A distributed network data asset penetration security detection method, system and storage medium

By employing a distributed network data asset penetration security detection method, combined with block encryption and random process theory, a multimodal detection package is constructed for asset detection. This solves the problem of existing technologies being unable to identify anonymized assets, and achieves efficient and secure network data asset management.

CN119696876BActive Publication Date: 2026-01-02JINQICHUANG (BEIJING) TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411821308.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-11
Publication Date
2026-01-02
Estimated Expiration
2044-12-11

AI Technical Summary

Technical Problem

Existing network data asset detection processes are unable to effectively detect both actively and passively anonymized assets, resulting in uncontrolled network data assets in cyberspace, making it impossible to pinpoint the source of threats and impacting network security.

Method used

A distributed network data asset penetration security detection method is adopted. The total traffic log is obtained through the detection node. Multimodal detection packets are constructed by combining block encryption and behavior-induced detection methods. Based on the random process theory, the random sending sequence and jump strategy are determined, and the detection packets are sent to unoccupied IP addresses to detect assets.

Benefits of technology

It improves detection efficiency and accuracy, effectively identifies hidden assets, avoids detection packets being hijacked and blocked by firewalls, and ensures the security and management precision of the network environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119696876B_ABST
    Figure CN119696876B_ABST
Patent Text Reader

Abstract

The application provides a kind of distributed network data asset penetration security detection method and system, it is related to data processing technical field.The method comprises: obtaining the total flow log in the detection range;Mark the network data asset of known IP address occupation, and record the first flow log of the network data asset of known IP address occupation;Construct multi-modal detection package;Determine the sending strategy, and send the multi-modal detection package according to the sending strategy to the IP address not occupied, to carry out asset detection;Analyze response information, obtain the occupation IP address and network data asset type corresponding to the response information, and obtain the second flow log of the occupation IP address corresponding to the response information;Until the sum of the flow amount of the first flow log and the second flow log is equal to the flow amount of the total flow log;Mark the occupation IP address and the network data asset type corresponding to the marked occupation IP address are output. Improve detection accuracy and coverage.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, in particular to a distributed network data asset penetration security detection method and system. BACKGROUND

[0002] Distributed network data assets refer to various data and device resources that exist in a distributed network environment. These assets include databases, servers, virtual machines, network devices, Internet of Things devices, applications, and disaster recovery systems, etc., which are distributed in multiple physical or logical locations and connected through networks for intercommunication and resource sharing. Due to the architecture of distributed networks, the storage, management, and access of these assets are scattered and may span different geographical locations or cloud platforms.

[0003] Network data asset detection is a technology or process for scanning, identifying, and classifying various data and device resources in a network. Through detection, active devices, occupied IP addresses, asset types (such as servers, databases, etc.), service states, and traffic information can be discovered. The goal of network data asset detection is to comprehensively understand all data assets in the network to ensure the management, security, and controllability of these assets. Network data asset detection can help organizations identify and manage various resources in a distributed environment, promptly discover unauthorized or potential "ghost assets", and avoid data leaks or network threats caused by uncontrolled assets. Through comprehensive detection and management of network assets, organizations can improve data security, optimize resource allocation, and reduce operational risks, thereby ensuring the overall health and business continuity of the network.

[0004] However, existing network data asset detection processes are often passive detection methods under the assumption that network data assets will generate traffic information, which cannot detect active and passive anonymized assets, and even if network data assets have traffic information, they cannot be accurately traced, which leads to uncontrolled network data assets in the network space, and when network anomalies occur, the threat source cannot be locked, posing a great threat to network security. SUMMARY

[0005] To solve the technical problem that the existing network data asset detection process is often a passive detection method under the assumption that network data assets will generate traffic information, which cannot detect active and passive anonymized assets, and even if network data assets have traffic information, they cannot be accurately traced, which leads to uncontrolled network data assets in the network space, and when network anomalies occur, the threat source cannot be locked, posing a great threat to network security, the present application provides a distributed network data asset penetration security detection method and system.

[0006] The technical scheme provided by the embodiment of the application is as follows:

[0007] The first aspect

[0008] The distributed network data asset penetration security detection method provided by the embodiment of the application is applied to a network data asset detection platform, wherein the network data asset detection platform comprises a plurality of detection nodes located at a core switch and a resource scheduling node located in the cloud, each detection node is connected with the resource scheduling node, and the method comprises the following steps:

[0009] S1: acquiring total flow logs in a detection range through the detection nodes, wherein the detection range is a set of IP addresses provided by the core switch;

[0010] S2: marking network data assets occupying known IP addresses and recording first flow logs of the network data assets occupying the known IP addresses;

[0011] S3: constructing a multi-modal detection packet in combination with a block encryption mode and a behavior induction detection mode;

[0012] S4: determining a sending strategy with a random sending time sequence and a random jump strategy based on a random process theory, and sending the multi-modal detection packet to unoccupied IP addresses in the detection range through the core switch according to the sending strategy to perform asset detection;

[0013] S5: in the case that response information is received, entering step S6, otherwise, changing the sending strategy and returning to step S4;

[0014] S6: analyzing the response information, acquiring the occupied IP addresses and network data asset types corresponding to the response information, and acquiring second flow logs of the occupied IP addresses corresponding to the response information;

[0015] S7: marking and removing all occupied IP addresses, updating the set of IP addresses, i.e., updating the detection range, returning to step S4, and continuing until the sum of flow amounts of the first flow logs and the second flow logs is equal to the flow amount of the total flow logs;

[0016] S8: outputting the marked occupied IP addresses and the network data asset types corresponding to the marked occupied IP addresses, and completing the detection of the network data assets.

