Network space surveying and mapping system and method
Through the combination of active and passive detection of the network asset collaborative measurement module, a dynamic priority detection model and spatiotemporal calibration factor are built to generate network asset-service correlation confidence, and visual map drawing is used to solve the problem of difficulty in identifying the attributes of IoT devices and improve the recognition accuracy and security.
Patent Information
- Application Number
- CN202510384620.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-04
AI Technical Summary
The prior art is difficult to accurately identify the properties of IoT devices, resulting in weak security, increasing the risk of attacks such as DDoS, and the combination of passive detection and active detection is difficult to improve the identification accuracy.
The network asset collaborative measurement module is used to combine active and passive detection. By constructing a dynamic priority detection model and spatiotemporal calibration factor, actively detect response and passive monitoring of traffic characteristics are fused, normalized feature sequences are processed using hypergraph correlation model and LSTM to generate network asset-service correlation confidence, and visual map drawing and management are combined with graph neural network model.
It significantly improves the accuracy and real-time nature of network asset discovery and identification, improves the security and reliability of terminals and intranet systems, and realizes situational awareness and information control in cyberspace.
Smart Images

Figure CN120263707A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network asset identification and mapping, and particularly relates to a network space mapping system and method. Background Technique
[0002] Network space mapping technology refers to taking network space resources as objects, based on computer science, network science, mapping science, and information science, using technologies such as network detection, network analysis, entity positioning, geographical mapping, and geographic information systems, through means such as detection, collection, processing, analysis, and display, to obtain the location, attributes, and topological structure of network space entity resources and virtual resources in the network space, and map them to the geographical space, and draw their coordinates, topology, surrounding environment, etc. information in the form of a map or other visual forms and display the relevant situation, and conduct spatial analysis and application accordingly. The network space mapping technology system mainly includes detection technology, analysis technology, positioning technology, verification technology, drawing technology, and application technology.
[0003] In the application scenarios of asset discovery, identification, and risk control, through network space mapping technology, network assets can be identified and controlled, which can better protect the data of individuals and organizations and prevent existing and potential risks. The essence of network space mapping technology is to visually express the network space, comprehensively display network information in the form of a network space map, realize the visualization and digitalization of the network space, so as to provide intuitive and valuable information for decision-makers to improve the accuracy of decision-making. However, a large number of Internet of Things devices are distributed in enterprises, families, and individuals, and their relatively weak security is prone to large-scale attacks such as DDoS, which increases the detection difficulty and reduces the accuracy of security personnel for cloud computing networks. At the same time, a large number of devices have removed product features to prevent detection and reduced the exposure surface, making it increasingly difficult to accurately identify device attributes. Summary of the Invention
[0004] The purpose of the present invention is to provide a network space mapping system and method to solve the problems raised in the above background technique.
[0005] To solve the above technical problems, the present invention provides the following technical solutions: A network space mapping system and method include the following functional modules: a network asset collaborative measurement module, a network asset association identification module, a network asset drawing module, and a network asset mapping application module; Preferably, the network asset collaborative measurement module is used for performing collaborative detection by combining active detection and passive detection on the network assets in the service area; the network asset association identification module is used for associating asset identification and service identification based on the data of collaborative measurement; the network asset mapping module is used for drawing a regional asset map of the regional assets according to the association result; the network asset surveying and mapping application module is used for applying and managing the service surveying and mapping of the drawn network asset map.
[0006] Preferably, the process of the network asset collaborative measurement module performing collaborative measurement includes the following steps: S101: Using a passive monitoring method including field parsing, traffic / protocol identification, and aggregated logs, obtain data for the network assets of concern, capture traffic, and extract session characteristics; S102: Perform multi-protocol detection on the target IP; S103: Real-time correct the active detection strategy through the data obtained by passive monitoring, and construct a dynamic priority detection model; S104: Integrate the active detection response and the traffic characteristics of passive monitoring, construct a multi-dimensional device fingerprint, associate the active detection result with the passive monitoring traffic time window, and match the active / passive data of the same device according to the port number or protocol characteristics; S105: Introduce a spatio-temporal calibration factor to map the asynchronous detection data to a unified time axis, and then correct the cross-segment observation deviation based on the network topology.
