IP asset management methods and apparatus, non-volatile storage media, electronic devices

By parsing the switch's ARP table to generate an IP asset management table and binding it to MAC addresses, and monitoring IP asset state transitions, the problem of IP asset state changes not being dynamically monitored in enterprise networks is solved, improving processing efficiency and management automation.

CN118677871BActive Publication Date: 2026-03-10CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-05
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing technologies fail to effectively monitor changes in the status of IP assets in enterprise networks, resulting in low processing efficiency, inability to detect new terminals coming online or old terminals going offline in a timely manner, and inability to achieve dynamic management and automated control of IP assets.

Method used

By obtaining the ARP table of the switches in the local area network, an IP asset management table is generated, binding IP addresses and MAC addresses, determining state transitions based on ARP packets, generating an IP asset state transition table, and managing it through audit results, thereby achieving dynamic monitoring and management of IP asset status.

Benefits of technology

It enables real-time, comprehensive detection and dynamic monitoring of the status of IP assets in the enterprise network, improves the processing efficiency of IP assets, and ensures timely response and automated management of changes in the status of IP assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118677871B_ABST
    Figure CN118677871B_ABST
Patent Text Reader

Abstract

This application discloses an IP asset management method and apparatus, a non-volatile storage medium, and an electronic device. The method includes: obtaining the Address Resolution Protocol (ARP) table of a switch within a local area network (LAN), and generating an IP asset management table based on the target set in the ARP table; binding IP addresses to corresponding MAC addresses based on their status and attributes; determining IP addresses experiencing state transitions based on ARP packets within the LAN, and generating an IP asset state transition table based on these state transitions; displaying the IP asset state transition table, receiving the audit results of the table, and managing the IP addresses based on the audit results and transition statuses. This application solves the technical problem of low efficiency in IP asset processing caused by the lack of dynamic monitoring of IP asset state changes in related technologies for enterprise networks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and more specifically, to an IP asset management method and apparatus, a non-volatile storage medium, and an electronic device. Background Technology

[0002] With the outbreak of various cybersecurity issues in recent years, cybersecurity vulnerabilities have emerged one after another, making it impossible for anyone to guarantee that application systems are free of vulnerabilities. Security professionals have gradually realized that the most effective way to protect cybersecurity is to minimize the number of Internet Protocol (IP) addresses exposed on the network. Therefore, the management of IP assets on the network is receiving increasing attention. Only with accurate network IP assets can cybersecurity protection be targeted and effective.

[0003] For enterprises to effectively manage IP assets, a prerequisite is a clear understanding of their internal assets, the ability to map all assets within their network, and the implementation of effective measures to control network assets that are joining, leaving, or experiencing anomalies, preventing security risks caused by unknown assets. Therefore, for enterprises, accurate asset mapping and management within their local area network (LAN) is a crucial prerequisite for effective network security. The relationship between network IP asset management and network security is as follows: Figure 1 As shown.

[0004] like Figure 1 If asset management is chaotic, unmanaged assets will be in an uncontrollable state, making them vulnerable to hacker attacks. If breached, this can lead to serious consequences for the company, such as business paralysis, network outages, and information leaks.

[0005] Currently, the main problems faced in enterprise network IP asset detection and management include: 1. Disorganized management of internal network devices; 2. Low timeliness of proactive IP asset reporting; 3. Unauthorized connections and concealment within the enterprise; 4. Lack of effective automated means to manage IP assets and update their status. These four problems lead to an uncontrollable state of IP assets within the enterprise network, exposing it to more uncontrollable risks and triggering unknown network security issues.

[0006] To address the aforementioned issues, after network asset mapping, comprehensive asset management is implemented to identify all assets. Then, full security control is carried out, ultimately enabling enterprises to manage assets legally and compliantly while avoiding hidden security risks.

[0007] Traditional asset detection and discovery methods primarily focus on active scanning, and many manufacturers have been continuously improving scanning mechanisms to enhance scanning efficiency. However, regardless of these improvements, for assets with system firewalls enabled, the scanner's IP address may lack the necessary permissions to access the asset, often resulting in scanning methods failing to detect the existence of some assets.

[0008] Later, methods using traffic analysis for IP asset discovery emerged. Traffic analysis provides network link traffic storage and full data analysis capabilities. By analyzing all traffic within the local area network (LAN), administrators can capture and identify data packets related to various IP assets, thus identifying the IP addresses that actively send data packets. Using traffic analysis for IP asset discovery effectively solves the problem of scanners being unable to access unknown assets; as long as an IP asset sends data packets outward, it can be captured by traffic analysis. However, this method is a passive analysis method, and its efficiency is somewhat lower for discovering silent assets that do not send out traffic.

[0009] In addition to the above, there is another method for asset discovery: collecting the Address Resolution Protocol (ARP) tables of all switches in the network. This method obtains a relatively accurate mapping between IP addresses and Media Access Control (MAC) addresses. However, because ARP tables have an aging period, ARP entries that exceed the aging period are deleted. Furthermore, when the terminals accessing the network frequently change, the mapping between IP addresses and MAC addresses becomes uncertain, potentially leading to omissions in asset discovery. Therefore, a long-term monitoring process is needed to improve the accuracy of asset discovery.

[0010] The advantages and disadvantages of traditional asset discovery technologies are shown in the table below.

[0011]

[0012] In the asset mapping phase, related technologies all employ one or more of the three methods mentioned above, achieving good accuracy through optimization by adding appropriate preprocessing methods. However, these technologies do not propose methods for dynamically monitoring changes in IP asset status, such as changes from online to prolonged offline or vice versa. Furthermore, the proposed management methods for addressing IP asset status changes fail to provide dynamic handling and management of IP assets, including security-related access control measures such as blocking unmanaged assets or automatically unblocking assets upon their return to online status. In other words, these technologies do not provide dynamic monitoring of IP asset status changes within enterprise networks, nor do they propose methods for doing so. Summary of the Invention

[0013] This application provides an IP asset management method and apparatus, a non-volatile storage medium, and an electronic device to at least solve the technical problem of low processing efficiency of IP assets caused by the lack of dynamic monitoring of IP asset status changes in related technologies for enterprise networks.

[0014] According to one aspect of the embodiments of this application, an IP asset management method is provided, comprising: obtaining the Address Resolution Protocol (ARP) table of a switch within a local area network (LAN), and generating an IP asset management table based on a target set in the ARP table, wherein the target set includes at least: Internet Protocol (IP) addresses managed by the switch, Media Access Control (MAC) addresses, and the correspondence between IP addresses and MAC addresses; the IP asset management table includes: the target set, the status of IP addresses, the attributes of IP addresses, and the IP addresses of the switch, wherein the status of the IP addresses includes at least: occupied and unoccupied, and the attributes of the IP addresses include at least: service address; and generating an IP asset management table based on the status of the IP addresses and the IP addresses managed by the switch. The IP address attributes bind IP addresses to corresponding MAC addresses; based on ARP packets within the local area network, it determines the IP address whose state has changed, and generates an IP asset state transition table based on the IP address's state transition status. This table includes at least: the IP address, the MAC address before the state change, the MAC address after the state change, and the transition status, which includes: new terminal online and old terminal offline. The system displays the IP asset state transition table, receives the review results, and manages the IP addresses based on the review results and transition status.

[0015] Optionally, obtaining the Address Resolution Protocol (ARP) table of the switches within the local area network includes: setting a first time window, wherein the length of the first time window is proportional to the number of nodes in the local area network; setting n time intervals within the first time window, wherein the length of each time interval is less than the effective duration of the ARP cache, and n is a positive integer greater than 1; and traversing the ARP tables of the switches within the local area network according to the n time intervals to obtain n ARP tables.

[0016] Optionally, an IP asset management table is generated based on the target set in the ARP table, including: determining whether the time to traverse the ARP table of the switch has been reached based on n time intervals; if the time to traverse the ARP table of the switch has been reached, reading the switch information of the first switch from the switch database, wherein the first switch is any switch within the local area network; determining whether the switch information of the second switch can be read, wherein the second switch is any switch within the local area network other than the first switch; if the switch information of the second switch cannot be read, saving the target set in the ARP table of the first switch to the IP asset management table corresponding to the first switch; if the switch information of the second switch can be read, logging into the second switch based on a remote login protocol or a secure shell protocol, and using a first preset ARP command to view the ARP table of the second switch, saving the target set in the ARP table of the second switch to the IP asset management table corresponding to the second switch.

[0017] Optionally, the Address Resolution Protocol (ARP) table of the switches within the local area network (LAN) is obtained, and an IP asset management table is generated based on the target set in the ARP table, including: Step S1, setting a second time window and generating an initial IP asset management table; Step S2, determining whether the current time is within the second time window; Step S3, if the current time is within the second time window, traversing all switches within the LAN; Step S4, determining whether there are any switches that have not been traversed; Step S5, if there are any switches that have not been traversed, obtaining the network segment information of the switch under the Layer 3 interface, wherein the network segment information includes: IP address and subnet mask; determining the network address, gateway address, broadcast address, and service address of the switch based on the network segment information, wherein the service address is the IP address used by the switch for terminal devices; obtaining the mapping relationship between IP address and MAC address using a first preset ARP command; and determining the mapping relationship between IP address and MAC address and the switch based on the mapping relationship between IP address and MAC address. The network address, gateway address, broadcast address, and service address of the machine are used to update the initial IP asset management table, resulting in the IP asset management table. After obtaining the IP asset management table, step S4 is executed; step S6, if there are no untraversed switches, step S2 is executed; step S7, if the current time is not within the second time window, the first information corresponding to the first IP address is obtained, and the status of the first IP address is set to occupied in the IP asset management table. The first IP address is the IP address whose MAC address can be found based on the correspondence between IP address and MAC address. The first information includes: the department, the name of the person in charge, and the contact information of the person in charge corresponding to the first IP address; the status of the IP address corresponding to the second IP address is set to unoccupied in the IP asset management table. The second IP address is the IP address whose MAC address cannot be found based on the correspondence between IP address and MAC address.

[0018] Optionally, based on the IP address's status and attributes, the IP address is bound to the corresponding MAC address. This includes: reading the IP address's status in the IP asset management table; if the IP address's status is unoccupied, reading the IP address and switch IP address in the IP asset management table, logging into the switch using a first preset script based on the Secure Shell protocol, replacing the IP address with a first preset address, and replacing the MAC address corresponding to the IP address with a second preset address; if the IP address's status is occupied, searching for the IP address's attributes in the IP asset management table; if the IP address's attributes are network number, gateway address, or broadcast address, no operation is performed; if the IP address's attributes are service address, searching for the IP address, MAC address, and switch IP address in the IP asset management table, logging into the switch corresponding to the switch IP address using a first preset script based on the Secure Shell protocol, replacing the IP address with a third preset address, and replacing the MAC address corresponding to the IP address with a fourth preset address.

