System and method for identifying computer network devices using inventory rules
By using inventory rules and weighting factors to identify computer network equipment, the problems of low identification efficiency and insufficient accuracy in the prior art are solved, and more efficient and accurate network equipment recognition is achieved, reducing interference to PLC equipment.
Patent Information
- Application Number
- CN202510490546.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2020-03-19
- Filing Date
- 2020-06-15
- Publication Date
- 2025-07-22
AI Technical Summary
The prior art has problems of low efficiency and insufficient accuracy when identifying computer network equipment, especially in CPS networks, especially in PLC equipment updates and vulnerability detection processes.
Inventory rules and weighting factors are used to identify computer network devices, intercept data services, analyze whether multiple inventory rules are met, use weighting factor values to prioritize the verification of satisfaction, and identify equipment and its parameters, including a combination of network filters, rule verification modules and network device identification modules.
It improves the recognition efficiency and accuracy of computer network equipment, reduces interference to PLC equipment, and enhances the accuracy and security of network equipment inventory.
Smart Images

Figure CN120358055A_ABST
Abstract
Description
[0001] This application is a divisional application of a Chinese patent application with an application date of June 15, 2020, an application number of 202010541680.3, and an invention title of "System and Method for Identifying Computer Network Devices Using Inventory Rules". Technical Field
[0002] The present disclosure relates to the field of computer networking, and more particularly to systems and methods for identifying computer network devices using inventory rules. Background Art
[0003] In today's world, with the widespread use of computer devices such as desktop and portable personal computers, as well as smart phones, tablet computers, and other mobile devices, various types of computer threats have become increasingly common. Examples of computer threats include network worms, Trojan horses, keyloggers, ransomware, computer viruses, and computer attacks. Computer attacks can be further classified into targeted attacks (also known as target attacks - TA) and sophisticated attacks (advanced persistent threats - APT) against cyber physical systems (CPS) and information systems. An information system is a collection of computing devices and communication devices used for their interconnection, also known as enterprise infrastructure. Hackers may have a variety of goals, from simply stealing employees' personal data to industrial espionage. Hackers often obtain information about the enterprise network architecture, the principle of internal file flow, the means used to protect the network and computer devices, or any other information specific to the information system. Such information allows hackers to bypass existing defense means, which often lack sufficient flexibility to meet all the requirements of the information system.
[0004] Modern computer networks (especially CPS networks) typically include multiple devices, namely controllers, sensors, actuators, and other network nodes. Many devices may use outdated software that contains known vulnerabilities. Given the existence of various complex and at least partially outdated technical devices, the process of updating software for such devices requires a large amount of time and resources. In at least some cases, it may even be impossible to update such outdated software due to the manufacturer's discontinuation of support. Thus, in order to ensure the security of the CPS network, it may be necessary to create an inventory of network devices in order to search for and eliminate vulnerabilities in computer devices at a higher level such as the gateway level. The term "device inventory" or simply "inventory" as used herein generally refers to the identification of devices connected to the network and the attributes / parameters of these devices (including but not limited to the version of the operating system, firmware, software, etc.). Additionally, the device inventory provides the network administrator with complete and accurate data about the devices and network services being used by the network, with the aim of ensuring network security.
[0005] There are at least two well-known methods for generating a computer network inventory in the prior art. The first method is called network scanning and involves active network interaction with network objects. However, this method involves the risk of interrupting the running processes of devices (such as CPS controllers - PLCs). In this example, the PLC may receive information about the status of controlled objects from control devices and sensors. In response to receiving this information, the PLC can act on actuators. The PLC is not programmed to interact with other network objects. Thus, after receiving an inventory request from the system, the execution of the PLC's instructions may be interrupted, and operator intervention may be required to restart the PLC or update its firmware. The second method is called passive analysis of network traffic to collect information about CPS devices, which addresses the risks inherent in active (network scanning) analysis. However, this method also has several drawbacks, such as a relatively low level of determining the attributes of CPS network devices.
[0006] In view of this, there is a need to more effectively identify computer network devices and / or identify and determine device attributes / parameters. Summary of the Invention
[0007] Aspects of the present disclosure relate to the field of computer networks.
[0008] Aspects of the present disclosure are designed to use inventory rules to identify network devices and identify / determine parameters associated with the identified network devices, or to effectively identify computer network devices using the weighting factors of inventory rules.
[0009] The technical effect of the present disclosure is to more effectively identify network devices.
[0010] In one exemplary aspect, a method for effectively identifying computer network devices using the weighting factors of inventory rules is disclosed. The method includes: intercepting data traffic across one or more communication links of a computer network; analyzing the intercepted data traffic to determine whether the intercepted data traffic satisfies one or more of a plurality of inventory rules, where each of the plurality of inventory rules includes one or more conditions that indicate the presence of a specific computer network device having a set of parameters, and each of the plurality of inventory rules has a weighting factor value that indicates the priority of applying the corresponding rule; and using the weighting factor values of one or more satisfied inventory rules to identify one or more devices of the computer network, where the satisfaction of each of the plurality of inventory rules is determined by verifying the satisfaction of each of the plurality of inventory rules in descending order of the corresponding weighting factor values of the plurality of inventory rules, so as to determine one or more satisfied inventory rules. In one aspect, the method further includes stopping the further verification of the inventory rules when an inventory rule among the plurality of inventory rules is first satisfied.
[0011] In one aspect, the method further includes stopping further verification of the inventory rules when the combined weighting factor value of the satisfied inventory rules is greater than a predetermined threshold.
[0012] In one aspect, the predetermined threshold includes a combined threshold set for all inventory rules.
[0013] In one aspect, the predetermined threshold includes a combined threshold for a predetermined group of inventory rules, wherein at least two of the inventory rules in the group of inventory rules identify the same device of the computer network or the same parameter of the same device of the computer network.
[0014] In one aspect, the intercepting of data traffic across one or more communication links of the computer network includes: intercepting only data traffic from a previously unrecognized device.
[0015] In one aspect, the weighting factor value depends on a previously recognized device.
