A Method, Device, Equipment and Storage Medium for Dynamically Obtaining the Network-Terminal Relationship of XDR
By using five-tuple and four-tuple information to associate endpoint and network devices, the method addresses the inefficiencies in traditional XDR systems, improving association accuracy and efficiency, and enhancing threat detection and response.
Patent Information
- Application Number
- CN202411800893.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2044-12-09
AI Technical Summary
The existing XDR device association methods are inefficient in complex network environments and are vulnerable to attacks, unable to adapt to the dynamic changes in device behavior and activities, resulting in misjudgment and misjudgment.
By constructing an association relationship table, using five-tuple and four-tuple information comparison, we automatically identify network hierarchical relationships, merge data from EDR devices and NDR devices, and establish dynamic associations between terminals and network devices.
It improves the accuracy and efficiency of equipment association, reduces manual intervention, enhances the detection and response capabilities of security incidents, and adapts to dynamic network environments.
Smart Images

Figure CN119621856B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer information security, and in particular to a method, device, equipment and storage medium for dynamically obtaining the network-end relationship of XDR. Background Art
[0002] With the continuous development of information technology, the network security threats faced by enterprises are becoming increasingly complex and diverse. Traditional Security Operations Center (SOC) tools usually rely on a single security data source or control point, such as Endpoint Detection and Response (EDR) or Network Detection and Response (NDR). This makes the threat detection and response capabilities appear one-sided and difficult to cope with increasingly complex attack methods. The SOC is usually responsible for centrally managing and responding to various security threats, while the EDR and NDR focus on data analysis at the endpoint and network levels respectively. Although they can independently identify and respond to potential threats to a certain extent, their capabilities in integrating information at different levels still have limitations.
[0003] To make up for these deficiencies, Extended Detection and Response (XDR) technology has emerged. XDR integrates data from multiple security control points, integrates data from multiple levels such as endpoints, networks, and clouds, and provides cross-platform comprehensive security protection. The goal of XDR is to achieve more efficient and accurate threat detection and automatic response capabilities through comprehensive data integration and intelligent analysis. However, although XDR can integrate security data across domains, how to associate the activities and behaviors of devices at different security control points remains an urgent problem to be solved.
[0004] Most current device association schemes rely on multiple static or dynamic identifiers for association, such as IP addresses, MAC addresses, etc. However, these methods have some significant limitations: First, IP and MAC addresses change with the network environment and can be forged, resulting in an unstable device association process and being vulnerable to attacks; Second, a single static association identifier cannot fully reflect the dynamic changes of device behavior and activities and lacks the ability to adapt to complex network environments; Finally, due to differences in different network policies and configurations, existing association methods often cannot be applied in all scenarios, resulting in certain misjudgments and missed judgments, leading to low association efficiency. Summary of the Invention
[0005] The present invention provides a method, apparatus, device, and storage medium for dynamically obtaining the network-terminal relationship of XDR to solve the problem of low device association efficiency of existing XDR in complex network environments.
[0006] The present invention achieves the above object through the following technical solutions:
[0007] A method for dynamically obtaining the network-terminal relationship of XDR includes:
[0008] Construct an association relationship table in the database. The association relationship table includes a data ID and a network hierarchy relationship. The network hierarchy relationship includes the ID of the EDR device, the IP of the EDR device, the ID of the NDR device, and the IP of the NDR device;
[0009] Obtain first information, where the first information includes the five-tuple information and four-tuple information of all the EDR devices and NDR devices in the same network deployment architecture. The five-tuple information includes the source IP, destination IP, source port, destination port, and network transmission protocol. The four-tuple information includes any IP, source port, destination port, and network transmission protocol;
[0010] Judge the network hierarchy relationship between the EDR device and the NDR device, including comparing whether the five-tuple information of the EDR device and the NDR device is the same. If it is the same, it is determined that the EDR device and the NDR device are the same device and record the network hierarchy relationship in the association relationship table. If it is not the same, then compare whether the four-tuple information of the EDR device and the NDR device is the same. If it is the same, it is determined that the EDR device and the NDR device are the same device and record the network hierarchy relationship in the association relationship table;
[0011] Obtain second information, where the second information includes the device data of all the EDR devices and the NDR devices in the same network deployment architecture;
[0012] Merge the device data of the EDR device and the NDR device based on the association relationship table.