[0017] The second aspect

[0018] The distributed network data asset penetration security detection system provided by the embodiment of the application comprises:

[0019] a processor;

[0020] A memory having computer readable instructions stored thereon, the computer readable instructions, when executed by the processor, implement the distributed network data asset penetration security detection method according to the first aspect.

[0021] Third aspect

[0022] The embodiment of the present application provides a computer readable storage medium, and a computer program is stored on the computer readable storage medium. The program is executed by a processor to implement the distributed network data asset penetration security detection method according to the first aspect.

[0023] The technical scheme provided by the embodiment of the present application has at least the following beneficial effects:

[0024] In the present application, active detection and passive detection are combined, passive detection is used to screen out unoccupied IP addresses that cannot be determined in the initial stage, and then the detection completeness is judged based on the traffic log, and the state that the traffic log is consistent with the traffic amount of the known occupied IP address is used as a detection termination flag. This detection method can greatly improve the detection efficiency and determine the clear detection cycle period, and avoid the influence of continuous invalid detection on the normal operation of network assets. In the detection process, the multi-modal detection packet is constructed by combining the block encryption mode and the recursive behavior induction detection method, the sending strategy with random sending time sequence and random jump strategy is determined based on the random process theory, and the multi-modal detection packet is sent to the unoccupied IP addresses in the detection range through the core switch according to the sending strategy, so that asset detection is performed. It can avoid that the detection packet becomes a hijacking target to threaten the safety of the detection target, and can effectively evade the firewall of the detection target with a dynamic and random sending strategy, avoid being identified as abnormal traffic by the firewall or detection system, and gradually induce anonymous asset response and issue asset type in a cycle to complete the security detection of the asset, improve the detection accuracy and coverage, and improve the network environment security. BRIEF DESCRIPTION OF DRAWINGS

[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0026] Figure 1 A flowchart of a distributed network data asset penetration security detection method provided by the embodiment of the present application is shown in the figure.

[0027] Figure 2 A structure diagram of a network data asset detection platform provided by the embodiment of the present application is shown in the figure.

[0028] Figure 3 A structural schematic diagram of a distributed network data asset penetration security detection system provided by an embodiment of the present application is provided. DETAILED DESCRIPTION

[0029] The technical solutions in the present application will be described below with reference to the drawings.

[0030] In the embodiments of the present application, the words such as "example", "for example" are used to represent an example, illustration or description. Any embodiment or design scheme described as "example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the word "example" is intended to present the concept in a specific manner. In addition, in the embodiments of the present application, the meaning expressed by "and / or" can be both, or can be either one of the two.

[0031] To make the technical problems, technical solutions and advantages of the present application clearer, the following will be described in detail with reference to the drawings and specific embodiments.

[0032] Reference is made to the accompanying drawings in the description of the present application. Figure 1 Fig. 1 shows a flowchart of a distributed network data asset penetration security detection method provided by an embodiment of the present application.

[0033] Reference is made to the accompanying drawings in the description of the present application. Figure 2 Fig. 2 shows a structural schematic diagram of a network data asset detection platform provided by an embodiment of the present application.

[0034] The present application provides a distributed network data asset penetration security detection method, which is applied to a network data asset detection platform, wherein the network data asset detection platform comprises a plurality of detection nodes located at core switches and a resource scheduling node located in the cloud, and each detection node is connected with the resource scheduling node.

[0035] The detection node is located in a core switch or a router, and is used for directly monitoring and acquiring network traffic. Since the core switch and the router are the key hubs of the network, all traffic passes through these devices, so that the detection node can capture the most network device information. The resource scheduling node is located in the cloud, and is responsible for dynamically allocating tasks of the detection nodes, preventing node overload and ensuring load balancing of the detection tasks.

[0036] The processing flow of the distributed network data asset penetration security detection method can comprise the following steps:

[0037] S1: acquiring total traffic logs in a detection range by the detection node.

[0038] The detection range is a set of IP addresses provided by the core switch.

[0039] The total flow log refers to a record of all flow data collected by the probe node in the network. The log contains communication information of all devices in the network, records flow activity of each IP address, time of data transmission, size of data packet, protocol type and other detailed information, and the role of the total flow log is to help identify and analyze all activities in the network, so as to understand the network behavior of different devices. The IP address set refers to a list of all active IP addresses provided by the core switch, and the set defines the probe range, that is, the probe node will monitor and record the flow in the set.

[0040] In a possible implementation, after S1 and before S2, further comprising:

[0041] Clustering the IP addresses in the total flow log according to flow amount.

[0042] Specifically, clustering the IP addresses in the total flow log according to flow amount by combining flow information and the Kuramoto model is specifically:

[0043] First, each flow amount recorded in the total flow log is initialized as a vibrator. Then, the Gaussian kernel coupling strength function between vibrators is determined:

[0044]

[0045] Wherein, σ represents the Gaussian kernel width parameter, exp represents the exponential function, K(i,j) represents the Gaussian kernel coupling strength value between the flow amount x i of the i-th vibrator and the flow amount x j of the j-th vibrator. Then, the vibrator phase is updated at the discrete time step by combining the Gaussian kernel coupling strength value:

[0046]

[0047] Wherein, Δt represents the discrete time step, θ i (t) and θ i (t+1) represent the vibrator phase of the i-th vibrator at time t and time t+1, respectively, ω0 represents the vibrator inherent frequency of the i-th vibrator, N represents the total number of vibrators, and θ j represents the vibrator phase of the j-th vibrator at time t. In the clustering process, the order parameter is used to determine the synchronization state of all vibrators. If the order parameter value is greater than the preset order parameter value, the clustering is stopped, the cluster is divided, otherwise, the Gaussian kernel width parameter is increased, and the clustering is performed again. The order parameter is calculated as follows:

[0048]

[0049] Wherein, r represents the order parameter value of the vibrator set, θi denotes the phonon phase of the i-th phonon, and || denotes taking the absolute value.

