An asset detection method based on multi-node collaboration
By adopting a multi-node collaboration strategy in asset detection, we ensure that each port is detected by different detection execution units, and the detection results are analyzed and processed through the decision subsystem, the problem of inaccurate asset detection results under the high security protection mechanism is solved, and more accurate and comprehensive asset detection results are achieved.
Patent Information
- Application Number
- CN202410686783.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-30
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-05-30
AI Technical Summary
The existing asset detection methods do not consider the evasion of the security protection mechanism, resulting in inaccurate asset detection results under the high security protection mechanism and no other ports are effectively detected.
The asset detection method based on multi-node collaboration is adopted. The scheduling subsystem issues resource application tasks according to the scheduling detection strategy, the detection execution subsystem applies for relevant resources and generates a detection execution unit. The multi-node collaboration strategy is used to generate detection tasks to ensure that each port is detected by different detection execution units. The detection results are analyzed and processed by the decision subsystem to output a unique decision result.
It improves the detection accuracy and comprehensiveness of high-security assets, avoids the detection execution unit being misjudged as a network attack and being blacklisted, and extends the service life and effectiveness of node resources.
Smart Images

Figure CN118677651B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security, and particularly relates to an asset detection method based on multi-node collaboration. Background Art
[0002] Currently, the asset detection strategy is multi-engine segmented detection. Each engine is responsible for detecting an address segment, that is, the address range is allocated based on the IP address. Within the same address range, the same engine performs concurrent detection, and the detection results usually come from the same engine without verification. For example, for different engine asset detection address range allocation, Engine 1: 28.21*.*, Engine 2: 28.22*.*, Engine 3: 28.23*.*.
[0003] Some asset security protection mechanisms are relatively high. High-frequency detection behaviors may be misidentified as network attack behaviors. When detecting such assets, if the same IP address and the same engine detect such assets, the asset detection is inaccurate, incomplete, or even false information may appear. For example, if the same IP address performs port scanning three or more times on its own different ports and the IP address is not in the whitelist, the subsequent access of the IP address is blocked, and the IP address is placed in a temporary blacklist. Usually, it can access the asset ports and services again after 6 - 12 hours. In this case, the subsequent port detection results for this asset will be incorrect and inaccurate.
[0004] Currently, the asset detection process mechanism has the following problems: First, asset detection does not consider avoiding security protection mechanisms. All asset detections use the same mechanism and strategy, resulting in only limited ports being detected under high security protection mechanisms, and the detection results of other ports are not effectively detected; Second, when detecting multiple ports and multiple services of the same asset, using the same node, the same engine, the same proxy, and the same IP address easily triggers the asset security protection mechanism, resulting in inaccurate asset detection results under high security protection mechanisms; Third, the asset detection results are not verified using the detection results of multiple nodes, resulting in a high false alarm rate for high security protection node detection results. Summary of the Invention
[0005] (1) Technical Problems to be Solved
[0006] The technical problem to be solved by the present invention is how to provide an asset detection method based on multi-node collaboration to solve problems such as asset detection not considering avoiding security protection mechanisms and inaccurate asset detection results under high security protection mechanisms.
[0007] (2) Technical Solutions
[0008] To solve the above technical problems, the present invention proposes an asset detection method based on multi-node collaboration, and the method includes the following steps:
[0009] S1. The scheduling subsystem issues a resource application task according to the scheduling detection strategy;
[0010] S2. The detection execution subsystem receives the resource application task of the scheduling subsystem. After determining that the system meets the requirements of the resource application task, it applies for relevant resources from the IP resource pool, proxy resource pool, and engine resource pool. After the application is successful, it generates a detection execution unit entity and returns a resource creation success response to the scheduling subsystem;
[0011] S3. After receiving the resource creation success response from the detection execution subsystem, the scheduling subsystem adopts a multi-node collaboration strategy to generate a detection task and issue it to the detection execution subsystem. The detection task includes multiple subtasks;
[0012] S4. After receiving the detection task from the scheduling subsystem, the detection execution subsystem, according to the detection task, uses different detection execution units to detect each port of the same resource to be tested, and at the same time uses multiple detection execution units to detect each port. After the detection results are returned, they are uniformly sent to the decision-making subsystem;
[0013] S5. The decision-making subsystem analyzes and processes multiple detection results for the same resource and the same port according to the detection results of the detection execution subsystem, outputs a unique detection decision result, and sends it to the storage subsystem to implement the storage of the detection results.
[0014] (III) Beneficial Effects
[0015] The present invention proposes an asset detection method based on multi-node collaboration. The beneficial effects of the present invention are as follows:
[0016] 1. Asset detection method with a high security level.
[0017] 2. The asset (high security level) detection results are more accurate and comprehensive.
[0018] 3. Improve the service life and effectiveness of node resources (IP addresses, detection engines, detection proxies). Description of the Drawings
[0019] Figure 1 It is an architecture diagram of the multi-node collaboration asset detection method provided by the technical solution of the present invention. Detailed Embodiment
[0020] To make the objectives, content, and advantages of the present invention clearer, the following further describes the detailed embodiments of the present invention in conjunction with the drawings and embodiments.
