A network topology detection method, device, apparatus and storage medium
By working collaboratively between the management terminal and the target client, network topology detection results are generated, solving the problem that traditional methods cannot accurately reflect network topology in complex and secure network environments, and achieving more accurate network topology detection.
Patent Information
- Application Number
- CN202510091133.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-01-21
AI Technical Summary
Traditional network topology detection methods cannot accurately reflect the true state of the network in complex and dynamic secure network environments, and are not easy to deploy and use.
The system creates topology probing tasks through the management console, obtains the scanning scheme of the target client, issues the scanning task and generates the probing results, combines the target database and current node data to perform network topology probing, and uses data such as the interface tables and address forwarding tables of switches and routers to verify accuracy.
It improves the accuracy and ease of use of network topology detection, ensuring the precision of network topology.
Smart Images

Figure CN119865374B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of network security, and in particular to a network topology detection method, device, equipment and storage medium. BACKGROUND
[0002] At present, in the security field, with the continuous promotion of the signal creation, the network environment and equipment become more complex and dynamic, which makes it more difficult to track and map the network topology, so it is necessary to continuously monitor and update the dynamic changes of the network topology to ensure the accuracy of the network topology. The traditional network topology detection method needs to support and run related network services by the detected equipment, and needs to configure related firewall policies, but in the security field, there are many security devices in different periods, and because of the security requirements, each device also deploys anti-scanning security components and strictly configures firewall policies, which does not support a large number of deployment probe programs, which leads to the fact that the traditional network topology detection method is not suitable for the current more complex security network environment, and cannot accurately reflect the real situation of the network.
[0003] In summary, how to improve the accuracy and ease of use of network topology detection is a problem to be solved at present. SUMMARY
[0004] Therefore, the purpose of the present application is to provide a network topology detection method, device, equipment and storage medium, which can improve the accuracy and ease of use of network topology detection. The specific scheme is as follows:
[0005] In a first aspect, the present application discloses a network topology detection method applied to a management end, comprising:
[0006] Creating a detection topology task for each target client of each target node, obtaining each target scanning scheme corresponding to each target client from a target database, and determining a target scanning task corresponding to each target client based on the detection topology task and each target scanning scheme;
[0007] Each target scanning task is sent to each corresponding target client, so that each target client performs a detection identification operation based on each target scanning task and generates a corresponding target detection result;
[0008] Obtaining each target detection result sent by each target client, and storing all target detection results in the target database, so as to perform network topology based on all target detection results and current target node data in the target database to obtain a network topology detection result;
[0009] The target nodes include switches and routers, the current target node data includes an interface table, an address forwarding table and an address resolution protocol table of a current network communication device, and each target detection result includes an IP address, a MAC address, an open port and an asset type corresponding to each target client.
[0010] Optionally, before the creating of the detection topology task for each target client of each target node, the method further includes:
[0011] The target nodes and the target clients corresponding to the target nodes are determined, and each target client is identified based on a preset environment identification operation to obtain each target scanning scheme corresponding to each target client.
[0012] Optionally, the environment identification of each target client based on the preset environment identification operation to obtain each target scanning scheme corresponding to each target client includes:
[0013] The current target node data of the target node is obtained based on a simple network management protocol, and the current target node data is stored in the target database.
[0014] An asset identification task is issued to each target client, so that each target client scans a target asset based on the asset identification task to obtain each target scanning scheme corresponding to each target client.
[0015] Optionally, the issuing of the asset identification task to each target client so that each target client scans a target asset based on the asset identification task to obtain each target scanning scheme corresponding to each target client includes:
[0016] The asset identification task is issued to each target client, so that each target client determines a target scanning type based on the asset identification task, and determines a target scanning mode based on the target scanning type.
[0017] The target asset is scanned by the target client using the target scanning mode, and whether the target scanning mode meets a preset matching condition is judged based on a corresponding scanning result.
[0018] If the scanning result represents that the target scanning mode meets the preset matching condition, the target scanning mode is determined as the target scanning scheme corresponding to the target client.
[0019] Optionally, the target scanning type is any one or a combination of full connection scanning based on a transmission control protocol, semi-open scanning based on a synchronous sequence number, and scanning based on a user datagram protocol; and the preset matching condition is a network condition and network protocol adaptation of the target scanning mode and the target client.