[0007] Preferably, the process of the network asset association identification module associating asset identification and service identification includes the following steps: S201: Construct a feature type dictionary, train the AFT model separately for each source, and use an adaptive feature transformer to align the multi-source feature spaces; S202: Construct a hypergraph association model to establish a high-order relationship of asset-service-protocol; S203: Process the normalized feature sequence through LSTM, splice the hypergraph topology embedding and the LSTM output, generate the weights of each data source based on Softmax normalization, and generate the confidence of network asset-service association by dynamically fusing the weights of multi-source data and the global topology features; S204: Introduce spatio-temporal consistency verification rules to verify the association connections across time periods or cross segments, and judge whether they are false connections; S205: Construct a horizontal federated learning model, combine model parameter aggregation and differential privacy, that is, use the local network asset data for model training, and encrypt the uploaded model parameters through the Paillier encryption algorithm; S206: Generate a global model after encryption and add noise, and finally transfer the knowledge of the federated global model to the lightweight edge model.
[0008] Preferably, the process of the network asset mapping module for mapping the network asset map specifically includes the following steps: S301: Stratify the heterogeneous data by dimension, construct a superimposable holographic view infrastructure, and visualize the physical distribution of network assets and the associated relationship of infrastructure, the service dependency and protocol interaction relationship between assets, and the asset risk level and threat propagation trend; where the stratification includes a basic layer in the physical topology dimension, a logical layer of service association, and a risk heat layer of dynamic heat; S302: Deeply integrate the real-time detection data with the historical knowledge base; S303: Establish a network asset relationship graph based on the graph neural network model, and generate a visual holographic map of network space resources; where the graph neural network model , where, is the node feature matrix of the th layer, with a dimension of , ([[]] is the number of nodes, is the feature dimension), is the asset adjacency matrix, is the asset feature matrix; S304: Integrate multi-dimensional data based on scenario requirements, generate a customized network asset visual map including a security protection view and a business topology view, and the generated security protection view is , , and the generated business topology view is , where the security protection view contains the asset set that meets the conditions, is the network asset, is the comprehensive dedication score of asset , is the exposure surface score of asset , is the number of open ports of asset , and 0.5 are the set high-risk threshold and high-exposure threshold, is the sub-graph that meets the conditions extracted from the asset relationship graph of the holographic map, is the service type label, is the screening condition that only includes assets related to database services.
[0009] Preferably, the process of the network asset surveying and mapping application module for the application and management of service surveying specifically includes the following steps: S401: Discover and identify specific services using a customized network asset visualization map that includes a security protection view and a service topology view; S402: Build a dynamic service asset library, evaluate the regional service status of users of specific services, and form a full life cycle management; S403: Finally, draw a connection relationship diagram of services and services in cyberspace and recommend services to specific users.
[0010] Compared with the prior art, the beneficial effects achieved by the present invention are as follows: The present invention conducts collaborative detection by combining active detection and passive detection of network assets in the service area, associates asset identification and service identification based on the data of collaborative measurement, draws a regional asset map of regional assets according to the association result, and applies and manages the drawn network asset map for service mapping, comprehensively displays network asset information, realizes cyberspace situation awareness and information control, and while maintaining low resource consumption, significantly improves the accuracy and real-time performance of asset discovery and identification, and improves the security and reliability of the terminal and the intranet system. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. In the drawings: Figure 1 is a schematic diagram of the system module composition provided by the embodiment of the present invention; Figure 2 is a flowchart of the method steps of the system module provided by the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0012] In order to further elaborate on the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following, in combination with the accompanying drawings and preferred embodiments, details the specific implementation manners, structures, features and their effects according to the present invention as follows.
