Method and system for automatically synchronizing network asset data and dynamically binding responsibility chain

By automatically synchronizing network asset data and dynamic binding of responsibility chains in a hybrid cloud environment, the problems of unclear asset information and unclear responsibility ownership are solved, and efficient asset management and rapid event handling are achieved in a hybrid cloud environment.

CN120416262APending Publication Date: 2025-08-01ZHEJIANG RADIO AND TELEVISION GROUP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510533113.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

In the prior art, network asset management has problems such as unclear asset information, unclear responsibility ownership, and difficulty in managing hybrid cloud environments, resulting in difficulty in tracing security incidents and inefficient incident handling.

Method used

By automatically synchronizing network asset data and dynamic binding of responsibility chain in a hybrid cloud environment, real-time synchronization of cloud asset mapping tables, local asset mapping tables and personnel information tables is used, and log collisions are carried out with the network authentication system logs, and assets and responsible persons are dynamically bound to achieve comprehensive and real-time updates of asset information and accurate binding of responsibility ownership.

Benefits of technology

It has achieved efficient synchronization of asset management in a hybrid cloud environment, with the accuracy of dynamic responsibility chain binding up to 99.5%, and the alarm direct rate is 100%, improving the timeliness of incident handling and security emergency response capabilities, ensuring that security incidents can be located and handled quickly and accurately.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120416262A_ABST
    Figure CN120416262A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a system for automatically synchronizing network asset data and dynamically binding a responsibility chain. According to the invention, through a data automation synchronization technology (supporting a hybrid cloud environment) and a dynamic responsible person association technology, a network asset management method which comprehensively covers various assets, adapts to various network environments and technical conditions and can be updated in time is constructed. According to the method, data support required by quick traceability and effective disposal is provided for an enterprise when encountering a network security event. The method not only enhances the management and monitoring capability of different types of assets, but also ensures that efficient safety management and emergency response can be realized no matter in a public cloud environment, a private cloud environment or a traditional local data center environment. Through the mode, a powerful support framework is provided for the network security of an enterprise, and the enterprise is assisted to keep a leading security management level in a continuously changing technical environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and particularly to a method for automatic synchronization of network asset data and dynamic binding of the responsibility chain. By means of an automatic data synchronization mechanism and a dynamic responsible person association technology, core problems such as unclear asset information and unclear responsibility attribution are solved. Background Art

[0002] In today's digital age, with the rapid development of information technology, network security has become a key area for ensuring social stability, economic development, and personal rights. However, there are still a series of technical problems to be solved in the current network security field, which seriously restrict the improvement of network security protection capabilities. The specific manifestations are as follows:

[0003] 1. Unclear asset information

[0004] Traditional asset management methods highly rely on manual input, and this mode has significant defects. On the one hand, due to the limitations of manual operations, it is extremely easy to miss information during the asset information input process, resulting in some key assets not being effectively included in the management scope; on the other hand, the manual input method is difficult to ensure timely update of information, and key information such as asset status and configuration often lags behind the actual changes. This unclear situation of asset information directly leads to great challenges in the traceability work when security incidents occur. Security personnel are difficult to quickly and accurately locate the root cause of the problem, thus affecting the overall security protection efficiency.

[0005] 2. Unclear responsibility attribution

[0006] In network security management, clarifying the binding relationship between assets and responsible persons is an important prerequisite for ensuring the timely and effective handling of security incidents. However, the binding mechanism between assets and responsible persons in the existing technology is relatively weak, lacking effective technical means and standardized processes. When security alarm information is generated, it is often impossible to accurately push it to the relevant responsible persons, resulting in a significant reduction in the timeliness of event handling. This unclear situation of responsibility attribution not only increases the difficulty of handling security incidents but also may lead to the phenomenon of responsibility shirking, further affecting the overall efficiency of network security management.

[0007] 3. Difficult management of hybrid cloud environments

[0008] With the wide application of cloud computing technology, more and more organizations are beginning to adopt a hybrid cloud architecture, that is, using public cloud, private cloud and local data center resources simultaneously. However, this hybrid cloud environment has brought unprecedented challenges to asset management. Public cloud, private cloud and local asset data are scattered and stored on different platforms, lacking a unified synchronization mechanism, resulting in difficult-to-achieve global asset visibility. Security managers are difficult to comprehensively and real-time master asset distribution, status and configuration information, thus unable to conduct unified and effective security management of the hybrid cloud environment.