[0019] Optionally, based on the ARP packets within the local area network, the IP address whose state transition has occurred is determined, and an IP asset state transition table is generated based on the state transition status of the IP address, including: Step S1, generating an initial IP asset state transition table, generating an initial host traffic transmission record table, and setting a target duration for acquiring traffic data from the switch; Step S2, determining whether a stop monitoring signal has been received; Step S3, if no stop monitoring signal has been received, acquiring the switch's traffic data, and adding the source address and packet time information of each data packet in the traffic data to the initial host traffic transmission record table to obtain the host traffic transmission record table; Step S4, determining whether the duration of data recorded in the host traffic transmission record table is equal to the target duration; Step S5, if the duration of data recorded in the host traffic transmission record table is not equal to the target duration, determining whether the traffic data contains... Including ARP packets, if the traffic data includes ARP packets, obtain the source IP address and source MAC address of the ARP packets, use the source IP address as a lookup condition to search the IP asset management table, and find the first MAC address corresponding to the source IP address in the found IP asset management table; Step S6, determine whether the source MAC address and the first MAC address are the same; Step S7, if the source MAC address and the first MAC address are different, add the source IP address, the first MAC address, the switch IP address, and the IP address status in the IP asset management table as the first newly added horizontal cell group to the initial IP asset status transition table, and set the transition status to new terminal online in the first newly added horizontal cell group; Step S8, if the source MAC address and the first MAC address are the same, repeat steps S2 and S3.

[0020] Optionally, if the duration of data recorded in the host traffic transmission record table is equal to the target duration, the method further includes: searching for the target IP address in the IP asset management table, wherein the target IP address is an IP address that has not been recorded in the IP asset status transition table within the target duration and whose status is occupied; adding the target IP address, the target MAC address corresponding to the target IP address, the switch IP address, and the status of the IP address as a second newly added horizontal cell group to the IP asset status transition table, and setting the transition status to old terminal offline in the second newly added horizontal cell group.

[0021] Optionally, after obtaining the source IP address and source MAC address of the ARP packet, the method further includes: converting the source MAC address into first identification information; after searching for the first MAC address corresponding to the source IP address in the found IP asset management table, the method further includes: converting the first MAC address into second identification information; determining whether the source MAC address and the first MAC address are the same, including: determining whether the first identification information and the second identification information are the same; after setting the transfer status to new terminal online in the first newly added horizontal cell group, the method further includes: converting the first MAC address in the first newly added horizontal cell group into first identification information.

[0022] Optionally, IP addresses are managed based on the audit results and transfer status, including: for the first target IP address, logging into the switch corresponding to the first target IP address, unbinding the first target IP address from the MAC address before the status change, binding the first target IP address to the MAC address after the status change, and updating the information of the first target IP address in the IP asset management table, wherein the first target IP address is the IP address whose audit result is passed, whose IP address status is occupied, and whose transfer status is the IP address of a new terminal online.

[0023] Optionally, the IP address is managed according to the audit results and transfer status, including: for the second target IP address, logging into the switch corresponding to the second target IP address, unbinding the second target IP address from the MAC address before the status change, replacing the second target IP address with the fourth preset address, and updating the information of the second target IP address in the IP asset management table, wherein the second target IP address is the IP address whose audit result is passed, whose IP address status is occupied, and whose transfer status is the old terminal offline.

[0024] Optionally, IP addresses are managed based on the audit results and transfer status, including: for a third target IP address, logging into the switch corresponding to the third target IP address, replacing the third target IP address with the fifth preset address, binding the third target IP address with the MAC address whose status has changed, and updating the information of the third target IP address in the IP asset management table, wherein the third target IP address is an IP address whose audit result is passed, whose IP address status is unoccupied, and whose transfer status is an IP address where a new terminal is online.

[0025] According to another aspect of the embodiments of this application, an IP asset management device is also provided, comprising: a first generation module, configured to obtain the Address Resolution Protocol (ARP) table of a switch within a local area network (LAN), and generate an IP asset management table based on a target set in the ARP table, wherein the target set includes at least: Internet Protocol (IP) addresses managed by the switch, Media Access Control (MAC) addresses, and the correspondence between IP addresses and MAC addresses; the IP asset management table includes: the target set, the status of IP addresses, the attributes of IP addresses, and the IP addresses of the switch, wherein the status of the IP addresses includes at least: occupied and unoccupied, and the attributes of the IP addresses include at least: service address; and a binding module, configured to bind the IP assets based on the status of the IP addresses and the IP addresses in the LAN. The P-address attribute binds the IP address to the corresponding MAC address; the second generation module is used to determine the IP address whose state has changed based on ARP packets within the local area network, and generate an IP asset state transition table based on the state transition of the IP address. The IP asset state transition table includes at least: the IP address, the MAC address before the state change, the MAC address after the state change, and the transition status, which includes: new terminal online and old terminal offline; the processing module is used to display the IP asset state transition table, receive the review results of the IP asset state transition table, and manage the IP addresses based on the review results and the transition status.

[0026] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, the storage medium including a stored program, wherein the program controls the device where the storage medium is located to execute the above-described IP asset management method when it runs.

[0027] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory and a processor, wherein the processor is configured to run a program stored in the memory, wherein the program executes the above-described IP asset management method when it runs.

[0028] According to another aspect of the embodiments of this application, a computer program is also provided, wherein the computer program, when executed by a processor, implements the above-described IP asset management method.

[0029] According to another aspect of the embodiments of this application, a computer program product is also provided, the computer program product including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and the computer program implements the above-mentioned IP asset management method when executed by a processor.

[0030] In this embodiment, the Address Resolution Protocol (ARP) table of the switches within the local area network (LAN) is obtained, and an IP asset management table is generated based on the target set in the ARP table. The target set includes at least: Internet Protocol (IP) addresses managed by the switches, Media Access Control (MAC) addresses, and the mapping between IP addresses and MAC addresses. The IP asset management table includes: the target set, the status of the IP addresses, the attributes of the IP addresses, and the IP addresses of the switches. The IP address status includes at least: occupied and unoccupied, and the IP address attributes include at least: service address. Based on the IP address status and attributes, the IP addresses are bound to the corresponding MAC addresses. The status of the ARP packets within the LAN is determined. The system generates transferred IP addresses and, based on the IP address status transfer status, creates an IP asset status transfer table. This table includes at least the IP address, the MAC address before the status change, the MAC address after the status change, and the transfer status, which includes: new terminal online and old terminal offline. The system displays the IP asset status transfer table, receives the review results, and manages IP addresses based on the review results and transfer status. It also uses the switch's ARP table to comprehensively and in real-time detect and discover valid IP addresses in the LAN, obtain the liveness status of each IP asset in the LAN, and improve the IP asset information to construct an enterprise network IP asset management table. Then, network traffic analysis is continuously performed, and the status changes of IP assets are monitored in conjunction with the ARP table resolution results of the switch. Based on the IP asset status in the IP asset management table, responses are made to the status changes of IP assets, thereby achieving the goal of dynamic monitoring of IP asset status changes in the enterprise network. This improves the technical efficiency of IP asset processing and solves the technical problem of low IP asset processing efficiency caused by the lack of dynamic monitoring of IP asset status changes in the enterprise network. Attached Figure Description

[0031] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0032] Figure 1 This diagram illustrates the relationship between network asset management and network security.

[0033] Figure 2 This is a flowchart of an IP asset management method according to an embodiment of this application;

[0034] Figure 3 This is a deployment topology diagram of a server for analyzing mirrored traffic and analyzing switch information according to an embodiment of this application;

[0035] Figure 4 This is a flowchart illustrating the generation of an IP asset management table according to an embodiment of this application;

[0036] Figure 5 This is a flowchart illustrating another method for generating an IP asset management table according to an embodiment of this application;

[0037] Figure 6 This is a flowchart illustrating how to bind an IP address to a MAC address that corresponds to the IP address, according to an embodiment of this application.

[0038] Figure 7 This is a flowchart illustrating the generation of an IP asset state transition table according to an embodiment of this application;

[0039] Figure 8 This is a flowchart illustrating how to manage IP addresses based on review results and transfer status, according to an embodiment of this application.

[0040] Figure 9 This is a flowchart of another IP asset management method according to an embodiment of this application;

[0041] Figure 10 This is a schematic diagram of real-time traffic data collected from a DCN mirrored according to an embodiment of this application;

[0042] Figure 11 This is a schematic diagram illustrating information about a switch in a DCN that requires ARP table collection according to an embodiment of this application;

[0043] Figure 12 This is a schematic diagram of IP address segment information under a partial Layer 3 interface according to an embodiment of this application;

[0044] Figure 13 This is a schematic diagram of configuration information obtained after analyzing the Layer 3 interface of a DCN switch according to an embodiment of this application.

[0045] Figure 14 This is a schematic diagram of an IP asset management table in a system according to an embodiment of this application;

[0046] Figure 15 This is a schematic diagram of the ARP status of an IP asset queried by the system after a state locking operation has been performed, according to an embodiment of this application.

[0047] Figure 16 This is a schematic diagram illustrating the statistics of IP addresses with traffic sending records as viewed in the system, according to an embodiment of this application.

[0048] Figure 17 This is a schematic diagram illustrating the specific information of a filtered ARP message according to an embodiment of this application.

[0049] Figure 18 This is a schematic diagram of a state transition table for a portion of IP assets in a database, according to an embodiment of this application.

[0050] Figure 19 This is a schematic diagram of an IP asset status transition table after the processing of approved entries, according to an embodiment of this application;

[0051] Figure 20 This is a structural diagram of an IP asset management device according to an embodiment of this application;

[0052] Figure 21 This is a hardware structure block diagram of a computer terminal for an IP asset management method according to an embodiment of this application. Detailed Implementation

[0053] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0054] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0055] Currently, related technologies lack dynamic monitoring of IP asset status changes within enterprise networks, and no methods for dynamically monitoring IP asset status changes have been proposed. Therefore, there is a problem of low efficiency in processing IP assets.

[0056] Related Technology 1: A method, apparatus, electronic device, and storage medium for network asset detection. The method includes: after acquiring the network segment to be detected, constructing ARP packets with 802.1q protocol tags for the IP addresses in the network segment, and then sending them to a switch through a trunk port. The switch forwards the ARP detection packets to the network being detected and analyzes the IP addresses and MAC addresses in the feedback data to determine live device assets. This method, which uses ARP packets for IP asset detection, obtains relatively accurate IP and MAC address information. However, if there are many network segments, sending a large number of ARP packets may lead to network instability and affect the collection of feedback packets.