[0016] In one exemplary aspect, a system for effectively identifying computer network devices using a weighting factor of inventory rules is disclosed, the system including: a hardware processor configured to: intercept data traffic across one or more communication links of a computer network; analyze the intercepted data traffic to determine whether the intercepted data traffic satisfies one or more of a plurality of inventory rules, wherein each of the plurality of inventory rules includes one or more conditions that indicate the presence of a specific computer network device having a set of parameters, wherein each of the plurality of inventory rules has a weighting factor value that indicates the priority of applying the corresponding rule; and use the weighting factor values of one or more of the satisfied inventory rules to identify one or more devices of the computer network, wherein the satisfaction of each of the plurality of inventory rules is determined by verifying the satisfaction of each of the plurality of inventory rules in descending order of the corresponding weighting factor values of the plurality of inventory rules, thereby determining one or more of the satisfied inventory rules.
[0017] In one exemplary aspect, a non - transitory computer - readable medium is disclosed, having stored thereon computer - executable instructions for effectively identifying computer network devices using weighted factors of inventory rules, including the following instructions: intercept data traffic across one or more communication links of a computer network; analyze the intercepted data traffic to determine whether the intercepted data traffic satisfies one or more of a plurality of inventory rules, wherein each of the plurality of inventory rules includes one or more conditions that indicate the presence of a specific computer network device having a set of parameters, and wherein each of the plurality of inventory rules has a weighted - factor value that indicates the priority of applying the corresponding rule; and use the weighted - factor values of one or more of the satisfied inventory rules to identify one or more devices of the computer network, wherein the satisfaction of each of the plurality of inventory rules is determined by verifying the satisfaction of each of the plurality of inventory rules in descending order of the corresponding weighted - factor values of the plurality of inventory rules, thereby determining one or more of the satisfied inventory rules. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The accompanying drawings are incorporated into and constitute a part of this specification, showing one or more exemplary aspects of the present disclosure, and the principles and implementations of these exemplary aspects are explained in conjunction with the following detailed description.
[0019] Figure 1a An example of a technical system in which aspects of the present invention can be implemented is schematically shown.
[0020] Figure 1b A specific example of a technical system in which aspects of the present invention can be implemented is schematically shown.
[0021] Figure 2 A diagram showing a system for identifying computer network devices using inventory rules according to aspects of the present disclosure.
[0022] Figure 3 A flowchart showing a method for identifying computer network devices using inventory rules according to aspects of the present disclosure.
[0023] Figure 4 An example of a general - purpose computer system is shown. DETAILED DESCRIPTION
[0024] The following exemplary aspects are described in the context of systems, methods, and computer - program products for identifying computer network devices using inventory rules. Those of ordinary skill in the art will recognize that the following is illustrative only and not intended in a limiting sense. Given the present disclosure, other aspects will be readily apparent to those skilled in the art. The detailed implementations of the exemplary aspects are now described with reference to the accompanying drawings. Throughout the drawings and the following description, like reference numerals are used to refer to like or similar items as much as possible.
[0025] Many of the definitions and concepts used when describing aspects of the present disclosure will now be introduced.
[0026] The term "Indicator of Compromise (IOC)", also known as "Indicator of Infection", refers to artifacts or residual characteristics that have invaded an information system and can be observed on a computer or network. Typical indicators of compromise may include triggered antivirus records, unknown Internet Protocol (IP) addresses, checksums of suspicious files, Uniform Resource Locators (URLs) of suspicious websites, domain names of botnet command centers, etc. There are many standards for indicators of compromise, including but not limited to:
[0027] OpenIOC (https: / / www.fireeye.com / blog / threat-research / 2013 / 09 / history-openioc.html), STIX (https: / / stix.mitre.org / ), CybOX (https: / / cybox.mitre.org), and so on.
[0028] The term "event in the information system security system" (hereinafter simply referred to as event) refers to a detected system state, service or network state indicating a possible violation of the information system security policy, violation of monitoring means and measures or their failure, or a previously unknown information system security-related situation.
[0029] The term "information security incident" (hereinafter simply referred to as incident) refers to one or more unexpected or unanticipated events that may harm business operations and threaten the security of information systems.
[0030] The term "controlled object" refers to a technical object that is subject to external actions (control and / or disturbance) in order to change the state of this technical object. On the one hand, such controlled objects may include devices (such as electric motors) or technical processes (or parts thereof).
[0031] The term "technical process (TP)" refers to a material production process, consisting of sequential state changes of material entities (work objects).
[0032] The term "technical process control (process control)" refers to a set of methods used to control process variables during the production of the final product.
[0033] The term "control loop" refers to the material entities and control functions required to automatically adjust the measured process variable value to a rated set value. A control loop may include detectors, sensors, controllers, and actuators.
[0034] The term "process variable PV" refers to the current measured value of a specific part of the TP being observed or monitored. The process variable may be, for example, a measurement value from a sensor.
[0035] The term "setpoint" refers to the value of the process variable that should be maintained.
[0036] The term "manipulated variable (MV)" refers to the parameter that is adjusted to keep the value of the process variable at the setpoint level.
[0037] The term "external action" refers to a method of changing the state of an element (such as an element of a technical system (TS)) that undergoes an action in a specific direction, and this action is transmitted in the form of a signal from one element of the TS to another element of the TS.
[0038] The term "controlled object state" refers to the sum of its basic attributes, which is represented by state parameters that are changed or maintained under the influence of external actions (including control actions from the control subsystem).
[0039] The term "state parameter" refers to one or more numerical values that characterize the basic attributes of an object. On the one hand, a state parameter is a numerical value of a physical quantity.
[0040] The term "formal state of the controlled object" refers to the state of the controlled object corresponding to the flow chart and other technical documents (in terms of TP) or business scheduling (in terms of equipment).
[0041] The term "control action" refers to an intentional (the goal of this action is to act on the state of the object) and legal (provided by TP) external action of the control subject of the control subsystem acting on a part of the controlled object, and as a result, the state of the controlled object is changed or the state of the controlled object is preserved.
[0042] The term "disturbance action" refers to an intentional or unintentional and illegal (not provided by TP) external action acting on the state of the controlled object, including actions acting on a part of the controlled object.