[0009] In response to the above problems, although there are individual solutions in the prior art that attempt to manage assets through asset probes or vulnerability scanning tools, these solutions still have many limitations in data maintenance and information synchronization. To address these challenges, it is necessary to develop a more efficient and intelligent asset management solution to achieve comprehensive and real-time updates of asset information, clarify the responsibility attribution, improve the global asset visibility in the hybrid cloud environment, and construct multi-dimensional asset portrait information to provide strong support for network security management. Summary of the Invention

[0010] The purpose of the present invention is to provide a method for automatic synchronization of network asset data and dynamic binding of responsibility chain, which integrates the hybrid cloud asset synchronization and dynamic responsible person association mechanism to solve the following problems existing in traditional asset management: fragmented asset information: asset data is scattered in the hybrid cloud environment, with low efficiency and easy errors in manual maintenance; static responsibility attribution: the binding of assets and responsible persons depends on manual configuration and is difficult to adapt to the dynamic changes of the organizational structure; insufficient security decision-making support: single asset data, lack of multi-dimensional information fusion such as vulnerabilities and usage behaviors.

[0011] The specific technical solutions adopted by the present invention are as follows:

[0012] In a first aspect, the present invention provides a method for automatic synchronization of network asset data and dynamic binding of responsibility chain. The network assets are located in a hybrid cloud environment composed of a public cloud, a private cloud and local terminals, and it includes:

[0013] S1. Obtain the cloud asset mapping table, cloud asset table, local asset mapping table, and local asset table that are pre-constructed and maintained for the target enterprise organization, and at the same time, regularly synchronize and update the personnel information table containing organizational structure and personnel information;

[0014] S2. Obtain all cloud asset data owned by the target enterprise organization in real time from the public cloud platform and the private cloud platform, and extract the first asset information of each cloud host. Retain the cloud hosts that exist in the cloud asset mapping table and whose first asset information is complete and unique, and continue to check whether they exist in the cloud asset table. If they exist, directly update their asset status information. If they do not exist, create a new cloud host in the cloud asset table and match the corresponding person based on the creator field of the cloud host in the personnel information table as the responsible person for the cloud host.

[0015] S3. Obtain all local terminals owned by the target enterprise organization in real time from the management system of the local terminal and extract the second asset information of each local terminal. For each local terminal, first match the responsible person in the local asset mapping table. If the responsible person is not matched, hang the local terminal to the root organization. Then, for each local terminal, check whether it exists in the local asset table. If it does not exist, create a new local terminal. Finally, trigger an asynchronous terminal asset responsibility chain dynamic binding task for each local terminal. Through the MAC address of the local terminal and the network authentication system log for log collision, if the collision is successful, update the asset responsible person and user information of the newly created local terminal in the local asset table, and the local terminal will be updated from the root organization to the organization where the responsible person is located.

[0016] As a preference of the above first aspect, the cloud asset mapping table is pulled regularly from the public cloud platform and the private cloud platform for incremental update, and the administrator maintains the abnormal data or missing fields; the cloud asset mapping table records the list of cloud hosts owned by the target enterprise organization, and each cloud host needs to record the corresponding VPC code and the responsible person in the table. The VPC code field is a required item, and the responsible person field may be missing. If the responsible person field is missing, match the corresponding person based on the creator field of the cloud host in the personnel information table as the responsible person for the cloud host. Whenever a cloud host is discarded because the VPC code cannot be found in the cloud asset mapping table, the administrator will be notified to re-maintain the cloud asset mapping table. If the responsible person field is missing, match the corresponding person based on the creator field of the cloud host in the personnel information table as the responsible person for the cloud host.

[0017] As a preference of the above first aspect, the cloud asset table records the unexpired cloud network asset information owned by the target enterprise organization. Each cloud network asset information includes the asset name, VPC code, main IP, server unique ID, asset responsible person, and asset status information of the cloud host.

[0018] Preferably, for the first aspect described above, the local asset mapping table is pulled from the management system of the local terminal at regular intervals for incremental updates, and the administrator maintains abnormal data or missing fields; the local asset mapping table records the list of local terminals owned by the target enterprise organization, and each local terminal needs to record the corresponding terminal IP, MAC address, asset responsible person, and the department to which the asset responsible person belongs in the table; whenever a local terminal is attached to the root organization and the MAC address of the local terminal fails to collide successfully with the network authentication system log, the administrator will be notified to re-maintain the asset responsible person and the department to which the asset responsible person belongs for this local terminal in the local asset mapping table.

