Asset identification method and apparatus, electronic device, and storage medium
Patent Information
- Application Number
- CN202310574257.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-19
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2043-05-19
AI Technical Summary
[0004]本申请实施例的目的在于提供一种资产识别方法、装置、电子设备及存储介质,用以改善现有技术中资产识别方式准确性低的问题
[0032]第四方面,本申请实施例提供一种计算机可读存储介质,其上存储有计算机程序,所述计算机程序被处理器执行时运行如上述第一方面提供的所述方法中的步骤。
Smart Images

Figure CN116760571B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and more specifically, to an asset identification method, apparatus, electronic device, and storage medium. Background Technology
[0002] In risk assessment, key risk factors are asset-centric; threats, vulnerabilities, and risks are all objectively present in relation to assets. Threats exploit asset vulnerabilities, making security incidents possible and thus creating security risks. Over the past few years, with the evolution of the security posture and the development of security concepts, more and more people have realized that in enterprise security operations management, asset security is the foundation of all security; therefore, asset identification is particularly important.
[0003] Currently, asset identification is mainly based on IP addresses. However, in practical applications, there may be overlapping IP addresses in the network. In such scenarios, relying on IP addresses may lead to misidentification and low accuracy. Summary of the Invention
[0004] The purpose of this application is to provide an asset identification method, apparatus, electronic device, and storage medium to improve the low accuracy of asset identification methods in the prior art.
[0005] In a first aspect, embodiments of this application provide an asset identification method, the method comprising:
[0006] Obtain multiple asset identification information, wherein each asset identification information includes an IP address and the network segment identifier corresponding to the IP address;
[0007] Assets in the network are identified based on the IP address and the network segment identifier corresponding to the IP address in the multiple asset identification information.
[0008] In the above implementation process, assets in the network are identified by the IP address in the asset identification information and the network segment identifier corresponding to the IP address. In this way, for scenarios where IP addresses overlap under different network segments, this method can be used to accurately identify assets.
[0009] Optionally, the asset identification information further includes asset information, and the step of identifying assets in the network based on the IP address and the network segment identifier corresponding to the IP address in the plurality of asset identification information includes:
[0010] If at least two of the multiple asset identification information have different IP addresses and network segment identifiers corresponding to those IP addresses, but the asset information is the same, then the assets corresponding to the at least two asset identification information are determined to be the same asset, wherein the asset information is attribute information used to characterize the uniqueness of the asset.
[0011] In the above implementation process, for the same asset in different network segments, its asset information can be combined to accurately identify it.
[0012] Optionally, the step of identifying assets in the network based on the IP address and the network segment identifier corresponding to the IP address in the plurality of asset identification information includes:
[0013] If at least two of the multiple asset identification information entries contain the same IP address and the corresponding network segment identifier, then the assets corresponding to the at least two asset identification information entries are determined to be the same asset. This enables the identification of assets with overlapping IP addresses across different network segments.
[0014] Optionally, obtaining multiple asset identification information includes:
[0015] Obtain the IP addresses of the assets collected by each collection device deployed in the network;
[0016] Each of the aforementioned acquisition devices is assigned a network segment identifier, and each network segment identifier corresponds to a preset IP address network segment.
[0017] Based on the IP address and the corresponding network segment identifier, generate corresponding asset identification information.
[0018] In the above implementation process, by configuring corresponding network segment identifiers for each acquisition device, asset identification information consisting of IP address plus network segment identifier can be directly generated, thereby distinguishing duplicate IP addresses under different network segments.
[0019] Optionally, obtaining multiple asset identification information includes:
[0020] Asset identification information is obtained from various acquisition devices deployed in the network, wherein the network segment identifier corresponding to the IP address in the asset identification information is added by the acquisition device.
[0021] In the above implementation process, network segment identifiers are added by the acquisition device, so that the identification device only needs to acquire asset identification information for identification, thereby improving identification efficiency.
[0022] Optionally, the method further includes:
[0023] If two different asset identification information have been identified as belonging to different assets, and the two different asset identification information are currently identified as belonging to the same asset, a conflict determination is made on their identification results.
[0024] In the above implementation process, when there is a conflict in asset identification, a conflict resolution is performed to improve the accuracy of asset identification.