[0043] The term "control subject" refers to a device that applies a control action to a controlled object or transmits a control action to another controlled object for transformation before directly applying the control action to the controlled object.
[0044] The term "multi-level control subsystem" refers to a set of control subjects involving multiple levels.
[0045] The term "Cyber-Physical System (CPS)" refers to the concept of an information system that integrates computing resources into physical processes. In such a system, sensors, devices, and information systems are connected along the entire value creation chain, beyond the boundaries of a single enterprise or business. These systems can interact with each other via standard Internet protocols for prediction, self-tuning, and adaptation to changes. Examples of CPS are technical systems, the Internet of Things (including wearable devices), and the Industrial Internet of Things.
[0046] The term "Internet of Things (IoT)" refers to a network of computers that are equipped with built-in technology for interacting with each other or with the outside world. The IoT includes technologies such as wearable devices, electronic systems in transportation, smart cars, smart cities, industrial systems, and more.
[0047] The term "Industrial Internet of Things (IIoT)" refers to devices connected to the Internet and extended analytical platforms that perform processing on data obtained from the connected devices. IIoT devices can be very diverse - from small weather sensors to complex industrial robots.
[0048] The term "technical system (TS)" refers to a set of control subjects and control objects (TP or equipment) of multi-level control subsystems that are functionally interconnected. In a technical system, the state change of the control object is achieved by the state change of the control subject. The structure of a technical system is formed by the basic elements of the technical system (the control subjects and control objects of the interconnected multi-level control subsystems) and the communication links between these elements. If the control object in the technical system is a technical process, the purpose of control is to change the state of the work object (raw material, processed blank, etc.) by causing the state change of the control object. If the control object in the technical system is equipment, the purpose of control may be to change the state of the equipment (vehicle, spacecraft, etc.). The functional relationship of TS elements often refers to the relationship between the states of these elements. There may not even be a direct physical link between the elements. For example, there may be no physical link between an actuator and a technical operation. However, for example, the cutting speed of a spindle may be functionally related to the rotation speed of the spindle even if these state parameters are not physically connected.
[0049] The term "control subject state" refers to the sum of the basic properties of the control subject, the state parameters that can be changed or maintained under the influence of external actions.
[0050] The term "basic attributes of the control subject" (and correspondingly basic parameters of the state) refers to attributes that directly affect the basic attributes of the state of the control object. The basic attributes of the control object can be attributes that directly affect the functional factors (precision, safety, efficacy) for TS control. Examples of basic attributes can include, but are not limited to: cutting conditions corresponding to form specified conditions, train movements corresponding to train routes, and processes to keep reactor temperature within an allowable range. Depending on the factors being controlled, the state parameters of the control object can be selected, and the state-related parameters of the control subject that apply control actions to the control object can be selected accordingly.
[0051] The term "state of technical system elements" refers to the state of control subjects and objects.
[0052] The term "true state of elements of a technical system" refers to the state of the elements of a technical system that act on a controlled object at a certain time, which is determined by measuring state parameters and intercepting signals (services) between TS elements. For example, sensors installed in the TS can be used to perform measurements of state parameters.
[0053] The term "true state of a technical system" refers to the sum of the true states of the interrelated elements of a technical system.
[0054] The term "cybernetic block" refers to the cyber-physical monitoring system elements that monitor the operation process of the elements of a technical system.
[0055] The term "state space" refers to a method of formalizing the state changes of a dynamic system (technical system or cyber-physical system).
[0056] The term "computer attack" (hereinafter also referred to as cyber attack) refers to targeted actions on information systems and computer telecommunication networks through hardware and software, aiming to undermine the information security in these systems and networks.
[0057] The term "targeted attack" (hereinafter also referred to as targeted attack - TA) refers to a special case of a computer attack targeting a specific organization or a specific individual.
[0058] The term "SIEM (Security Information and Event Management) system" refers to a means for overall control of organizational information security and management of events obtained from various sources. The SIEM system can analyze events from network devices and various applications in real time.
[0059] Figure 1a An example of a technical system (TS) is schematically shown, which includes: a control subject 110a; a control subject 110b that can be configured to form a multi-level control subsystem 120; a horizontal communication link 130a and a vertical communication link 130b. The control subject 110b can be grouped by levels 140.
[0060] Figure 1b A specific example of an implementation of a technical system 100' is schematically shown. The control subject 110a' can be a TP or a device. On the one hand, control actions can be scheduled by an automatic control system (ACS) 120' to the control subject 110a'. The ACS 120' can have three levels 140', and these three levels 140' are in the horizontal level through horizontal communication links (links within the same level, Figure 1bThe control subjects 110b' (not shown) are interconnected horizontally through horizontal communication links 130b' and vertically through vertical communication links 130b' (links between different levels of the ACS system). The relationship between the control subjects 110b' can be a functional relationship. In other words, under normal circumstances, a change in the state of a control subject 110b' at one level can cause a change in the state of the control subject 110b' connected to it at the same level and / or any other level. Information about the change in the state of the control subject 110b' can be transmitted in the form of signals along the horizontal communication links and / or vertical communication links 130b' established between the control subjects 110b'. In other words, information about the change in the state of a specific control subject 110b' is an external action with respect to other control subjects 110b'. The levels 140' within the ACS 120' can be identified based on the purpose of the control subject 110b'. The number of levels may vary depending on the complexity of the automatic control system 120'. A simple technical system can include one or more lower levels. On the one hand, wired networks, wireless networks, and micro integrated circuits can be used for the physical connection between the elements of the TS (110a', 110b') and the subsystems of the TS100. On the one hand, Ethernet, Industrial Ethernet, or any industrial network among various industrial networks can be used for the logical link between the elements of the TS (110a', 110b') and the subsystems of the TS100. Industrial networks and protocols use the following various types and standards: Profibus, FIP, ControlNet, Interbus-S, DeviceNet, P-NET, WorldFIP, LongWork, Modbus, and so on.
[0061] The topmost level (supervisory control and data acquisition level - SCADA) can be a scheduler / operator control level, including at least the following control subjects 110b': controllers, control computer human-machine interfaces (HMIs) ( Figure 1b shown in the context of a SCADA control subject). This level can be aimed at tracking the element states of the TS (110a', 110b'), obtaining and accumulating information about the element states of the TS (110a', 110b'), and making corrections when needed.