[0021] The present invention provides an asset detection method based on multi-node collaboration. Through multi-node collaborative detection, problems such as the asset detection not considering the avoidance of security protection mechanisms and inaccurate asset detection results for assets with high security protection mechanisms are solved, and the asset detection accuracy of high-security protection nodes is effectively improved.
[0022] To achieve the above object, the present invention provides an asset detection method based on multi-node collaboration, including:
[0023] Based on multi-node collaborative detection, an IP address resource pool, a proxy resource pool, and an engine resource pool are adopted to avoid triggering the security mechanism of assets (high security level), prevent the detection execution unit from being blacklisted, and ensure the effectiveness of the entire detection result.
[0024] Based on multi-node collaborative detection, multiple results are detected and output for the same asset and the same port / service, and the decision tree algorithm is used for auxiliary decision-making to improve the asset detection accuracy.
[0025] The present invention provides an asset detection method based on multi-node collaboration. The method includes the following steps:
[0026] S1. The scheduling subsystem issues a resource application task according to the scheduling detection strategy;
[0027] S2. The detection execution subsystem receives the resource application task of the scheduling subsystem. After determining that the system meets the resource application task requirements, it applies for relevant resources from the IP resource pool, the proxy resource pool, and the engine resource pool. After the application is successful, it generates a detection execution unit entity and returns a resource creation success response to the scheduling subsystem;
[0028] S3. After receiving the resource creation success response from the detection execution subsystem, the scheduling subsystem adopts a multi-node collaboration strategy to generate a detection task and issue it to the detection execution subsystem. The detection task includes multiple subtasks;
[0029] S4. After receiving the detection task from the scheduling subsystem, the detection execution subsystem, according to the detection task, uses different detection execution units to detect each port of the same resource to be measured, and at the same time uses multiple detection execution units to detect each port. After the detection results are returned, they are uniformly sent to the decision-making subsystem;
[0030] S5. The decision-making subsystem analyzes and processes multiple detection results for the same resource and the same port according to the detection results of the detection execution subsystem, outputs a unique detection decision result, and sends it to the storage subsystem to realize the storage of the detection results.
[0031] Embodiment 1:
[0032] The present invention provides an asset detection method based on multi-node collaboration, which is designed and written in strict accordance with the national standards for computer information system security and relevant industry standards.
[0033] As Figure 1 shown, the multi-node collaborative asset detection method and process architecture of the embodiment of the present invention are executed according to the following process:
[0034] S1. The scheduling subsystem issues a resource application task according to the scheduling detection strategy. The resource application task includes the detection address space, the number of detection execution units, the number of IP address resources used by the detection execution units, the type of proxy used for detection and the number of proxy resources, the type of engine used for detection and the number of engines.
[0035] S2. The detection execution subsystem receives the resource application task of the scheduling subsystem. After determining that the system meets the task resource application requirements, it applies for relevant resources from the IP resource pool, the proxy resource pool, and the engine resource pool. After the application is successful, it generates a detection execution unit entity and returns a resource creation success response to the scheduling subsystem.
[0036] S3. After receiving the resource creation success response from the detection execution subsystem, the scheduling subsystem adopts the following multi-node collaboration strategies, including using different detection execution units for different ports of the asset, using multiple detection execution units for one port, using different IP addresses for the detection execution units, using different detection proxies for the detection execution units, using different detection engines for the detection execution units, and randomizing the detection execution intervals, etc. The scheduling subsystem generates a detection task and issues it to the detection execution subsystem. The detection task includes multiple subtasks, and the subtask format includes: detection execution unit, resource address, resource port, resource service, IP address used for detection, detection proxy, detection engine.
[0037] S4. After receiving the detection task from the scheduling subsystem, the detection execution subsystem, according to the detection task, uses different detection execution units (customized different IP addresses, detection proxies and detection engines) to detect each port of the same resource to be measured. At the same time, multiple detection execution units (to verify the correctness of the detection results) are used to detect each port. After the detection results are returned, they are uniformly sent to the decision-making subsystem.
[0038] S5. The decision-making subsystem analyzes and processes multiple detection results for the same resource and the same port according to the detection results of the detection execution subsystem, makes an auxiliary decision based on the majority voting algorithm or the decision tree algorithm, outputs a unique detection decision result, and sends it to the storage subsystem to realize the storage of the detection results.
[0039] Embodiment 2:
[0040] An asset detection method based on multi-node collaboration, including: The multi-node collaborative asset detection system includes: an application layer, an intermediate layer, and a resource layer. Based on multi-node collaborative detection, it effectively improves the effectiveness of asset detection results and the accuracy of asset detection for high-security protection nodes.
[0041] Further, the application layer of the multi-node collaborative asset detection includes a scheduling subsystem and a decision-making subsystem.
[0042] Further, the intermediate layer of the multi-node collaborative asset detection includes a detection execution subsystem and a storage subsystem.