[0025] Optionally, the conflict determination of the identification results includes:
[0026] The final identification result is the identification result that the two different asset identification information currently identified belong to the same asset.
[0027] In the above implementation process, conflict resolution is performed on the identification results to obtain the final identification result, so as to avoid the problem of the same asset being identified as different assets.
[0028] Secondly, embodiments of this application provide an asset identification device, the device comprising:
[0029] The information acquisition module is used to acquire multiple asset identification information, wherein each asset identification information includes an IP address and the network segment identifier corresponding to the IP address;
[0030] The asset identification module is used to identify assets in the network based on the IP address and the network segment identifier corresponding to the IP address in the multiple asset identification information.
[0031] Thirdly, embodiments of this application provide an electronic device, including a processor and a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps of the method provided in the first aspect above are performed.
[0032] Fourthly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the steps of the method provided in the first aspect above.
[0033] Other features and advantages of this application will be set forth in the following description and will be apparent in part from the description or may be learned by practicing embodiments of this application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description
[0034] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0035] Figure 1 A flowchart illustrating an asset identification method provided in this application embodiment;
[0036] Figure 2 This is a schematic diagram of asset identification information collected by a data acquisition device, provided in an embodiment of this application.
[0037] Figure 3 This is a schematic diagram illustrating the generation of asset identification information provided in an embodiment of this application;
[0038] Figure 4 A structural block diagram of an asset identification device provided in an embodiment of this application;
[0039] Figure 5 This is a schematic diagram of the structure of an electronic device for performing an asset identification method, provided as an embodiment of this application. Detailed Implementation
[0040] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0041] It should be noted that the terms "system" and "network" in the embodiments of this invention can be used interchangeably. "Multiple" refers to two or more; therefore, in the embodiments of this invention, "multiple" can also be understood as "at least two". "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / ", unless otherwise specified, generally indicates that the preceding and following related objects have an "or" relationship.
[0042] This application provides an asset identification method that identifies assets in a network by using the IP address in the asset identification information and the network segment identifier corresponding to the IP address. In this way, for scenarios where IP addresses overlap under different network segments, this method can be used to accurately identify assets.
[0043] Please refer to Figure 1 , Figure 1 A flowchart of an asset identification method provided in this application embodiment, the method including the following steps:
[0044] Step S110: Obtain multiple asset identification information.
[0045] In this embodiment of the application, the execution subject of the method is an identification device. The identification device can obtain asset identification information of various assets in the network. Since some of the obtained asset identification information may belong to the same asset, in order to uniquely identify these assets, the obtained asset identification information includes the IP address and the network segment identifier corresponding to the IP address.
[0046] Among them, the network segment identifier refers to the identifier corresponding to the network segment to which the IP address belongs. The identifier can be added to the IP address by the identification device after obtaining the IP address, or the IP address obtained by the identification device may itself carry the corresponding network segment identifier.
[0047] Step S120: Identify assets in the network based on the IP address and the network segment identifier corresponding to the IP address in multiple asset identification information.
[0048] Multiple asset identification information can be a subset of asset identification information currently acquired by the identification device, and may not represent the asset identification information of all assets in the network. In such scenarios, during identification, these multiple asset identification information sets can be identified first, and then the identified assets can be merged into the already identified assets. Of course, multiple asset identification information sets can also represent the asset identification information of all assets that can be acquired at the moment.
[0049] During identification, if at least two asset identification records contain the same IP address and the corresponding network segment identifier, then the assets corresponding to these at least two asset identification records are determined to be the same asset. Here, "same" means that both the IP address and the corresponding network segment identifier are identical; that is, identical asset identification records are identified as asset identification records corresponding to the same asset. If there are different asset identification records, they are identified as a separate asset.
[0050] For example, if a total of 10 asset identification information is obtained, and 2 of them are the same, then these two asset identification information are identified as the same asset, while the other 8 asset identification information are different, then they are identified as 8 different assets, that is, a total of 9 assets are identified.
[0051] These nine assets may have already had their asset identification information acquired and identified previously. Therefore, they can be compared with already identified assets. This comparison also involves comparing the asset identification information of these nine assets with that of already identified assets. If a match is found, it is merged into the list of already identified assets. If no match is found, it indicates a newly added asset, which can be added to the asset list. This allows for the statistical analysis of assets on the network, facilitating timely identification of newly added assets.