[0062] The intermediate level (CONTROL level) can be the controller level, which at least includes the following control entities: programmable logic controller (PLC), counter, repeater, regulator. The control entity 110b' of type "PLC" can receive information about the status of the control entity 110a' from the control entities of type "measurement and control equipment" and the control entities of type "sensor". The control entity of type "PLC" can formulate (create) control actions according to the programming control algorithm for the control entities of type "actuator". The actuator can directly execute the action at the lower level (specifically, apply it to the controlled object). On the one hand, the actuator can be part of the execution device (equipment). Regulators such as PID regulators (proportional integral derivative controllers or PID controllers) can be devices in the feedback control loop.
[0063] The lower level (input level / output level) can be the hierarchy of such control entities, such as: sensors and measuring devices that monitor the status of the controlled object 110a' and actuators. The actuator can directly act on the status of the control entity 110a' to make it conform to the formal status, that is, the status corresponding to the technology transfer, technical drawings or other technical documents (in terms of TP) or the business schedule (in terms of equipment). At this level, it is possible to coordinate the signals from the control entities 110b' of type "sensor" with the inputs of the intermediate control entities, and to coordinate the control actions executed by the control entities 110b' of type "PLC" with the control entities 110b' of type "actuator" that implement these actions. As mentioned above, the actuator can be part of the execution device. The execution device can move the regulating element according to the signal from the regulator or the control device. The execution device can be the last connecting part in the automatic control chain and generally can be composed of the following blocks:
[0064] · Amplifying devices (contactors, frequency converters, amplifiers, etc.);
[0065] · Actuators (electric actuators, pneumatic actuators or hydraulic actuators) with feedback elements (output shaft position sensors, end position signaling, manual drivers, etc.);
[0066] · Regulating elements (valves, gates, dampers, air dampers, etc.).
[0067] According to the application conditions, the execution device can have different designs. The main blocks of the execution device usually include an actuator and a regulating element.
[0068] On the one hand, the execution device as a whole can be called an actuator.
[0069] Figure 2An exemplary embodiment of a system (hereinafter referred to as an inventory system) for identifying computer network devices using inventory rule 210 is shown. In the illustrated example, the inventory system 210 can be a component of a cyber-physical system (CPS) 200. On the one hand, the inventory system 210 can be configured to perform passive analysis on intercepted data traffic to collect and accumulate information about various devices of a corresponding computer network (in the given example, the computer network of the CPS 200). On the one hand, the network filter 211 of the inventory system 210 can be configured to intercept data traffic. The network filter 211 can be configured to intercept each data packet exchanged between the PLC 110b' and the SCADA 110b' components and can be configured to send the intercepted data packets to the rule verification module 212 for verification. On the one hand, the intercepted data traffic can include network packets, which include network, transport, and application layer data. On the one hand, the network filter 211 can be configured to intercept data traffic across one or more communication link layers of a computer network (e.g., the transport layer, network layer, or data link layer according to the OSI model) for a certain range of IP addresses. Each data packet includes a header part and a payload part.
[0070] On the one hand, the rule verification module 212 can be configured to analyze a plurality of inventory rules to determine whether the intercepted data traffic satisfies any of the inventory rules 214. On the one hand, the plurality of inventory rules can be stored, for example, in a database of the inventory rules 214. Each of the plurality of inventory rules can include a condition indicating the presence of a specific computer network device with a set of specific parameters / attributes. In other words, each inventory rule can contain some conditions that, if satisfied, indicate the presence of a network device with given parameters in the computer network of the CPS 200. On the one hand, each inventory rule can have an associated weighted factor value. The weighted factor value can depend on previously identified computer network devices. On the one hand, the weighted factor value of each inventory rule determines the priority of applying the rule.
[0071] On the one hand, the network device identification module 213 can be configured to use the satisfied inventory rules to identify one or more devices of a computer network and the parameters associated with the identified devices. On the one hand, during the identification process, the network device identification module 213 can be configured to consider the weighted factor value of each satisfied inventory rule. On the one hand, the network device identification module 213 can be configured to store data about the identified devices in a dedicated database, such as a database containing the device list 215.
[0072] On the one hand, the rule verification module 212 can be configured to search for values in the header portion and / or payload portion of multiple intercepted data packets that match corresponding parameter values included in multiple inventory rules. Optionally, the rule verification module 212 can include a payload data checker to implement one or more (payload) data checking techniques; or one or more deep packet inspection (DPI) techniques can be utilized separately. DPI techniques are well known in the art and will not be elaborated here for the sake of brevity. On the one hand, if the rule verification module 212 determines that one or more inventory rules are satisfied, the network device identification module 213 can use the satisfied inventory rules to identify one or more devices of the computer network and the parameters associated with the identified devices. Such device parameters can include, but are not limited to:
[0073] a) Device identifier;
[0074] b) Device name;
[0075] c) Device model;
[0076] d) Device type;
[0077] e) Security status;
[0078] f) Manufacturer;
[0079] g) Protocol;
[0080] h) Characteristics of the installed operating system (OS);
[0081] i) Characteristics of the installed software.
[0082] The device identifier parameter can be used to provide clear device identification. The device identifier parameter can include, for example, the MAC address of the device, the IP address of the device, or a combination of these addresses. In various aspects, any other unique device identifier can be used as the device identifier parameter.
[0083] The network device identification module 213 can be configured to determine the device name parameter using, for example, the NetBIOS Name Service (NBNS), Domain Name Resolution (DNS), and / or other protocols.
[0084] The device type parameter can include one of the following: HMI / SCADA, relay protection, server, workstation, PLC, engineering station, mobile device, or any other network device.
[0085] The security status parameter can be an indicator of the presence or absence of critical primary security events. The security status can take one of the following example values:
[0086] Critical value - Indicates that at least one critical event involving the device has been detected. For example, if an unpatched vulnerability regarding the corresponding device is known, the security status may include a critical value.