[0013] Further, obtaining the first information includes:
[0014] Receive the original five-tuple information and original four-tuple information of the EDR device and the NDR device in the same network deployment architecture;
[0015] Convert the original five-tuple information and the original four-tuple information into standard five-tuple information and standard four-tuple information respectively;
[0016] Perform time mapping analysis on the standard five-tuple information and standard four-tuple information to obtain the first information.
[0017] Further, after obtaining the first information and before determining the network hierarchy relationship between the EDR device and the NDR device, it further includes cutting the first information according to a preset time window and storing it in the database, and then determining the network hierarchy relationship between the EDR device and the NDR device within each time window.
[0018] Further, merging the device data of the EDR device and the NDR device based on the association relationship table includes:
[0019] Identifying the device data of all the EDR devices and the NDR device to obtain third information, where the third information is the ID of the EDR device corresponding to the device data of the EDR device and the NDR device, the IP of the EDR device, the ID of the NDR device, and the IP of the NDR device;
[0020] Filtering out the device data of the EDR device and the NDR device belonging to the same device according to the third information and the association relationship table;
[0021] Merging the device data of the EDR device and the NDR device belonging to the same device.
[0022] The present invention also provides a device for dynamically obtaining the network end relationship of XDR, including:
[0023] A construction module for constructing an association relationship table in the database, where the association relationship table includes a data ID and a network hierarchy relationship, and the network hierarchy relationship includes the ID of the EDR device, the IP of the EDR device, the ID of the NDR device, and the IP of the NDR device;
[0024] A first acquisition module for acquiring first information, where the first information includes the five-tuple information and four-tuple information of all the EDR devices and NDR devices in the same network deployment architecture, the five-tuple information includes the source IP, destination IP, source port, destination port, and network transmission protocol, and the four-tuple information includes any IP, source port, destination port, and network transmission protocol;
[0025] A judgment module for judging the network hierarchy relationship between the EDR device and the NDR device, including comparing whether the five-tuple information of the EDR device and the NDR device is consistent. If it is consistent, it is judged that the EDR device and the NDR device are the same device and the network hierarchy relationship is recorded in the association relationship table. If it is inconsistent, it is compared whether the four-tuple information of the EDR device and the NDR device is consistent. If it is consistent, it is judged that the EDR device and the NDR device are the same device and the network hierarchy relationship is recorded in the association relationship table;
[0026] A second acquisition module, which is used to acquire second information, and the second information includes device data of all the EDR devices and NDR devices in the same network deployment architecture;
[0027] A merging module, which is used to merge the device data of the EDR devices and NDR devices based on the association relationship table.
[0028] Further, the first acquisition module includes:
[0029] A receiving module, which is used to receive the original five-tuple information and original four-tuple information of the EDR devices and NDR devices in the same network deployment architecture;
[0030] A conversion module, which is used to convert the original five-tuple information and the original four-tuple information into standard five-tuple information and standard four-tuple information respectively;
[0031] A mapping module, which is used to perform time mapping analysis on the standard five-tuple information and standard four-tuple information to obtain the first information.
[0032] Further, the merging module includes:
[0033] An identification module, which is used to identify the device data of all the EDR devices and NDR devices to obtain third information, and the third information is the ID of the EDR device corresponding to the device data of the EDR device and NDR device, the IP of the EDR device, the ID of the NDR device, and the IP of the NDR device;
[0034] A screening module, which is used to screen out the device data of the EDR devices and NDR devices belonging to the same device according to the third information and the association relationship table;
[0035] A merging sub-module, which is used to merge the device data of the EDR devices and NDR devices belonging to the same device.