[0057] Related technology 2, a network asset monitoring method and a network asset monitoring device, proposes a network asset monitoring method that mainly focuses on whether there are significant changes in the service port data of network devices. It can monitor frequent changes in network assets, mainly including: scanning designated network assets to obtain network asset data, and then comparing and analyzing the network asset data with a preset network asset database and a preset asset statistical model to determine if network asset changes exist. This scheme detects network asset changes by comparing the scanned asset results with a preset network asset information database and asset statistical model. However, this scheme may suffer from inaccurate preset data, leading to limited effectiveness, and it only uses network scanning, a relatively inefficient method.

[0058] Related technology 3, a monitoring system and method for discovering live assets based on logging into switches, proposes a monitoring system for discovering live assets based on logging into switches. This system logs into core switches located within the core layer and access switches within the access layer, obtains their ARP table information, and compares it with known asset information to determine if the asset information has changed. This scheme obtains IP addresses and MAC addresses by checking the switch's ARP table, exhibiting good stability and accuracy. However, this scheme only categorizes asset status into online and offline assets, which does not fully reflect the dynamic nature of asset status and has certain limitations. Furthermore, monitoring assets only at the switch level cannot accurately obtain the dynamic changes of IP assets.

[0059] Related technology 4, network asset detection methods, devices, electronic devices, and storage media, provides a network asset detection method based on generating corresponding detection requests using multiple protocols to address the problem of low accuracy in network asset detection results due to network stability issues in related technologies. This scheme uses multiple protocols such as Network Control Message Protocol (NIC), Address Resolution Protocol (ARP), and Transmission Control Protocol (TCP) to detect network assets, improving accuracy through comprehensive judgment of multiple results. However, regardless of the protocol used, detection primarily relies on actively sending data packets for scanning. While simple to implement, this method is susceptible to network fluctuations and the actual state of the host during scanning, leading to potential omissions and failing to improve the accuracy of network asset detection.

[0060] Related technology 5, Static IP + ARP Configuration for Network Management, proposes a method for managing organizational networks using a combination of static IP and ARP configuration. This primarily addresses IP address theft within the organization by setting static IPs on terminals and binding IP and MAC addresses on the switch side. However, after binding IP and MAC addresses, the paper fails to dynamically analyze the status changes of the bound IP assets. It cannot promptly detect new terminal attempts to connect or the potential shutdown of older terminals. Furthermore, the handling of status changes is done manually, without any automated process for unified management and processing.

[0061] Related Technology 6, "On the Application of IP Network Traffic Analysis in Network Management," proposes the components of a network traffic analysis system, explains several network traffic analysis methods, and elaborates on the application scenarios of network traffic analysis in network management, enabling functions such as handling abnormal traffic, monitoring network faults, and managing user behavior. However, this paper does not explain the resolution methods for specific protocols (such as ARP and Domain Name System (DNS) protocols) in terms of traffic analysis. Regarding abnormal traffic handling, it only addresses post-event monitoring and handling of problems, failing to propose methods for managing IP assets in the network using traffic analysis, thus failing to achieve timely detection and pre-emptive control of problematic terminals accessing the network.

[0062] To address the problems that the aforementioned related technologies have failed to solve, this application provides relevant solutions, which are described in detail below.

[0063] According to an embodiment of this application, a method embodiment for IP asset management is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0064] Figure 2 This is a flowchart of an IP asset management method according to an embodiment of this application, such as... Figure 2 As shown, the method includes the following steps:

[0065] Step S202: Obtain the Address Resolution Protocol (ARP) table of the switches within the local area network, and generate an IP asset management table based on the target set in the ARP table. The target set includes at least: Internet Protocol (IP) addresses managed by the switches, Media Access Control (MAC) addresses, and the correspondence between IP addresses and MAC addresses. The IP asset management table includes: the target set, the status of IP addresses (also known as asset status), the attributes of IP addresses (also known as attributes or asset attributes), and the IP addresses of the switches. The status of IP addresses includes at least: occupied (also known as in use) and unoccupied (also known as not in use). The attributes of IP addresses include at least: service address.

[0066] Preferably, the aforementioned local area network is, for example, an enterprise internal network. The service address is the IP address provided by the switch for use by terminal devices.

[0067] The ARP table mentioned in step S202, also known as the ARP cache or ARP mapping table, is a temporary data structure used to store the mapping relationship between IP addresses and their corresponding MAC addresses. In network communication, communication between devices requires the use of IP addresses and MAC addresses. IP addresses are used for location at the network layer, while MAC addresses are used for communication between devices at the data link layer.

[0068] When one device needs to communicate with another, it first looks up the ARP table to determine the target device's MAC address. If the mapping already exists in the ARP table, the device will directly use that MAC address for communication. If the mapping does not exist in the ARP table, the device will query the target device's MAC address by sending an ARP request broadcast packet. Other devices receiving the request will check if their own IP address matches the IP address in the request. If they match, the device will send an ARP response packet, informing the requester of its own MAC address. Upon receiving the response, the requester will add the IP address-MAC address mapping to its ARP table and use that MAC address for communication.

[0069] The ARP table has the following characteristics: 1. Dynamic maintenance: The mapping relationships in the ARP table are dynamically maintained. When devices communicate with each other, the corresponding mapping relationships are added to the ARP table. 2. Caching: The mapping relationships in the ARP table are not permanently stored. They typically have an aging period (e.g., the default aging period in Linux systems is 1 minute). Entries exceeding this time limit are automatically cleared. 3. Conflict resolution: In some cases, two devices may have the same IP address but different MAC addresses. In this situation, the ARP protocol can resolve conflicts, ensuring normal network communication.

[0070] An IP address is a unique identifier used to identify and locate devices on the Internet. The status of an IP address typically includes the following: 1. Occupied: This means the IP address has already been assigned to a device or network and is in use. In this case, other devices cannot use this IP address. 2. Unoccupied: This indicates that the IP address has not yet been assigned to any device or network and can be used to assign it to a device that needs it.

[0071] It's worth noting that besides the two basic states mentioned above, IP address states can be further categorized, such as: Reserved addresses: Some IP addresses are reserved for specific purposes, such as private network addresses (e.g., 192.168.xx), broadcast addresses, multicast addresses, etc. Dynamically assigned: IP addresses may be dynamically assigned to devices via Dynamic Host Configuration Protocol (DHCP), meaning a device's IP address may change when it connects to a network. Statically assigned: In contrast to dynamic assignment, static IP addresses are manually configured and do not change with device connections. Invalid or undefined: Some IP addresses may be invalid or undefined due to configuration errors or other reasons. Temporarily unavailable: In some cases, IP addresses may be temporarily unavailable due to network problems or other reasons.

[0072] Step S204: Based on the status and attributes of the IP address, bind the IP address to the corresponding MAC address.

[0073] Binding IP addresses to their corresponding MAC addresses refers to associating a network device's IP address with its unique hardware identifier (MAC address). The primary purpose of this is to improve network security, prevent address spoofing and conflicts, and optimize network performance. By binding IP and MAC addresses, malicious users can be prevented from launching network attacks by forging IP addresses. Even if an IP address is forged, communication is impossible without the correct MAC address. In a network, if two devices use the same IP address, a conflict will occur, causing network connectivity problems. Binding ensures that each IP address is assigned to only one device, reducing the likelihood of conflicts. In some cases, network devices (such as routers or switches) can use binding information to optimize packet forwarding and improve network efficiency.

[0074] Step S206: Based on the ARP packets in the local area network, determine the IP address whose state has changed, and generate an IP asset state transition table based on the state transition of the IP address. The IP asset state transition table includes at least: IP address, MAC address before the state change of the IP address, MAC address after the state change of the IP address, and transition status. The transition status includes: new terminal online and old terminal offline.

[0075] The process of "old terminal going offline" involves several steps: 1. **Old terminal going offline:** When a device (old terminal) no longer needs a particular IP address, or due to network failure, device damage, or other reasons, it will stop using that IP address. In this case, the network administrator may release the IP address for reassignment to other devices. 2. **New terminal going online:** When a new device (new terminal) needs to connect to the network, it requires an IP address for network communication. The network administrator will assign an IP address to this device; this process is called "new terminal going online." After going online, the new terminal can use the assigned IP address for network communication.

[0076] Step S208: Display the IP asset status transition table, receive the audit results of the IP asset status transition table, and manage the IP addresses based on the audit results and transition status.

[0077] Understandably, step S208 displays the IP asset status transition table to the auditor and receives the auditor's review result on the transition status in the IP asset status transition table, such as: review passed or review failed.

[0078] The management of IP addresses mentioned in step S208 includes at least: releasing the MAC address before the state change corresponding to the IP address, and binding the IP address to the MAC address after the state change corresponding to the IP address.

[0079] Based on the above steps, the Address Resolution Protocol (ARP) table of the switches within the local area network (LAN) is obtained. An IP asset management table is generated based on the target set in the ARP table. The target set includes at least: Internet Protocol (IP) addresses managed by the switches, Media Access Control (MAC) addresses, and the mapping between IP addresses and MAC addresses. The IP asset management table includes: the target set, the status of the IP addresses, the attributes of the IP addresses, and the IP addresses of the switches. The IP address status includes at least: occupied and unoccupied, and the IP address attributes include at least: service address. Based on the IP address status and attributes, the IP addresses are bound to the corresponding MAC addresses. The occurrence of a status is determined based on the ARP packets within the LAN. The system transfers IP addresses and generates an IP asset status transition table based on the IP address status transition information. This table includes at least the IP address, the MAC address before the status change, the MAC address after the status change, and the transition status (new terminal online, old terminal offline). The system displays the IP asset status transition table, receives review results, and manages IP addresses based on these results and transition statuses. It comprehensively and in real-time detects and discovers valid IP addresses in the LAN by parsing the switch's ARP table, obtaining the liveness status of each IP asset in the LAN and improving the IP asset information to construct an enterprise network IP asset management table. Then, it continuously analyzes network traffic, combines the switch's ARP table resolution results to monitor IP asset status changes, and responds to IP asset status changes based on the IP asset status in the management table. This achieves the goal of dynamic monitoring of IP asset status changes in the enterprise network, thereby improving the technical efficiency of IP asset processing.

[0080] In some preferred embodiments, obtaining the Address Resolution Protocol (ARP) tables of switches within the local area network (LAN) can be achieved by: analyzing all switches within the enterprise's internal network (LAN) and mirroring all Layer 3 switches responsible for traffic forwarding. To monitor the traffic flow between each IP asset and other assets in the enterprise network, it is necessary to collect traffic from all switches that perform traffic forwarding within the enterprise. This traffic is then mirrored to an analysis server. This analysis server, connected to the enterprise network, has access to all switches, facilitating the collection and analysis of the switches' ARP tables. Figure 3 This is a deployment topology diagram of a server for analyzing mirrored traffic and analyzing switch information according to an embodiment of this application, such as... Figure 3 As shown, through Figure 3The topology diagram shows servers deployed to analyze mirrored traffic and switches within the enterprise network. These servers access all switches within the enterprise's internal network and collect and analyze the switches' ARP tables.