[0087] Warning value - Indicates that there is at least one event involving the device that is likely to affect the security of the device, but this impact on the device may not be critical. For example, the security status can include a warning value that indicates that the latest version of the operating system or firmware may not be installed on the device, but no critical vulnerabilities have been detected on the device.
[0088] Safe value - Indicates that there are no critical warning security events.
[0089] As described above, the database of inventory rule 214 can contain multiple inventory rules. On the other hand, the database of inventory rule 214 can contain the following exemplary but non-limiting inventory rules for identifying devices and corresponding device parameters:
[0090] a. Seller rule, which utilizes a list of known MAC addresses and / or IP addresses of devices.
[0091] b. Asset rule, which is configured to search for digital signatures that identify one or more devices and one or more parameters associated therewith. This rule can enable network devices to identify module 213 to determine specific device parameters, such as but not limited to device model, firmware version on the device, software and / or hardware version numbers, OS version identifiers, information about the services provided by the device, and other parameters.
[0092] c. Protocol rule, which can be configured to search for digital signatures to identify one or more network protocols being used by the intercepted data traffic. This protocol rule can be a specific case of the asset rule, which can be used to identify network protocols.
[0093] d. Fingerprint rule, which is configured to use digital fingerprints to determine one or more device parameters. On the one hand, this fingerprint rule can utilize multiple generated TCP / IP fingerprints. As used herein, the term "generated fingerprint" means defining a fingerprint based on a rule, particularly the process of generating a network device fingerprint using IP scan results and service scan results. That is, IP scan results can be used to generate an operating system (OS) fingerprint based on Transmission Control Protocol (TCP) / IP packets, and service scan results can be used to generate a service fingerprint based on service banners. As used herein, the term "service scan" means scanning ports corresponding to IP addresses determined to be active based on IP scan results. That is, a service scan involves determining whether a port of a specific IP address is currently providing a service. There is no particular limit to the number of ports to be scanned for the service scan. On the one hand, the fingerprint rule can enable network devices to identify module 213 to determine device parameters such as device model and operating system.
[0094] On the one hand, if a device parameter has been recognized by at least two different inventory rules, the inventory rule with the largest weighted factor value is selected for device identification. For example, the weighted factor value of an asset rule can be equal to 90, which may be greater than the weighted factor value of a seller rule (e.g., 20). Accordingly, if the network device identification module 213 uses the seller rule and the asset rule to identify a device and its device parameters, the asset rule (with the largest weighted factor value) can obtain the priority for device identification. In one instance, this situation may be caused by the lower accuracy of the seller rule compared to the asset rule. For example, in a network with multiple routers, the MAC address or IP address may not identify the device itself, but rather the router that connects the subject device to the network. In contrast, the asset rule can allow the identification of the device itself and the corresponding device parameters, such as the device manufacturer.
[0095] On the other hand, if a device parameter has been recognized by at least three different inventory rules such that at least two different inventory rules recognize the same value of the device, the network device identification module 213 can accumulate these values. For example, if inventory rule Α (with a weighted factor value of 30) and inventory rule B (with a weighted factor value of 40) have determined that the OS of the device is Windows 10, while inventory rule C (with a weighted factor value of 50) has determined that the OS of the device is Windows 7, the network device identification module 213 can use inventory rules A and B because their combined weighted factor value (70) is higher than the weighted factor value of rule C (50). Thus, in the given instance, the network device identification module 213 can determine that the OS of the device is Windows 10.
[0096] On yet another hand, different network service data belonging to the same device can be used to satisfy at least two of the above inventory rules. For example, one rule can be satisfied by analyzing network layer data, while another rule can use transport layer data.
[0097] As mentioned above, on the one hand, the weighted factor value of each inventory rule can depend on the previously recognized computer network devices and the parameters of those devices. For example, if a specific rule has been used to identify a specific device with specific parameters and the analyst has confirmed the correctness of the device identification, the weight of that specific rule can be increased accordingly.
[0098] On still another hand, the weighted factor value can depend on the topology of the computer network. For example, if the topology of the computer network is a bus, i.e., there is no router in the network, the asset rule and the seller rule can be assigned the same weighted factor value, or the seller rule can be assigned a larger weighted factor value than the asset rule. In the second case, Figure 2The operating speed of the system shown, because the asset rules will no longer be verified when the seller's rules are met.
[0099] On the one hand, in the case of changing the inventory rules or adding new inventory rules, the rule verification module 212 can be configured to verify the changed inventory rules or the corresponding new inventory rules by analyzing the same network traffic that meets the changed inventory rules. Therefore, the system and method for using inventory rules to identify computer system devices proposed by the present invention can immediately identify new devices and their parameters in a computer network after adding new inventory rules or changing existing inventory rules.
[0100] On the other hand, the rule verification module 212 can be configured to verify the satisfaction of inventory rules in descending order of the weighted factor values of each inventory rule. On yet another hand, when a certain inventory rule is first satisfied, the rule verification module 212 can stop further analyzing the intercepted network traffic and can stop further verifying the inventory rules. Once at least one inventory rule is satisfied, the network device identification module can be configured to identify at least one device in the computer network and the parameters of the device according to the satisfied inventory rule and considering the weighted factor value associated with the rule. Therefore, first of all, the rule verification module 212 can check the highest priority rule (with the largest weighted factor value) and may not even check the low priority rules (with the lowest weighted factor value). Advantageously, this feature can improve system efficiency.
[0101] On the one hand, after at least one inventory rule is satisfied, if the combined weighted factor value of all those satisfied inventory rules is greater than a predetermined threshold, the network device identification module 213 can identify at least one device in the computer network and the parameters of the device according to each satisfied inventory rule. Therefore, if the combined weighted factor value of the satisfied rules is less than the predetermined threshold, the network device identification module 213 may not identify computer network devices at all. This function can reduce the number of type I errors when low priority rules misidentify computer network devices or their parameters. Therefore, the accuracy of identifying computer network device parameters can be improved.
[0102] On the one hand, the network device identification module 213 can specify the above threshold using one of the following methods:
[0103] a) Separate thresholds for each inventory rule;
[0104] b) A joint threshold for all inventory rules;
[0105] c) A joint threshold for a set of rules, where the set of rules includes at least two inventory rules that identify the same computer network device or the parameters of the same computer network device.