[0050] Finally, the phonons are divided based on the phonon density to obtain a plurality of clusters, wherein each cluster corresponds to a self-clustering region:

[0051]

[0052] C = S(p ij ), p ij ≥ p 期望 , S(p ij ) ≥ S 期望 (p ij )

[0053] wherein [θ i , θ j ] denotes the number of phonons whose phonon phases are located between the phonon phase θ i of the i-th phonon and the phonon phase θ j of the j-th phonon, p ij denotes the phonon number density between θ i and θ j , p 期望 denotes a preset phonon number density, C denotes a cluster set comprising a plurality of clusters, S denotes the number of clusters in the cluster set C, and S 期望 denotes a preset cluster number.

[0054] It should be noted that this step clusters the IP addresses in the total flow log by flow amount to discover network assets with similar flow patterns. Using the Kolmoto model combined with the coupling strength of the Gaussian kernel to cluster the flow data can detect the data synchronization patterns in the network, helping to identify devices with similar behavior characteristics. By adjusting the Gaussian kernel width parameter and using the synchronization state of the phonon phase for dynamic clustering, the system can more accurately divide the self-clustering region, thereby identifying hidden ghost assets and abnormal flow patterns, improving the comprehensiveness and accuracy of network data asset detection.

[0055] S2: Label the network data assets occupying the known IP addresses and record the first flow log of the network data assets occupying the known IP addresses.

[0056] wherein the network data assets occupying the known IP addresses are a set comprising all network data assets with flow information and whose IP addresses are also explicitly known. By analyzing the total flow log, all known network data assets with flow information and explicit IP addresses are labeled. In this process, the system classifies these known assets occupying IP addresses into a set and records their first flow log, providing baseline data for comparison and identification in the subsequent detection process.

[0057] In a possible implementation, the network data assets include databases, network devices, servers, virtual machines, application programs, Internet of Things devices, and disaster recovery systems.

[0058] It can be understood that these asset types represent the main data carriers and service nodes in modern networks, and constitute the core foundation of distributed networks. By identifying and managing these assets, the security and operational stability of the network can be more comprehensively guaranteed.

[0059] S3: Construct a multi-modal detection package combining a block encryption method and a behavior-induced detection method.

[0060] The block encryption method is a method of dividing data into multiple independent blocks and encrypting each block separately. This method not only enhances the security of data transmission, but also can locate the specific damaged block and perform self-destruction or retransmission when hijacked or tampered with, ensuring the integrity and security of the overall data. Common block encryption algorithms include AES and DES. The behavior-induced detection method is a detection method that induces requests recursively to guide the target device to provide key information when responding. It uses specific request types (such as description requests, identity verification requests, etc.) to induce the target network asset to respond to its type and state, in order to identify hidden or disguised "ghost assets".

[0061] The detection package can perform penetrating detection on ghost assets and has the ability of autonomous verification and autonomous release. If the detection package is hijacked and implanted with a virus during transmission, it will automatically destroy itself and modify the detection package encryption field and method, and then resend the detection package. This ensures the safety of the active detection process and avoids the detection information becoming a hijacking target network risk. The detection package can induce ghost assets to describe their own network data asset types when responding.

[0062] In a possible implementation, S3 specifically includes:

[0063] S301: Obtain the detection target IP address:

[0064]

[0065] Wherein, A unknown represents the detection target IP address, i.e., the set of unoccupied IP addresses, IP v represents the vth detection target IP address, A total represents the set of IP addresses, A known represents the set of occupied IP addresses.

[0066] S302: determine the probe packet content with the behavior induction probe mode, wherein the probe packet content includes a recursive form of induction request type, and the recursive form of induction request type includes a description request, an identity authentication request, a state check request and a configuration check request in the form of execution order arrangement:

[0067]

[0068] wherein P represents the probe packet content, D, I, S and C represent the description request, the identity authentication request, the state check request and the configuration check request respectively, and → represents the execution order, represents the inclusion.

[0069] wherein the description request is sent to the target device and requires the return of basic description information of the device, such as device type (router, server, etc.), operating system version, device model, etc. This is a basic request, which aims to preliminarily identify the type and manufacturer of the device, and the request can be GET / system / info or SNMP sysDescr. The identity authentication request can observe whether the target device responds to the identity authentication request or returns relevant authentication information by attempting to log in or performing a handshake, and the request can be SSH login attempt or TLS / SSL handshake. The state check request is used to check the real-time state of the device, which can be ICMP ping request or SNMP ifOperStatus. The configuration check request queries the network configuration information of the device, such as IP address, subnet mask, gateway or routing table. This can help understand the network topology position of the device and its connection relationship with other devices, and the request can be GET / network / config or SNMP IP Routing Table. This phased request type gradually guides the device to feedback information from basic information to configuration details, which can effectively improve the response rate. The basic description and state requests are usually unrestricted, while the identity authentication and configuration requests have certain security requirements. This design can help the probe packet collect more device information while avoiding triggering too many security alerts. In the formula, the parentheses represent recursive operations, i.e. each request can be repeated as needed. This ensures that if the initial request does not obtain the expected response, the request parameters can be adjusted recursively and re-sent according to the feedback, thereby increasing the probability of obtaining an effective response. This recursive induction request type is arranged in the order of execution and gradually guides the target device to gradually obtain basic to advanced device information. Each request is designed to be relatively simple, and the device will usually respond. This induction strategy gradually guides the target device to feedback information while minimizing the possibility of device denial of response, thereby effectively improving the coverage and accuracy of the probe.