[0043] Further, the resource layer of the multi-node collaborative asset detection includes an IP resource pool, a proxy resource pool, and an engine resource pool.
[0044] Further, for the high-security protection nodes in the asset detection method based on multi-node collaboration, by reasonably scheduling the IP address resource pool, proxy resource pool, and engine resource pool, different IP addresses, different network proxies, and different engines are used to detect each port and service of the detection target, preventing the detection execution unit from being blacklisted due to triggering the asset security protection mechanism and ensuring the effectiveness of the detection results.
[0045] Further, for the high-security protection nodes in the asset detection method based on multi-node collaboration, multiple nodes are used to jointly detect each port and service of the detection target. Multiple results are output for the same asset and the same port / service detection. The decision tree algorithm is used for auxiliary decision-making to improve the accuracy of asset detection.
[0046] The beneficial effects of the present invention are as follows:
[0047] 1. A method for detecting assets with a high security level.
[0048] 2. The detection results of assets (with a high security level) are more accurate and comprehensive.
[0049] 3. Improve the service life and effectiveness of node resources (IP addresses, detection engines, detection proxies).
[0050] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and deformations can be made, and these improvements and deformations should also be regarded as the protection scope of the present invention.
Claims
1. An asset detection method based on multi-node collaboration, characterized in that: The method comprises the following steps: S1, the scheduling subsystem issues resource application tasks based on the scheduling detection strategy; S2. The detection execution subsystem receives the resource application task from the scheduling subsystem. After determining that the system meets the resource application task requirements, it applies for relevant resources from the IP resource pool, proxy resource pool, and engine resource pool. After the application is successful, the detection execution unit entity is generated and a successful resource creation response is returned to the scheduling subsystem. S3. After receiving the successful response of resource creation from the detection execution subsystem, the scheduling subsystem adopts a multi-node coordination strategy to generate a detection task and sends it to the detection execution subsystem. The detection task includes multiple subtasks. S4, after the detection execution subsystem receives the detection task from the scheduling subsystem, it uses different detection execution units to detect each port of the same resource to be tested according to the detection task, and uses multiple detection execution units to detect each port. After the detection results are returned, they are uniformly sent to the decision subsystem; S5. The decision subsystem analyzes and processes multiple detection results of the same resource and the same port based on the detection results of the detection execution subsystem, outputs a unique detection decision result, and sends it to the storage subsystem to store the detection results; in, For high-security protection nodes, by reasonably scheduling the IP address resource pool, proxy resource pool and engine resource pool, different IP addresses, different network proxies and different engines are used to detect each port and service of the detection target to prevent the detection execution unit from being blacklisted due to the triggering of asset security protection mechanism, thus ensuring the validity of the detection results; For high-security protection nodes, multiple nodes are used to jointly detect each port and service of the detection target. Multiple results are output for the same asset and the same port / service detection. The decision tree algorithm is used to assist decision-making and improve the accuracy of asset detection. The multi-node collaboration strategy in S3 includes: using different detection execution units for different ports of assets, using multiple detection execution units for one port, using different IP addresses for detection execution units, using different detection agents for detection execution units, using different detection engines for detection execution units, and randomizing detection execution intervals.
2. The asset detection method based on multi-node collaboration as claimed in claim 1, characterized in that: The method is based on a multi-node collaborative asset detection system, which includes: an application layer, an intermediate layer and a resource layer. The application layer includes a scheduling subsystem and a decision-making subsystem, the intermediate layer includes a detection execution subsystem and a storage subsystem, and the resource layer includes an IP resource pool, an agent resource pool and an engine resource pool.
3. The asset detection method based on multi-node collaboration as claimed in claim 2, characterized in that: Resource application tasks include: detecting address space, detecting the number of execution units, detecting the number of IP address resources used by the execution unit, detecting the type of proxy used and the number of proxy resources used, and detecting the type of engine used and the number of engines used.
4. The asset detection method based on multi-node collaboration as claimed in claim 3, characterized in that: The subtask format in S3 includes: detection execution unit, resource address, resource port, resource service, detection IP address, detection agent and detection engine.
5. The asset detection method based on multi-node collaboration as claimed in claim 3, characterized in that: In S4, different IP addresses, detection agents and detection engines customized by different detection execution units are used to detect each port of the same resource to be tested, and multiple detection execution units are used to verify the correctness of the detection result for each port.
6. The asset detection method based on multi-node collaboration as claimed in claim 3, characterized in that: In S5, auxiliary decision making is performed according to the majority voting algorithm, and a unique detection decision result is output.
7. The asset detection method based on multi-node collaboration as claimed in claim 3, characterized in that: In S5, a decision tree algorithm is used to assist decision making and a unique detection decision result is output.
Citation Information
Patent Citations
Port service detection method, device and equipment and computer readable storage medium
CN114826635A
Intelligent vulnerability mining method and device based on decision tree and storage medium
CN115733686A
Distributed port resource detection method and device, equipment and storage medium
CN117097533A