Network topology discovery method, system and device based on multi-source heterogeneous data and storage medium

By building asset model sets, connection model sets and behavior model sets, and combining these model sets to build physical connection relationship sets and network access relationship sets, the problem that the existing technology cannot truly reflect the network connection situation is solved, and a comprehensive and accurate display of network topology is achieved.

CN119996213APending Publication Date: 2025-05-13STATE GRID HEBEI ELECTRIC POWER CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510098796.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-12-04
Filing Date
2025-01-22
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Existing network topology discovery technologies cannot truly reflect the actual connection between devices in the network, especially the network access relationship between devices.

Method used

By obtaining host information, network device information, network traffic information and asset fingerprint information in the network space in real time, a set of asset models, connection model sets and behavior model sets are built, and a set of physical connection relationships and network access relationships are built in combination with these model sets to form a complete network topology.

Benefits of technology

It realizes an accurate reflection of the physical connection relationship and network access relationship between devices in the network space, comprehensively displays the real connection situation of the network, and facilitates network management and troubleshooting.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996213A_ABST
    Figure CN119996213A_ABST
Patent Text Reader

Abstract

The invention discloses a network topology discovery method, system and device based on multi-source heterogeneous data and a storage medium. The method comprises the following steps: acquiring host information, network device information, network traffic information and asset fingerprint information of the device in a network space in real time; constructing an asset model set for reflecting the characteristics of each host according to the host information, the network flow information and the asset fingerprint information; according to the host information, the network equipment information and the network flow information, constructing a connection model set for reflecting connection relationships between the network equipment and between the network equipment and the host; constructing a behavior model set for reflecting internal actions and external actions of the host according to the host information and the network flow information; constructing a physical connection relation set according to the asset model set and the connection model set, and constructing a network access relation set according to the behavior model set and the asset model set; according to the invention, the physical connection relationship between the devices in the network can be accurately reflected, and the network access relationship between the devices can also be reflected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to network topology discovery, and in particular to a network topology discovery method, system, device and storage medium based on multi-source heterogeneous data. Background Art

[0002] In recent years, with the rapid development of information technology, the demand for electronic equipment in various industries has continued to increase, and the complexity of the network environment has continued to increase. It is difficult to effectively manage and maintain the existing network environment by manual means alone. Network equipment often fails to be managed or mismanaged, which may cause serious consequences. In addition, due to the complexity of the network structure, when more and more new devices are connected to the network, many devices may be in the same broadcast domain because the network administrator fails to grasp the overall network topology. When the communication between subnets is not isolated, if any device in the network has a problem, it will not only affect the security of other devices in the broadcast domain where the device is located, but also affect the security of hosts in other subnets. In view of this, new means are urgently needed to discover and display the network topology, assist manual management, and reduce the possibility of management errors; and reflect the connection relationship and actual interaction status of each device in the network, and monitor the operation status of various devices in real time to ensure the smooth and safe operation of the network environment.

[0003] The existing network topology discovery technology mainly obtains the Media Access Control (MAC) address forwarding table or Address Resolution Protocol (ARP) table and Spanning Tree Protocol (STP) information of network management devices such as switches and routers through SNMP protocol or private protocol, supplemented by discovering hidden assets through detection technologies such as fping and nmap, to achieve network topology discovery and generation. However, the network topology discovered by the above methods can only reflect the physical relationship between the direct connections of various devices, and the network access relationship generated by the actual data interaction between devices cannot be reflected; and the topology discovery is radiated from network management devices such as switches and routers, which mainly reflects the connection relationship between other devices and network management devices, and the connection relationship between other devices cannot be reflected. Therefore, the existing topology discovery technology cannot truly and comprehensively reflect the actual connection status of the network. Summary of the invention

[0004] Purpose of the invention: The purpose of the present invention is to provide a network topology discovery method, system, device and storage medium based on multi-source heterogeneous data that can not only accurately reflect the physical connection relationship between devices in the network but also reflect the network access relationship between devices.

