification results.
[0064] The topology diagram uses different dimensions to present the attribute information of network assets associated with network devices within a defined network domain. This topology diagram can organize and summarize the identified network assets, mainly the connection relationships between network devices, and their actual operating status through certain means, to obtain the communication connection relationships between all network devices within the defined network domain.
[0065] This invention, through logging into the account information of network devices, obtains the host devices and adjacent network devices carried by the network devices, identifies the asset information associated with each network device in different attribute dimensions, further summarizes the asset information associated with all network devices in the specified network domain in different attribute dimensions, and draws asset topology information. Specifically, it can construct a topology diagram of network devices in the specified network domain by comparing the connection relationship of each network device within the specified network range and based on the connection relationship of the network devices.
[0066] Understandably, considering that network devices may be associated with multiple network devices during communication, resulting in conflicts between associated asset information, which is not conducive to the construction of the topology diagram, we can identify the network assets that are in conflict with the topology diagram to confirm the network devices directly connected to the associated network devices. For example, if switch A and switch B both detect the same host, then we can identify the host and confirm the first switch directly connected to the host.
[0067] Furthermore, as Figure 1-4 In terms of specific implementation, this application provides a network asset identification device, such as... Figure 5 As shown, the device includes: an acquisition unit 51, an identification unit 51, and a processing unit 53.
[0068] Acquisition unit 51 is used to acquire login attribute information of network devices within a specified network domain; The identification unit 52 is used to identify the associated network asset information of the network device using the login attribute information, and store the associated network asset information in the form of tabular data in the network layer; Processing unit 53 is used to process the tabular data of associated network asset information into asset information associated with network devices in different attribute dimensions through structured processing.
[0069] The network asset identification device provided in this invention, compared with the existing technology of manually reporting network assets, obtains the login attribute information of network devices within a set network domain, uses the login attribute information to identify the associated network asset information of the network devices, stores the associated network asset information in the form of tabular data in the network layer, and processes the tabular data of associated network asset information into asset information associated with network devices in different attribute dimensions through structured processing. The entire process can directly use the login attribute information to automatically identify the network asset information associated with network devices without manual input of network assets, ensuring the accuracy of network asset identification. After the network device logs in, it can quickly and accurately discover and identify unknown and known network assets in the computer network, improve the perception ability of computer assets in the intranet, and improve the efficiency of network asset identification.
[0070] In specific application scenarios, the acquisition unit is specifically used to acquire network devices within a set network domain, receive network device information provided by resource users, the network device information including device identifier and device login information; configure the device login information using preset fields, and combine the device identifier with the configured device login information to obtain the login attribute information of the network device.
[0071] In specific application scenarios, the identification unit includes: A module is established to enable device login service using the login attribute information of the network device and to establish a connection between network resources and network devices using the login protocol supported by the device login service. The acquisition module is used to acquire at least one protocol table information of network device communication based on the connection between network resources and network devices; The determination module is used to determine the associated network asset information of the network device based on at least one protocol table information of the network device communication, and store the associated network asset information in the form of tabular data in the network layer.
[0072] In specific application scenarios, the acquisition module is specifically used to obtain the version identifier of the network device by executing a device version acquisition instruction based on the connection between network resources and network devices; determine the acquisition instruction of the device resource matching the network device from a pre-configured instruction library according to the version identifier of the network device; and obtain at least one protocol table information of network device communication by executing the acquisition instruction of the device resource.
[0073] In specific application scenarios, obtaining at least one protocol table information for network device communication includes obtaining routing table information and link layer neighbor table information for network device communication. The determining module is specifically used to obtain the original network asset information of the network device communication by parsing the routing table information and link layer neighbor table information of the network device; to filter out the associated network asset information of the network device from the original network asset information of the network device communication, and to store the associated network asset information in the form of tabular data in the network layer.
[0074] In specific application scenarios, the determining module is further used to verify the device identifier recorded in the original network asset information using a remote scanning tool based on the original network asset information of the network communication device, and to determine the communication status corresponding to the original network asset. If the communication status corresponding to the original network asset is connected, the original network asset information is used as the associated network asset information of the network device, and the associated network asset information is stored in the network layer in the form of tabular data.