[0081] According to some optional embodiments of this application, the Address Resolution Protocol (ARP) table of a switch within a local area network (LAN) can be obtained by the following method: setting a first time window, wherein the length of the first time window is proportional to the number of nodes in the LAN; setting n time intervals within the first time window, wherein the length of each time interval is less than the effective duration of the ARP cache, and n is a positive integer greater than 1; and traversing the ARP tables of the switches within the LAN according to the n time intervals to obtain n ARP tables.

[0082] Furthermore, generating an IP asset management table based on the target set in the ARP table can be achieved as follows: Based on n time intervals, determine if the time to traverse the switch's ARP table has been reached; if the time to traverse the switch's ARP table has been reached, read the switch information of the first switch from the switch database, where the first switch is any switch within the LAN; determine if the switch information of the second switch can be read, where the second switch is any switch within the LAN other than the first switch; if the switch information of the second switch cannot be read, save the target set in the first switch's ARP table to the IP asset management table corresponding to the first switch; if the switch information of the second switch can be read, log in to the second switch based on a remote login protocol or a secure shell protocol, and use the first preset ARP command to view the second switch's ARP table, saving the target set in the second switch's ARP table to the IP asset management table corresponding to the second switch.

[0083] In summary, this embodiment dynamically manages the IP address status of IP assets based on the handling of IP address and MAC address correspondences. Therefore, this embodiment chooses to use the method of resolving the switch's ARP table to probe IP assets in the enterprise network. It is worth noting that, to ensure the accuracy of the IP asset probe results, this embodiment sets a window period (the size of the window period is proportional to the size of the enterprise network). Within the window period, the switch's ARP table is read and resolved at regular intervals to obtain the set of correspondences between all IP addresses and MAC addresses on the switch at that time. The results of this analysis of IP addresses and MAC addresses are then stored in the enterprise network's full IP asset management table. After the window period ends, the enterprise adds other information, such as the responsible persons for the surviving assets, from the management table to the table. The interval for reading ARP entries is generally determined by the ARP aging time of the switch whose information is being read. Generally, as long as the reading interval is less than the ARP table aging time, it can be ensured that no ARP entries are missed.

[0084] as follows Figure 4 This refers to the specific implementation process of a cyclic scanning switch, from... Figure 4 As can be seen, once the cyclic scan begins execution, it will not terminate unless an unexpected event occurs in the program. The cyclic scan task is either in the state of scanning switches to analyze the ARP table and generate the IP asset table, or in the state of waiting to scan switches.

[0085] The Enterprise Network Full IP Asset Management Table (IP Asset Management Table) lists all IP addresses according to the network segments the enterprise has allocated. For example, if the enterprise uses the 192.168.1.0 / 24 network segment, the IP Asset Management Table will list 256 addresses: 192.168.1.0-192.168.1.255. If the enterprise uses multiple network segments, the IP Asset Management Table will list all addresses for each network segment. The table below shows all the fields in the IP Asset Management Table.

[0086]

[0087] As shown in the table above, the entries in the IP asset management table may include, but are not limited to: number, IP address, MAC address, IP address status, IP address attributes, department, responsible person, telephone number, and switch number. The IP address, MAC address, and IP address status are obtained by resolving the switch's ARP table. The IP address attributes and switch IP are obtained by analyzing the Layer 3 interface configuration of the switch, indicating which switch the IP asset's IP address is configured on. Other fields will be manually compiled by the enterprise after the IP asset detection window.

[0088] Specifically, the IP address status is categorized as either in use or inactive. For IP addresses in use, all field information needs to be collected. For inactive IP addresses, only a unique identifier (number) is required. This identifier can be a numerical sequence or a company-defined abbreviation, ensuring it is unique. The IP address's attributes indicate whether it is a network address, gateway address, or broadcast address. All addresses except network addresses, gateway addresses, and broadcast addresses are marked as service addresses.

[0089] According to some alternative embodiments of this application, obtaining the Address Resolution Protocol (ARP) table of the switch within the local area network and generating an IP asset management table based on the target set in the ARP table can also be achieved through the following methods:

[0090] Step S1: Set the second time window and generate the initial IP asset management table.

[0091] Step S2: Determine whether the current time is within the second time window.

[0092] Step S3: If the current time is within the second time window, traverse all switches in the local area network.

[0093] Step S4: Determine if there are any switches that have not been traversed.

[0094] Step S5: If there are switches that have not been traversed, obtain the network segment information of the switch under the Layer 3 interface. The network segment information includes: IP address and subnet mask.

[0095] The network address, gateway address, broadcast address, and service address of the switch are determined based on the network segment information. The service address is the IP address that the switch provides for use by terminal devices.

[0096] Use the first preset ARP command to obtain the mapping between IP address and MAC address.

[0097] Based on the mapping between IP addresses and MAC addresses, the network address, gateway address, broadcast address, and service address of the switch, update the initial IP asset management table to obtain the IP asset management table. After obtaining the IP asset management table, execute step S4.

[0098] Step S6: If there are no untraversed switches, proceed to step S2.

[0099] Step S7: If the current time is not within the second time window, obtain the first information corresponding to the first IP address, and set the status of the first IP address to be occupied in the IP asset management table. The first IP address is the IP address whose MAC address can be found based on the correspondence between IP address and MAC address. The first information includes: the department, the name of the person in charge, and the contact information of the person in charge corresponding to the first IP address.

[0100] In the IP asset management table, the status of the IP address corresponding to the second IP address is set to unoccupied. The second IP address is an IP address whose MAC address cannot be found based on the correspondence between IP address and MAC address.

[0101] Figure 5 This is another flowchart for generating an IP asset management table according to an embodiment of this application, such as... Figure 5 As shown, an IP asset management table can also be generated using the following method.

[0102] First, set an asset detection window period. The specific duration of the window period is determined by the size of the enterprise network, for example, it can be set to 15 days. Then, generate an empty table showing all of the enterprise's IP assets under management.

[0103] Then, the enterprise provides the addresses of all switches in its network. An automated script logs into each switch sequentially to obtain the addresses of all Layer 3 interfaces in the configuration, for example: xxxx (IP address) xxxx (mask). Then, using the IP address and mask, the network address, gateway address, broadcast address, and all service addresses available to terminals for this network are calculated.

[0104] Secondly, after analyzing all the network address ranges configured on all switches, the status of all IP addresses in the enterprise network is obtained as available IP addresses, and a full enterprise IP asset management table containing three fields: IP address, IP address attributes, and switch IP address is generated.

[0105] Secondly, by using DisplayArp, the mapping relationship between IP addresses and MAC addresses is obtained, and the MAC addresses and asset status corresponding to the IP addresses in the enterprise's full IP asset management table are updated. For example, the status of the IP address is updated from unused to used.

[0106] Finally, within the window period, at intervals shorter than the aging time, the IP address configuration and ARP table of the Layer 3 interfaces on each switch are repeatedly acquired and analyzed, and the analysis results are updated to the enterprise's full IP asset table.

[0107] It's important to note that after the window period ends, enterprises should complete the information for IP assets in use in the full IP asset table, and set the status of all other IP addresses that haven't resolved to MAC addresses to "inactive," thus completing the construction of the enterprise's full IP asset management table. Furthermore, even after the full IP asset management table is built, it's still necessary to periodically collect and analyze the Layer 3 interface configurations of switches, and promptly update the switches where the IP asset's IP address resides, so that the corresponding switches can be located for subsequent IP asset status transfers.

[0108] In some optional embodiments of this application, step S204 can be implemented in the following ways:

[0109] Read the status of IP addresses in the IP asset management table;

[0110] If the IP address read is in an unoccupied state, read the IP address in the IP asset management table and the switch IP address, use the first preset script based on the Secure Shell protocol to log in to the switch, replace the IP address with the first preset address, and replace the MAC address corresponding to the IP address with the second preset address.

[0111] If the IP address is found to be occupied, check the IP address's attributes in the IP asset management table. If the IP address's attributes are network number, gateway address, or broadcast address, no action is taken.

[0112] When the IP address is a service address, look up the IP address, MAC address, and switch IP address in the IP asset management table, log in to the switch corresponding to the switch IP address using the first preset script based on the Secure Shell protocol, replace the IP address with the third preset address, and replace the MAC address corresponding to the IP address with the fourth preset address.

[0113] In summary, in order to strictly control the internal IP assets of an enterprise, this embodiment, after constructing the IP asset management table, binds IP addresses and MAC addresses on the switch side according to the information in the IP asset management table, so as to lock the status of IP assets, ensure that IP addresses in an inactive state are not arbitrarily connected and that IP addresses in an inactive state cannot be arbitrarily changed to other terminals.

[0114] Specifically, the IP asset status on the switch can be locked using the rules shown in the table below, based on the asset information in the enterprise's full IP asset table.

[0115]

[0116] After constructing the enterprise's full IP asset management table, the status of all IP assets in the full IP asset table is locked on the switch side according to the IP asset status locking rules shown in the table above. Figure 6 This is a flowchart illustrating how to bind an IP address to a corresponding MAC address according to an embodiment of this application. Figure 6 As shown, the method specifically includes the following process.

[0117] First, read the enterprise's full IP asset table one by one to obtain the asset status. If the asset status is not in use, then obtain the asset IP address and the switch IP address.

[0118] Then, use a script to log in to the switch via Secure Shell (SSH) and use Arp Static xxxx (IP address) aaaa-aaaa-aaaa to block the asset's IP address. After the operation is complete, update the MAC address of the asset in the enterprise's full IP asset management table to aaaa-aaaa-aaaa.

[0119] Arp Static is a network technology used to bind a device's IP address to its corresponding MAC address. This allows the sender to directly use the bound MAC address when sending data packets to the device, without needing to perform an ARP lookup.

[0120] Secondly, if the asset is in use, then when checking its attributes, if the asset's attribute is a network number, gateway address, or broadcast address, then no action is taken. If the asset's attribute is a service address, then the asset's IP address, MAC address, and switch IP address are obtained.

[0121] Finally, a script is used to log in to the switch via SSH, and Arp Static xxxx (IP address) xxxx (MAC address) is used to bind the asset's IP address and MAC address to prevent the terminal with that IP address from being changed at will, thus achieving the purpose of strict control over the access terminal.

[0122] As some optional embodiments of this application, step S206 can be implemented in the following ways:

[0123] Step S1: Generate the initial IP asset state transition table, generate the initial host traffic transmission record table, and set the target duration for obtaining traffic data from the switch.