[0005] Technical solution: The network topology discovery method based on multi-source heterogeneous data of the present invention includes the following processes:

[0006] Obtain host information, network device information, network traffic information and device asset fingerprint information in the network space in real time;

[0007] An asset model set is constructed based on host information, network traffic information, and asset fingerprint information to reflect the characteristics of each host; a connection model set is constructed based on host information, network device information, and network traffic information to reflect the connection relationship between network connection devices and hosts; a behavior model set is constructed based on host information and network traffic information to reflect the internal and external actions of the host;

[0008] A physical connection relationship set is constructed based on the asset model set and the connection model set, and a network access relationship set is constructed based on the behavior model set. The two relationship sets constitute a complete network topology.

[0009] Based on the above method, the information data collected in the network space are combined and organized into asset model sets, connection model sets and behavior model sets, which respectively reflect the characteristic information of the host itself in the network space, the connection relationship between network devices and between them and the host, and the internal and external actions of the host. The physical connection relationship between devices in the network space can be constructed through the connection model set, and the specific characteristic information of each host in the connection model can be supplemented in conjunction with the asset model, and the problems of repeated hosts and redundant connection relationships in the connection model can be solved. The topological structure of the network space can be concisely described, so that the physical connection relationship set between specific devices in the network space can be accurately constructed. The network devices here include switches, routers and firewalls; the behavior model set is based on According to the internal and external actions of the host, the hosts with data interaction can be accurately judged, and then the characteristic information of the hosts with network access relationships can be supplemented through the asset model set, and then the network access relationship set between the hosts in the network space can be established; the physical connection relationship set and the network access relationship set are combined together to form a complete network topology. The network topology structure is jointly constructed by heterogeneous data from four sources. Compared with a single source, the data source is more comprehensive to avoid missing surviving nodes and unclear connection relationships. The network topology constructed in this way can not only truly and accurately reflect the physical connection relationship between specific devices in the network space, but also reflect the network access relationship between devices. It can truly and comprehensively reflect the actual connection status of the network, which is convenient for network management.

[0010] Preferably, the host information includes host asset information and host behavior information. The host asset information includes the software and hardware information of the host itself; the host behavior information includes the information of the host's own operation and running status and the information of the interaction between different hosts.

[0011] Preferably, the connection information of the network devices in the network space is obtained through login interaction and Simple Network Management Protocol (SNMP) interaction, and the connection information includes the connection relationship between the network devices and between the network devices and the host.

[0012] Preferably, the traffic behavior information and traffic characteristic information are obtained by collecting mirrored traffic from the switch.

[0013] Preferably, the traffic behavior information includes network access information, remote login information and file transfer information; the traffic characteristic information includes source media access control address MAC, destination media access control address MAC, source Internet Protocol address IP, destination Internet Protocol address IP, source port, destination port, protocol, number of packets sent, number of packets received, number of bytes sent, number of bytes received, traffic generation time and traffic end time.

[0014] Preferably, the asset fingerprint information is collected from surviving assets in cyberspace.

[0015] Preferably, the asset model set is constructed based on the host asset information, traffic characteristic information and asset fingerprint information. When constructing the asset model set, duplicate asset models are removed based on the network card information and asset fingerprint information in the host information; the connection model set is constructed based on the connection information, information on interaction between different hosts in the host behavior information and traffic characteristic information; the behavior model set is constructed based on the host behavior information, traffic behavior information and traffic characteristic information.

[0016] Preferably, the physical connection relationship set is constructed by using the asset model set to remove duplicate connection relationships in the connection model set and complete the host information; the network access relationship set is constructed by using the asset model set to complete the host information in the behavior model set.

[0017] By integrating the asset model set with the connection model set and the behavior model set respectively, the specific feature information of each host in the connection model set and the behavior model set can be completed, and removing redundant connection relationships in the connection model set can simplify the final network topology.