[0036] The present invention also provides an XDR network-end relationship dynamic acquisition device, including:
[0037] A memory, which is used to store a computer program;
[0038] A processor, which is used to implement the steps of the method for dynamically acquiring the network-end relationship of an XDR when executing the computer program.
[0039] The present invention also provides a storage medium, which is a readable storage medium. A computer program is stored on the storage medium, and when the computer program is executed by a processor, the steps of the method for dynamically obtaining the network-terminal relationship of a certain XDR are implemented.
[0040] The beneficial effects of the present invention are as follows:
[0041] By comparing the five-tuple and four-tuple information, the present invention automatically identifies the network hierarchical relationship, laying a foundation for the association between the terminal and the network device. This method does not rely on traditional complex association algorithms, and innovatively identifies the communication relationship between devices by comparing structured information, effectively reducing manual intervention and significantly improving the association efficiency. Description of the Drawings
[0042] Figure 1 It is a flowchart of the method for dynamically obtaining the network-terminal relationship of a certain XDR in the embodiment of the present application;
[0043] Figure 2 It is a schematic diagram of the association relationship table in the embodiment of the present application. Detailed Embodiments
[0044] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Components of the embodiments of the present invention described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.
[0045] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0046] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0047] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by terms such as "upper", "lower", "inner", "outer", "left", "right", etc. is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the inventive product is customarily placed during use, or the orientation or positional relationship commonly understood by those skilled in the art. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present invention.
[0048] In addition, terms such as "first", "second", etc. are only used for distinguishing descriptions and should not be understood as indicating or implying relative importance.
[0049] In the description of the present invention, it should also be noted that unless otherwise clearly specified and defined, terms such as "set", "connect" should be understood in a broad sense. For example, "connect" can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0050] In the present invention, the term "XDR" represents extended detection and response; "EDR" represents endpoint detection and response; "NDR" represents network detection and response.
[0051] The following will describe the specific embodiments of the present invention in detail with reference to the drawings.
[0052] As Figure 1 shown, a method for dynamically obtaining the network - endpoint relationship of XDR includes:
[0053] Construct an association relationship table in the database. The association relationship table includes a data ID and a network - level relationship. The network - level relationship includes the ID of the EDR device, the IP of the EDR device, the ID of the NDR device, and the IP of the NDR device. For example, the association relationship table is as Figure 2 shown. Where id represents the data ID, end - id represents the ID of the EDR device, end - ip represents the IP of the EDR device, net - id represents the ID of the NDR device, and net - ip represents the IP of the NDR device;
[0054] Data collection: Obtain the first information, where the first information includes the five-tuple information and four-tuple information of all the EDR devices and NDR devices in the same network deployment architecture. The five-tuple information includes source IP, destination IP, source port, destination port, and network transmission protocol. The four-tuple information includes any IP, source port, destination port, and network transmission protocol; Obtain the second information, where the second information includes the device data of all the EDR devices and NDR devices in the same network deployment architecture.
[0055] The device data includes: security events, security threats, and network anomalies of the EDR devices; security events, security threats, and network anomalies of the NDR devices.
[0056] Judge the network hierarchical relationship between the EDR device and the NDR device, including comparing whether the five-tuple information of the EDR device and the NDR device is consistent. If it is consistent, judge that the EDR device and the NDR device are the same device and record the network hierarchical relationship in the association relationship table. If it is not consistent, compare whether the four-tuple information of the EDR device and the NDR device is consistent. If it is consistent, judge that the EDR device and the NDR device are the same device and record the network hierarchical relationship in the association relationship table;
[0057] If the five-tuples of the terminal device and the network device are exactly the same, this indicates that the terminal device communicates directly with the network device using the original IP address without passing through an intermediate device or proxy server. In this case, the terminal device and the network device can be defined as the same device.