[0106] On the one hand, the network filter 211 can be configured to intercept only network traffic from newly identified devices that have not been previously recognized. Data regarding previously identified devices can be placed, for example, on a device list database 215 by a network device identification module 213.
[0107] On the one hand, inventory rules can be written in a formal language, an example of a formal language being YAML. An example of a seller rule is as follows:
[0108] id:4
[0109] confidence:20
[0110] vendor_mac_list:['00:13:d5','94:b8:c5','00:0a:dc']
[0111] host:{vendor:HostVendor_Rugged,key:src_mac}
[0112] This rule identifies devices with a manufacturer (host field) of HostVendor_Rugged, provided that the MAC address of the device is included in the list vendor_mac_list. An identifier id = 4 and a weighting factor value (confidence value) = 20 will be assigned to the device.
[0113] An example of an asset rule is as follows:
[0114] id:13009
[0115] confidence:90
[0116] message:"Siemens Siprotec Model"
[0117] protocols:[goose]
[0118] prefilter:{pattern:"^.{8}\\x61.+7(SD|SA|UT|SJ|VK|VE)(4|5|6|8)\\d\\d?",flags:"Hsi"}
[0119] host:{type:HostType_Plc,vendor:HostVendor_Siemens,key:src_mac}
[0120] asset:{
[0121] type:hardware,
[0122] key:AssetKey_Model,
[0123] pattern:"(7[A-Za-z][A-Za-z]\\d\\d\\d?)",
[0124] #ParamLoc_PlcModel_Siprotec_Param1='SIPROTEC'+$p0
[0125] param_loc:ParamLoc_PlcModel_Siprotec_Param1}
[0126] This rule can be used for data of protocol GOOSE (protocol field). The prefilter field will contain a template for searching for matches of the rule conditions in the network data layer. The network device described by the host field serves as the source of the network service that meets the rule (this device can be a router or device to be identified). In the given example, the device type is PLC, the manufacturer (seller) is Siemens, and the device address (key) is the MAC address of the device. The asset field specifies the device and the device parameters to be identified by the rule. The asset field can contain values such as type (the type of information extracted from the network service; in the given example, information about the hardware) and pattern (a template for extracting the necessary information from the network service after prefiltering the rule). The value of param_loc can contain the result of extracting information from the network service.
[0127] An example of a protocol rule is as follows:
[0128] id:200006
[0129] confidence:75
[0130] message:"RDP Protocol"
[0131] protocols:[tcp]prefilter:{pattern:"rdpdr.*cliprdr.*rdpsnd",flags:"Hsi"}
[0132] asset:{type:software,key:AssetKey_CommonProto,description:
[0133] CommonProto_Rdp_OverTcp}
[0134] In this example, the protocol rule utilizes TCP layer data with an indication pre-filter, and after meeting this rule, the protocol RDP (Remote Desktop Protocol) can be identified.
[0135] An example of the fingerprint rule is as follows:
[0136] id:15000005
[0137] confidence:50
[0138] message:"General Electric C60 / B30(SYN+ACK)"
[0139] ip_flags:[]ttl:[[27,30]]
[0140] tcp_flags:[syn,ack]
[0141] tcp_win_size:[
[4096] ]
[0142] tcp_options:[mss]
[0143] eth_padding:"(ether[padding_offset:2]==0x8888)"
[0144] host:{type:HostType_Plc,vendor:HostVendor_GE,key:src_ip}asset:{type:hardware,key:AssetKey_Model,description:PlcModel_GeneralElectric_C60_B30}
[0145] The conditions for meeting this rule can be that the range of the ttl protocol parameter is from 27 to 30, the presence of flags syn and ack, the TCP protocol window size (tcp_win_size) is equal to 4096, and the presence of the transport layer option mss (Maximum Segment Size). In addition, the analyzed network service data should meet the BPF filter eth_padding.
[0146] Figure 3A flowchart showing a method of identifying computer network devices using inventory rules according to aspects of the present disclosure is shown. At step 301, network filter 211 may intercept network traffic. Network filter 211 may be configured to intercept each data packet exchanged between PLC 110b' and SCADA 110b' components and may be configured to send the intercepted data packets to rule verification module 212 for verification. In one aspect, the intercepted data traffic may include network packets that include network, transport, and application layer data. Each data packet includes a header portion and a payload portion.
[0147] Next, at step 302, rule verification module 212 may analyze the intercepted network traffic to determine whether the intercepted data traffic satisfies any inventory rules. In one aspect, a plurality of inventory rules may be stored, for example, in a database of inventory rules 214. Each of the plurality of inventory rules may include a condition indicating the presence of a specific computer network device having a set of specific parameters / attributes. In other words, each inventory rule may contain conditions that, if satisfied, indicate the presence of a network device with given parameters in the computer network of CPS200. In one aspect, each inventory rule may have an associated weighting factor value. The weighting factor value may depend on previously identified computer network devices. In one aspect, the weighting factor value of each inventory rule determines the priority of applying that rule.
[0148] In response to satisfying one or more inventory rules, at step 303, network device identification module 213 may use the satisfied inventory rules to identify one or more devices of the computer network and the parameters associated with the identified devices. In one aspect, during the identification process, network device identification module 213 may consider the weighting factor values of each satisfied inventory rule. In one aspect, network device identification module 213 may store data about the identified devices in a database containing device list 215. The specific exemplary aspects described above for the Figure 2 system in also apply to this method.
[0149] Therefore, the system and method proposed by the present invention can solve the technical problem of the low level of identifying network device parameters and provide the technical effect of the present invention, that is, improving the accuracy of using inventory rules and considering the corresponding weighting factor values to identify and / or determine network device parameters.
[0150] Figure 4 A block diagram of a computer system 20 showing aspects of a system and method for detecting malicious files that may be implemented according to an exemplary aspect is shown. Computer system 20 may represent Figure 2in the inventory system 210 and can take the form of multiple computing devices or a single computing device, such as, a desktop computer, a notebook computer, a laptop computer, a mobile computing device, a smart phone, a tablet computer, a server, a mainframe, an embedded device, and other forms of computing devices.