[0020] Optionally, the network topology detection method further comprises:
[0021] The current target node data of the target node is collected based on a preset collection time and a simple network management protocol, and the current target node data is updated to the target database.
[0022] Optionally, the network topology is executed based on all the target detection results and the current target node data in the target database to obtain a network topology detection result, comprising:
[0023] A first relationship table and a second relationship table are determined from the target detection results and the current target node data in the target database; the first relationship table is a relationship table of a switch interface and a MAC address, and the second relationship table is a relationship table of an IP address and a MAC address;
[0024] All the target detection results are fused with the first relationship table, the second relationship table, and the current target node data to obtain the network topology detection result.
[0025] In a second aspect, the present application discloses a network topology detection device applied to a management end, comprising:
[0026] A scanning task determination module is configured to create a detection topology task for each target client of each target node, to obtain each target scanning scheme corresponding to each target client from a target database, and to determine a target scanning task corresponding to each target client based on the detection topology task and each target scanning scheme;
[0027] A scanning task issuing module is configured to issue each target scanning task to each corresponding target client, so that each target client performs a detection identification operation based on each target scanning task and generates a corresponding target detection result;
[0028] A topology detection result acquisition module is configured to acquire each target detection result sent by each target client, and to store all the target detection results to the target database, so that a network topology is executed based on the target detection results and the current target node data in the target database to obtain a network topology detection result;
[0029] The target nodes include switches and routers, the current target node data includes an interface table, an address forwarding table and an address resolution protocol table of a current network communication device, and the target detection results each include an IP address, a MAC address, an open port and an asset type corresponding to each of the target clients.
[0030] In a third aspect, the present application discloses an electronic device, comprising:
[0031] a memory for saving a computer program;
[0032] a processor for executing the computer program to implement the network topology detection method.
[0033] In a fourth aspect, the present application discloses a computer readable storage medium for saving a computer program, wherein the computer program is executed by a processor to implement the network topology detection method.
[0034] In the present application, when performing network topology detection, the management end creates a detection topology task for each target client of each target node, obtains each target scanning scheme corresponding to each target client from a target database, and determines a target scanning task corresponding to each target client based on the detection topology task and each target scanning scheme; the management end sends each target scanning task to each corresponding target client, so that each target client performs a detection identification operation based on each target scanning task and generates a corresponding target detection result; the management end obtains each target detection result sent by each target client and stores all target detection results in the target database, so as to perform network topology based on the target detection results in the target database and current target node data to obtain a network topology detection result; wherein the target nodes include switches and routers, the current target node data includes an interface table, an address forwarding table and an address resolution protocol table of a current network communication device, and the target detection results each include an IP address, a MAC address, an open port and an asset type corresponding to each of the target clients. It can be seen that the present application sends a target scanning task matched with each target client from the management end based on a target scanning scheme, and each target client performs a detection identification operation based on the target scanning task to generate a corresponding target detection result. The management end saves the target detection result in the target database after obtaining the target detection result, and then determines a network topology detection result based on the target detection result in the target database and the current target node data. Since the current target node data includes an interface table, an address forwarding table and an address resolution protocol table of a current network communication device, and each target detection result includes an IP address, a MAC address, an open port and an asset type corresponding to each target client, the determined network topology detection result is more accurate, and the accuracy of the network topology is improved. Attached Figure Description
[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0036] Figure 1 This is a flowchart of a network topology detection method disclosed in this application;
[0037] Figure 2 This is a diagram of an overall deployment architecture disclosed in this application;
[0038] Figure 3 This is a schematic diagram of the automatic environmental identification process disclosed in this application;
[0039] Figure 4 This is a schematic diagram of a topology exploration phase process disclosed in this application;
[0040] Figure 5 This is a schematic diagram of the structure of a network topology detection device disclosed in this application;
[0041] Figure 6 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation
[0042] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0043] Currently, in the security field, with the continuous advancement of domestic IT innovation, network environments and devices are becoming more complex and dynamic. This makes tracking and mapping network topology more difficult, thus requiring a continuous monitoring and updating mechanism for dynamic changes in network topology to ensure its accuracy. Traditional network topology probing methods require the probed device to support and run relevant network services and configure relevant firewall policies. However, in the security field, there are often many security devices from different eras, and due to security requirements, each device also deploys anti-scanning and probe security components and configures strict firewall policies, which do not support the deployment of a large number of probe programs. This makes traditional network topology probing methods unsuitable for today's increasingly complex security network environment and unable to accurately reflect the true network situation. To solve the above technical problems, this application discloses a network topology probing method that can improve the accuracy and ease of use of network topology probing.