[0052] In the above implementation process, assets in the network are identified by the IP address in the asset identification information and the network segment identifier corresponding to the IP address. In this way, for scenarios where IP addresses overlap under different network segments, this method can be used to accurately identify assets.
[0053] Based on the above embodiments, multiple data collection devices can be deployed in the network. These devices can be used to collect asset identification information of assets in the network, such as information scanning devices. In some scenarios, network assets, such as gateways and proxies, may have multiple IP addresses belonging to one or more network segments. That is, multiple IP addresses of the same device may belong to different network segments. In such scenarios, if assets are identified solely based on IP addresses and network segment identifiers, the same asset may be identified as multiple different assets.
[0054] To identify assets in this scenario, asset identification information can also include asset information, which can be attribute information used to characterize the uniqueness of an asset, such as the asset's equipment information. When identifying assets, if at least two of the multiple asset identification information have different IP addresses and network segment identifiers corresponding to those IP addresses, but the asset information is the same, then it can be determined that the assets corresponding to at least two asset identification information are the same asset.
[0055] In some implementations, asset information can refer to information about the asset itself, such as a device serial number. In this case, even if the IP address and its corresponding network segment identifier are different, if the device serial number is the same, they can be considered the same asset. However, in many cases, the data acquisition device cannot obtain the device serial number. Therefore, asset identification can be performed first based on the IP address and network segment identifier. If the obtained asset identification information contains asset information, it can be combined with the asset information for identification. At this point, if the asset information in two asset identification pieces is the same, these two asset identification pieces may originate from the same data acquisition device or from different data acquisition devices.
[0056] In other implementations, asset information may refer to information about the asset that is publicly displayed, such as a customer number. In this case, the customer number displayed by the asset may differ for different manufacturers' data acquisition devices. That is, different manufacturers' data acquisition devices may collect different asset information for the same asset, while the same data acquisition device may obtain different asset information for different assets, and the same data acquisition device may obtain the same asset information for the same asset. In this case, the aforementioned asset information attribute representing the uniqueness of the asset can be understood as the asset information being unique for the same data acquisition device. Therefore, if the asset information in two asset identification pieces is the same, then these two asset identification pieces originate from the same data acquisition device.
[0057] When the asset information is a customer number, the data acquisition device typically obtains it through a proxy service. This means that different manufacturers have proxy services associated with the assets. When the data acquisition device scans the asset identification information through the proxy service, the proxy service generates a customer number based on that asset and sends it to the data acquisition device. At this point, the data acquisition device will collect the asset information contained within the asset identification information. However, in scenarios without a proxy service or other similar situations, the data acquisition device often cannot obtain asset information, so asset identification is primarily based on IP address and network segment identifiers.
[0058] For example, such as Figure 2 As shown, the acquisition device 1 (represented as acquisition source 1 in the figure) can acquire two IP addresses, 10.10.2.35 and 192.168.1.68. These two IP addresses belong to different network segments, namely network segment A and network segment C. In order to distinguish these two asset identification information, network segment identifiers are added to these two IP addresses to form asset identification information of 10.10.2.35A and 192.168.1.68C respectively.
[0059] At this time, the acquisition device 1 collects two IP addresses of device 1 through the proxy. When device 1 sends the IP address to the acquisition device, it can attach its asset information, which may include the aforementioned customer number. Device 1 transmits asset information to the acquisition device through the proxy. In this way, for different manufacturers' proxies, unique asset information is generated. Therefore, for device 1, different acquisition devices may obtain different asset information. This depends on the proxy service deployed on device 1. The proxy service is related to the acquisition device, so different acquisition devices may obtain different asset information for the same device.
[0060] Therefore, if the acquisition device 1 acquires two IP addresses of device 1, and these two IP addresses belong to different network segments, and the asset information corresponding to these two IP addresses is the same, then it can be considered that these two asset identification information belong to the same asset.
[0061] exist Figure 2 In the diagram, the acquisition device 2 (represented as acquisition source 2) can acquire two IP addresses on device 2 through a proxy, namely 10.20.22.33 and 192.168.1.68. After adding the network segment identifier to these two IP addresses, the generated asset identification information includes 10.20.22.23B and 192.168.1.68D.