[0070] S303: Block encryption is performed on the probe packet content, and the encryption method is as follows:

[0071]

[0072] H probe = hash(E(P) || N)

[0073]

[0074] wherein P i represents the i-th probe packet content block, i = 1, 2, …, n, n represents the total number of probe packet content blocks, E represents the encrypted probe packet content after encryption of the probe packet content P, K represents the dynamic key, K' represents the updated dynamic key, K i represents the dynamic key corresponding to the i-th probe packet content block, CustomEncrypt(P, K) represents a custom encryption algorithm for P and the dynamic key K, H(N) represents the hash value of the random value N, represents the bitwise XOR operation, represents the bitwise XOR operation from i = 1 to i = n, Enc Block (P i , K i ) represents encryption of each block P i using the corresponding dynamic key K i , H probe represents the integrity hash value for verification, hash represents the hash operation, || represents the concatenation operation, H received represents the actual hash value received, if represents the conditional part, then represents the execution part, self_destruct represents the self-destruction operation, E' represents the encrypted probe packet content obtained by encrypting the probe packet content using the updated dynamic key, and send represents the sending operation.

[0075] It should be noted that this encryption method has an anti-hijacking and self-destruction encryption formula, which has the ability of autonomous verification and autonomous release. If the probe packet is hijacked and implanted with a virus during transmission, it will be automatically destroyed and the probe packet encryption field and method will be modified. This encryption method protects the integrity and security of the probe packet through block encryption and dynamic key updating. The probe packet content is divided into multiple blocks, each block is encrypted using an independent dynamic key, and a hash value of a random value is XORed. The hash value generated by the encryption result is used for self-verification to detect whether tampering has occurred. If the verification fails, the system will trigger a self-destruction operation and automatically regenerate and send the encrypted probe packet. This mechanism ensures that even if the probe packet is hijacked or tampered with during transmission, it can be automatically destroyed or updated, effectively preventing data from being maliciously intercepted and tampered with.

[0076] In particular, for each block P i The algorithm for encryption can be AES or DES in particular. i

[0077] In one possible implementation, the dynamic key updating method is as follows:

[0078]

[0079] U = hash(RNG‖T)

[0080] wherein K b ' ase denotes the generated reference key, RNG denotes a strong random number generator, T denotes a current timestamp, U denotes a unique identifier about T and RNG, and K' denotes the updated dynamic key.

[0081] Optionally, the hash function can be SHA-256, and the strong random number generator can be UUIDv4.

[0082] It should be noted that in this encryption scheme, the dynamic key is updated by the combination of the reference key, the unique identifier, and the timestamp. The reference key is generated by the hash value of the initial key and the random value. Then, the dynamic key is further updated by the hash value of the reference key, the timestamp, and the unique identifier. The unique identifier is generated by the hash value of the strong random number generator and the current timestamp. This dynamic key updating mechanism enhances security, makes the key random and time-dependent, and effectively prevents key leakage and data hijacking.

[0083] S304: Combine the probe target IP address and the encrypted probe packet content to obtain a multi-modal probe packet:

[0084] P * = [IP v E]

[0085] wherein P * denotes the multi-modal probe packet.

[0086] S4: Determine a sending strategy with random sending timing and random jump strategy based on random process theory, and send the multi-modal probe packet to unoccupied IP addresses in the probe range through the core switch according to the sending strategy for asset detection.

[0087] ​Among them, the random process theory is a mathematical method for studying the random changes of a system or process over time or space. It is used to describe and predict the probability distribution of event occurrence, so that each step in the process is a random result dependent on the previous state. Random sending timing is a way to randomly select the sending time point within a certain time interval. By randomizing the sending timing, the fixedness of the sending mode can be avoided, making the sending of probe packets more covert and reducing the risk of being detected or blocked by the firewall. The random jump strategy refers to the strategy of randomly selecting the next action between different probe stages according to the feedback results. By randomly adjusting the jump during the probe process, such as switching protocols or changing the sending frequency, the diversity of the probe can be increased, making it difficult for defense mechanisms to predict and block. It should be noted that the random process theory is used to design a probe strategy with dynamic adjustment capability, making the probe behavior more random and difficult to be detected by the firewall.

[0088] For non-responsive asset devices, most of them are blocked by the firewall. In order to deal with this situation, a probe strategy with dynamic adjustment capability is designed using the random process theory, making the probe behavior more random and difficult to be detected by the firewall, in order to deal with those ghost network assets (i.e. traffic information is difficult to monitor, and even if the probe packet is received, it will deliberately pretend not to receive and not respond), to improve the detection coverage and accuracy of network assets.

[0089] In one possible implementation, the random process theory includes a conditional probability model based on probe feedback results and a Poisson process theory. S4 specifically includes:

[0090] S401: Determine the jump probability between different probe stages based on the probe feedback results, wherein the probe stages include the initial probe stage, the non-response retry stage, the protocol switching stage and the increasing sending frequency stage, the probe feedback results include the response, the non-response and the protocol error, and each jump probability constitutes a random jump strategy:

[0091]

[0092] wherein F acc represents the cumulative feedback value, k represents the feedback trace step, ln represents the natural logarithm, respectively represent the tth response probe feedback result, the non-response probe feedback result and the protocol error probe feedback result with a value of 1, P jump (S i → S j represents the jump probability from the ith probe stage S i to the jth probe stage S j , S1, S2, S3 and S4 respectively represent the initial probe stage, the non-response retry stage, the protocol switching stage and the increasing sending frequency stage.