[0075] In specific application scenarios, the device further includes: The construction unit is used to construct a topology diagram of network devices within a set network domain after the network asset information in tabular form is processed into asset information associated with network devices in different attribute dimensions through structured processing. The topology diagram uses different dimensions to present the attribute information of network assets associated with network devices within a set network domain. The identification unit is used to identify the conflicting network asset information if there is a conflict between the associated network asset information of different network devices in the topology diagram. The adjustment unit is used to adjust the associated network asset information of conflicting network devices in the topology diagram based on the association identification results.
[0076] It should be noted that other corresponding descriptions of the functional units involved in the network asset identification device provided in this embodiment can be found in [reference needed]. Figures 1-4 The corresponding description in [the document] will not be repeated here.
[0077] Based on the above, Figures 1-4 Accordingly, this application embodiment also provides a storage medium storing a computer program thereon, which, when executed by a processor, implements the above-described method. Figures 1-4 The method for identifying network assets is shown.
[0078] Based on this understanding, the technical solution of this application can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or portable hard drive), and includes several instructions to cause a computer device (such as a personal computer, server, or network device) to execute the methods described in the various implementation scenarios of this application.
[0079] Based on the above, Figures 1-4 The method shown, and Figure 5 To achieve the above objectives, this application also provides a physical device for identifying network assets, as illustrated in the virtual device embodiment. Specifically, this device may be a computer, smartphone, tablet, smartwatch, server, or network equipment, etc. The physical device includes a storage medium and a processor; the storage medium stores a computer program; the processor executes the computer program to achieve the above-described objectives. Figures 1-4 The method for identifying network assets is shown.
[0080] Optionally, the physical device may also include a user interface, a network interface, a camera, radio frequency (RF) circuitry, sensors, audio circuitry, a Wi-Fi module, etc. The user interface may include a display screen, input units such as a keyboard, etc., and optional user interfaces may also include USB interfaces, card reader interfaces, etc. The network interface may optionally include standard wired interfaces, wireless interfaces (such as Wi-Fi interfaces), etc.
[0081] In an exemplary embodiment, see Figure 6 The aforementioned physical device includes a communication bus, a processor, a memory, and a communication interface. It may also include input / output interfaces and a display device. The various functional units can communicate with each other via the bus. The memory stores a computer program, and the processor executes the program stored in the memory to perform the network asset identification method described in the above embodiments.
[0082] Those skilled in the art will understand that the physical device structure for identifying network assets provided in this embodiment does not constitute a limitation on the physical device, and may include more or fewer components, or combine certain components, or have different component arrangements.
[0083] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages the hardware and software resources of the identified physical device of the aforementioned network assets, supporting the operation of information processing programs and other software and / or programs. The network communication module is used to enable communication between the various components within the storage medium, as well as communication with other hardware and software in the information processing physical device.
[0084] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented using software plus necessary general-purpose hardware platforms, or it can be implemented through hardware. By applying the technical solution of this application, compared with the existing methods, this application can directly use login attribute information to automatically identify network asset information associated with network devices, without the need for manual input of network assets, ensuring the accuracy of network asset identification. After logging into the network device, it can quickly and accurately discover and identify unknown and known network assets in the computer network, improving the perception capability of computer assets in the intranet and improving the efficiency of network asset identification.
[0085] Those skilled in the art will understand that the accompanying drawings are merely schematic diagrams of a preferred embodiment, and the modules or processes shown in the drawings are not necessarily essential for implementing this application. Those skilled in the art will understand that the modules in the apparatus of the embodiment can be distributed within the apparatus of the embodiment as described, or can be modified to be located in one or more apparatuses different from this embodiment. The modules of the above-described embodiment can be combined into one module, or further divided into multiple sub-modules.
[0086] The serial numbers in this application are for descriptive purposes only and do not represent the superiority or inferiority of any particular implementation scenario. The above disclosures are merely a few specific implementation scenarios of this application; however, this application is not limited thereto, and any variations conceived by those skilled in the art should fall within the protection scope of this application.