[0062] When receiving the IP address sent by the data acquisition device 2, the data acquisition device 2 will also send its asset information to the data acquisition device 2 through a proxy. Therefore, although the IP address and network segment identifier in the two asset identification information are different, the asset information is the same. So, the two asset identification information can be considered to belong to the same asset. That is, 10.20.22.23B and 192.168.1.68D are considered to be the asset identification information corresponding to the data acquisition device 1.
[0063] After the identification device obtains the asset identification information from the acquisition device 1 and the acquisition device 2, although the IP address (192.168.1.68) in two of the asset identification information is the same, their network segment identifiers are different, so they can be considered to belong to different assets. In this way, asset identification of duplicate IPs in different network segments can be achieved through the network segment identifier.
[0064] Furthermore, in practical applications, asset identification information for the same asset may be collected by different acquisition devices. For example, network segment C of device 1 may also be collected by acquisition device 3. In this case, the asset identification information collected by acquisition device 3 is also 192.168.1.68C. As can be seen from the above identification, this asset identification information has been identified as the asset identification information of device 1. Therefore, if the asset identification information collected by acquisition device 3 is obtained, it will be identified and confirmed as the asset identification information of device 1. Moreover, by matching the IP address and network segment identifier, it is found that it is the same as the asset identification information of device 1 (i.e., the IP address and network segment identifier are the same). In this case, even if the asset information is different, it can still be considered as the same asset.
[0065] In other implementations, asset information may also include the asset's location information, such as the coordinates of the asset. This allows for further identification by combining the location information with the asset's location; for example, if the coordinates are the same and other asset identification information is also identical, it can be determined that they are the same asset. Alternatively, as mentioned above, even if the IP addresses and network segment identifiers are different, if the coordinates are the same, they can be considered the same asset. Of course, each asset corresponds to unique coordinate information. This allows for accurate asset identification.
[0066] In the above implementation process, for the same asset in different network segments, its asset information can be combined to accurately identify it.
[0067] Based on the above embodiments, in the method of acquiring multiple asset identification information, the identification device can obtain the IP address of the asset it has collected from each collection device deployed in the network, determine the network segment identifier configured for each collection device, and each network segment identifier corresponds to a preset IP address network segment. Then, based on the IP address and the corresponding network segment identifier, the corresponding asset identification information is generated.
[0068] For example, the identification device pre-collects relevant information about each acquisition device, such as the network segment range that each acquisition device can collect, and then configures a network segment identifier for each acquisition device based on the network segment range that the acquisition device can collect. For example, as mentioned above... Figure 2 In the example, the network segment identifiers of the data acquisition device 1 are configured as network segment A and network segment C, and the network segment identifiers of the data acquisition device 2 are configured as network segment B and network segment D. In this implementation, the data acquisition devices only collect the IP addresses of the assets and transmit them to the identification device. The identification device obtains multiple IP addresses from each data acquisition device. After obtaining multiple IP addresses, the identification device obtains the network segment identifier configured for that data acquisition device based on the source of the IP address. Then, it determines the network segment identifier to which each IP address belongs based on the correspondence between the network segment identifier and the IP address network segment. Finally, it generates asset identification information based on the IP address and the corresponding network segment identifier. Here, the network segment identifier to which the IP address belongs can be determined based on the network segment range to which the IP address belongs (i.e., the IP address network segment). If the identification device obtains two IP addresses sent by data acquisition device 1, and the identification device is configured with the network segment range of data acquisition device 1, then the network segment identifier corresponding to each IP address can be determined based on the network segment range to which the IP address belongs.
[0069] like Figure 3 As shown, network segments A and C are configured for data acquisition device 1 (represented as data acquisition source 1 in the figure). The IP addresses of device 1 (represented as asset 1 in the figure) collected by it include 10.10.2.35 and 192.168.1.68. When generating asset identification information, the corresponding IP addresses are added with the corresponding network segment identifiers, and the obtained asset identification information includes 10.10.2.35A and 192.168.1.68C. Similarly, network segments B and D are configured for data acquisition device 2 (represented as data acquisition source 2 in the figure). The IP addresses of device 2 (represented as asset 2 in the figure) collected by it include 10.20.22.33 and 192.168.1.68. When generating asset identification information, the corresponding IP addresses are added with the corresponding network segment identifiers, and the obtained asset identification information includes 10.20.22.33B and 192.168.1.68D.