[0044] See Figure 1 As shown in the figure, this invention discloses a network topology detection method, applied to a management terminal, including:
[0045] Step S11: Create a probe topology task for each target client of each target node, obtain each target scanning scheme corresponding to each target client from the target database, and determine the target scanning task corresponding to each target client based on the probe topology task and each target scanning scheme.
[0046] In this embodiment, the overall deployment architecture is as follows: Figure 2 As shown, the system includes a management terminal and detection clients (i.e., clients). The management terminal manages each detection client and issues target scanning tasks to them. It also aggregates and receives asset data (i.e., target detection results) scanned by each client. Based on the collected data, it displays network assets and generates a complete network topology. Clients are deployed on a small number of machines under key network nodes (i.e., target nodes) for asset scanning, discovery, and identification within the network domain. In other words, if there are 5 machines under a target node, 3 of them can be deployed as clients under that target node, enabling them to perform asset scanning, discovery, and identification within the network domain. Target nodes include switches and routers.
[0047] In this embodiment, before creating a probe topology task for each target client of each target node, it is also necessary to determine the target node and each target client corresponding to the target node, and perform environmental identification on each target client based on a preset environment identification operation to obtain the target scanning scheme corresponding to each target client. For example... Figure 3As shown, the specific process of identifying the environment of each target client based on the preset environment identification operation to obtain each target scanning scheme corresponding to each target client can include: obtaining current target node data of the target node based on the simple network management protocol, and storing the current target node data into the target database; issuing an asset identification task to each target client so that each target client scans the target asset based on the asset identification task to obtain each target scanning scheme corresponding to each target client. The target client can scan the target asset based on the NMAP (Network Mapper) technology when performing asset scanning.
[0048] In a specific embodiment, when determining the scanning scheme, an asset identification task is issued to each target client so that each target client determines a target scanning type based on the asset identification task, and determines a target scanning mode based on the target scanning type; the target client scans the target asset by using the target scanning mode, and judges whether the target scanning mode meets a preset matching condition based on the corresponding scanning result; if the scanning result represents that the target scanning mode meets the preset matching condition, the target scanning mode is determined as the target scanning scheme corresponding to the target client. The target scanning type is any one or a combination of more than one of a full connection scanning based on a transmission control protocol, a semi-open scanning based on a synchronous sequence number, and a scanning based on a user datagram protocol; the preset matching condition is that the target scanning mode is adapted to the network situation and network protocol in which the target client is located. Meanwhile, a new target scanning mode can be obtained by modifying the parameters of the current target scanning mode, so as to exclude the influence of network fluctuation and other factors on the adaptability of the target scanning mode to the network environment in which the target client is located. That is, the client determines different target scanning modes according to different scanning types, scanning speeds, and scanning frequencies, and scans the target client by using these target scanning modes to obtain corresponding scanning results, so as to determine the target scanning scheme most suitable for the target client from these target scanning modes based on the obtained scanning results. After obtaining the target scanning scheme, the target client can return the target scanning scheme to the management end, and then the management end uploads the target scanning scheme to the target database.
[0049] It can be understood that the process of automatic environment identification can have various execution modes, including but not limited to automatic execution after initial installation, management end initiated execution, or automatic execution at a fixed period.
[0050] In this embodiment, as Figure 4As shown, the management end can create a probe topology task for the target clients after determining the target clients under each target node, and then obtain the target scanning schemes corresponding to the target clients from the target database, so as to determine the target scanning tasks corresponding to the target clients based on the probe topology task and the target scanning schemes. It can be understood that the target scanning schemes corresponding to different target clients can be different, the probe topology tasks can be different, and the target scanning tasks can also be different.
[0051] Step S12, each target scanning task is issued to each corresponding target client, so that each target client performs a probe identification operation based on each target scanning task and generates a corresponding target probe result.