[0013] The embodiments of the present invention are combined with Figure 1 , and provide the following technical solutions: A cyberspace mapping system and method, the system includes the following functional modules: A network asset collaborative measurement module, which is used to conduct collaborative detection by combining active detection and passive detection of network assets in the service area; A network asset association identification module, which is used to associate asset identification and service identification based on the data of collaborative measurement; A network asset drawing module, which is used to draw a regional asset map of regional assets according to the association result; A network asset mapping application module, which is used to apply and manage the drawn network asset map for service mapping; In the embodiments of the present invention, in combination with Figure 2 , the process of collaborative measurement by the network asset collaborative measurement module includes the following steps: S101: Use passive monitoring methods including field parsing, traffic / protocol identification, and aggregated logs to obtain data for the network assets of concern, capture traffic, and extract session characteristics; S102: Perform multi-protocol detection on the target IP; S103: Dynamically correct the active detection strategy based on the data obtained through passive monitoring, and construct a dynamic priority detection model; Exemplarily, in the priority detection model, establish a passive baseline to calculate the traffic information entropy, and at the same time perform active detection compensation. Introduce a relative time coordinate system to solve the problem of spatio-temporal inconsistency between active detection and passive monitoring data. When the data obtained through passive monitoring triggers the active detection strategy, judge the active detection mode that meets the trigger condition. The active detection mode includes three active detection strategies: fast detection, standard detection, and deep detection. When new IPs appear or the traffic entropy suddenly increases in the data obtained through passive monitoring, trigger the fast detection mode with a detection depth of the Top1000 ports and basic protocols. When a service including unknown TLS is found in the data obtained through passive monitoring, trigger the standard detection mode with a detection depth of the Top5000 ports and extended protocol stacks. When high-risk assets or continuous abnormal behaviors are found in the data obtained through passive monitoring, trigger the deep detection mode of full-port detection and vulnerability verification payloads; Further, under the above three trigger conditions, in combination with the priority perform correction of the active detection strategy, that is, use the priority to sort the asset detection priority list according to the situation feedback by the passive monitoring data, select assets starting from the highest priority until satisfied. When the remaining resources cannot cover all high-priority assets, start adaptive degradation, that is, reduce the scanning depth, similar to changing from full-port scanning to common port scanning, and at the same time adjust the concurrency of active detection, that is, dynamically limit the current according to network congestion, and assign an initial priority to newly discovered assets without historical data. When the passive monitoring data is incomplete, enable the backup detection strategy. For example, when the distribution of asset traffic protocol types is uniform, judge its behavior as complex or abnormal and need to be detected preferentially; when the entropy value is low, reduce the priority; Specifically, the calculation formula of the priority is: , where is the weight coefficient of the passive monitoring data, used to control the influence intensity of the information entropy on the priority, is the passive traffic information entropy of the asset , is the theoretical maximum value of the information entropy, related to the number of protocol types , that is , is the time decay factor weight coefficient, which is used to control the influence intensity of the time interval on the priority. is the production The time interval since the last active detection. is the maximum allowable detection interval threshold. If an asset has not been detected for more than this time, its priority is forcibly increased.
[0014] S104: Integrate the active detection response and the traffic characteristics of passive monitoring to construct a multi-dimensional device fingerprint. Associate the active detection results with the passive monitoring traffic time window, and match the active / passive data of the same device according to the port number or protocol characteristics. S105: Introduce a spatio-temporal calibration factor to map the asynchronous detection data to a unified time axis, and then correct the cross-segment observation deviation based on the network topology.
[0015] In this embodiment, the process of the network asset association identification module for asset identification and service identification association includes the following steps: S201: Construct a feature type dictionary, train the AFT model separately for each source, and use an adaptive feature transformer to align the multi-source feature spaces. Exemplarily, through a learnable linear transformation matrix and a normalization operation, map the features of different data sources to a unified semantic space. Different data sources include the original feature vectors such as port numbers, protocol types, and traffic sizes. The learnable linear transformation matrix is , and the normalization operation is , and the feature transformation formula is: , where is the transformed feature vector, that is, the feature representation aligned to the unified semantic space. is from the th data source, and the th sample feature. The sample feature is the port number, protocol type, and traffic size in the original feature vector, such as , is the compensated feature offset vector after normalization. Exemplarily, in the actual application of aligning firewall log and NetFlow traffic data features, through the input features: The firewall features as source 1 include: port number (discrete), protocol type (categorical), connection status (categorical), and the NetFlow traffic data features as source 2 include: traffic size (continuous), number of packets (continuous), TCP flag bits (categorical); The processing flow steps using the AFT model with an adaptive feature transformer are: Perform source 1 transformation, that is, map the discrete features to continuous vectors. Perform source 2 transformation, that is, normalize the traffic size and the number of packets. Output unified features: service type score, traffic intensity, connection risk index. Service type score, traffic intensity, connection risk index.