[0151] As shown, the computer system 20 includes a central processing unit (CPU) 21, a system memory 22, and a system bus 23 that connects various system components, including the memory associated with the central processing unit 21. The system bus 23 can include a bus memory or a bus memory controller, a peripheral bus, and a local bus capable of interacting with any other bus architecture. Examples of buses can include PCI, ISA, PCI-Express, HyperTransport TM , InfiniBand TM , SerialATA (Serial ATA), I2C, and other suitable interconnects. The central processing unit 21 (also referred to as a processor) can include a single set or multiple sets of processors with single-core or multi-core. The processor 21 can execute one or more computer-executable codes implementing the disclosed technology. The system memory 22 can be any memory for storing data used herein and / or computer programs executable by the processor 21. The system memory 22 can include volatile memory such as random access memory (RAM) 25 and non-volatile memory such as read-only memory (ROM) 24, flash memory, etc., or any combination thereof. The basic input / output system (BIOS) 26 can store basic processes for transferring information between elements of the computer system 20, such as those basic processes when loading an operating system using the ROM 24.
[0152] The computer system 20 may include one or more storage devices, such as one or more removable storage devices 27, one or more non-removable storage devices 28, or a combination thereof. The one or more removable storage devices 27 and non-removable storage devices 28 are connected to the system bus 23 via a storage interface 32. On the one hand, the storage devices and the corresponding computer-readable storage media are power-independent modules for storing computer instructions, data structures, program modules, and other data of the computer system 20. The system memory 22, the removable storage devices 27, and the non-removable storage devices 28 may use various computer-readable storage media. Examples of computer-readable storage media include: machine memories such as cache, SRAM, DRAM, zero-capacitor RAM, dual-transistor RAM, eDRAM, EDO RAM, DDR RAM, EEPROM, NRAM, RRAM, SONOS, PRAM; flash memory or other storage technologies such as solid-state drives (SSDs) or flash drives; magnetic tape cartridges, tapes, and disk storage devices such as hard disk drives or floppy disks; optical storage devices such as compact discs (CD-ROMs) or digital versatile discs (DVDs); and any other medium that can be used to store the desired data and be accessed by the computer system 20.
[0153] The system memory 22, the removable storage devices 27, and the non-removable storage devices 28 of the computer system 20 can be used to store an operating system 35, additional program applications 37, other program modules 38, and program data 39. The computer system 20 may include a peripheral interface 46 for communicating data from input devices 40 (such as keyboards, mice, styli, game controllers, voice input devices, touch input devices) or other peripheral devices (such as printers or scanners) via one or more I / O ports (such as serial ports, parallel ports, universal serial bus (USB), or other peripheral interfaces). A display device 47 (such as one or more monitors, projectors, or integrated displays) may also be connected to the system bus 23 via an output interface 48 (such as a video adapter). In addition to the display device 47, the computer system 20 may also be equipped with other peripheral output devices (not shown), such as speakers and other audio-visual devices.
[0154] The computer system 20 can operate in a network environment using a network connection to one or more remote computers 49. The remote computer(s) 49 can be a local computer workstation or server, including most or all of the elements described above when characterizing the nature of the computer system 20. Other devices may also exist in the computer network, such as, but not limited to, routers, network stations, peer devices, or other network nodes. The computer system 20 can include one or more network interfaces 51 or network adapters for communicating via one or more networks, such as a local area computer network (LAN) 50, a wide area computer network (WAN), an intranet, and the Internet. Examples of network interfaces 51 can include Ethernet interfaces, Frame Relay interfaces, SONET interfaces, and wireless interfaces.
[0155] Aspects of the present disclosure can be a system, a method, and / or a computer program product. The computer program product can include a computer-readable storage medium (medium) having computer-readable program instructions thereon for causing a processor to perform aspects of the present disclosure.
[0156] A computer-readable storage medium can be a tangible device that can retain and store program code in the form of instructions or data structures and that is accessible to a processor of a computing device, such as the computing system 20. A computer-readable storage medium can be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of them. By way of example, such a computer-readable storage medium can include a random access memory (RAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a flash memory, a hard disk, a portable computer diskette, a memory stick, a floppy disk, or even a mechanical encoding device, such as a punch card or raised structures in which instructions are recorded. As used herein, a computer-readable storage medium should not be construed to be a transitory signal per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or transmission medium, or electrical signals transmitted through a wire.
[0157] The computer-readable program instructions described herein can be downloaded to respective computing devices from a computer-readable storage medium or can be downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network interface in each computing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the respective computing device.
[0158] The computer-readable program instructions for performing the operations described in this disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state-setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages and conventional procedural programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter case, the remote computer may be connected to the user's computer through any type of network, including a LAN or WAN, or may establish a connection with an external computer (e.g., through the Internet). In some embodiments, an electronic circuit (e.g., including a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA)) may be personalized by executing the computer-readable program instructions by utilizing the state information of the computer-readable program instructions to perform aspects of this disclosure.
[0159] In aspects, the systems and methods described in this disclosure may be solved in terms of modules. As used herein, the term "module" refers to a real-world device, component, or arrangement of components implemented using hardware (such as through an application-specific integrated circuit (ASIC) or FPGA) or as a combination of hardware and software. For example, a module function is implemented through a microprocessor system and a set of instructions that, when executed, transform the microprocessor system into a dedicated device. A module may also be implemented as a combination of the two, where some functions are facilitated only by hardware and other functions are facilitated by a combination of hardware and software. In some embodiments, at least a portion of the modules (and in some cases all of the modules) may be executed on a processor of a computer system. Accordingly, each module may be implemented in various suitable configurations and should not be limited to any particular embodiment illustrated herein.
[0160] For clarity, not all conventional features of the aspects are disclosed herein. It should be appreciated that in the development of any actual implementation of this disclosure, numerous specific implementation decisions must be made to achieve the specific goals of the developer, and these specific goals will vary for different implementations and different developers. It should be understood that such development efforts may be complex and time-consuming, but are still routine engineering tasks for those of ordinary skill in the art who benefit from this disclosure.