[0052] In this embodiment, the management end can issue each target scanning task to the corresponding target client after determining the target scanning task corresponding to each target client. The target client will perform a probe identification operation based on the target scanning task received thereby to obtain a corresponding target probe result. The target probe result includes the IP (Internet Protocol) address, MAC address (Media Access Control Address), open port, and asset type corresponding to each target client. Specifically, the target client can perform a probe identification operation based on the NMAP technology. In addition, since the client continuously generates new network relationship data at the network key nodes (switches, routers) when scanning the probe assets, the management end will collect the current target node data of the target node based on the preset collection time and the Simple Network Management Protocol when the target client performs the probe identification operation as shown, and update the current target node data to the target database, continuously improving and updating the topology network. The current target node data includes the interface table, address forwarding table, and address resolution protocol table of the current network communication device. Figure 4
[0053] Step S13, each target probe result sent by each target client is obtained, and all target probe results are stored in the target database, so as to perform network topology based on all target probe results and current target node data in the target database to obtain a network topology probe result.
[0054] In this embodiment, the management end saves the target detection result into the target database after obtaining the target detection result returned by the target client, and then performs network topology based on all the target detection results in the target database and the current target node data to obtain the current network topology detection result. In a specific implementation, the specific process of the management end performing network topology based on all the target detection results in the target database and the current target node data to obtain the network topology detection result can include: determining a first relationship table and a second relationship table from the target detection results in the target database and the current target node data; the first relationship table is a relationship table of switch interfaces and MAC addresses, and the second relationship table is a relationship table of IP addresses and MAC addresses; and fusing all the target detection results with the first relationship table, the second relationship table and the current target node data to obtain the network topology detection result.
[0055] It can be seen that, based on the target scanning scheme, the management end issues the target scanning task matched with each target client to each target client, and each target client performs the detection identification operation based on the target scanning task to generate the corresponding target detection result. After obtaining the target detection result, the management end saves the target detection result to the target database, and then determines the network topology detection result based on the target detection result in the target database and the current target node data. Since the current target node data includes the interface table, the address forwarding table and the address resolution protocol table of the current network communication device, and each target detection result includes the corresponding IP address, MAC address, open port and asset type of each target client, the determined network topology detection result is more accurate, and the accuracy of the network topology is improved.
[0056] Referring to Figure 5 The application discloses a network topology detection device applied to a management end and comprising:
[0057] The scanning task determination module 11 is configured to create a detection topology task for each target client of each target node, obtain each target scanning scheme corresponding to each target client from the target database, and determine a target scanning task corresponding to each target client based on the detection topology task and each target scanning scheme.
[0058] The scanning task issuing module 12 is configured to issue each target scanning task to each corresponding target client, so that each target client performs a detection identification operation based on each target scanning task and generates a corresponding target detection result.
[0059] The topology detection result acquisition module 13 is configured to acquire each target detection result sent by each target client, and store all the target detection results in the target database, so as to perform network topology based on the target detection results and current target node data in the target database to obtain a network topology detection result.
[0060] The target node includes a switch and a router, the current target node data includes an interface table, an address forwarding table and an address resolution protocol table of a current network communication device, and each target detection result includes a corresponding IP address, a MAC address, an open port and an asset type of each target client.
[0061] It can be seen that, based on the target scanning scheme, the management end sends a target scanning task matched with each target client to each target client, and each target client performs a detection and identification operation based on the target scanning task to generate a corresponding target detection result. After the management end acquires the target detection result, the management end stores the target detection result in the target database, and then determines a network topology detection result based on the target detection result and current target node data in the target database. Since the current target node data includes an interface table, an address forwarding table and an address resolution protocol table of a current network communication device, and each target detection result includes a corresponding IP address, a MAC address, an open port and an asset type of each target client, the determined network topology detection result is more accurate, and the accuracy of the network topology is improved.
[0062] In one specific embodiment, the apparatus can further include:
[0063] The scanning scheme determination module is configured to determine the target node and each target client corresponding to the target node, perform environment identification on each target client based on a preset environment identification operation to acquire each target scanning scheme corresponding to each target client.
[0064] In one specific embodiment, the scanning scheme determination module can specifically include:
[0065] The node data storage submodule is configured to acquire current target node data of the target node based on a simple network management protocol, and store the current target node data in the target database.
[0066] The scanning scheme determination submodule is configured to send an asset identification task to each target client, so that each target client scans a target asset based on the asset identification task to acquire each target scanning scheme corresponding to each target client.
[0067] In one specific embodiment, the scanning scheme determination submodule can specifically include:
[0068] The scanning mode determination unit is configured to issue an asset identification task to each of the target clients, so that each of the target clients determines a target scanning type based on the asset identification task, and determines a target scanning mode based on the target scanning type;
[0069] The scanning result judgment unit is configured to scan the target asset by the target client using the target scanning mode, and judge whether the target scanning mode meets a preset matching condition based on a corresponding scanning result.