[0058] The XDR system will analyze the four-tuple information of the terminal device and the network device. The four-tuple includes any IP (source IP or destination IP), source port, destination port, and network transmission protocol. In this case, although the five-tuples of the terminal device and the network device are not exactly the same, if their four-tuple information is consistent, it also indicates that the EDR device and the NDR device are the same device. Different source IPs indicate that the source IP of the device recorded by the network device is the IP address of the upper-layer routing device of the network where the terminal device is located. There may be some network-level forwarding or proxying, and the communication between the terminal device and the network device does not occur directly but passes through some intermediate devices or proxies. Different destination IPs mean that the terminal device is accessing the IP address of the lower-layer routing device instead of directly accessing the destination IP address, involving network-level routing forwarding or destination proxy services.
[0059] Merge the device data of the EDR device and the NDR device based on the association relationship table.
[0060] The network deployment architecture mentioned above is a cloud deployment architecture.
[0061] By analyzing the data after merging the association relationship table, the present invention improves the data analysis efficiency, thereby quickly analyzing potential security threats and network anomalies, enhancing the understanding of the network environment, and strengthening the detection and response capabilities for security incidents.
[0062] In some embodiments, it is necessary to perform data preprocessing on the first information, that is, obtain the first information, including:
[0063] Receiving the original five-tuple information and original four-tuple information of the EDR device and the NDR device in the same network deployment architecture;
[0064] Converting the original five-tuple information and the original four-tuple information into standard five-tuple information and standard four-tuple information respectively;
[0065] Performing time mapping parsing on the standard five-tuple information and standard four-tuple information to obtain the first information. Perform unified formatting processing according to the recorded time to ensure the consistency and accuracy of the data time.
[0066] In some embodiments, the above data preprocessing means are also used to preprocess the second information.
[0067] In some embodiments, after obtaining the first information and before determining the network hierarchy relationship between the EDR device and the NDR device, it further includes cutting the first information according to a preset time window and storing it in the database, and then determining the network hierarchy relationship between the EDR device and the NDR device within each time window. The selection of the time window is based on the frequency of network traffic changes and the requirements of data analysis.
[0068] In some embodiments, based on the association relationship table, the device data of the EDR device and the NDR device are merged, including:
[0069] Identifying the device data of all the EDR devices and the NDR devices to obtain the third information, where the third information is the ID of the EDR device corresponding to the device data of the EDR device and the NDR device, the IP of the EDR device, the ID of the NDR device, and the IP of the NDR device;
[0070] Filtering out the device data of the EDR device and the NDR device belonging to the same device according to the third information and the association relationship table;
[0071] Merging the device data of the EDR device and the NDR device belonging to the same device.
[0072] The present invention also provides a device for dynamically obtaining the network-end relationship of XDR, including:
[0073] A building module for building an association relationship table in a database, where the association relationship table includes a data ID and a network hierarchy relationship, and the network hierarchy relationship includes the ID of the EDR device, the IP of the EDR device, the ID of the NDR device, and the IP of the NDR device;
[0074] A first acquisition module for acquiring first information, where the first information includes the five-tuple information and four-tuple information of all the EDR devices and NDR devices in the same network deployment architecture, the five-tuple information includes the source IP, destination IP, source port, destination port, and network transmission protocol, and the four-tuple information includes any IP, source port, destination port, and network transmission protocol;
[0075] A judgment module for judging the network hierarchy relationship between the EDR device and the NDR device, including comparing whether the five-tuple information of the EDR device and the NDR device is the same. If it is the same, it is judged that the EDR device and the NDR device are the same device and the network hierarchy relationship is recorded in the association relationship table. If it is not the same, then compare whether the four-tuple information of the EDR device and the NDR device is the same. If it is the same, it is judged that the EDR device and the NDR device are the same device and the network hierarchy relationship is recorded in the association relationship table;
[0076] A second acquisition module for acquiring second information, where the second information includes the device data of all the EDR devices and the NDR devices in the same network deployment architecture;
[0077] A merging module for merging the device data of the EDR device and the NDR device based on the association relationship table.