Claims
1. A method for identifying network assets, characterized in that, include: Retrieve login attribute information of network devices within a specified network domain; The login attribute information is used to identify the associated network asset information of the network device, and the associated network asset information is stored in the network layer in the form of tabular data. Specifically, this is achieved by: using the login attribute information of the network device to enable the device login service; establishing a connection between the network resource and the network device using the login protocol supported by the device login service; based on the connection between the network resource and the network device, obtaining the version identifier of the network device by executing the device version collection command; determining the collection command for the device resource matching the network device from a pre-configured command library according to the version identifier of the network device; obtaining the table structure data of the network device involved in the packet forwarding function during communication by executing the collection command for the device resource; and obtaining the original network asset information of the network device communication by parsing the routing table information and link layer neighbor table information of the network device. The associated network asset information of the network devices is filtered out from the original network asset information of the network device communication, and the associated network asset information is stored in the network layer in the form of tabular data. The table structure data includes at least a forwarding table, an ARP table, and a routing table. The forwarding table stores MAC addresses, which are used to identify the location of the network devices. The ARP table stores the address resolution protocol of the network devices. This address resolution protocol runs in each network device and is used to implement the mapping of the network device's IP address to its MAC address. The routing table stores the IP addresses of the network devices, which are addresses assigned to each network device on the network and are used to record the path information for communication between different network segments. The tabular data of associated network asset information is processed into asset information associated with network devices in different attribute dimensions through a structured processing method. A topology diagram of network devices within a defined network domain is constructed using the attribute information of the network assets in different dimensions. The topology diagram uses different dimensions to present the attribute information of the network assets associated with the network devices within the defined network domain. If there are conflicts between the associated network asset information of different network devices in the topology diagram, then the conflicting network asset information is identified and associated. Based on the association identification results, adjust the associated network asset information of conflicting network devices in the topology diagram.
2. The method according to claim 1, characterized in that, The acquisition of login attribute information of network devices within a specified network domain specifically includes: The system acquires network devices within a defined network domain and receives network device information provided by resource users. The network device information includes device identifiers and device login information. The device login information is configured using preset fields, and the device identifier is combined with the configured device login information to obtain the login attribute information of the network device.
3. The method according to claim 1, characterized in that, The step of filtering out the associated network asset information of the network devices from the original network asset information of the network device communication, and storing the associated network asset information in the form of tabular data in the network layer, specifically includes: Based on the original network asset information of the network device, a remote scanning tool is used to verify the device identifier recorded in the original network asset information to determine the communication status corresponding to the original network asset. If the communication status corresponding to the original network asset is connected, the original network asset information is used as the associated network asset information of the network device, and the associated network asset information is stored in the network layer in the form of tabular data.
4. A device for identifying network assets, characterized in that, include: The acquisition unit is used to acquire login attribute information of network devices within a specified network domain. The identification unit is used to identify the associated network asset information of the network device using the login attribute information, and store the associated network asset information in the network layer in the form of tabular data. Specifically, it does so by: using the login attribute information of the network device to enable the device login service; using the login protocol supported by the device login service to establish a connection between the network resource and the network device; based on the connection between the network resource and the network device, obtaining the version identifier of the network device by executing the device version collection command; determining the collection command of the device resource matching the network device from a pre-configured command library according to the version identifier of the network device; obtaining the table structure data of the network device involved in the packet forwarding function during communication by executing the collection command of the device resource; and obtaining the original network asset information of the network device communication by parsing the routing table information and link layer neighbor table information of the network device. The associated network asset information of the network devices is filtered out from the original network asset information of the network device communication, and the associated network asset information is stored in the network layer in the form of tabular data. The table structure data includes at least a forwarding table, an ARP table, and a routing table. The forwarding table stores MAC addresses, which are used to identify the location of the network devices. The ARP table stores the address resolution protocol of the network devices. This address resolution protocol runs in each network device and is used to implement the mapping of the network device's IP address to its MAC address. The routing table stores the IP addresses of the network devices, which are addresses assigned to each network device on the network and are used to record the path information for communication between different network segments. The processing unit is used to process the tabular data of associated network asset information into asset information of network devices associated with different attribute dimensions through structured processing. The construction unit is used to construct a topology diagram of network devices within a set network domain after the network asset information in tabular form is processed into asset information associated with network devices in different attribute dimensions through structured processing. The topology diagram uses different dimensions to present the attribute information of network assets associated with network devices within a set network domain. The identification unit is used to identify the conflicting network asset information if there is a conflict between the associated network asset information of different network devices in the topology diagram. The adjustment unit is used to adjust the associated network asset information of conflicting network devices in the topology diagram based on the association identification results.
5. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method for identifying network assets according to any one of claims 1 to 3.
6. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method for identifying network assets according to any one of claims 1 to 3.