[0018] The network topology discovery system based on multi-source heterogeneous data of the present invention comprises:

[0019] Information collection module: used to obtain real-time host information, network device information, network traffic information and device asset fingerprint information in the network space;

[0020] Information integration module: used to construct an asset model set reflecting the characteristics of different devices in the network space based on host information, network traffic information and asset fingerprint information; to construct a connection model set reflecting the connection relationship between devices in the network space based on host information, network device information and network traffic information; to construct a behavior model set reflecting the internal and external actions of the device based on host information and network traffic information;

[0021] Connection relationship integration module: used to build a physical connection relationship set based on the asset model set and the connection model set, and to build a network access relationship set based on the behavior model set and the asset model set. The two relationship sets constitute a complete network topology.

[0022] Preferably, the host information in the information acquisition module includes host asset information and host behavior information. The host asset information includes the host's own software and hardware information; the host behavior information includes the host's own operation and running status information and the information of the interaction between different hosts.

[0023] Preferably, the information collection module obtains connection information of network devices in the network space through login interaction and Simple Network Management Protocol (SNMP) interaction, and the connection information includes connection relationships between network devices and between network devices and hosts.

[0024] Preferably, the information collection module obtains the flow behavior information and flow characteristic information by collecting the switch mirror flow.

[0025] Preferably, the traffic behavior information includes network access information, remote login information and file transfer information; the traffic characteristic information includes source media access control address MAC, destination media access control address MAC, source Internet Protocol address IP, destination Internet Protocol address IP, source port, destination port, protocol, number of packets sent, number of packets received, number of bytes sent, number of bytes received, traffic generation time and traffic end time.

[0026] Preferably, the asset fingerprint information in the information collection module is collected from surviving assets in cyberspace.

[0027] Preferably, the asset model set in the information integration module is constructed based on the host asset information, traffic characteristic information and asset fingerprint information. When constructing the asset model set, duplicate asset models are removed based on the network card information and asset fingerprint information in the host information; the connection model set is constructed based on the connection information, information on interaction between different hosts in the host behavior information and traffic characteristic information; the behavior model set is constructed based on the host behavior information, traffic behavior information and traffic characteristic information.

[0028] Preferably, the connection relationship integration module uses the asset model set to remove duplicate connection relationships in the connection model set and complete the host information to obtain a physical connection relationship set; and uses the asset model set to complete the host information in the behavior model set to obtain a network access relationship set.

[0029] The device described in the present invention includes one or more processors, one or more memories and one or more programs, wherein the one or more programs are stored in the one or more memories and are configured to be executed by the one or more processors, and the one or more programs include instructions for executing any of the above methods.

[0030] The computer-readable storage medium storing one or more programs of the present invention includes one or more programs including instructions, and when the instructions are executed by a computing device, the computing device executes any one of the above methods.

[0031] Beneficial effects: Compared with the prior art, the present invention has the following significant effects: by collecting host information, network device information, network traffic information and device asset fingerprint information in real time during network airborne operation, the information data in the network space can be fully and accurately acquired, and then the acquired multi-source heterogeneous data are integrated with each other to obtain a physical connection relationship set and a network access relationship set, which can not only accurately reflect the physical connection relationship between network devices and between network devices and hosts in the network space, but also reflect the network access relationship between hosts, more comprehensively reflect the real connection status of the network, and facilitate the management of the network. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 Schematic diagram of the overall process of this method;

[0033] Figure 2 Schematic diagram of the specific process of this method. DETAILED DESCRIPTION

[0034] As shown in the figure, the network topology discovery method based on multi-source heterogeneous data provided by the present invention includes the following process:

[0035] Through host monitoring, network control collection, traffic collection and detection scanning, real-time acquisition of host information, network device information, network traffic information and device asset fingerprint information in the network space;

[0036] An asset model set is constructed based on host information, network traffic information, and asset fingerprint information to reflect the characteristics of each host; a connection model set is constructed based on host information, network device information, and network traffic information to reflect the connection relationship between network devices and between network devices and hosts; a behavior model set is constructed based on host information and network traffic information to reflect the internal and external actions of the host;

[0037] A physical connection relationship set is constructed based on the asset model set and the connection model set, and a network access relationship set is constructed based on the behavior model set and the asset model set. The two relationship sets constitute a complete network topology.