[0078] In some embodiments, the first acquisition module includes:
[0079] A receiving module for receiving the original five-tuple information and original four-tuple information of the EDR device and the NDR device in the same network deployment architecture;
[0080] A conversion module for converting the original five-tuple information and the original four-tuple information into standard five-tuple information and standard four-tuple information respectively;
[0081] A mapping module for performing time mapping analysis on the standard five-tuple information and standard four-tuple information to obtain the first information.
[0082] In some embodiments, the merging module includes:
[0083] An identification module, which is used to identify the device data of all the EDR devices and the NDR devices to obtain third information, where the third information is the ID of the EDR device corresponding to the device data of the EDR device and the NDR device, the IP of the EDR device, the ID of the NDR device, and the IP of the NDR device;
[0084] A screening module, which is used to screen out the device data of the EDR device and the NDR device belonging to the same device according to the third information and the association relationship table;
[0085] A merging sub-module, which is used to merge the device data of the EDR device and the NDR device belonging to the same device.
[0086] The present invention also provides a device for dynamically obtaining the network end relationship of XDR, including:
[0087] A memory for storing a computer program;
[0088] A processor, which is used to implement the steps of the method for dynamically obtaining the network end relationship of XDR when executing the computer program.
[0089] The present invention also provides a storage medium, which is a readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the method for dynamically obtaining the network end relationship of XDR are implemented.
[0090] Through the present invention above, the XDR system collects data from EDR (Endpoint Detection and Response) and NDR (Network Detection and Response), extracts the association relationships in the communication records, and through the association relationships, the XDR system can discover potential security threats and network anomalies, thereby enhancing the understanding of the network environment and enhancing the detection and response capabilities for security events.
[0091] It can be seen that according to the present invention, the XDR system can effectively compare and merge the records of terminal devices and network devices. The analysis of the five-tuple and four-tuple ensures the accuracy of communication between devices, and the merged asset information provides clear and consistent asset records. This method improves the accuracy and reliability of asset management, and helps with better network security and performance monitoring. It greatly improves the management efficiency of the XDR system and provides precise device data management support for network security. It ensures that the system can adapt to the dynamically changing network environment, and improves the efficiency and association accuracy of data analysis.
[0092] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.
Claims
1. A method for dynamically obtaining the network-side relationship of XDR, characterized in that, Including: Construct an association relationship table in the database. The association relationship table includes a data ID and a network hierarchy relationship. The network hierarchy relationship includes the ID of the EDR device, the IP of the EDR device, the ID of the NDR device, and the IP of the NDR device; Obtain first information, which includes the five-tuple information and four-tuple information of all the EDR devices and NDR devices in the same network deployment architecture. The five-tuple information includes the source IP, destination IP, source port, destination port, and network transmission protocol. The four-tuple information includes any IP, source port, destination port, and network transmission protocol; Obtain second information, which includes the device data of all the EDR devices and the NDR devices in the same network deployment architecture; Judge the network hierarchy relationship of the EDR device and the NDR device, including comparing whether the five-tuple information of the EDR device and the NDR device is consistent. If it is consistent, judge that the EDR device and the NDR device are the same device and record the network hierarchy relationship in the association relationship table. If it is inconsistent, compare whether the four-tuple information of the EDR device and the NDR device is consistent. If it is consistent, judge that the EDR device and the NDR device are the same device and record the network hierarchy relationship in the association relationship table; Merging the device data of the EDR device and the NDR device based on the association relationship table includes: identifying the device data of all the EDR devices and the NDR devices to obtain third information, where the third information is the ID of the EDR device, the IP of the EDR device, the ID of the NDR device, and the IP of the NDR device corresponding to the device data of the EDR device and the NDR device; screening out the device data of the EDR device and the NDR device that belong to the same device according to the third information and the association relationship table; merging the device data of the EDR device and the NDR device that belong to the same device.