[0019] Preferably, for the first aspect described above, the local asset table records the information of the unexpired local terminals owned by the target enterprise organization, and each local terminal information includes the terminal name, terminal IP, MAC address, device type, asset responsible person, and asset status information.

[0020] Preferably, for the first aspect described above, the personnel information table is synchronized from the personnel management system of the target enterprise organization at regular intervals and includes the full organizational structure and personnel information within the enterprise.

[0021] Preferably, the specific implementation method of S2 is as follows:

[0022] Real-time obtain the full amount of cloud asset data owned by the target enterprise organization from the public cloud platform and the private cloud platform, extract the first asset information of each cloud host, and the first asset information includes the creator, VPC code, main IP, and server unique ID; check whether the VPC code of each cloud host exists in the cloud asset mapping table, discard the cloud hosts whose VPC codes do not exist in the cloud asset mapping table, perform integrity verification and uniqueness verification on the information fields of the first asset information of all the remaining cloud hosts, and retain the cloud hosts that pass the verification as the cloud temporary asset library; for each cloud host in the cloud temporary asset library, generate a first unique key based on its VPC code, main IP, and server unique ID, then check whether there is a cloud host corresponding to this first unique key in the cloud asset table. If it exists, update the asset status information in the cloud asset table according to the corresponding first asset information. If it does not exist, create a new cloud host in the cloud asset table and trigger the responsible person matching task, and match the corresponding person based on the creator field of the cloud host in the personnel information table as the asset responsible person of this cloud host, and at the same time determine the organization to which the asset responsible person belongs.

[0023] Preferably, the specific implementation method of S3 is as follows:

[0024] Obtain all local terminals owned by the target enterprise organization in real time from the management system of the local terminal as the local temporary asset library, and extract the second asset information of each local terminal. The second asset information includes the terminal IP, MAC address, and device type. For each local terminal in the local temporary asset library, first match the responsible person in the local asset mapping table based on the terminal IP or MAC address of each local terminal. If the responsible person is matched, further match the organization to which the responsible person belongs in the personnel information table and mount the local terminal under the corresponding responsible person. If the responsible person is not matched, mount the local terminal to the root organization. Then, generate a second unique key for each local terminal based on its terminal IP, MAC address, and device type, and then check whether there is a local terminal corresponding to the second unique key in the local asset table. If it exists, update the asset status information in the local asset table according to the corresponding second asset information. If it does not exist, create a new local terminal in the local asset table. After each local terminal completes the search operation in the local asset table, trigger an asynchronously executed terminal asset responsibility chain dynamic binding task. Collide the MAC address of the local terminal with the network authentication system log. If the collision is successful, update the asset responsible person and user information of the newly created local terminal in the local asset table, and the local terminal will be updated from the root organization to the organization where the responsible person is located.

[0025] As a preference of the first aspect above, the specific execution method of the terminal asset responsibility chain dynamic binding task is as follows:

[0026] First, regularly obtain network authentication system log data from the network authentication server of the enterprise organization, and parse and extract data from the network authentication system log. The extracted fields include timestamp, MAC address, login account, logged-in terminal IP, and log type.

[0027] Then, collide and match the MAC address in the network authentication system log with the MAC address in the local asset table; each local terminal in the local asset table obtains the latest network authentication system log with the same MAC address through the collision match as the source log required for information update.

[0028] Finally, for each local terminal in the local asset table that matches the source log, extract each unique login account entered during network authentication in the source log, and use this login account to match the corresponding person in the personnel information table. Then, determine whether there is already an asset responsible person field for this local terminal in the local asset table. If it exists, add the matched person as the asset user of this local terminal in the local asset table, and update the asset status information in the local asset table using the timestamp and log type in the source log. If it does not exist, add the matched person as both the asset responsible person and the asset user of this local terminal in the local asset table, and update the asset status information in the local asset table using the timestamp and log type in the source log.

[0029] As a preference of the first aspect above, after associating an asset responsible person with each network asset in the cloud asset table and the local asset table, determine the organization to which the asset responsible person belongs in the latest personnel information table, so as to attach each network asset under the corresponding organization; when there is an alarm message, a disposal message or other information that needs to be notified for a network asset, notify the corresponding asset responsible person or organization responsible person through a preset notification method.