[0038] The host information obtained by the host monitoring through the host monitoring software includes host asset information and host behavior information. The host monitoring software refers to a software program installed on host devices such as servers and workstations, which collects host hardware and software configuration information and host operating status through the host system information generation mechanism, generates host logs and transmits them to the outside.

[0039] Host asset information includes the host's own hardware and software information, including: hardware asset information such as processor, memory, hard disk, network card, peripherals, etc.; software asset information such as users, user groups, sessions, partitions, startup tasks, files, drivers, software packages, executable files, processes, services, applications, database software, malicious code software, encryption modules, trusted computing, etc.; network asset information such as network interface, network routing, access control policy, ARP table, MAC address table, network monitoring, etc.

[0040] Host behavior information includes information on the host's own operations and operating status, as well as information on interactions between different hosts, including operational behavior information such as user addition and deletion, user attribute change file addition and deletion, file access, peripheral interface addition and deletion, and route addition and deletion; status behavior information such as peripheral interface enable and disable, partition mounting and unmounting, process start and stop, network interface start and stop, and driver loading and unmounting; interactive behavior information such as peripheral connection and disconnection, session login and logout, session operation, and network interface connection and disconnection.

[0041] The network control acquisition obtains the connection information of network devices in the network space through login interaction and simple network management protocol SNMP interaction. The connection information includes the connection relationship between network devices and between them and the host. The network devices include multiple switches, routers and security protection equipment, etc. The security protection equipment includes firewalls, etc.

[0042] The login interaction means: firstly, preset the user name and password of the collection object, then periodically remotely log in to the device background through protocols such as ssh and x11, input system or device instructions, query and obtain internal information, and the device background includes switches, routers and firewall backgrounds; the information obtained through the login interaction includes: the routing, VLAN, ACL, ARP, neighbor network equipment and other information of the switch, the routing, ACL, neighbor network equipment and other information of the router, the routing, ARP, policy of the firewall device, etc.

[0043] The SNMP interaction means: firstly, presetting the system object identifier (sysbjectID; referred to as: OID) of the collection object, for example: 1.3.6.1.2.1.1.2, and then sending the OID to the specified device through the SNMP command to obtain the information generated by the network device. The collection objects include switches and routers; the information obtained by SNMP interaction includes: ARP information, MAC address table, etc.

[0044] The connection information includes: switch routing, VLAN, ACL, ARP, neighbor network equipment and other information; router routing, ACL, neighbor network equipment and other information; firewall routing, ARP, policy and other information. For more details, please refer to Figure 2 ; Based on the comprehensive analysis of the direct routes in the routing table in the connection information and the LLDP neighbor information, ARP table, and VLAN information, all directly connected subnets of the three-layer switches and routers can be obtained; all adjacent routing nodes of the three-layer switches and routers can be obtained through the non-direct routes in the routing table and the breadth-first traversal algorithm; then, the multi-area topologies are spliced ​​together through boundary devices such as firewalls to build a preliminary physical connection relationship between devices in the network space.

[0045] The traffic collection is performed by collecting the switch mirror traffic and analyzing it one by one according to the network layer to generate traffic feature information and traffic behavior information; specifically, the original traffic data packets in the network space are obtained in real time, the action keywords of the data packets are extracted, and they are merged according to the action causal relationship to form traffic behavior; the characteristic keywords of the data packets are periodically merged according to the five-tuple to form traffic feature information.

[0046] The traffic behavior information includes the link layer, network layer, UDP and TCP network access information, telnet, SSH, XDMCP, RADIUS and VNC remote login information, FTP and TFTP file transfer information; the traffic feature information includes the source media access control address MAC, the destination media access control address MAC, the source Internet Protocol address IP, the destination Internet Protocol address IP, the source port, the destination port, the protocol, the number of packets sent, the number of packets received, the number of bytes sent, the number of bytes received, the traffic generation time and the traffic end time.