[0070] The scanning scheme determination unit is configured to determine the target scanning mode as the target scanning scheme corresponding to the target client if the scanning result indicates that the target scanning mode meets the preset matching condition.
[0071] In one specific embodiment, the apparatus can further include:
[0072] The node data updating module is configured to collect current target node data of the target node based on a preset collection time and a simple network management protocol, and update the current target node data to the target database.
[0073] In one specific embodiment, the topology detection result acquisition module 13 can specifically include:
[0074] The relationship table determination unit is configured to determine a first relationship table and a second relationship table from the target detection result and the current target node data in the target database; the first relationship table is a relationship table of a switch interface and a MAC address, and the second relationship table is a relationship table of an IP address and a MAC address.
[0075] The topology detection result acquisition unit is configured to fuse all the target detection results with the first relationship table, the second relationship table and the current target node data to obtain a network topology detection result.
[0076] Further, the embodiment of the present application also discloses an electronic device, Figure 6 is the structure diagram of the electronic device 20 according to an exemplary embodiment, and the content in the figure cannot be considered as any limitation on the use range of the present application.
[0077] Figure 6A structural schematic diagram of an electronic device 20 is provided in the embodiments of the present application. The electronic device 20 can specifically include at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25 and a communication bus 26. The memory 22 is configured to store a computer program, and the processor 21 is configured to load and execute the computer program to implement the related steps in the network topology detection method disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in the embodiments of the present application can be specifically an electronic computer.
[0078] In the embodiments of the present application, the power supply 23 is configured to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 is capable of creating a data transmission channel between the electronic device 20 and external devices, and the communication protocol followed by the communication interface 24 can be any communication protocol applicable to the technical solution of the present application, which is not limited specifically herein; the input / output interface 25 is configured to obtain external input data or output data to the outside, and the specific interface type can be selected according to the specific application needs, which is not limited specifically herein.
[0079] In addition, the memory 22 as a carrier for resource storage can be a read-only memory, a random access memory, a magnetic or optical disk, etc., and the resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage mode can be temporary storage or permanent storage.
[0080] The operating system 221 is configured to manage and control each hardware device on the electronic device 20 and the computer program 222, and can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program capable of completing the network topology detection method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 can further include a computer program capable of completing other specific work.
[0081] Further, the present application further discloses a computer readable storage medium for storing a computer program; wherein the computer program is executed by the processor to implement the network topology detection method disclosed in the foregoing embodiments. The specific steps of the method can refer to the corresponding contents disclosed in the foregoing embodiments, which will not be repeated here.
[0082] The embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts of each embodiment can be referred to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and the relevant parts can refer to the method part.
[0083] Those skilled in the art will further appreciate that the units and algorithm steps of the various examples described in connection with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or combinations of both. To clearly illustrate this interchangeability of hardware and software, various examples have been described herein in terms of their functionality, which has been described generally and symbolically in flow charts. Having thus described the functionality of the examples, a person of ordinary skill in the art will be able to implement such functions in hardware and / or software, using the means and methods available to those skilled in the art. The examples described herein are not meant to limit the scope of the application, but merely to provide examples of the methods and systems being described.
[0084] The steps of a method or algorithm described in connection with the embodiments disclosed herein can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module can reside in random access memory (RAM), flash memory, read-only memory (ROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0085] Finally, it should be noted that the terms "first", "second", and the like, herein do not denote any order, quantity, combination, or importance, but rather are used to distinguish one element from another, and are more especially used for the purpose of distinction from other elements in the specification. Also, the terms "comprise", "include" or "contain" or any other variant thereof are intended to encompass non-exclusive inclusions, such that processes, methods, articles, or apparatuses that comprise, include, or contain a list of elements are not limited to those elements, but can include other elements not expressly listed or inherent to such processes, methods, articles, or apparatuses. Without further limitation, an element defined by the phrase "comprising a... " does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0086] The above has described the technical solutions provided by the present application in detail, and the principles and implementation manners of the present application have been described by using specific examples; the above example descriptions are only used to help understand the method and core idea of the present application; meanwhile, for those skilled in the art, according to the idea of the present application, the specific implementation manners and application ranges can be changed; in conclusion, the content of the present description should not be understood as limiting the present application.