[0124] Step S2: Determine whether a stop monitoring signal has been received.

[0125] Step S3: If no stop monitoring signal is received, acquire the traffic data of the switch, and add the source address and message time information of each data packet in the traffic data to the initial host traffic transmission record table to obtain the host traffic transmission record table.

[0126] Step S4: Determine whether the duration of the data recorded in the host traffic sending record table is equal to the target duration.

[0127] Step S5: If the duration of the data recorded in the host traffic transmission record table is not equal to the target duration, determine whether the traffic data includes ARP packets. If the traffic data includes ARP packets, obtain the source IP address and source MAC address of the ARP packets, use the source IP address as the lookup condition, search the IP asset management table, and find the first MAC address corresponding to the source IP address in the found IP asset management table.

[0128] Step S6: Determine whether the source MAC address is the same as the first MAC address.

[0129] Step S7: If the source MAC address is different from the first MAC address, add the source IP address, the first MAC address, the switch IP address, and the status of the IP address in the IP asset management table as the first newly added horizontal cell group to the initial IP asset status transition table, and set the transition status to new terminal online in the first newly added horizontal cell group.

[0130] Step S8: If the source MAC address is the same as the first MAC address, repeat steps S2 and S3.

[0131] Preferably, if the duration of data recorded in the host traffic transmission record table is equal to the target duration, the following steps can be performed: search for the target IP address in the IP asset management table, wherein the target IP address is an IP address that has not been recorded in the IP asset status transition table within the target duration and whose status is occupied; add the target IP address, the target MAC address corresponding to the target IP address, the switch IP address, and the status of the IP address as a second newly added horizontal cell group to the IP asset status transition table, and set the transition status to old terminal offline in the second newly added horizontal cell group.

[0132] Preferably, after obtaining the source IP address and source MAC address of the ARP packet, the following steps can be performed: converting the source MAC address into first identification information.

[0133] After finding the first MAC address corresponding to the source IP address in the IP asset management table, you can continue to perform the following steps: convert the first MAC address into second identification information.

[0134] To determine whether the source MAC address is the same as the first MAC address, you can do so by checking whether the first identification information is the same as the second identification information.

[0135] After setting the transfer status to "New Terminal Online" in the first newly added horizontal cell group, the following steps can be performed: convert the first MAC address in the first newly added horizontal cell group into the first identification information.

[0136] In summary, after constructing the enterprise's full IP asset management table in this embodiment, the asset status in the table is not static. IP addresses in use may change MAC addresses due to business needs requiring different terminals, or they may be temporarily disabled. Conversely, unused IP addresses may need to be enabled again for business purposes. Therefore, while strictly managing IP addresses and terminal access, it is necessary to have methods to analyze changes in IP asset status so that enterprises can understand changes in their internal network IP addresses and manage them accordingly.

[0137] This embodiment primarily monitors ARP packets in the network when monitoring changes in IP asset status. ARP packets are mainly used to query the MAC addresses of other IP addresses in the network. Although after building a full set of enterprise IP assets, all in-use IP addresses are bound to their MAC addresses and all in-use IP addresses are blocked, when a new terminal accesses the network using a certain IP address, the terminal will use the ARP protocol to report its IP address and MAC address to other hosts in the network. However, because the IP address is already bound to other MAC addresses, the terminal cannot ultimately communicate with other hosts. In the daily operations of an enterprise, the onboarding of new terminals is a relatively normal requirement. Therefore, it is necessary to promptly detect and record changes in IP asset status, generating an IP asset state transition table, which includes the fields shown in the table below.

[0138]

[0139] The explanations for each field in the table above are as follows:

[0140] 1. IP Address: IP addresses in the enterprise's full IP asset management table. When IP asset status changes, only the business address is monitored, not the network address, gateway address, or broadcast address.

[0141] 2. MAC address: The MAC address corresponding to the IP address in the enterprise's full IP asset management table.

[0142] 3. Switch IP: The IP address of the switch where the IP address in the enterprise's full IP asset management table is located.

[0143] 4. Current Status: The status of the IP asset in the enterprise's full IP asset management table, including at least two states: in use or not in use.

[0144] 5. Transition Status: Based on the analysis of ARP packets in the traffic, the trend of IP asset status changes is obtained. The main transition statuses are new terminal online and old terminal offline. The possible relationships between the current status and transition status are shown in the table below.

[0145]

[0146] The explanation of the table above is as follows:

[0147] MAC Address in New Status: When the transition status is that a new terminal has come online, this field indicates the MAC address obtained in the new status. If the transition status is that the old terminal has gone offline, there is no new MAC address.

[0148] Review: For asset status transfer entries obtained through automated analysis, manual review by the enterprise is required. Entries that pass review will be processed and marked as processed in the "Processed" field. Entries that fail review or are not reviewed will not be processed.

[0149] Disposal: For entries that have been approved and disposed of, this field will be marked as disposed.

[0150] Figure 7 This is a flowchart illustrating the generation of an IP asset state transition table according to an embodiment of this application, such as... Figure 7 As shown, the method includes the following steps.

[0151] It should be noted that the traffic analysis and monitoring program will continue to run unless a clear signal to stop monitoring is received.

[0152] First, all network traffic is analyzed, and the source address and message time of data packets are stored in the host traffic record table. Then, using the IP addresses of in-use IP assets in the enterprise's full IP asset management table as query criteria, the system searches for IP addresses that do not appear in the traffic record table within a target time period. It should be noted that this target time period is called the quiet period, which is set by the enterprise and is typically 15 days. The transfer status of these in-use IP assets during this period is the old terminal's offline status.

[0153] Secondly, determine if the message is an ARP message. If it is, analyze the source IP address and source MAC address in the message. Then, use the IP address as a query condition to query the enterprise's full IP asset management table. When it is found that the MAC address in the ARP message is different from the MAC address corresponding to that IP address in the enterprise's full IP asset management table, it indicates that the transfer status of these IP assets is that a new terminal has come online.

[0154] Finally, update the IP asset status transfer table with information such as IP address, MAC address, switch IP and current status (the above four fields are obtained from the IP asset management table), transfer status, and new status MAC (the above two fields are information analyzed in this step), update the audit field to unaudited, and update the disposal status to undisposed.

[0155] As some alternative embodiments of this application, the management of IP addresses based on the audit results and transfer status in step S208 can be achieved by the following method: For the first target IP address, log in to the switch corresponding to the first target IP address, unbind the first target IP address from the MAC address before the status change, bind the first target IP address to the MAC address after the status change, and update the information of the first target IP address in the IP asset management table. Here, the first target IP address is the IP address whose audit result is passed, whose IP address status is occupied, and whose transfer status is the IP address of a new terminal online.

[0156] Preferably, the management of IP addresses based on the audit results and transfer status in step S208 can also be achieved by the following method: For the second target IP address, log in to the switch corresponding to the second target IP address, unbind the second target IP address from the MAC address before the status change, replace the second target IP address with the fourth preset address, and update the information of the second target IP address in the IP asset management table, wherein the second target IP address is the IP address whose audit result is passed, whose IP address status is occupied, and whose transfer status is the old terminal offline.

[0157] Preferably, the management of IP addresses based on the audit results and transfer status in step S208 can also be achieved by the following method: For the third target IP address, log in to the switch corresponding to the third target IP address, replace the third target IP address with the fifth preset address, bind the third target IP address with the MAC address whose status has changed, and update the information of the third target IP address in the IP asset management table. Here, the third target IP address is the IP address whose audit result is passed, whose IP address status is unoccupied, and whose transfer status is the IP address of a new terminal online.

[0158] In summary, after obtaining the IP asset state transition table in the enterprise network, to ensure that these state transitions are permitted, the enterprise network administrator needs to confirm them and mark the approval field of the IP assets that do require state transitions as approved. In step S208, the approved entries in the IP asset state table will be processed (managed), and the processing field of the entry will be updated to processed after processing.

[0159] Figure 8 This is a flowchart illustrating how to manage IP addresses based on review results and transfer status, according to an embodiment of this application. Figure 8 As shown, step S208 can also be achieved through the following steps.

[0160] First, analyze each entry in the IP Asset Transfer Table. When an entry's review status is "Approved" and its disposal status is "Undisposed," proceed with the disposal of that entry's asset transfer status. The disposal process follows the rules in the table below.

[0161]

[0162]

[0163] In summary, step S208 enables dynamic handling of IP asset state transfers. By releasing the old state and binding the new state, and through traffic analysis combined with IP address and MAC address binding, the system can strictly manage the online presence of new terminals and the offline presence of old terminals, thus achieving relatively strict dynamic management of IP assets in the enterprise network.

[0164] As can be seen from the detailed explanations of steps S202 to S208, this application can accurately detect and discover all IP assets in an enterprise network, and lock the state of IP assets by binding IP addresses and MAC addresses. With the help of traffic analysis technology, it can monitor the state transition of IP assets, and replace MAC addresses by unbinding and binding IP assets, thereby completing the secure access and secure offline of IP assets. This solves the shortcomings of traditional asset management methods that cannot effectively monitor the state transition of IP assets and respond to and handle them, and finally realizes dynamic security management of IP assets in the enterprise network.

[0165] Figure 9 This is a flowchart of another IP asset management method according to an embodiment of this application, such as... Figure 9 As shown, the method includes the following steps:

[0166] Step S901, construct the IP asset management table: Through multiple cycles of ARP collection and resolution of the switch over a period of time, identify the status of all IP addresses in the enterprise network, and add information such as the users of the active IP assets through supplementary methods by the enterprise, and construct the full IP asset management table of the enterprise network.

[0167] Step S902: Based on the IP asset management table information, lock the IP asset status on the switch: According to the IP asset management table, block unused IP assets on the switch side, and bind IP addresses and MAC addresses of in-use IP assets on the switch side to achieve strict control over IP assets.

[0168] Step S903: Monitor IP asset status changes through traffic analysis technology and generate an IP asset status transition table: Based on the IP address, attributes, IP asset status attributes, and IP address and MAC address information in the ARP packets collected by traffic analysis, determine the transition status of the IP asset and generate the IP asset status transition table.

[0169] Step S904: Review the IP asset state transition table and process the approved records: Process the IP asset state transition entries approved by the enterprise on the switch side and update the IP address and MAC address binding relationship of the IP assets.

[0170] It should be noted that, Figure 9 Preferred embodiments of the shown examples can be found in [reference needed]. Figure 2 The relevant descriptions of the embodiments shown will not be repeated here.

[0171] The following section discusses specific application scenarios. Figures 2 to 9 The provided methods are explained.