[0047] The detection scan is to scan the network space through tools such as fping, arping, nmap, hping, etc., to discover surviving assets, including known and unknown surviving assets, and obtain asset fingerprint information of all detected assets; the asset fingerprint information includes: operating system, open ports, communication protocol, protocol version number, service name and protocol stack fingerprint and other information.

[0048] The detection scan is triggered manually. After obtaining most of the asset-related information in the cyberspace through host monitoring and traffic collection, the detection scan is used to further supplement and discover some difficult-to-find assets, such as inactive assets and active assets that have not been detected by the above two methods.

[0049] The original information data collected through the four methods of host monitoring, network control collection, traffic collection and detection scanning include but are not limited to: host asset information, host behavior information, connection information, traffic behavior information, traffic feature information and asset fingerprint information.

[0050] After the original information data is processed by the cyberspace model, an asset model set, a connection model set and a behavior model set are obtained, and the existing model library is updated; the cyberspace model processing refers to abstracting and summarizing all the information appearing in the cyberspace according to different types, obtaining a data definition collection that can fully characterize the cyberspace, matching the collected original information with the data definition collection, and finally generating a model data set of a specific cyberspace, that is, defining different types of model sets, and then classifying and integrating all the original information that conforms to the model set type into several independent models and classifying them into the model set. The specific content of the specific cyberspace is reflected by these abstract and summarized model sets. In this embodiment, the model is embodied in the form of a model table, and the model table includes multiple types of information.

[0051] In order to illustrate the specific processing process of the network space model, the following takes the specific construction process of the asset model set as an example. Before the explanation, it is first defined that the asset model set is a data set of several asset models that can reflect the characteristics of different hosts in the network space based on the host asset information, traffic feature information and asset fingerprint information; the asset model construction process is as follows:

[0052] S1. When any type of information a among the three types of information, namely, host asset information, traffic characteristic information and asset fingerprint information, is collected for the first time, an independent asset model A1 is constructed for it, which is actually an independent asset model table.

[0053] S2. Continue to collect information. When information of the same type as information a is collected, build another independent asset model A2 for it, and then go to step S4; when information b of any of the remaining two types of host asset information, traffic characteristic information and asset fingerprint information is collected, determine whether a and b reflect different types of information of the same device. If so, fill b into A1 and go to step S3; otherwise, build another independent asset model A3 for b, and then go to step S4.

[0054] S3. Continue to collect information. When the collected information is of the same type as a or b, build an independent asset model A4 for it, and then go to step S4; when the collected information is different from the types of a and b and is the last type of information c remaining in step S1, determine whether the device it reflects is the same as the device reflected by A1. If they are the same, fill c into A1, and the asset model A1 is completed; otherwise, build an independent asset model A5 for it, and then go to step S4.

[0055] S4. Use asset model A2, A3, A4 or A5 as the new asset model A1, and the type of information in A2, A3, A4 or A5 as the new type a, and then return to step S2 until all original information is collected.

[0056] The above-mentioned A1, A2, A3, A4 and A5, as well as a, b and c are all name codes, and their specific contents can vary. Through the above steps, multiple independent asset models with the name code A1 but different specific contents can be constructed, and all asset models constitute an asset model set.

[0057] The construction principles of the remaining model sets are the same as above, and the specific construction process will not be repeated later.

[0058] Compared with the construction of other model sets, the asset model set has one more step: based on the network card information obtained by host monitoring and the fingerprint information obtained by detection scanning, the host is normalized to remove the duplicate asset models in all asset models that have been built in step S4; this is done because there are multiple IP addresses in the host, that is, the same host has multiple host asset information of the same type (such as IP addresses), which will cause asset model duplication.

[0059] The asset models used to construct the asset model set are shown in Table 1.