[0093] where feedback backtracking step represents the considered historical feedback depth. exp(Rresp+0.5R prot_crr ) considers the nonlinear feedback effect of response and protocol error, enhancing the sensitivity of jump. ln(1+F acc ) accumulates the feedback effect by logarithmic processing, making the jump probability gradually increase after multiple non-responses. represents the exponential processing of non-response feedback, making the jump probability gradually decrease with the increase of non-response times.

[0094] where the initial detection stage is the starting stage of the detection process, and the system sends detection packets with default parameters and sending frequency. When the detection packet does not receive a response, the system enters the non-response retry stage, and tries to obtain a response again by adjusting the sending parameters and re-sending the detection packet. The goal of this stage is to re-try detection in a slightly different way, which may increase the sending frequency or change the content of the detection packet to cope with the situation of being shielded by the firewall or network anomaly. In the case of multiple non-responses, the system will switch the detection protocol (for example, from ICMP to TCP or UDP) to avoid detection being blocked by the firewall or other security devices, that is, the protocol switching stage. In the case of repeated non-responses, the system will gradually increase the sending frequency of detection packets to ensure coverage to the target asset. By increasing the sending frequency, the system can improve the detection success rate in a shorter time, but also needs to pay attention to not triggering security alerts.

[0095] It should be noted that the jump probability of each detection stage is dynamically adjusted by the conditional probability model based on the detection feedback results and the random process theory. Specifically, it combines response, non-response, protocol error and other feedback types to generate a cumulative feedback value, which determines the jump strategy from the initial detection to the non-response retry, protocol switching, and increasing sending frequency stages. This process ensures that the detection packet can be adjusted flexibly when facing different response situations, maximizing the success rate and coverage of detection.

[0096] S402: Combine the cumulative feedback value to determine the jump interval between different detection stages by Poisson process theory, and each jump interval constitutes a random sending time sequence:

[0097]

[0098] T i =T i (0) ·(1+A i )+D i

[0099]

[0100]

[0101] A i = sin(F acc ) + cos 2 (F acc ) + ln(1 + |F acc |)

[0102] wherein L i denotes the triggering time of the i-th jump in the random sending timing, T i denotes the time interval between the i-th jump and the (i-1)-th jump, T i-1 denotes the time interval between the (i-1)-th jump and the (i-2)-th jump, T i (0) denotes the initial jump interval of the i-th jump generated based on the Poisson distribution, D i denotes the perturbation term of the i-th jump, A i denotes the feedback adjustment term of the i-th jump, U i and U i-1 denote the uniform random numbers in the interval (0, 1) introduced in the i-th jump and the (i-1)-th jump, respectively, and || denotes the absolute value.

[0103] It should be noted that based on the Poisson process theory, the jump intervals between different detection stages are dynamically calculated by accumulating the feedback values to form the random sending timing. Specifically, it adjusts the jump time interval in combination with the detection results, adds the perturbation term and the feedback term, so that the detection behavior has the randomness and dynamic adjustment ability in time. This mechanism not only improves the concealment of detection, but also effectively avoids the risk that the detection packet is intercepted or filtered by the firewall due to the fixed sending interval.

[0104] S403: Send the multi-modal detection packet to the unoccupied IP address in the detection range according to the sending strategy composed of the random sending timing and the random jump strategy, to perform asset detection.

[0105] It should be noted that the designed dynamically adaptive detection strategy enables the detection packet to flexibly cope with the response situation of different network assets. The feedback results are used to adjust the jump probability between each detection stage, so that the detection process reasonably jumps according to the response (if there is a response, no response, protocol error). The random sending interval is calculated by using the Poisson process, and the perturbation and feedback adjustment are added, so that the detection timing is more unpredictable, avoiding being identified and intercepted by the firewall rule. Finally, these jump strategies and random timing are combined to dynamically send multi-modal detection packets, covering the unoccupied addresses in the target IP range, to achieve higher detection success rate and security.

[0106] In a possible implementation, after S4, the method further includes:

[0107] The computing resource consumption proportion of each detection node is monitored to maintain the computing resource consumption proportion of the detection node less than the preset computing resource consumption proportion as a target, and the computing resource is divided to different detection nodes by the resource scheduling node.

[0108] It should be noted that by monitoring the computing resource consumption proportion of each detection node, the load thereof is ensured to be kept below the preset threshold. The resource scheduling node dynamically allocates the computing resource, and transfers the overloaded task to other detection nodes to realize balanced allocation of the resource, thereby avoiding overload of a single node and improving the overall efficiency and stability of the detection system. Specifically, the size of the preset computing resource consumption proportion can be set by a person skilled in the art according to actual needs, which is not limited in the present application.

[0109] S5: In the case of receiving the response information, step S6 is entered, otherwise, the sending strategy is changed and step S4 is returned.

[0110] It should be noted that whether the response information of the target is received is judged to determine the subsequent operation of the detection process. If the response information is received, the analysis step S6 is entered. If no response is received, the sending strategy is modified and step S4 is returned, and the sending mode is adjusted to re-perform the detection attempt, thereby improving the success rate and coverage of the detection.

[0111] S6: The response information is analyzed to obtain the occupied IP address and the network data asset type corresponding to the response information, and the second flow log of the occupied IP address corresponding to the response information is obtained.