[0016] Semantic-level alignment of multi-source heterogeneous data is achieved through an adaptive feature transformer, providing high-quality standardized feature inputs for subsequent asset association analysis.
[0017] S202: Construct a hypergraph association model to establish a high-order relationship among assets, services, and protocols. Exemplarily, traditional bipartite graph models cannot represent multi-element relationships. For example, a network asset may open multiple ports, and a service may depend on multiple protocols. By using the standardized features mapped to a unified semantic space, a hypergraph association model defines nodes including asset nodes, service nodes, and port nodes, as well as hyperedges representing a complete service instance. The features of associated nodes are aggregated through hyperedges to update the node representation and perform hierarchical updates. The first layer is to learn local association patterns, such as port-service binding relationships, and the second layer is to learn global topological patterns, such as business system dependency chains. That is, the normalized features are directly used as the initial embedding of hypergraph nodes. For the same entity from different data sources, such as the same IP in firewall logs and NetFlow data, after alignment by AFT, they are merged into a single node in the hypergraph, achieving a leap from multi-source heterogeneous data to global association awareness and avoiding duplicate associations.
[0018] S203: Process the normalized feature sequence through LSTM, splice the hypergraph topology embedding with the LSTM output, generate the weights of each data source based on Softmax normalization, and generate the network asset-service association confidence by dynamically fusing the weights of multi-source data and global topological features. S204: Introduce spatio-temporal consistency verification rules to verify cross-period or cross-network segment association connections and determine whether they are false connections. S205: Construct a horizontal federated learning model, combine model parameter aggregation with differential privacy, that is, use local network asset data for model training and encrypt the uploaded model parameters through the Paillier encryption algorithm. S206: Generate a global model after encryption and add noise, and finally transfer the knowledge of the federated global model to a lightweight edge model. In this embodiment, the process of drawing a network asset map by the network asset drawing module specifically includes the following steps: S301: Stratify heterogeneous data by dimension to build a stackable holographic view infrastructure, and visualize the physical distribution of network assets and the associated relationships of infrastructure, the service dependencies and protocol interaction relationships between assets, and the asset risk levels and threat propagation trends; the stratification includes a basic layer in the physical topology dimension, a logical layer of service associations, and a risk heat layer of dynamic heat; S302: Deeply integrate real-time detection data with the historical knowledge base; S303: Establish a network asset relationship map based on the graph neural network model to generate a visualized holographic map of network space resources; the graph neural network model , where, is the node feature matrix of the th layer, with a dimension of , ( is the number of nodes, is the feature dimension), is the asset adjacency matrix, is the asset feature matrix; S304: Integrate multi-dimensional data based on scenario requirements to generate a customized network asset visualization map including a security protection view and a business topology view. The generated security protection view is , , and the generated business topology view is , where the security protection view contains a set of assets that meet the conditions, is a network asset, is the comprehensive dedication score of asset , is the exposure surface score of asset , is the number of open ports of asset , and 0.5 are the set high-risk threshold and high-exposure threshold, is a subgraph that meets the conditions extracted from the asset relationship map of the holographic map, is the service type label, is the screening condition that only includes assets related to database services.
[0019] In this embodiment, the application and management process of the network asset mapping application module for service mapping specifically includes the following steps: S401: Use a customized network asset visualization map including a security protection view and a business topology view to discover and identify specific services; S402: Build a dynamic service asset library to evaluate the regional service status of users of specific services and form a full life cycle management; S403: Finally, draw a connection relationship diagram of services and services in the cyber space to recommend services for specific users.
[0020] The above are only the preferred embodiments of the present invention, and do not impose any form of limitation on the present invention. Although the present invention has been disclosed above with the preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some changes or modifications to equivalent embodiments by using the disclosed technical content within the scope of the technical solution of the present invention. However, as long as it does not depart from the content of the technical solution of the present invention, any brief modifications, equivalent changes and modifications made to the above embodiments according to the technical essence of the present invention still fall within the scope of the technical solution of the present invention.