[0172] Taking the data communication network (DCN) of Company A as an example, Company A's DCN is currently very large, with numerous branch points, involving all office locations and data centers carrying business operations in various dispersed locations. Each branch point has multiple aggregation switches, and all traffic within a branch point is forwarded through the branch point's egress core switch (Bras). Different branch points are interconnected through the branch point's egress core switch (Bras) to achieve interoperability. Through analysis of Company A's DCN, over 80 switches responsible for internal Layer 3 traffic forwarding requiring mirroring and 187 switches requiring ARP table collection were identified.

[0173] To better implement the methods provided in this application, Company A developed a system for viewing and managing results from traffic analysis, switch management, and ARP collection. Figure 10 This is a schematic diagram of real-time traffic data collected from a DCN mirrored according to an embodiment of this application.

[0174] Figure 11 This is a statistical table of switches in Company A's DCN that require ARP collection, which can be queried and exported.

[0175] Currently, the Nanjing company's DCN network contains switches from four brands: Huawei, Ruijie, Cisco, and H3C. Therefore, during the implementation, scripts were written to log in to these four brands, enabling operations such as SSH login, obtaining and parsing Layer 3 interface configurations, obtaining and parsing ARP information, binding and unbinding, and blocking and unblocking via scripts.

[0176] In practice, a 30-day window is set. During this period, information is collected from the switches multiple times to generate a comprehensive IP asset management table for the enterprise. When creating the comprehensive IP asset management table, after logging into the switch, the configuration of the IP address ranges of the Layer 3 interfaces on the switch is first collected and analyzed, and then the ARP table on the switch is collected and analyzed. Figure 12 It is the IP address range information of some Layer 3 interfaces that has been analyzed and stored in the database.

[0177] To provide a more intuitive view of the IP address ranges on the switches within the system, the system associates switch IP addresses with the aforementioned IP address ranges, displaying more information about the Layer 3 interfaces, such as... Figure 13 As shown.

[0178] By repeatedly collecting and analyzing the ARP tables of multiple DCN switches during the window period, and combining this with analysis of the address ranges in the switch's Layer 3 interfaces, partial information about IP assets was obtained. Enterprises then added information about the IP asset users, generating an IP asset management table. After reviewing the IP assets during the window period, over 34,000 IP assets were brought under management. For example... Figure 14 This is an example of a comprehensive enterprise IP management table built within the system.

[0179] After constructing the enterprise's full IP asset management table, lock the status of all IP assets on the switch side. For assets in use, use the arp static command on their corresponding switches to bind the IP address and MAC address. For assets not in use, use the arp static command on their corresponding switches to bind the IP address and aaaa-aaaa-aaaa to achieve the purpose of blocking. Figure 15 It refers to the ARP status of the IP asset queried in the system after the state is locked on the switch side.

[0180] Traffic analysis technology was used to collect and analyze all traffic in Company A's DCN network, mainly focusing on the following:

[0181] 1) Record the source addresses that send traffic within the network within a certain period of time. This is used for later statistics on which addresses in use have not initiated traffic within a certain period of time, indicating that the IP asset may have been taken offline.

[0182] 2) Analyze ARP packets, including the IP and MAC addresses, and compare them with the MAC addresses in the IP asset management table to identify new terminals that are about to go online.

[0183] Figure 16 It is a statistical record that can be viewed in the system for IP addresses that have sent traffic records, including IP address, number of packets sent, packet size, and the time of the most recent packet sent.

[0184] This embodiment utilizes traffic analysis techniques to capture and analyze ARP packets in the network, identifying the IP and MAC addresses within them. A corresponding script was developed to filter and analyze ARP packets within the network traffic. Figure 17 It contains the specific information of the filtered ARP message.

[0185] The main purpose of using traffic analysis techniques to analyze traffic is to generate IP asset state transition tables. Figure 18 It displays information from a portion of the IP asset state transition tables stored in the database.

[0186] By using traffic analysis technology and comparing the full list of managed IP assets, a status transition table was generated showing all IP assets in "unreviewed" and "unprocessed" states. Users of the relevant IP assets can proactively report their IP asset status transition needs to the enterprise security management personnel. When the enterprise security management personnel see a relevant status transition entry in the status transition table, they can mark that entry as reviewed. For example, in... Figure 18 In the process, the enterprise security management personnel confirmed the state transition requirements for the three IP addresses 132.229.152.110, 132.229.152.111, and 132.229.165.252, and set their approval status to "approved." After scanning the IP asset status table and finding approved but unprocessed entries, the system automatically logs into the corresponding switch using a script to perform ARP unbinding and binding operations. Once the operation is complete, the status of the entry is set to "processed." Figure 19 As shown.

[0187] Through the above embodiment of dynamic management of IP asset status of enterprise A's DCN network, it can be seen that the present invention can effectively realize the detection of all IP assets, the monitoring of IP asset status, and the strict access and offline control of IP assets.

[0188] In addition, this embodiment statistically analyzed the status transition items and approval items monitored daily over 30 days, as shown in the table below.

[0189] Serial Number 1 2 3 4 5 6 7 8 9 10 State transition entries 112 86 79 159 170 139 91 88 168 289 Entries approved 15 10 5 7 10 18 20 17 36 19 Serial Number 11 12 13 14 15 16 17 18 19 20 State transition entries 352 58 78 39 97 89 134 276 215 217 Entries approved 19 28 10 3 8 35 26 19 17 21 Serial Number 21 22 23 24 25 26 27 28 29 30 Number of transition states 167 184 241 78 91 72 71 165 154 202 Entries approved 17 29 34 21 41 19 10 27 16 48

[0190] As can be seen from the table above, by filtering the entire traffic and analyzing ARP packets, the daily state transition of IP assets can be monitored. However, since the state of IP assets has been locked in advance on the switch, this state transition cannot be actually executed without the approval of the company's security administrator.

[0191] Company A's security management requirements stipulate that only IP assets that have been reported to the company's security administrator in advance and have passed the security vulnerability scan assessment can enter the network. Only then can the administrator set the state transition entry of the IP asset to "approved". This can improve the security of IP assets in the network, thereby improving the overall security of the network.

[0192] Without proper control over IP asset state transitions, numerous new terminals enter the network daily. If these new terminals haven't undergone security vulnerability scanning and assessment, they can easily become network vulnerabilities. As shown in the table above, using the method provided in this application, at least dozens of IP asset state transitions are rejected daily due to lack of prior reporting, effectively preventing the entry of IP assets with unknown security into the network. Currently, many related asset management methods lack the ability to detect such potential IP asset state transitions in a timely manner, leading to a significant number of IP assets with unknown security entering the network daily, posing a substantial threat to network security.

[0193] In summary, this embodiment analyzes the status of all IP assets in the enterprise network by cyclically resolving the ARP tables of all switches within a set window period at a frequency less than the ARP table aging time. After the window period, the switch's ARP binding function is used to bind the IP and MAC addresses of in-use and inactive IP assets, locking the IP asset status and strictly controlling IP asset access. By recording the IP addresses that actively send data packets in the traffic, IP assets that have not been used for a period of time are identified. ARP traffic is analyzed, parsing the IP and MAC addresses in the ARP traffic and comparing them with the MAC addresses in the IP asset management table to identify IP assets attempting to change their MAC addresses. Based on the current IP address status and the status in the IP asset management table, the asset status transition situation is analyzed, and an IP asset status transition table is constructed. In addition, the IP asset status transition table records the attempted access of new terminals and the possible offline status of old terminals. For entries in the IP asset status transition table that have been approved, the MAC address is dynamically replaced on the switch, and the MAC address is locked again to achieve secure access and secure offline management of IP assets.

[0194] The above methods enable accurate detection and discovery of all IP assets in an enterprise network. By binding IP addresses and MAC addresses, the state of IP assets can be locked. With the help of traffic analysis technology, the state transition of IP assets can be monitored. By unbinding and binding IP assets, the MAC address can be replaced, thereby completing the secure access and secure shutdown of IP assets. This solves the shortcomings of traditional asset management methods that cannot effectively monitor the state transition of IP assets and respond to and handle them. Ultimately, dynamic security management of IP assets in the enterprise network is achieved.

[0195] Figure 20 This is a structural diagram of an asset management device according to an embodiment of this application, such as... Figure 20 As shown, the device includes:

[0196] The first generation module 200 is used to obtain the Address Resolution Protocol (ARP) table of the switches in the local area network and generate an IP asset management table based on the target set in the ARP table. The target set includes at least: Internet Protocol (IP) addresses managed by the switches, Media Access Control (MAC) addresses, and the correspondence between IP addresses and MAC addresses. The IP asset management table includes: the target set, the status of the IP addresses, the attributes of the IP addresses, and the IP addresses of the switches. The status of the IP addresses includes at least: occupied and unoccupied, and the attributes of the IP addresses include at least: service address.

[0197] The binding module 202 is used to bind an IP address to a corresponding MAC address based on the IP address's status and attributes.

[0198] The second generation module 204 is used to determine the IP address whose state has changed based on the ARP packets in the local area network, and generate an IP asset state transition table based on the state transition of the IP address. The IP asset state transition table includes at least: IP address, MAC address before the state change of the IP address, MAC address after the state change of the IP address, and transition status. The transition status includes: new terminal online and old terminal offline.

[0199] The processing module 206 is used to display the IP asset status transition table, receive the audit results of the IP asset status transition table, and manage the IP addresses based on the audit results and the transition status.

[0200] Optionally, the first generation module 200 is further configured to perform the following steps: setting a first time window, wherein the length of the first time window is proportional to the number of nodes in the local area network; setting n time intervals within the first time window, wherein the length of each time interval is less than the effective duration of the ARP cache, and n is a positive integer greater than 1; and traversing the ARP tables of the switches in the local area network according to the n time intervals to obtain n ARP tables.

[0201] Optionally, the first generation module 200 is further configured to perform the following steps: based on n time intervals, determine whether the time for traversing the ARP table of the switch has been reached; if the time for traversing the ARP table of the switch has been reached, read the switch information of the first switch from the switch database, wherein the first switch is any switch within the local area network; determine whether the switch information of the second switch can be read, wherein the second switch is any switch within the local area network other than the first switch; if the switch information of the second switch cannot be read, save the target set in the ARP table of the first switch to the IP asset management table corresponding to the first switch; if the switch information of the second switch can be read, log in to the second switch based on the remote login protocol or the secure shell protocol, and use the first preset ARP command to view the ARP table of the second switch, and save the target set in the ARP table of the second switch to the IP asset management table corresponding to the second switch.