[0112] It should be noted that the received response information is analyzed in detail to extract the corresponding occupied IP address and the type of network data asset, and the second flow log of the IP address is recorded. This step provides a necessary data basis for subsequent analysis and comparison, which is helpful for further confirming whether the detection process is completed.

[0113] S7: All occupied IP addresses are marked and removed, the IP address set is updated, that is, the detection range is updated, and step S4 is returned until the sum of the flow amounts of the first flow log and the second flow log is equal to the flow amount of the total flow log.

[0114] It should be noted that the confirmed occupied IP address is marked and removed from the detection range, and the IP address set is updated, thereby reducing the subsequent detection range. The process is executed in a loop until the total amount of the first flow log and the second flow log is equal to the flow amount of the total flow log, ensuring that all network data assets are effectively identified and recorded.

[0115] S8: The marked occupied IP address and the network data asset type corresponding to the marked occupied IP address are output, and the detection of the network data asset is completed.

[0116] In practical application, the scheme can comprehensively detect and identify data assets in a distributed network. Specifically, first, the total traffic log and IP address set are obtained through the detection node to determine the active devices in the network. Then, known network data assets are marked and initial traffic information is recorded. Multi-modal detection packets are constructed through block encryption and behavior induction to ensure the security of data transmission and the effectiveness of detection. Random process theory is used to design random sending timing and hopping strategies to improve the concealment and coverage of detection. According to the detection results, if there is a response, the asset information and the second traffic log are analyzed and obtained, and if there is no response, the strategy is adjusted and retried. In the process of continuously updating the detection range and IP address set, it is ensured that all traffic log information is covered. Finally, the confirmed network data assets are output to achieve efficient and accurate asset management. Through dynamic adjustment, penetrating detection and recursive verification, hidden assets can also be detected, improving the security and management accuracy of the network.

[0117] In a possible implementation, after S8, the method further includes:

[0118] Setting an asset detection trigger event, wherein the asset detection trigger event is triggered when the difference between the sum of the traffic amounts of the first traffic log and the second traffic log and the traffic amount of the total traffic log is greater than a preset difference.

[0119] It should be noted that the size of the preset difference can be set by the person skilled in the art according to actual needs, and the present application does not limit it. By setting the asset detection trigger event, when the difference between the sum of the first traffic log and the second traffic log and the total traffic log exceeds the preset threshold, the system will trigger an additional detection process. This design ensures that any possible missed or unidentified network assets can be detected in time, thereby improving the comprehensiveness and accuracy of detection and effectively reducing the risk of ghost assets.

[0120] The technical scheme provided by the embodiment of the present application has at least the following beneficial effects:

[0121] In the present application, active detection and passive detection are combined, passive detection is used in the initial stage to screen out undetermined unoccupied IP addresses, and then the detection completeness is judged based on the traffic log, and the state that the traffic log is consistent with the traffic amount of known occupied IP addresses is used as a detection termination flag, this detection method can greatly improve the detection efficiency and determine the clear detection cycle period, and avoid the influence of continuous invalid detection on the normal operation of network assets. In the detection process, the multi-modal detection packet is constructed by combining the block encryption mode and the behavior induction detection method in the form of recursion, and the sending strategy with random sending time sequence and random jump strategy is determined based on the random process theory, and the multi-modal detection packet is sent to the unoccupied IP addresses in the detection range through the core switch according to the sending strategy, so as to perform asset detection, which can avoid that the detection packet becomes a hijacking target, threatens the safety of the detection target, and can effectively avoid the firewall of the detection target with a dynamic and random sending strategy, avoids being identified as abnormal traffic by the firewall or detection system, and gradually induces the anonymous asset response and issues the asset type, so as to complete the safe detection of the asset, improve the detection accuracy and coverage, and improve the network environment security.

[0122] Reference is made to the accompanying drawings Figure 3 , which shows a structural schematic diagram of a distributed network data asset penetration security detection system provided by the present application.

[0123] The present application also provides a distributed network data asset penetration security detection system 20, which is applied to the distributed network data asset penetration security detection method described above, and comprises:

[0124] A processor 201.

[0125] A memory 202, the memory 202 stores computer readable instructions, and when the computer readable instructions are executed by the processor 201, the distributed network data asset penetration security detection method of the method embodiment is realized.

[0126] The distributed network data asset penetration security detection system 20 provided by the present application can execute the distributed network data asset penetration security detection method described above, and realize the same or similar technical effects, in order to avoid repetition, the present application will not be described again.

[0127] The technical scheme provided by the embodiment of the present application has at least the following beneficial effects:

[0128] In the present application, active detection and passive detection are combined, passive detection is used to screen out undetermined unoccupied IP addresses in the initial stage, then the detection completeness is judged based on the traffic log, and the state that the traffic log is consistent with the traffic amount of known occupied IP addresses is used as a detection termination flag, this detection method can greatly improve the detection efficiency and determine the clear detection cycle, avoid the influence of continuous invalid detection on the normal operation of network assets. In the detection process, the multi-modal detection packet is constructed by combining the block encryption mode and the recursive form of behavior induction detection method, and the sending strategy with random sending timing and random jump strategy is determined based on the random process theory, and the multi-modal detection packet is sent to the unoccupied IP addresses in the detection range through the core switch according to the sending strategy, to perform asset detection, which can avoid the detection packet becoming a hijacking target, threatening the safety of the detection target, and can effectively evade the firewall of the detection target with a dynamic and random sending strategy, avoid being identified as abnormal traffic by the firewall or detection system, and gradually induce anonymous asset response and issue asset type in a cycle, to complete the safe detection of assets, improve the detection accuracy and coverage, and improve the network environment security.