Claims
1. A cyber space mapping system and method, characterized in that: It includes the following functional modules: Network Asset Collaborative Measurement Module, Network Asset Association Identification Module, Network Asset Mapping Module, and Network Asset Surveying and Mapping Application Module; the Network Asset Collaborative Measurement Module is used to perform collaborative detection that combines active detection and passive detection on the network assets in the service area; the Network Asset Association Identification Module is used to associate asset identification and service identification based on the data of collaborative measurement; the Network Asset Mapping Module is used to draw a regional asset map of the regional assets according to the association result; the Network Asset Surveying and Mapping Application Module is used to apply and manage the service surveying of the drawn network asset map.
2. The cyber space mapping system and method according to claim 1, characterized in that: The process of the Network Asset Collaborative Measurement Module performing collaborative measurement includes the following steps: S101: Use a passive monitoring method including field parsing, traffic / protocol identification, and aggregated logs to obtain data on the network assets of concern, capture traffic, and extract session characteristics; S102: Perform multi-protocol detection on the target IP; S103: Dynamically correct the active detection strategy through the data obtained by passive monitoring, and construct a dynamic priority detection model; S104: Integrate the active detection response and the traffic characteristics of passive monitoring, construct a multi-dimensional device fingerprint, associate the active detection result with the passive monitoring traffic time window, and match the active / passive data of the same device according to the port number or protocol characteristics; S105: Introduce a spatio-temporal calibration factor to map the asynchronous detection data to a unified time axis, and then correct the cross-segment observation deviation based on the network topology.
3. A cyberspace mapping system and method according to claim 2, characterized in that: The construction of the dynamic priority detection model includes: In the priority detection model, establish a passive baseline to calculate the traffic information entropy, and at the same time perform active detection compensation. Introduce a relative time coordinate system to solve the problem of spatio-temporal inconsistency between active detection and passive monitoring data. When the data obtained by passive monitoring triggers the active detection strategy, judge the active detection mode that meets the trigger condition. The active detection modes include three active detection strategies: fast detection, standard detection, and deep detection. When a new IP appears or the traffic entropy suddenly increases in the data of passive monitoring, trigger the fast detection mode with a detection depth of Top1000 ports and basic protocols. When a service including unknown TLS is found in the data of passive monitoring, trigger the standard detection mode with a detection depth of Top5000 ports and an extended protocol stack. When high-risk assets or continuous abnormal behaviors are found in the data of passive monitoring, trigger the deep detection mode of full-port detection and vulnerability verification payload.
4. A cyber space mapping system and method according to claim 3, characterized in that: The priority detection model further includes: combining priorities under the three triggering conditions to correct the active detection strategy, that is, using priorities to sort the asset detection priority list based on the feedback of passive monitoring data, selecting assets starting from the highest priority until satisfied. When the remaining resources cannot cover all high-priority assets, adaptive degradation is initiated, that is, reducing the scanning depth, changing from full-port scanning to common-port scanning, and at the same time adjusting the concurrency of active detection, that is, dynamically limiting the current according to network congestion, and assigning an initial priority to newly discovered assets without historical data. When the passive monitoring data is incomplete, a backup detection strategy is enabled, that is, when the distribution of asset traffic protocol types is uniform, its behavior is judged to be complex or abnormal and requires priority detection, and the priority is reduced when the entropy value is low.
5. A cyberspace mapping system and method according to claim 4, characterized in that: The said priority The calculation formula is as follows: wherein, is the weight coefficient of passive monitoring data, used to control the influence intensity of information entropy on the priority, is the passive traffic information entropy of the asset is the theoretical maximum value of the information entropy, related to the number of protocol types i.e., is the time decay factor weight coefficient, used to control the influence intensity of the time interval on the priority, is the time interval since the last active detection, is the maximum allowable detection interval threshold. The priority of an asset that has not been detected for more than this time is forcibly increased. 6. A cyber space mapping system and method according to claim 1, characterized in that: The process of the Network Asset Association Identification Module associating asset identification and service identification includes the following steps: S201: Construct a feature type dictionary, train the AFT model separately for each source, and use an adaptive feature transformer to align the multi-source feature spaces; S202: Construct a hypergraph association model to establish a high-order relationship of asset-service-protocol; S203: Process the normalized feature sequence through LSTM, splice the hypergraph topology embedding with the LSTM output, generate the weights of each data source based on Softmax normalization, and generate the confidence of network asset-service association by dynamically fusing the weights of multi-source data and the global topology features; S204: Introduce the spatio-temporal consistency verification rule to verify the associated connections across time periods or network segments and determine whether they are false connections; S205: Construct a horizontal federated learning model, combine the model parameter aggregation with differential privacy, that is, use the local network asset data for model training, and encrypt the uploaded model parameters through the Paillier encryption algorithm; S206: Generate a global model after encryption and add noise, and finally transfer the knowledge of the federated global model to the lightweight edge model.