[0202] Optionally, the first generation module 200 is further configured to perform the following steps: Step S1, set a second time window and generate an initial IP asset management table; Step S2, determine whether the current time is within the second time window; Step S3, if the current time is within the second time window, traverse all switches in the local area network; Step S4, determine whether there are any switches that have not been traversed; Step S5, if there are any switches that have not been traversed, obtain the network segment information of the switch under the Layer 3 interface, wherein the network segment information includes: IP address and subnet mask; determine the network address, gateway address, broadcast address and service address of the switch based on the network segment information, wherein the service address is the IP address of the switch used by terminal devices; use a first preset ARP command to obtain the correspondence between IP address and MAC address; based on the correspondence between IP address and MAC address, the network address, gateway address, broadcast address and service address of the switch are determined. The IP asset management table is updated based on the address and business address. After obtaining the IP asset management table, step S4 is executed. Step S6: If there are no untraversed switches, step S2 is executed. Step S7: If the current time is not within the second time window, the first information corresponding to the first IP address is obtained, and the status of the first IP address is set to occupied in the IP asset management table. The first IP address is an IP address whose MAC address can be found based on the correspondence between IP address and MAC address. The first information includes: the department, the name of the person in charge, and the contact information of the person in charge corresponding to the first IP address. The status of the second IP address is set to unoccupied in the IP asset management table. The second IP address is an IP address whose MAC address cannot be found based on the correspondence between IP address and MAC address.

[0203] Optionally, the binding module 202 is also used to perform the following steps: read the status of the IP address in the IP asset management table; if the read IP address status is unoccupied, read the IP address and switch IP address in the IP asset management table, log in to the switch using a first preset script based on the Secure Shell protocol, replace the IP address with a first preset address, and replace the MAC address corresponding to the IP address with a second preset address; if the read IP address status is occupied, search for the IP address's attributes in the IP asset management table; if the IP address's attributes are network number, gateway address, or broadcast address, no operation is performed; if the IP address's attributes are service address, search for the IP address, MAC address, and switch IP address in the IP asset management table, log in to the switch corresponding to the switch IP address using a first preset script based on the Secure Shell protocol, replace the IP address with a third preset address, and replace the MAC address corresponding to the IP address with a fourth preset address.

[0204] Optionally, the second generation module 204 is further configured to perform the following steps: Step S1, generate an initial IP asset state transition table, generate an initial host traffic transmission record table, and set a target duration for acquiring traffic data from the switch; Step S2, determine whether a stop monitoring signal has been received; Step S3, if no stop monitoring signal has been received, acquire the switch's traffic data and add the source address and packet time information of each data packet in the traffic data to the initial host traffic transmission record table to obtain the host traffic transmission record table; Step S4, determine whether the duration of data recorded in the host traffic transmission record table is equal to the target duration; Step S5, if the duration of data recorded in the host traffic transmission record table is not equal to the target duration, determine whether the traffic data includes ARP packets. If the traffic data includes ARP packets... The process involves: obtaining the source IP address and source MAC address of the ARP packet; using the source IP address as a lookup condition to search the IP asset management table; and finding the first MAC address corresponding to the source IP address in the found IP asset management table; step S6: determining whether the source MAC address and the first MAC address are the same; step S7: if the source MAC address and the first MAC address are different, adding the source IP address, the first MAC address, the switch IP address, and the IP address status from the IP asset management table as the first newly added horizontal cell group to the initial IP asset status transition table, and setting the transition status to "new terminal online" in the first newly added horizontal cell group; step S8: if the source MAC address and the first MAC address are the same, repeating steps S2 and S3.

[0205] Optionally, if the duration of data recorded in the host traffic transmission record table is equal to the target duration, the second generation module 204 is further configured to perform the following steps: search for the target IP address in the IP asset management table, wherein the target IP address is an IP address that has not been recorded in the IP asset status transition table within the target duration and whose status is occupied; add the target IP address, the target MAC address corresponding to the target IP address, the switch IP address, and the status of the IP address as a second newly added horizontal cell group to the IP asset status transition table, and set the transition status to old terminal offline in the second newly added horizontal cell group.

[0206] Optionally, after obtaining the source IP address and source MAC address of the ARP packet, the IP asset management device further performs the following steps: converting the source MAC address into first identification information; after searching for the first MAC address corresponding to the source IP address in the found IP asset management table, the IP asset management device further performs the following steps: converting the first MAC address into second identification information; the IP asset management device further performs the following steps: determining whether the first identification information and the second identification information are the same; the IP asset management device further performs the following steps: converting the first MAC address in the first newly added horizontal cell group into first identification information.

[0207] Optionally, the processing module 206 is also used to perform the following steps: for the first target IP address, log in to the switch corresponding to the first target IP address, unbind the first target IP address from the MAC address before the status change, bind the first target IP address to the MAC address after the status change, and update the information of the first target IP address in the IP asset management table, wherein the first target IP address is the one whose audit result is passed, the IP address status is occupied, and the transfer status is the IP address of the new terminal online.

[0208] Optionally, the processing module 206 is also used to perform the following steps: for the second target IP address, log in to the switch corresponding to the second target IP address, unbind the second target IP address from the MAC address before the status change of the second target IP address, replace the second target IP address with the fourth preset address, and update the information of the second target IP address in the IP asset management table, wherein the second target IP address is the one whose audit result is passed, the IP address status is occupied, and the transfer status is the IP address whose old terminal is offline.

[0209] Optionally, the processing module 206 is also used to perform the following steps: for the third target IP address, log in to the switch corresponding to the third target IP address, replace the third target IP address with the fifth preset address, bind the third target IP address with the MAC address whose status has been changed, and update the information of the third target IP address in the IP asset management table, wherein the third target IP address is the one whose audit result is passed, the IP address status is unoccupied, and the transfer status is the IP address of the new terminal online.

[0210] It should be noted that the above Figure 20 The modules in the above can be program modules (e.g., a set of program instructions that implement a specific function) or hardware modules. For the latter, they can be represented in the following forms, but are not limited to these: each of the above modules is represented by a processor, or the functions of each of the above modules are implemented by a processor.

[0211] It should be noted that, Figure 20 Preferred embodiments of the shown examples can be found in [reference needed]. Figure 2 The relevant descriptions of the embodiments shown will not be repeated here.

[0212] Figure 21 A hardware block diagram of a computer terminal for implementing an IP asset management method is shown. Figure 21 As shown, the computer terminal 210 may include one or more processors 2102 (shown as 2102a, 2102b, ..., 2102n in the figure) 2102 (processor 2102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 2104 for storing data, and a transmission module 2106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 21 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 210 may also include... Figure 21 The more or fewer components shown, or having the same Figure 21 The different configurations shown.

[0213] It should be noted that the aforementioned one or more processors 2102 and / or other data processing circuitry are generally referred to herein as "data processing circuitry". This data processing circuitry may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 210. As involved in the embodiments of this application, this data processing circuitry serves as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).

[0214] The memory 2104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the IP asset management method in this embodiment. The processor 2102 executes various functional applications and data processing by running the software programs and modules stored in the memory 2104, thereby realizing the aforementioned IP asset management method. The memory 2104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 2104 may further include memory remotely located relative to the processor 2102, and these remote memories can be connected to the computer terminal 210 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0215] The transmission module 2106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 210. In one example, the transmission module 2106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission module 2106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0216] The display may be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 210.

[0217] It should be noted here that, in some optional embodiments, the above... Figure 21 The computer terminal shown may include hardware elements (including circuitry), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware and software elements. It should be noted that... Figure 21 This is only one instance of a specific particular instance, and is intended to illustrate the types of components that may exist in the aforementioned computer terminal.

[0218] It should be noted that, Figure 21 The computer terminal shown is used to execute Figure 2 The IP asset management method shown above applies to this electronic device as well, and will not be repeated here.

[0219] This application also provides a non-volatile storage medium, which includes a stored program, wherein the program, when running, controls the device where the storage medium is located to execute the above-mentioned IP asset management method.

[0220] A non-volatile storage medium performs the following functions: It retrieves the Address Resolution Protocol (ARP) table of the switches within the local area network (LAN), and generates an IP asset management table based on the target set in the ARP table. The target set includes at least: Internet Protocol (IP) addresses managed by the switches, Media Access Control (MAC) addresses, and the mapping between IP addresses and MAC addresses. The IP asset management table includes: the target set, the status of the IP addresses, the attributes of the IP addresses, and the IP addresses of the switches. The IP address status includes at least: occupied and unoccupied, and the IP address attributes include at least: service address. Based on the IP address status and IP address attributes... Bind IP addresses to their corresponding MAC addresses; determine the IP addresses whose states have changed based on ARP packets within the local area network, and generate an IP asset state transition table based on the state transition information of the IP addresses. The IP asset state transition table includes at least: the IP address, the MAC address corresponding to the IP address before the state change, the MAC address corresponding to the IP address after the state change, and the transition status, which includes: new terminal online and old terminal offline; display the IP asset state transition table, receive the review results of the IP asset state transition table, and manage the IP addresses based on the review results and the transition status.

[0221] This application also provides an electronic device, including a memory and a processor, wherein the processor is used to run a program stored in the memory, wherein the program executes the above-described IP asset management method during runtime.

[0222] The processor runs a program that performs the following functions: retrieves the Address Resolution Protocol (ARP) table of the switches within the local area network (LAN), and generates an IP asset management table based on the target set in the ARP table. The target set includes at least: Internet Protocol (IP) addresses managed by the switches, Media Access Control (MAC) addresses, and the mapping between IP addresses and MAC addresses. The IP asset management table includes: the target set, the status of the IP addresses, the attributes of the IP addresses, and the IP addresses of the switches. The IP address status includes at least: occupied and unoccupied, and the IP address attributes include at least: service address. Based on the IP address status and IP address attributes... Bind IP addresses to their corresponding MAC addresses; determine the IP addresses whose states have changed based on ARP packets within the local area network, and generate an IP asset state transition table based on the state transition information of the IP addresses. The IP asset state transition table includes at least: the IP address, the MAC address corresponding to the IP address before the state change, the MAC address corresponding to the IP address after the state change, and the transition status, which includes: new terminal online and old terminal offline; display the IP asset state transition table, receive the review results of the IP asset state transition table, and manage the IP addresses based on the review results and the transition status.

[0223] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0224] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0225] In the above embodiments of this application, the information collected is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data all comply with relevant laws, regulations and standards, take necessary protective measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.