[0161] It should also be understood that the terminology or terms used herein are for the purpose of description and not of limitation, and that the terms or phrases of this specification will be interpreted by those of ordinary skill in the art in light of the teachings and guidance presented herein in combination with the knowledge of those of ordinary skill in the relevant art. Moreover, no term in the specification or claims is intended to have a rare or special meaning unless expressly set forth otherwise.
[0162] Aspects disclosed herein cover current and future known equivalent variations of known modules illustrated herein. Moreover, although numerous aspects and applications have been illustrated and described, it will be apparent to those of ordinary skill in the art upon benefit of this disclosure that many more modifications may be made without departing from the inventive concepts disclosed herein.
[0163] Cross - reference to related applications
[0164] This application is a divisional application of Chinese Application No. 202010541680.3, filed on June 15, 2020, which is related to U.S. Patent Application No. 16 / 823,541, filed on March 19, 2020, and this application claims priority to Russian Application No. 2019130602, filed on September 19, 2020, the entire contents of all of these applications are incorporated herein by reference.
Claims
1. A method for effectively identifying computer network devices using weighted factors of inventory rules, the method comprising: Intercepting data traffic across one or more communication links of a computer network; Analyzing the intercepted data traffic to determine whether the intercepted data traffic satisfies one or more of a plurality of inventory rules, wherein each of the plurality of inventory rules includes one or more conditions that indicate the presence of a specific computer network device having a set of parameters, and wherein each of the plurality of inventory rules has a weighted factor value that indicates the priority of applying the corresponding rule; and Using the weighted factor values of one or more satisfied inventory rules to identify one or more devices of the computer network, wherein the one or more satisfied inventory rules are determined by verifying the satisfaction of each of the plurality of inventory rules in descending order of the corresponding weighted factor values of the plurality of inventory rules.
2. The method according to claim 1, further comprising: Stopping further verification of the inventory rules when an inventory rule among the plurality of inventory rules is first satisfied.
3. The method according to claim 1, further comprising: Stopping further verification of the inventory rules when the combined weighted factor value of the satisfied inventory rules is greater than a predetermined threshold.
4. The method according to claim 3, wherein The predetermined threshold includes a combined threshold set for all inventory rules.
5. The method according to claim 3, wherein, The predetermined threshold includes a combined threshold of a predetermined group of inventory rules, wherein at least two inventory rules in the inventory rule group identify the same device of the computer network or the same parameters of the same device of the computer network.
6. The method according to claim 1, wherein, The intercepting data traffic across one or more communication links of a computer network includes: intercepting only data traffic from previously unidentified devices.
7. The method according to claim 1, wherein The weighted factor value depends on previously identified devices.
8. A system for effectively identifying computer network devices using weighted factors of inventory rules, the system comprising: A hardware processor configured to: Intercept data traffic across one or more communication links of a computer network; Analyze the intercepted data traffic to determine whether the intercepted data traffic satisfies one or more of a plurality of inventory rules, wherein each of the plurality of inventory rules includes one or more conditions that indicate the presence of a specific computer network device having a set of parameters, and wherein each of the plurality of inventory rules has a weighted factor value that indicates the priority of applying the corresponding rule; and Using the weighted factor values of one or more satisfied inventory rules to identify one or more devices of the computer network, wherein the one or more satisfied inventory rules are determined by verifying the satisfaction of each of the plurality of inventory rules in descending order of the corresponding weighted factor values of the plurality of inventory rules.
9. The system according to claim 8, the processor further configured to: Stop further verification of the inventory rule when the inventory rule among the multiple inventory rules is first satisfied.
10. The system according to claim 8, wherein the processor is further configured to: Stop further verification of the inventory rule when the combined weighting factor value of the satisfied inventory rules is greater than a predetermined threshold.
11. The system according to claim 10, wherein, The predetermined threshold includes a combined threshold set for all inventory rules.
12. The method according to claim 10, wherein, The predetermined threshold includes a combined threshold of a predetermined inventory rule group, wherein at least two inventory rules in the inventory rule group identify the same device of the computer network or the same parameter of the same device of the computer network.
13. The method according to claim 8, wherein The intercepting of data traffic by one or more communication links across the computer network includes: intercepting only data traffic from a previously unrecognized device.
14. The method according to claim 8, wherein, The weighting factor value depends on the previously recognized device.
15. A non-transitory computer-readable medium having stored thereon computer-executable instructions for effectively identifying computer network devices using weighting factors of inventory rules, including the following instructions: Intercept data traffic by one or more communication links across the computer network; Analyze the intercepted data traffic to determine whether the intercepted data traffic satisfies one or more of the multiple inventory rules, wherein Each of the multiple inventory rules includes one or more conditions that indicate the presence of a specific computer network device having a set of parameters, wherein each of the multiple inventory rules has a weighting factor value that indicates the priority of applying the corresponding rule; and Use the weighting factor values of one or more satisfied inventory rules to identify one or more devices of the computer network, wherein the satisfaction of each of the multiple inventory rules is verified in descending order of the corresponding weighting factor values of the multiple inventory rules to determine the one or more satisfied inventory rules.
16. The non-transitory computer-readable medium according to claim 15, wherein the instructions further include the following instructions: Stop further verification of the inventory rule when the inventory rule among the multiple inventory rules is first satisfied.
17. The non-transitory computer-readable medium according to claim 15, wherein the instructions further include the following instructions: Stop further verification of the inventory rule when the combined weighting factor value of the satisfied inventory rules is greater than a predetermined threshold.
18. The non-transitory computer-readable medium according to claim 17, wherein, The predetermined threshold includes a combined threshold set for all inventory rules.
19. The non-transitory computer-readable medium according to claim 17, wherein, The predetermined threshold includes a combined threshold of a predetermined inventory rule group, wherein at least two inventory rules in the inventory rule group identify the same device of the computer network or the same parameter of the same device of the computer network.
20. The non-transitory computer-readable medium according to claim 15, wherein, The intercepting of data traffic by one or more communication links across the computer network includes: intercepting only data traffic from a previously unrecognized device.
Citation Information
Patent Citations
Three dimensional position estimation mechanism
US20190130602A1