[0060] Table 1 Asset Model Table

[0061]

[0062]

[0063]

[0064] The connection model set is constructed based on the connection information collected by the network control, the information on the interaction between different hosts in the host behavior information, and the traffic feature information. The traffic feature information is needed here because the IP address is dynamically allocated between the host and the router through the DHCP protocol. The allocated IP address may not be within the range of the directly connected subnet or adjacent routing node in the connection information. It is necessary to supplement and determine the corresponding connection relationship based on the traffic feature information; the connection model is shown in Table 2.

[0065] Table 2 Connection model table

[0066] Model Subclasses Detailed Description Physical network interface A Network Interface List Physical network interface B Network Interface List Discover connected assets Asset Model Data Source Manual discovery / automatic discovery

[0067] The specific content of the network interface list is shown in Table 3.

[0068] Table 3 Network interface list

[0069]

[0070]

[0071] The behavior model set is constructed based on host behavior information, traffic behavior information and traffic feature information. The behavior model is shown in Table 4.

[0072] Table 4 Behavior model

[0073]

[0074]

[0075]

[0076] The network access table is shown in Table 5.

[0077] Table 5 Network access table

[0078]

[0079] The method for constructing the physical connection relationship set in (3) is as follows: the connection model set is compared and analyzed based on the interface information, MAC address table and routing table of the switch, router and firewall to obtain the connection relationship between the host, switch, router and firewall; the asset model set is compared and analyzed based on the IP, Mac address information and address mask of the host to obtain the mutual connection relationship between the hosts; the connection relationships obtained above constitute the preliminary physical connection relationship set, but since the host has multiple IP addresses, the hosts in the preliminary physical connection relationship set are repeated and the connection relationships are redundant, and the topological structure of the network space cannot be simply described. The host network card list information obtained by the host detection in the asset model set and the device fingerprint information obtained by the detection scan are used to normalize the host, and the physical connection relationship between the host and the same network device is merged, so as to analyze and obtain the final physical connection relationship set.

[0080] The method for constructing a network access relationship set is as follows: based on the internal and external actions of the host in the behavior model set, the hosts with data interaction can be analyzed and sorted out, and then the feature information of the hosts with network access relationships can be supplemented through the asset model set, and then the network access relationship set between the hosts in the network space can be established.

[0081] The method provided by the present invention performs network control collection on switches, routers, firewalls and other devices, generates multi-region topology and splices it. Use host monitoring and traffic collection and analysis technology to discover assets in the cyberspace, and complete the attributes of related assets. The assets are the devices in the cyberspace. Use detection scanning to obtain device fingerprint information, and merge and normalize multi-port assets through fingerprint information comparison. The above four types of collection methods are combined to generate asset models, connection models, and behavior models and update them accordingly, which can fully and truly reflect the physical connection relationship and network access relationship between devices in the cyberspace.

[0082] The network topology discovery method provided by the present invention can not only correctly and truly reflect the physical connection relationship of the entire network, but also reflect the actual data interaction relationship of each device in the network, thereby facilitating the management of the network, timely discovering and handling network anomalies, and enhancing the security of the network.

[0083] The network topology discovery system based on multi-source heterogeneous data of the present invention comprises:

[0084] Information collection module: used to acquire information data in the network space in real time through host monitoring, network control collection, flow collection and detection scanning;

[0085] Information integration module: used to build an asset model set that reflects the characteristics of different devices in the network space based on the information data obtained by host monitoring, traffic collection and detection scanning; to build a connection model set that reflects the connection relationship between devices in the network space based on the information data obtained by host monitoring, traffic collection and network control collection; to build a behavior model set that reflects the internal and external actions of the device based on the information data obtained by host monitoring and traffic collection;

[0086] Connection relationship integration module: used to build a physical connection relationship set based on the asset model set and the connection model set, and to build a network access relationship set based on the behavior model set. The two relationship sets constitute a complete network topology.

[0087] The host information acquired by the host monitoring in the information acquisition module includes host asset information and host behavior information. The host asset information includes the host's own software and hardware information; the host behavior information includes the host's own operation and running status information and the information of the interaction between different hosts.