2. The method for dynamically obtaining the network-side relationship of XDR according to claim 1, wherein, Obtaining the first information includes: Receiving the original five-tuple information and original four-tuple information of the EDR device and the NDR device in the same network deployment architecture; Respectively converting the original five-tuple information and the original four-tuple information into standard five-tuple information and standard four-tuple information; Performing time mapping analysis on the standard five-tuple information and the standard four-tuple information to obtain the first information.
3. The method for dynamically obtaining the network-side relationship of XDR according to claim 1 or 2, characterized in that After obtaining the first information and before judging the network hierarchy relationship of the EDR device and the NDR device, it further includes cutting the first information according to a preset time window and storing it in the database, and then judging the network hierarchy relationship of the EDR device and the NDR device within each time window.
4. A device for dynamically obtaining the network-side relationship of XDR, characterized in that, Including: A construction module, which is used to construct an association relationship table in the database. The association relationship table includes a data ID and a network hierarchy relationship. The network hierarchy relationship includes the ID of the EDR device, the IP of the EDR device, the ID of the NDR device, and the IP of the NDR device; A first acquisition module, which is used to acquire first information. The first information includes quintuple information and quadruple information of all the EDR devices and NDR devices in the same network deployment architecture. The quintuple information includes source IP, destination IP, source port, destination port, and network transmission protocol. The quadruple information includes any IP, source port, destination port, and network transmission protocol. A judgment module, which is used to judge the network layer relationship between the EDR device and the NDR device, including comparing whether the quintuple information of the EDR device and the NDR device is the same. If it is the same, it is judged that the EDR device and the NDR device are the same device and the network layer relationship is recorded in the association relationship table. If it is not the same, then compare whether the quadruple information of the EDR device and the NDR device is the same. If it is the same, it is judged that the EDR device and the NDR device are the same device and the network layer relationship is recorded in the association relationship table. A second acquisition module, which is used to acquire second information. The second information includes device data of all the EDR devices and the NDR devices in the same network deployment architecture. A merging module, which is used to merge the device data of the EDR device and the NDR device based on the association relationship table. The merging module includes: An identification module, which is used to identify the device data of all the EDR devices and the NDR devices to obtain third information. The third information is the ID of the EDR device corresponding to the device data of the EDR device and the NDR device, the IP of the EDR device, the ID of the NDR device, and the IP of the NDR device. A screening module, which is used to screen out the device data of the EDR device and the NDR device belonging to the same device according to the third information and the association relationship table. A merging sub-module, which is used to merge the device data of the EDR device and the NDR device belonging to the same device.
5. The dynamic acquisition device for XDR network-side relationships according to claim 4, characterized in that The first acquisition module includes: A receiving module, which is used to receive the original quintuple information and the original quadruple information of the EDR device and the NDR device in the same network deployment architecture. A conversion module, which is used to convert the original quintuple information and the original quadruple information into standard quintuple information and standard quadruple information respectively. A mapping module, which is used to perform time mapping analysis on the standard quintuple information and the standard quadruple information to obtain the first information.
6. A device for dynamically obtaining the network-side relationship of XDR, characterized in that, It includes: A memory, which is used to store computer programs. A processor, which is used to implement the steps of a method for dynamically obtaining the network end relationship of XDR as described in any one of claims 1 to 3 when executing the computer program.
7. A storage medium, characterized in that, The storage medium is a readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of a method for dynamically obtaining the network end relationship of XDR as described in any one of claims 1 to 3 are implemented.
Citation Information
Patent Citations
System and method for automated integration of endpoint detection and response (EDR) data to open extended detection and response (XDR) framework
US20230252134A1
Data processing method and apparatus
WO2021244449A1