Claims
1. A network topology discovery method, characterized by, The application is applied to a management end, and comprises the following steps: creating a probe topology task for each target client of each target node, obtaining each target scanning scheme corresponding to each target client from a target database, and determining a target scanning task corresponding to each target client based on the probe topology task and each target scanning scheme; downloading each target scanning task to each corresponding target client, so that each target client performs a probe identification operation based on each target scanning task and generates a corresponding target probe result; obtaining each target probe result sent by each target client, and storing all target probe results in the target database, so as to perform network topology based on all target probe results in the target database and current target node data to obtain a network topology probe result; wherein the target node comprises a switch and a router, the current target node data comprises an interface table, an address forwarding table and an address resolution protocol table of a current network communication device, and each target probe result comprises an IP address, a MAC address, an open port and an asset type corresponding to each target client.
2. The network topology discovery method of claim 1, wherein, Before the step of creating a probe topology task for each target client of each target node, the following step is further included: determining the target node and each target client corresponding to the target node, performing environment identification on each target client based on a preset environment identification operation to obtain each target scanning scheme corresponding to each target client.
3. The network topology discovery method of claim 2, wherein, The step of performing environment identification on each target client based on a preset environment identification operation to obtain each target scanning scheme corresponding to each target client comprises the following steps: obtaining current target node data of the target node based on a simple network management protocol, and storing the current target node data in the target database; downloading an asset identification task to each target client, so that each target client scans a target asset based on the asset identification task to obtain each target scanning scheme corresponding to each target client.
4. The network topology discovery method of claim 3, wherein, The step of downloading an asset identification task to each target client, so that each target client scans a target asset based on the asset identification task to obtain each target scanning scheme corresponding to each target client comprises the following steps: downloading an asset identification task to each target client, so that each target client determines a target scanning type based on the asset identification task, and determines a target scanning mode based on the target scanning type; scanning the target asset by the target client based on the target scanning mode, and judging whether the target scanning mode meets a preset matching condition based on a corresponding scanning result; if the scanning result represents that the target scanning mode meets the preset matching condition, the target scanning mode is determined as the target scanning scheme corresponding to the target client.
5. The network topology discovery method of claim 4, wherein, The target scanning type is any one or a combination of more than one of a full connection scanning based on a transmission control protocol, a semi-open scanning based on a synchronous sequence number, and a scanning based on a user datagram protocol; and the preset matching condition is a network condition in which the target scanning mode and the target client are located and network protocol adaptation.
6. The network topology discovery method of claim 1, wherein, Also included are: Current target node data of the target node is collected based on a preset collection time and a simple network management protocol, and the current target node data is updated to the target database.
7. The network topology discovery method according to any of claims 1 to 6, characterized in that, The network topology is executed based on all target detection results and current target node data in the target database to obtain network topology detection results, including: A first relationship table and a second relationship table are determined from the target detection results and the current target node data in the target database; the first relationship table is a relationship table of a switch interface and a MAC address, and the second relationship table is a relationship table of an IP address and a MAC address; All target detection results are fused with the first relationship table, the second relationship table, and the current target node data to obtain network topology detection results.
8. A network topology discovery apparatus, characterized by comprising: Applied to a management end, including: A scanning task determination module is configured to create a detection topology task for each target client of each target node, to obtain each target scanning scheme corresponding to each target client from a target database, and to determine a target scanning task corresponding to each target client based on the detection topology task and each target scanning scheme; A scanning task issuing module is configured to issue each target scanning task to each corresponding target client, so that each target client performs a detection identification operation based on each target scanning task and generates a corresponding target detection result; A topology detection result acquisition module is configured to acquire each target detection result sent by each target client, and to store all target detection results to the target database, so that a network topology is executed based on target detection results and current target node data in the target database to obtain network topology detection results; The target node includes a switch and a router, the current target node data includes an interface table, an address forwarding table, and an address resolution protocol table of a current network communication device, and each target detection result includes an IP address, a MAC address, an open port, and an asset type corresponding to each target client.
9. An electronic device, comprising: Including: A memory is configured to save a computer program; A processor is configured to execute the computer program to implement the network topology detection method of any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, A memory is configured to save a computer program, wherein the computer program is executed by a processor to implement the network topology detection method of any one of claims 1 to 7.
Citation Information
Patent Citations
Asset management system based on network asset information collection
CN108011893A
Asset scanning method and device
CN112583875A