[0088] The network control acquisition in the information acquisition module obtains the connection information of network devices in the network space through login interaction and simple network management protocol SNMP interaction. The connection information includes the connection relationship between network devices and between network devices and hosts.

[0089] The traffic collection in the information collection module obtains traffic behavior information and traffic feature information by collecting the switch mirror traffic.

[0090] The traffic behavior information includes network access information, remote login information and file transfer information; the traffic feature information includes source media access control address MAC, destination media access control address MAC, source Internet Protocol address IP, destination Internet Protocol address IP, source port, destination port, protocol, number of sent packets, number of received packets, number of sent bytes, number of received bytes, traffic generation time and traffic end time.

[0091] The detection scan in the information collection module is used to obtain surviving assets in the cyberspace and collect their asset fingerprint information.

[0092] The asset model set in the information integration module is constructed based on the host asset information, traffic characteristic information and asset fingerprint information. When constructing the asset model set, duplicate asset models are removed based on the network card information obtained from host monitoring and the fingerprint information obtained from detection scanning; the connection model set is constructed based on the connection information, the information on the interaction between different hosts in the host behavior information and the traffic characteristic information; the behavior model set is constructed based on the host behavior information, traffic behavior information and traffic characteristic information.

[0093] In the connection relationship integration module, the asset model set is used to remove duplicate connection relationships in the connection model set and complete the host information to obtain a physical connection relationship set; the asset model set is used to complete the information of the host in the behavior model set to obtain a network access relationship set.

[0094] The device described in the present invention includes one or more processors, one or more memories and one or more programs, wherein the one or more programs are stored in the one or more memories and are configured to be executed by the one or more processors, and the one or more programs include instructions for executing the above method.

[0095] The computer-readable storage medium storing one or more programs of the present invention includes one or more programs including instructions, and when the instructions are executed by a computing device, the computing device executes the above method.

Claims

1. A network topology discovery method based on multi-source heterogeneous data, characterized in that: The process includes: Obtain host information, network device information, network traffic information and device asset fingerprint information in the network space in real time; An asset model set is constructed based on host information, network traffic information, and asset fingerprint information to reflect the characteristics of each host; a connection model set is constructed based on host information, network device information, and network traffic information to reflect the connection relationship between network devices and between network devices and hosts; a behavior model set is constructed based on host information and network traffic information to reflect the internal and external actions of the host; A physical connection relationship set is constructed based on the asset model set and the connection model set, and a network access relationship set is constructed based on the behavior model set and the asset model set. The two relationship sets constitute a complete network topology.

2. A network topology discovery method based on multi-source heterogeneous data according to claim 1, characterized in that: The host information includes host asset information and host behavior information. The host asset information includes the software and hardware information of the host itself; the host behavior information includes the information of the host's own operation and running status and the information of the interaction between different hosts.

3. A network topology discovery method based on multi-source heterogeneous data according to claim 2, characterized in that: The connection information of network devices in the network space is obtained through login interaction and Simple Network Management Protocol (SNMP) interaction. The connection information includes the connection relationship between network devices and between network devices and hosts.

4. A network topology discovery method based on multi-source heterogeneous data according to claim 3, characterized in that: By collecting switch mirror traffic, traffic behavior information and traffic characteristic information are obtained.

5. A network topology discovery method based on multi-source heterogeneous data according to claim 4, characterized in that: The traffic behavior information includes network access information, remote login information and file transfer information; Traffic characteristic information includes source media access control address MAC, destination media access control address MAC, source Internet Protocol address IP, destination Internet Protocol address IP, source port, destination port, protocol, number of sent packets, number of received packets, number of sent bytes, number of received bytes, traffic generation time and traffic end time.

6. A network topology discovery method based on multi-source heterogeneous data according to claim 4, characterized in that: The asset fingerprint information is collected from surviving assets in cyberspace.