[0129] It should be understood that the processor in the embodiments of the present application can be a central processing unit (CPU), and the processor can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0130] It should also be understood that the memory in the embodiments of the present application can be volatile or nonvolatile memory, or can include both volatile and nonvolatile memory. The nonvolatile memory can be read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically EPROM (EEPROM), or flash memory. The volatile memory can be random access memory (RAM) used as external cache. By way of example, and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0131] The above-described embodiments can be implemented in whole or in part by software, hardware (e.g., circuitry), firmware, or any combination thereof. When implemented in software, the above-described embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are wholly or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center through wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. containing one or more available medium collections. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. The semiconductor medium can be a solid-state disk.

[0132] It should be understood that the term "and / or" herein merely describes an association relationship of associated objects, which means that there can be three relationships, for example, A and / or B can represent three cases of A alone, A and B together, and B alone, where A and B can be singular or plural. In addition, the character " / " herein generally represents an "or" relationship between the front and rear associated objects, but it can also represent an "and / or" relationship, which can be understood in the context before and after.

[0133] In the present application, "at least one" means one or more, and "multiple" means two or more. "At least one of the following" or the like means any combination of the items, including any combination of single or multiple items. For example, at least one of a, b, or c can represent a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple.

[0134] It should be understood that in various embodiments of the present application, the size of the sequence number of the above-described processes does not mean the order of execution, and the execution order of the processes should be determined by their functions and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0135] Those skilled in the art can clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0136] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the devices, apparatuses and units described above can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.

[0137] In several embodiments provided by the present application, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0138] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0139] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically independently, or two or more units can be integrated into one unit.

[0140] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the parts that contribute to the prior art or parts of the technical solutions can be embodied in the form of a software product stored in a storage medium, including a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various program code storage media.

[0141] The embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the program is executed by a processor to realize the distributed network data asset penetration security detection method as described in the method embodiment.

[0142] The computer readable storage medium provided by the present application can realize the steps and effects of the distributed network data asset penetration security detection method of the above-mentioned method embodiment, and the present application will not be repeated here to avoid repetition.

[0143] The technical solutions provided by the embodiment of the present application have at least the following beneficial effects:

[0144] In the present application, active detection and passive detection are combined, passive detection is used to screen out unoccupied IP addresses that cannot be determined in the initial stage, and then the detection completeness is judged based on the traffic log, and the state that the traffic log is consistent with the traffic amount of the known occupied IP address is used as a detection termination flag. This detection method can greatly improve the detection efficiency and determine the clear detection cycle period, and avoid the influence of continuous invalid detection on the normal operation of network assets. In the detection process, the multi-modal detection packet is constructed by combining the block encryption mode and the recursive behavior induction detection method, the sending strategy with random sending time sequence and random jump strategy is determined based on the random process theory, and the multi-modal detection packet is sent to the unoccupied IP addresses in the detection range through the core switch according to the sending strategy, so as to perform asset detection. This can avoid that the detection packet becomes a hijacking target, threatens the safety of the detection target, and can effectively avoid the firewall of the detection target with a dynamic and random sending strategy, avoids being identified as abnormal traffic by the firewall or detection system, and gradually induces the anonymous asset response and issues the asset type to complete the security detection of the asset, improves the detection accuracy and coverage, and improves the network environment security.

[0145] The above merely describes the specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0146] The following points need to be explained:

[0147] (1) The attached drawings of the embodiments of the present application only involve the structures involved in the embodiments of the present application, and other structures can be referred to the general design.

[0148] (2) In order to be clear, the thickness of the layer or area is enlarged or reduced in the drawings used for describing the embodiments of the present application, that is, the drawings are not drawn according to the actual proportion. It can be understood that when the elements such as layer, film, area or substrate are referred to as being located on or under another element, the element can be directly located on or under another element or there can be intermediate elements.

[0149] (3) In the case of no conflict, the embodiments of the present application and the features in the embodiments can be combined with each other to obtain new embodiments.