[0030] In a second aspect, the present invention provides a system for automated synchronization of network asset data and dynamic binding of a responsibility chain. The network assets are located in a hybrid cloud environment composed of a public cloud, a private cloud, and local terminals, and it includes:

[0031] An information table acquisition module, configured to acquire a cloud asset mapping table, a cloud asset table, a local asset mapping table, and a local asset table that are pre-constructed and maintained for a target enterprise organization, and simultaneously synchronize and update a personnel information table including an organizational structure and personnel information at regular intervals;

[0032] A cloud platform synchronization and binding module, configured to obtain in real time all cloud asset data owned by a target enterprise organization from a public cloud platform and a private cloud platform and extract first asset information of each cloud host, retain the cloud hosts that exist in the cloud asset mapping table and whose first asset information is complete and unique, and continue to check whether they exist in the cloud asset table. If they exist, directly update their asset status information. If they do not exist, create new cloud hosts in the cloud asset table and match the corresponding person in the personnel information table based on the creator field of the cloud host as the responsible person of the cloud host;

[0033] The local terminal synchronization and binding module is used to obtain all local terminals owned by the target enterprise organization in real time from the management system of the local terminal and extract the second asset information of each local terminal. For each local terminal, first match the responsible person in the local asset mapping table. If the responsible person is not matched, hang the local terminal to the root organization. Then, check whether each local terminal exists in the local asset table. If it does not exist, create a new local terminal. Finally, trigger an asynchronous terminal asset responsibility chain dynamic binding task for each local terminal. Through the MAC address of the local terminal and the network authentication system log for log collision, if the collision is successful, update the asset responsible person and user information of the newly created local terminal in the local asset table, and the local terminal will be updated from the root organization to the organization where the responsible person is located.

[0034] Compared with the prior art, the present invention has the following beneficial effects:

[0035] 1) Efficient and automated synchronization of hybrid cloud assets

[0036] Through the carefully designed interface and efficient data conversion engine, the present invention realizes the deep seamless integration of public cloud, private cloud and local terminal assets. This innovative technology breaks the dilemma of isolated data and difficult coordination among different platforms in traditional asset management methods, enabling enterprises to centrally manage all assets in the hybrid cloud environment on a unified platform. The newly added asset information from different sources can be quickly synchronized to the security management platform, greatly improving the efficiency and accuracy of asset management and avoiding security risks caused by information lag or errors.

[0037] 2) Precise binding of dynamic responsibility chain

[0038] Based on the advanced real-time log collision technology and the close synchronization mechanism with the organizational structure, the present invention realizes the automatic association and binding of responsible persons. This dynamic binding method has extremely high accuracy and reliability, with an association accuracy rate of up to 99.5% and an alarm direct reach rate of 100%. In practical applications, when security alarm information is generated, the system can quickly and accurately push the alarm information to the relevant responsible persons, ensuring that the event can be responded to and processed in the first time. This not only greatly improves the timeliness of event handling, reduces delays and losses caused by unclear responsibilities, but also enhances the enterprise's security emergency response ability. For example, when a security vulnerability appears in a certain network device, the system can immediately send the alarm information to the person in charge of the device according to the responsibility chain binding information, enabling them to quickly take measures to repair it and prevent the further exploitation of the vulnerability.

[0039] 3) Network asset management method with comprehensive coverage and timely update

[0040] The present invention constructs a network asset management method that comprehensively covers various types of assets, adapts to diverse network environments and technical conditions, and can be updated in a timely manner. This method fully considers the complex and ever-changing hybrid cloud architecture of modern enterprises, as well as various challenges faced in network security management, such as unclear asset information and ambiguous responsibility attribution. Through this method, enterprises can obtain the key data support required for quickly tracing the source and effectively handling network security incidents. When an enterprise encounters a network security incident, security managers can quickly obtain detailed information about the attacked assets, responsible person information, and related vulnerability information through this method, providing a strong basis for subsequent emergency handling. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0042] Figure 1 It is a system structure diagram on which the implementation of the method in the embodiment of the present invention depends.

[0043] Figure 2 It is a flowchart of cloud asset synchronization and dynamic binding of the responsibility chain in the embodiment of the present invention.

[0044] Figure 3 It is a flowchart of terminal asset synchronization in the embodiment of the present invention.