7. A network topology discovery method based on multi-source heterogeneous data according to claim 6, characterized in that: The asset model set is constructed based on the host asset information, traffic feature information and asset fingerprint information. When constructing the asset model set, duplicate asset models are removed based on the network card information and asset fingerprint information in the host information. The connection model set is constructed based on the connection information, information on the interaction between different hosts in the host behavior information and traffic feature information. The behavior model set is constructed based on host behavior information, traffic behavior information and traffic characteristic information.

8. The network topology discovery method based on multi-source heterogeneous data according to claim 7 is characterized by: The physical connection relationship set is constructed by using the asset model set to remove duplicate connection relationships in the connection model set and complete the host information; the network access relationship set is constructed by using the asset model set to complete the host information in the behavior model set.

9. A network topology discovery system based on multi-source heterogeneous data, characterized in that: The system comprises: Information collection module: used to obtain real-time host information, network device information, network traffic information and device asset fingerprint information in the network space; Information integration module: used to construct an asset model set reflecting the characteristics of different devices in the network space based on host information, network traffic information and asset fingerprint information; to construct a connection model set reflecting the connection relationship between devices in the network space based on host information, network device information and network traffic information; to construct a behavior model set reflecting the internal and external actions of the device based on host information and network traffic information; Connection relationship integration module: used to build a physical connection relationship set based on the asset model set and the connection model set, and to build a network access relationship set based on the behavior model set and the asset model set. The two relationship sets constitute a complete network topology.

10. A network topology discovery system based on multi-source heterogeneous data according to claim 9, characterized in that: The host information in the information collection module includes host asset information and host behavior information. The host asset information includes the host's own software and hardware information; the host behavior information includes the host's own operation and running status information and the information of the interaction between different hosts.

11. A network topology discovery system based on multi-source heterogeneous data according to claim 10, characterized in that: The information collection module obtains the connection information of network devices in the network space through login interaction and simple network management protocol SNMP interaction, and the connection information includes the connection relationship between network devices and between network devices and hosts.

12. A network topology discovery system based on multi-source heterogeneous data according to claim 11, characterized in that: The information collection module obtains flow behavior information and flow characteristic information by collecting switch mirror flow.

13. A network topology discovery system based on multi-source heterogeneous data according to claim 12, characterized in that: The traffic behavior information includes network access information, remote login information and file transfer information; Traffic characteristic information includes source media access control address MAC, destination media access control address MAC, source Internet Protocol address IP, destination Internet Protocol address IP, source port, destination port, protocol, number of sent packets, number of received packets, number of sent bytes, number of received bytes, traffic generation time and traffic end time.

14. A network topology discovery system based on multi-source heterogeneous data according to claim 12, characterized in that: The asset fingerprint information in the information collection module is collected from surviving assets in cyberspace.

15. A network topology discovery system based on multi-source heterogeneous data according to claim 14, characterized in that: The asset model set in the information integration module is constructed based on the host asset information, traffic feature information and asset fingerprint information. When constructing the asset model set, duplicate asset models are removed based on the network card information and asset fingerprint information in the host information. The connection model set is constructed based on the connection information, information on the interaction between different hosts in the host behavior information and traffic feature information. The behavior model set is constructed based on host behavior information, traffic behavior information and traffic characteristic information.

16. A network topology discovery system based on multi-source heterogeneous data according to claim 15, characterized in that: The physical connection relationship set in the connection relationship integration module uses the asset model set to remove duplicate connection relationships in the connection model set and complete the host information; the network access relationship set is constructed by using the asset model set to complete the host information in the behavior model set.

17. A device, characterized in that : comprising one or more processors, one or more memories and one or more programs, wherein the one or more programs are stored in the one or more memories and are configured to be executed by the one or more processors, and the one or more programs include instructions for executing any one of the methods according to claims 1 to 8.

18. A computer-readable storage medium storing one or more programs, characterized in that: The one or more programs include instructions which, when executed by a computing device, cause the computing device to perform any one of the methods according to claims 1 to 8.