[0150] The above merely describes the specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for distributed network data asset penetration security probing, the method comprising: The method is applied to a network data asset detection platform, wherein the network data asset detection platform comprises a plurality of detection nodes located at a core switch and a resource scheduling node located in the cloud, each detection node is connected with the resource scheduling node, and the method comprises the following steps: S1: obtaining total flow logs in a detection range through the detection nodes, wherein the detection range is a set of IP addresses provided by the core switch; S2: marking network data assets occupying known IP addresses and recording first flow logs of network data assets occupying known IP addresses; S3: constructing multi-modal detection packets in combination with a block encryption mode and a behavior-induced detection mode; S4: determining a sending strategy with random sending timing and random jump strategy based on a random process theory, and sending the multi-modal detection packets to unoccupied IP addresses in the detection range through the core switch according to the sending strategy to perform asset detection; S5: if response information is received, entering step S6, otherwise, changing the sending strategy and returning to step S4; S6: analyzing the response information to obtain corresponding occupied IP addresses and network data asset types, and obtaining second flow logs of the corresponding occupied IP addresses; S7: marking and removing all occupied IP addresses, updating the set of IP addresses, i.e. updating the detection range, and returning to step S4 until the sum of flow amounts of the first flow logs and the second flow logs is equal to the flow amount of the total flow logs; S8: outputting the marked occupied IP addresses and the network data asset types corresponding to the marked occupied IP addresses, and completing the detection of the network data assets; Wherein, the S3 specifically comprises: S301: obtaining a detection target IP address: Wherein, A unknown represents the detection target IP address, i.e. the unoccupied IP address set, IP v represents the vth detection target IP address, A total represents the IP address set, A known represents the occupied IP address set; S302: determining a detection packet content with a behavior-induced detection mode, wherein the detection packet content comprises an induced request type in a recursive form, and the induced request type in the recursive form comprises a description request, an identity authentication request, a state check request and a configuration check request in the form of arrangement according to execution order: wherein P indicates a probe packet content, D, I, S, and C respectively indicate a description request, an authentication request, a status check request, and a configuration check request, and → indicates an execution order, indicates contains; S303: block-encrypting the detection packet content, and the encryption mode specifically comprises: H probe = hash(E(P) || N) Among them, P i Let E represent the content block of the i-th probe packet, i = 1, 2, ..., n, where n represents the total number of probe packet content blocks. Let E represent the probe packet content after encryption of probe packet content P. Let K represent the dynamic key, and K' represent the updated dynamic key. i Let P represent the dynamic key corresponding to the i-th probe packet content block, CustomEncrypt(P,K) represent the custom encryption algorithm for P and the dynamic key K, and H(N) represent the hash value of the random value N. This indicates a bitwise XOR operation. Enc represents a bitwise XOR operation from i=1 to i=n. Block (P i ,K i ) indicates that for each block P i Use the corresponding dynamic key K i Encryption, H probe This represents the integrity hash value used for verification. `hash` indicates a hash operation, and `||` indicates a join operation. received This indicates the actual hash value received, if indicates the conditional part, then indicates the execution part, self_destruct indicates the self-destruct operation, E` indicates the probe packet content obtained after encrypting the probe packet content using the updated dynamic key, and send indicates the sending operation. S304: combining the detection target IP address and the encrypted detection packet content to obtain the multi-modal detection packet: P * = [IP v E 、 ] wherein P * represents the multi-modal detection package.

2. The distributed network data asset penetration probing method of claim 1, wherein, The network data assets comprise databases, network devices, servers, virtual machines, application programs, Internet of Things devices and disaster recovery systems.

3. The distributed network data asset penetration probing method of claim 1, wherein, The updating mode of the dynamic key specifically comprises: U = hash (RNG‖T) where K' = K + H (T, RNG, U) base where K' = K + H (T, RNG, U) K' = K + H (T, RNG, U) 4. The method of claim 1, wherein, The random process theory comprises a conditional probability model based on detection feedback results and a Poisson process theory; The S4 specifically comprises: S401: determining jump probabilities between different detection stages in combination with detection feedback results, wherein the detection stages comprise an initial detection stage, a non-response retry stage, a protocol switching stage and an incremental sending frequency stage, the detection feedback results comprise response, non-response and protocol error, and each jump probability constitutes the random jump strategy: wherein F acc denotes the cumulative feedback value, k denotes the feedback trace step, ln denotes the natural logarithm, respectively denote the t-th time response detection feedback result, non-response detection feedback result and protocol error detection feedback result with value 1, P jump (S i → S j ) denotes the jump probability from the i-th detection stage S i to the j-th detection stage S j ; S1, S2, S3 and S4 respectively denote the initial detection stage, non-response retry stage, protocol switching stage and incremental sending frequency stage. S402: in combination with the cumulative feedback value, determine the jump interval between different detection stages by the Poisson process theory, each jump interval constitutes the random sending timing: T i = T i (0) • (1 + A i ) + D i A i = sin(F acc )+ cos 2 (F acc )+ ln(1+ |F acc |) wherein, L i denotes the triggering moment of the i-th jump in the random transmission timing, T i denotes the time interval between the i-th jump and the (i-1)-th jump, T i-1 denotes the time interval between the (i-1)-th jump and the (i-2)-th jump, T i (0) denotes the initial jump interval of the i-th jump generated based on the Poisson distribution, D i denotes the perturbation term of the i-th jump, A i denotes the feedback adjustment term of the i-th jump, U i and U i-1 denote the uniform random numbers in the interval (0, 1) introduced in the i-th jump and the (i-1)-th jump, respectively, and || denotes the absolute value. S403: send the multi-modal detection packet to the unoccupied IP address within the detection range according to the sending strategy composed of the random sending timing and the random jump strategy, so as to perform asset detection.

5. The distributed network data asset penetration probing method of claim 1, wherein, After the S4, further comprising: monitor the proportion of the computing resource consumption of each detection node, and maintain the proportion of the computing resource consumption of the detection node to be less than the preset proportion of the computing resource consumption as the target, and divide the computing resource to different detection nodes by the resource scheduling node.

6. The distributed network data asset penetration probing method of claim 1, wherein, After the S8, further comprising: set an asset detection trigger event, wherein the asset detection trigger event is triggered in the case that the difference between the sum of the traffic amount of the first traffic log and the second traffic log and the traffic amount of the total traffic log is greater than the preset difference.

7. The distributed network data asset penetration probing method of claim 1, wherein, After the S1 and before the S2, further comprising: cluster the IP addresses in the total traffic log according to the traffic amount.

8. A distributed network data asset penetration security probing system, comprising: comprise: a processor; a memory, wherein the memory has computer readable instructions stored thereon, and the computer readable instructions are executed by the processor to implement the distributed network data asset penetration security detection method according to any one of claims 1 to 7.

9. A computer-readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to implement the distributed network data asset penetration security detection method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Distributed network asset detection method

    CN109660401A

  • Method and device for discovering assets based on traffic logs, electronic equipment and medium

    CN116567062A