[0226] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0227] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0228] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0229] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to related technologies, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0230] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. An IP asset management method characterized by, The method comprises: acquiring an address resolution protocol (ARP) table of a switch in a local area network, and generating an IP asset management table according to a target set in the ARP table, wherein the target set at least includes an internet protocol (IP) address managed by the switch, a media access control (MAC) address, and a correspondence between the IP address and the MAC address, the IP asset management table includes the target set, a state of the IP address, an attribute of the IP address, and an IP address of the switch, wherein the state of the IP address at least includes occupied and unoccupied, and the attribute of the IP address at least includes a service address; binding the IP address and the MAC address corresponding to the IP address according to the state of the IP address and the attribute of the IP address; determining an IP address whose state changes according to an ARP message in the local area network, and generating an IP asset state transition table according to a state transition of the IP address, wherein the IP asset state transition table at least includes the IP address, a MAC address corresponding to the IP address before a state change, a MAC address corresponding to the IP address after the state change, and a transition state, wherein the transition state includes a new terminal online and an old terminal offline; displaying the IP asset state transition table, receiving an audit result of the IP asset state transition table, and managing the IP address according to the audit result and the transition state; binding the IP address and the MAC address corresponding to the IP address according to the state of the IP address and the attribute of the IP address, comprising: reading the state of the IP address in the IP asset management table; if the read state of the IP address is unoccupied, reading the IP address and a switch IP address in the IP asset management table, logging in the switch using a first preset script based on a secure shell protocol, replacing the IP address with a first preset address, and replacing the MAC address corresponding to the IP address with a second preset address; if the read state of the IP address is occupied, finding the attribute of the IP address in the IP asset management table, and not performing any operation in a case where the attribute of the IP address is a network number, a gateway address, or a broadcast address; in a case where the attribute of the IP address is a service address, finding the IP address, the MAC address, and the switch IP address in the IP asset management table, and logging in the switch corresponding to the switch IP address using a first preset script based on a secure shell protocol, replacing the IP address with a third preset address, and replacing the MAC address corresponding to the IP address with a fourth preset address.

2. The method of claim 1, wherein, acquiring an address resolution protocol (ARP) table of a switch in a local area network, comprising: setting a first time window, wherein the length of the first time window is proportional to the number of nodes in the local area network; In the first time window, n time intervals are set, each of which has a length less than the ARP cache validity duration, and n is a positive integer greater than 1; According to the n time intervals, the ARP tables of the switches in the local area network are traversed to obtain n ARP tables.

3. The method of claim 2, wherein, According to the target set in the ARP table, an IP asset management table is generated, including: According to the n time intervals, it is judged whether the time for traversing the ARP table of the switch is reached; In the case where the time for traversing the ARP table of the switch is reached, the switch information of a first switch is read from a switch database, wherein the first switch is any one of the switches in the local area network; It is judged whether the switch information of a second switch can be read, wherein the second switch is other than the first switch in the local area network; If the switch information of the second switch cannot be read, the target set in the ARP table of the first switch is saved to the IP asset management table corresponding to the first switch; If the switch information of the second switch can be read, the second switch is logged in based on a remote login protocol or a secure shell protocol, and the ARP table of the second switch is viewed using a first preset ARP command, and the target set in the ARP table of the second switch is saved to the IP asset management table corresponding to the second switch.

4. The method of claim 1, wherein, An address resolution protocol (ARP) table of a switch in a local area network is obtained, and an IP asset management table is generated according to a target set in the ARP table, including: Step S1, a second time window is set, and an initial IP asset management table is generated; Step S2, it is judged whether the current time is in the second time window; Step S3, if the current time is in the second time window, all switches in the local area network are traversed; Step S4, it is judged whether there is a switch that has not been traversed; Step S5, in the case where there is a switch that has not been traversed, the network segment information of the switch under a three-layer interface is obtained, wherein the network segment information includes the IP address and the mask; According to the network segment information, the network number address, the gateway address, the broadcast address, and the service address of the switch are determined, wherein the service address is an IP address used by a terminal device of the switch; A first preset ARP command is used to obtain the correspondence between the IP address and the MAC address; According to the correspondence between the IP address and the MAC address, the network number address, the gateway address, the broadcast address, and the service address of the switch, the initial IP asset management table is updated to obtain the IP asset management table, and after the IP asset management table is obtained, step S4 is executed; Step S6, in the case where there is no switch that has not been traversed, step S2 is executed; Step S7, if the current time is not in the second time window, obtaining first IP address corresponding to the first information, and setting the state of the IP address of the first IP address in the IP asset management table to be occupied, wherein the first IP address is the IP address of the MAC address which can be found according to the corresponding relationship between the IP address and the MAC address, and the first information includes: the department corresponding to the first IP address, the name of the person in charge and the contact information of the person in charge; In the IP asset management table, the state of the IP address corresponding to the second IP address is set to be unoccupied, wherein the second IP address is the IP address of the MAC address which cannot be found according to the corresponding relationship between the IP address and the MAC address.

5. The method of claim 1, wherein, According to the ARP message in the local area network, the IP address whose state changes is determined, and an IP asset state transition table is generated according to the state transition of the IP address, including: Step S1, generating an initial IP asset state transition table, generating an initial host flow sending record table, and setting a target time length for obtaining the flow data of the switch; Step S2, judge whether to receive stop monitoring signal; Step S3, in the case where the stop monitoring signal is not received, obtaining the flow data of the switch, and adding the source address and message time information of each data packet in the flow data to the initial host flow sending record table to obtain a host flow sending record table; Step S4, judge whether the time length of the data recorded in the host flow sending record table is equal to the target time length; Step S5, in the case where the time length of the data recorded in the host flow sending record table is not equal to the target time length, judge whether the ARP message is included in the flow data, if the ARP message is included in the flow data, obtain the source IP address and the source MAC address of the ARP message, take the source IP address as a search condition, search the IP asset management table, and search the first MAC address corresponding to the source IP address in the searched IP asset management table; Step S6, judge whether the source MAC address is same as the first MAC address; Step S7, in the case where the source MAC address is not same as the first MAC address, taking the source IP address, the first MAC address, the switch IP address and the state of the IP address in the IP asset management table as a first newly added horizontal cell group, adding to the initial IP asset state transition table, and setting the transition state to new terminal online in the first newly added horizontal cell group; Step S8, in the case where the source MAC address is same as the first MAC address, repeating step S2 and step S3.

6. The method of claim 5, wherein, In the case where the time length of the data recorded in the host flow sending record table is equal to the target time length, the method further comprises: searching a target IP address in the IP asset management table, wherein the target IP address is an IP address that is not recorded in the IP asset state transition table and is in a state of being occupied within the target time length; adding the target IP address, a target MAC address corresponding to the target IP address, the switch IP address, and the state of the IP address as a second newly-added horizontal cell group to the IP asset state transition table, and setting the transition state as old terminal offline in the second newly-added horizontal cell group.

7. The method of claim 5, wherein, after obtaining the source IP address and the source MAC address of the ARP packet, the method further comprises: converting the source MAC address into first identification information; after searching for the first MAC address corresponding to the source IP address in the found IP asset management table, the method further comprises: converting the first MAC address into second identification information; determining whether the source MAC address and the first MAC address are the same, comprising: determining whether the first identification information and the second identification information are the same; after setting the transition state as new terminal online in the first newly-added horizontal cell group, the method further comprises: converting the first MAC address in the first newly-added horizontal cell group into first identification information.

8. The method of claim 1, wherein, managing the IP address according to the audit result and the transition state, comprising: for a first target IP address, logging into a switch corresponding to the first target IP address, unbinding the first target IP address and a MAC address before a state change of the first target IP address, binding the first target IP address and a MAC address after the state change of the first target IP address, and updating information of the first target IP address in the IP asset management table, wherein the first target IP address is an IP address whose audit result is passed, whose state is occupied, and whose transition state is new terminal online.

9. The method according to claim 1 or 8, characterized in that, managing the IP address according to the audit result and the transition state, comprising: for a second target IP address, logging into a switch corresponding to the second target IP address, unbinding the second target IP address and a MAC address before a state change of the second target IP address, replacing the second target IP address with a fourth preset address, and updating information of the second target IP address in the IP asset management table, wherein the second target IP address is an IP address whose audit result is passed, whose state is occupied, and whose transition state is old terminal offline.

10. The method of claim 1, wherein, managing the IP address according to the audit result and the transition state, comprising: For a third target IP address, log in a switch corresponding to the third target IP address, replace the third target IP address with a fifth preset address, bind the third target IP address with a changed MAC address corresponding to the third target IP address, and update information of the third target IP address in the IP asset management table, wherein the third target IP address is passed in the audit result, the state of the IP address is not occupied, and the transfer state is an IP address of a new terminal online.

11. An IP asset management apparatus, characterized by comprising: Comprise: A first generation module is configured to acquire an address resolution protocol (ARP) table of a switch in a local area network, and generate an IP asset management table according to a target set in the ARP table, wherein the target set at least includes an internet protocol (IP) address managed by the switch, a media access control (MAC) address, and a corresponding relationship between the IP address and the MAC address, the IP asset management table includes the target set, a state of the IP address, an attribute of the IP address, and an IP address of the switch, the state of the IP address at least includes occupied and not occupied, and the attribute of the IP address at least includes a business address; A binding module is configured to bind the IP address and the MAC address having the corresponding relationship according to the state of the IP address and the attribute of the IP address; A second generation module is configured to determine an IP address with a state transfer according to an ARP packet in the local area network, and generate an IP asset state transfer table according to a state transfer condition of the IP address, wherein the IP asset state transfer table at least includes the IP address, a MAC address before a state change of the IP address, a MAC address after the state change of the IP address, and a transfer state, and the transfer state includes a new terminal online and an old terminal offline; A processing module is configured to display the IP asset state transfer table, receive an audit result of the IP asset state transfer table, and manage the IP address according to the audit result and the transfer state. The binding module is further configured to read the state of the IP address in the IP asset management table, read the IP address and the switch IP address in the IP asset management table if the read state of the IP address is unoccupied, log in the switch using a first preset script based on a secure shell protocol, replace the IP address with a first preset address, and replace the MAC address corresponding to the IP address with a second preset address, and find the attribute of the IP address in the IP asset management table if the read state of the IP address is occupied, do not perform any operation if the attribute of the IP address is a network number, a gateway address or a broadcast address, find the IP address, the MAC address and the switch IP address in the IP asset management table if the attribute of the IP address is a service address, log in the switch corresponding to the switch IP address using a first preset script based on a secure shell protocol, replace the IP address with a third preset address, and replace the MAC address corresponding to the IP address with a fourth preset address.

12. A non-volatile storage medium, comprising: The non-volatile storage medium includes a stored program, wherein the program, when executed, controls a device in which the non-volatile storage medium is located to perform the IP asset management method of any one of claims 1 to 10.

13. An electronic device, comprising: comprise: a memory and a processor configured to execute a program stored in the memory, wherein the program, when executed, performs the IP asset management method of any one of claims 1 to 10.

14. A computer program product comprising a computer program, characterized in that, The computer program, when executed by a processor, implements the IP asset management method of any one of claims 1 to 10.

Citation Information

Patent Citations

  • Monitoring system and method for discovering survival assets based on switch login

    CN112819289A

  • Network equipment processing method and device, equipment and storage medium

    CN117955795A