[0070] In practical applications, the IP address obtained by the identification device may itself carry a network segment identifier. For example, a cloud platform may have its own cloud identifier, which can be used as a network segment identifier. Therefore, after obtaining the IP address, the identification device can first determine whether the IP address carries a network segment identifier. If not, it can add a network segment identifier to the IP address in the manner described above. If it does, it can directly identify assets based on the IP address and its carried network segment identifier.
[0071] In the above implementation process, by pre-configuring the range of network segments and configuring the range of network segments that can be collected for each collection device, it is possible to determine which network segment the IP belongs to based on the range of network segments to which the collected IP address belongs, and then determine the corresponding network segment identifier, generating asset identification information of IP address + network segment identifier. Thus, based on the matching of asset identification information, the unique identification of assets when the IP address ranges of multiple internal network segments overlap can be achieved.
[0072] Based on the above embodiments, in the method of obtaining multiple asset identification information, asset identification information can also be obtained from various collection devices deployed in the network, wherein the network segment identifier corresponding to the IP address in the asset identification information is added by the collection device.
[0073] In this implementation, the acquisition device has the ability to add network segment identifiers. For example, the range of network segments that the acquisition device can acquire can be pre-configured on the acquisition device. After the acquisition device acquires the IP address of the asset, it can also determine the network segment identifier corresponding to the IP address based on the network segment range to which the IP address belongs. Then, the corresponding network segment identifier is added to the IP address to generate asset identification information. Subsequently, the generated asset identification information can be sent to the identification device, or the identification device can actively acquire it.
[0074] In the above implementation process, network segment identifiers are added by the acquisition device, so that the identification device only needs to acquire asset identification information for identification, thereby improving identification efficiency.
[0075] Based on the above embodiments, since the asset identification information collected by different acquisition devices is limited, i.e., the collected asset identification information is not comprehensive, during identification, asset identification information belonging to the same asset may be identified as information of different assets. Therefore, to avoid this misidentification problem, conflict resolution can be performed for conflicting asset identifications. For example, if two different asset identification information belonging to different assets has been identified, and the current identification of these two different asset identification information belongs to the same asset, then a conflict resolution is performed on their identification results.
[0076] For example, in the historical identification results, there is asset identification information 1 corresponding to asset A and asset identification information 2 corresponding to asset B. These two asset identification information were collected by different acquisition devices. Subsequently, asset identification information 1 and asset identification information 2 were collected again by the same acquisition device (of course, this may not be just asset identification information 1 and asset identification information 2, but may include asset identification information 1 and / or asset identification information 2). And the acquisition device identifies these two asset identification information as the same asset, such as asset 2. Then, when performing asset identification at this time, there is an asset conflict.
[0077] When making conflict resolutions, one approach is to configure the identification device by default to believe that two different asset identification information belongs to the same asset with a higher degree of confidence. Therefore, the identification result that the two different asset identification information currently identified belong to the same asset can be directly used as the final identification result and saved. The remaining identification results are deleted from the historical identification results to facilitate subsequent identifications.
[0078] Alternatively, conflict resolution can be based on the number of identification results. For example, among the three identification results mentioned above, the currently obtained asset identification information (IP address + network segment identifier) is matched with the historical identification results to find two identification results. At this time, one of these two identification results is identified as asset 1, and the other is identified as asset 2. The current identification result is asset 2. At this time, there are two identification results that are both asset 2, while there is only one identification result for asset 1. According to the majority voting rule, the identification result that identifies asset 2 is taken as the final identification result.
[0079] Alternatively, these three identification results can be output to the administrator, who can then make a manual judgment on them, and the result obtained from the manual judgment can be stored as the final identification result.
[0080] Based on the above embodiments, in order to achieve rapid asset identification, after obtaining asset identification information, a hash value can be generated from the asset identification information. Then, it is searched from the historical identification results to see if there is a hash value with the same hash value. If there is, the asset is directly merged and identified, that is, merged into the identified assets. If not, it is considered a new asset, and it is identified as a new asset and stored in the historical identification results.
[0081] Based on the above embodiments, in the method of obtaining multiple asset identification information, multiple asset identification information can also be obtained from a constructed first information queue. Specifically, newly collected asset identification information is obtained from various collection devices deployed in the network and stored in the first information queue. After asset identification is performed using the multiple asset identification information, the multiple asset identification information can be stored in a constructed second information queue.