7. A network space mapping system and method according to claim 6, characterized in that: The alignment of the multi-source feature space using the adaptive feature transformer includes: mapping the features of different data sources to a unified semantic space through a learnable linear transformation matrix and a normalization operation. The different data sources include the original feature vectors such as port numbers, protocol types, traffic sizes, etc. The learnable linear transformation matrix is , and the normalization operation is . The feature transformation formula is: , where is the transformed feature vector, that is, the feature representation aligned to the unified semantic space, is the th sample feature from the th data source. The sample feature is the annoying port number, protocol type, and traffic size in the original feature vector, such as , is the compensated feature offset vector after normalization.
8. A cyber space mapping system and method according to claim 7, characterized in that: The construction of the hypergraph association model includes: defining nodes including asset nodes, service nodes, and port nodes, and hyperedges representing a complete service instance through the hypergraph association model, aggregating the features of associated nodes through hyperedges, updating the node representation, and performing hierarchical updates. The first layer is to learn local association patterns, such as port-service binding relationships, and the second layer is to learn global topological patterns, such as business system dependency chains; that is, the normalized features are directly used as the initial embedding of the hypergraph nodes. For the same entity from different data sources, such as the same IP in firewall logs and NetFlow data, after alignment by AFT, they are merged into a single node in the hypergraph.
9. A network space mapping system and method according to claim 1, characterized in that: The specific process of the network asset mapping module for network asset map drawing includes the following steps: S301: Stratify the heterogeneous data by dimension, construct an overlayable holographic view infrastructure, and visualize the physical distribution of network assets and the associated relationships of infrastructure, the service dependencies and protocol interaction relationships between assets, and the asset risk levels and threat propagation trends; the stratification includes the basic layer of the physical topology dimension, the logical layer of service association, and the risk heat layer of dynamic heat; S302: Deeply integrate the real-time detection data with the historical knowledge base; S303: Establish a network asset relationship graph based on the graph neural network model to generate a visualized holographic map of network space resources; the graph neural network model , where is the node feature matrix of the th layer, with a dimension of , ([[]] is the number of nodes, is the feature dimension), is the asset adjacency matrix, is the asset feature matrix; S304: Integrate multi-dimensional data based on scenario requirements to generate a customized network asset visual map including a security protection view and a business topology view. The generated security protection view is , , and the generated business topology view is . Among them, the security protection view contains a set of assets that meet the conditions, is a network asset, is the comprehensive dedication score of the asset , is the exposure surface score of the asset , is the number of open ports of the asset , and 0.5 are the set high-risk threshold and high-exposure threshold, is a subgraph that meets the conditions extracted from the asset relationship graph of the holographic map, is a service type label, is a screening condition that only includes assets related to database services.
10. A cyber space mapping system and method according to claim 9, characterized in that: The specific process of the network asset survey and mapping application module for service survey and mapping application and management includes the following steps: S401: Use a customized network asset visual map including a security protection view and a business topology view to discover and identify specific services; S402: Construct a dynamic service asset library, evaluate the regional service status of users of specific services, and form a full life cycle management; S403: Finally, draw a connection relationship diagram of services and services in the cyberspace and recommend services to specific users.
Citation Information
Patent Citations
Network asset surveying and mapping discovery method and device based on big data
CN111555988A
Asset surveying and mapping method and system based on cyberspace surveying and mapping multi-source fusion
CN117650994A
Cybersecurity risk analysis and anomaly detection using active and passive external reconnaissance
US20210360032A1