[0082] Understandably, the first information queue here can refer to the queue used to store newly acquired asset identification information, and the second information queue can refer to the queue used to store historical asset identification information. Since assets in the network are not necessarily changing in real time, if asset identification information of all assets in the network is periodically acquired for identification, there may be a problem that multiple asset identification information obtained may overlap with previously acquired asset identification information. Therefore, two information queues can be used to store newly acquired asset identification information and previously acquired asset identification information respectively.
[0083] To avoid duplicate identification, the newly acquired asset identification information from each acquisition device can be stored in the first information queue. Then, multiple asset identification information can be retrieved from the first information queue for identification. This avoids the problem of the identification device having to re-identify all the acquired asset identification information each time.
[0084] Furthermore, to further improve recognition efficiency, multiple asset identification information can be obtained from the first information queue, and then compared with the asset identification information in the second information queue. Identical asset identification information is filtered out, and then the remaining asset identification information that is different from the asset identification information in the second information queue is identified. This can effectively reduce the problem of repeated identification of the same asset identification information.
[0085] In the above implementation process, new asset identification information and historical asset identification information are stored in two information queues respectively. This avoids the problem of repeatedly identifying the same asset identification information and wasting resources.
[0086] Based on the above embodiments, in order to improve the efficiency of asset identification information collection, asset scanning tasks can also be obtained from the task queue. The asset scanning task includes a scanning network segment range. Then, in response to the execution of the asset scanning task, the asset scanning task is sent to the collection device within the corresponding scanning network segment range to instruct the collection device to collect asset identification information within the corresponding network segment.
[0087] Since assets in the network do not change constantly, and new assets may only be added after a certain period of time, the identification device does not need to instruct the acquisition device to collect comprehensive asset identification information in real time, thus avoiding wasting resources. Therefore, a task queue can be set up, storing multiple asset scanning tasks. Each asset scanning task can correspond to a different scanning network segment. The identification device can periodically retrieve an asset scanning task from the task queue to execute. The identification device is configured with corresponding scanning network segments for each acquisition device. After retrieving an asset scanning task from the task queue, the identification device can find the corresponding acquisition device based on the scanning network segment range of the asset scanning task, and then issue the asset scanning task to the corresponding acquisition device, instructing it to collect asset identification information within its scanning network segment range, i.e., to obtain the asset identification information of the assets within its scanning network segment range. After obtaining the asset information, the identification device performs asset identification, and then retrieves the next asset scanning task from the task queue after a period of time. This asynchronous identification and scanning of assets in the network effectively reduces the problem of repeatedly acquiring the same asset identification information, resulting in faster scanning speed and higher accuracy.
[0088] Alternatively, the identification device can acquire asset scanning tasks from the task queue separately and then execute each asset scanning task. In this case, each asset scanning task is assigned to a different acquisition device, and each task is executed independently without affecting the others, which can also improve the efficiency of asset identification information acquisition.
[0089] In other implementations, since the identification device is configured with the network segment range that each acquisition device can collect, the asset scanning task mentioned above can include the scanning target, that is, the scanning target refers to the acquisition device. In this way, the identification device can directly determine the corresponding acquisition device based on the asset scanning task, and then send the scanning task to the acquisition device.
[0090] In the above implementation process, asset scanning tasks are obtained from the task queue. This allows asset scanning tasks to be sent to collection devices in different network segments each time. In this way, the asset identification information can be obtained asynchronously through the task queue, which improves the efficiency of information acquisition.
[0091] In some implementations, in the process of acquiring multiple asset identification information, the identification device may also periodically send asset detection messages to the acquisition device, which are used to instruct the acquisition device to collect asset identification information.
[0092] In other words, the data acquisition device does not actively collect asset identification information. It only scans the assets to obtain asset identification information after receiving an asset detection message from the identification device.
[0093] Of course, the data acquisition device can also periodically trigger asset scans to obtain asset identification information and then send it to the identification device.
[0094] Based on the above embodiments, after asset identification based on multiple asset identification information, in order to quickly identify assets in the future, profiles can be created for these identified assets, that is, a knowledge graph of these assets can be constructed, which includes the assets and the corresponding asset identification information. In this way, when identifying assets in the future, the obtained asset identification information can be compared with the asset identification information of each node in the knowledge graph, thus effectively improving the efficiency of asset identification.
[0095] Furthermore, after constructing a knowledge graph of assets, it is convenient to directly sort out assets based on the knowledge graph, such as to count assets, find new assets, and find the distribution of assets, which facilitates the effective management of assets in the network.
[0096] Please refer to Figure 4 , Figure 4 This is a structural block diagram of an asset identification device 200 provided in an embodiment of this application. The device 200 may be a module, program segment, or code on an electronic device. It should be understood that this device 200 is similar to the one described above. Figure 1 The method implementation corresponds to this and can be executed. Figure 1 The various steps involved in the method embodiment and the specific functions of the device 200 can be found in the description above. To avoid repetition, detailed descriptions are omitted here.
[0097] Optionally, the device 200 includes:
[0098] The information acquisition module 210 is used to acquire multiple asset identification information, wherein each asset identification information includes an IP address and the network segment identifier corresponding to the IP address;
[0099] The asset identification module 220 is used to identify assets in the network based on the IP address and the network segment identifier corresponding to the IP address in the plurality of asset identification information.
[0100] Optionally, the asset identification information further includes asset information. The asset identification module 220 is used to determine that the assets corresponding to the at least two asset identification information are the same asset if at least two of the multiple asset identification information have different IP addresses and network segment identifiers corresponding to the IP addresses, but the asset information is the same.
[0101] Optionally, the asset identification module 220 is configured to determine that the assets corresponding to the at least two asset identification information are the same asset if at least two of the multiple asset identification information have the same IP address and the network segment identifier corresponding to the IP address.
[0102] Optionally, the information acquisition module 210 is used to acquire the IP addresses of the assets collected by each acquisition device deployed in the network; determine the network segment identifier configured for each acquisition device, each network segment identifier corresponding to a preset IP address network segment; and generate corresponding asset identification information based on the IP address and the corresponding network segment identifier.
[0103] Optionally, the information acquisition module 210 is used to acquire asset identification information from various acquisition devices deployed in the network, wherein the network segment identifier corresponding to the IP address in the asset identification information is added by the acquisition device.
[0104] Optionally, the asset identification module 220 is further configured to make a conflict determination on the identification results when two different asset identification information has been identified as belonging to different assets and the two different asset identification information are currently identified as belonging to the same asset.
[0105] Optionally, the asset identification module 220 is further configured to use the identification result that the two different asset identification information currently identified belong to the same asset as the final identification result.
[0106] It should be noted that those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0107] Please refer to Figure 5 , Figure 5 This is a schematic diagram of an electronic device for performing an asset identification method, provided in an embodiment of this application. The electronic device may include: at least one processor 310, such as a CPU; at least one communication interface 320; at least one memory 330; and at least one communication bus 340. The communication bus 340 is used to enable direct communication between these components. In this embodiment, the communication interface 320 is used for signaling or data communication with other node devices. The memory 330 may be a high-speed RAM or a non-volatile memory, such as at least one disk storage device. Optionally, the memory 330 may also be at least one storage device located remotely from the aforementioned processor. The memory 330 stores computer-readable instructions. When these computer-readable instructions are executed by the processor 310, the electronic device performs the aforementioned... Figure 1 The method and process are shown.
[0108] Understandable. Figure 5 The structure shown is for illustrative purposes only; the electronic device may also include components that are more advanced than those shown. Figure 5 The more or fewer components shown, or having the same Figure 5 The different configurations shown. Figure 5 The components shown can be implemented using hardware, software, or a combination thereof.
[0109] This application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, performs the following... Figure 1 The method process executed by the electronic device in the illustrated method embodiment.
[0110] This embodiment discloses a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, and when the program instructions are executed by a computer, the computer can perform the methods provided in the above-described method embodiments, such as including:
[0111] Obtain multiple asset identification information, wherein each asset identification information includes an IP address and the network segment identifier corresponding to the IP address;
[0112] Assets in the network are identified based on the IP address and the network segment identifier corresponding to the IP address in the multiple asset identification information.
[0113] In summary, the embodiments of this application provide an asset identification method, apparatus, electronic device, and storage medium. The method identifies assets in a network based on the IP address in the asset identification information and the network segment identifier corresponding to the IP address. Thus, in scenarios where IP addresses overlap under different network segments, this method can be used to accurately identify assets.
[0114] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.
[0115] Furthermore, the units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0116] Furthermore, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0117] In this document, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, without necessarily requiring or implying any such actual relationship or order between these entities or operations.
[0118] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. An asset identification method, characterized in that, The method includes: Obtain multiple asset identification information, wherein each asset identification information includes an IP address and the network segment identifier corresponding to the IP address; Assets in the network are identified based on the IP address and the network segment identifier corresponding to the IP address in the multiple asset identification information. The asset identification information further includes asset information. The step of identifying assets in the network based on the IP address and the network segment identifier corresponding to that IP address from the plurality of asset identification information includes: If at least two of the multiple asset identification information have different IP addresses and network segment identifiers corresponding to those IP addresses, but the asset information is the same, then the assets corresponding to the at least two asset identification information are determined to be the same asset, wherein the asset information is attribute information used to characterize the uniqueness of the asset; If at least two of the multiple asset identification information entries contain the same IP address and the network segment identifier corresponding to that IP address, then the assets corresponding to the at least two asset identification information entries are determined to be the same asset. If two different asset identification information have been identified as belonging to different assets, and the two different asset identification information are currently identified as belonging to the same asset, the identification result that the two different asset identification information belong to the same asset shall be taken as the final identification result. The acquisition of multiple asset identification information includes: Multiple asset identification information is obtained from the constructed first information queue, wherein newly acquired asset identification information is obtained from various acquisition devices deployed in the network and stored in the first information queue; The multiple asset identification information is compared with the asset identification information in the second information queue, and the same asset identification information is filtered out to obtain the remaining asset identification information that is different from the asset identification information in the second information queue. The second information queue is used to store historically processed asset identification information.
2. The method according to claim 1, characterized in that, The acquisition of multiple asset identification information includes: Obtain the IP addresses of the assets collected by each collection device deployed in the network; Each of the aforementioned acquisition devices is assigned a network segment identifier, and each network segment identifier corresponds to a preset IP address network segment. Based on the IP address and the corresponding network segment identifier, generate corresponding asset identification information.
3. The method according to claim 1, characterized in that, The acquisition of multiple asset identification information includes: Asset identification information is obtained from various acquisition devices deployed in the network, wherein the network segment identifier corresponding to the IP address in the asset identification information is added by the acquisition device.
4. An asset identification device, characterized in that, The device includes: The information acquisition module is used to acquire multiple asset identification information, wherein each asset identification information includes an IP address and the network segment identifier corresponding to the IP address; The asset identification module is used to identify assets in the network based on the IP address and the network segment identifier corresponding to the IP address in the multiple asset identification information. The asset identification information further includes asset information. Specifically, the asset identification module is used to determine that the assets corresponding to at least two of the multiple asset identification information are the same asset if at least two of the asset identification information have different IP addresses and corresponding network segment identifiers, but the asset information is the same. The asset information is attribute information representing the uniqueness of the asset. If at least two of the multiple asset identification information have the same IP address and corresponding network segment identifier, the assets corresponding to at least two of the asset identification information are the same asset. If two different asset identification information belonging to different assets have been identified, and the current identification of the two different asset identification information belonging to the same asset is used as the final identification result, the identification result of the two different asset identification information belonging to the same asset is taken as the final identification result. Specifically, the information acquisition module is used to acquire multiple asset identification information from a constructed first information queue. Specifically, newly acquired asset identification information is acquired from various acquisition devices deployed in the network and stored in the first information queue. The multiple asset identification information is compared with the asset identification information in a second information queue, and identical asset identification information is filtered out to obtain the remaining asset identification information that is different from the asset identification information in the second information queue. The second information queue is used to store historically processed asset identification information.
5. An electronic device, characterized in that, It includes a processor and a memory, the memory storing computer-readable instructions that, when executed by the processor, perform the method as described in any one of claims 1-3.
6. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it performs the method as described in any one of claims 1-3.
Citation Information
Patent Citations
Asset identification method and device
CN110535727A
Asset management method, device and system, computer equipment and readable storage medium
CN110544018A
Network asset management method and device based on multiple local area networks, and readable storage medium
CN115796440A