[0045] Figure 4 It is a flowchart of dynamic binding of the responsibility chain of terminal assets in the embodiment of the present invention.

[0046] Figure 5 It is a flowchart of personnel system synchronization in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0047] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will give a detailed description of the specific embodiments of the present invention with reference to the drawings. Many specific details are set forth in the following description in order to fully understand the present invention. However, the present invention can be implemented in many other ways different from those described herein. Those skilled in the art can make similar improvements without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below. The technical features in the various embodiments of the present invention can be combined correspondingly without conflict.

[0048] In the description of the present invention, it should be understood that when an element is considered to be "connected" to another element, it can be directly connected to the other element or indirectly connected, that is, there is an intermediate element. On the contrary, when an element is called "directly" connected to another element, there is no intermediate element.

[0049] In a preferred embodiment of the present invention, a method for automatic synchronization of network asset data and dynamic binding of the responsibility chain is provided. The network assets of the present invention are located in a hybrid cloud environment composed of a public cloud, a private cloud, and a local terminal. The method specifically includes the following processes:

[0050] S1. Obtain the cloud asset mapping table, cloud asset table, local asset mapping table, and local asset table that are pre-constructed and maintained for the target enterprise organization, and at the same time, regularly synchronize and update the personnel information table containing the organizational structure and personnel information.

[0051] In the embodiment of the present invention, the cloud asset mapping table is pulled from the public cloud platform and the private cloud platform regularly for incremental update, and the administrator maintains the abnormal data or missing fields; the cloud asset mapping table records the list of cloud hosts owned by the target enterprise organization, and each cloud host needs to record the corresponding VPC code and the responsible person in the table. Among them, the VPC code field is a mandatory item, and the responsible person field may be missing. If the responsible person field is missing, the corresponding person is matched based on the creator field of the cloud host in the personnel information table as the responsible person of the cloud host; whenever a cloud host is discarded because the VPC code cannot be found in the cloud asset mapping table, the administrator will be notified to re-maintain the cloud asset mapping table. If the responsible person field is missing, the corresponding person is matched based on the creator field of the cloud host in the personnel information table as the responsible person of the cloud host.

[0052] In the embodiment of the present invention, the cloud asset table records the unexpired cloud network asset information owned by the target enterprise organization. Each cloud network asset information includes the asset name, VPC code, main IP, server unique ID, asset responsible person, and asset status information of the cloud host. When a cloud host is discarded because the VPC code cannot be found in the cloud asset mapping table, the network will be notified.

[0053] In an embodiment of the present invention, the local asset mapping table is pulled from the management system of the local terminal at regular intervals for incremental update, and the administrator maintains the abnormal data or missing fields; the local asset mapping table records the list of local terminals owned by the target enterprise organization, and each local terminal needs to record the corresponding terminal IP, MAC address, asset responsible person, and the department to which the asset responsible person belongs in the table; whenever a local terminal is attached to the root organization and the MAC address of the local terminal collides unsuccessfully with the network authentication system log, the administrator re-maintains the asset responsible person and the department to which the asset responsible person belongs for the local terminal in the local asset mapping table.

[0054] In an embodiment of the present invention, the local asset table records the information of the non-expired local terminals owned by the target enterprise organization, and each local terminal information includes terminal name, terminal IP, MAC address, device type, asset responsible person, and asset status information.

[0055] In an embodiment of the present invention, the personnel information table is synchronized from the personnel management system of the target enterprise organization at regular intervals and contains the full organizational structure and personnel information within the enterprise.

[0056] S2. Real-time obtain the full cloud asset data owned by the target enterprise organization from the public cloud platform and the private cloud platform, extract the first asset information of each cloud host, retain the cloud hosts that exist in the cloud asset mapping table and whose first asset information is complete and unique, and continue to check whether they exist in the cloud asset table. If they exist, directly update their asset status information. If they do not exist, create new cloud hosts in the cloud asset table and match the corresponding personnel based on the creator field of the cloud hosts in the personnel information table as the responsible persons for the cloud hosts.

[0057] In an embodiment of the present invention, the specific implementation method of the above S2 is as follows:

[0058] Real-time obtain the full amount of cloud asset data owned by the target enterprise organization from the public cloud platform and the private cloud platform, and extract the first asset information of each cloud host. The first asset information includes the creator, VPC code, main IP, and server unique ID. Check whether the VPC code of each cloud host exists in the cloud asset mapping table, discard the cloud hosts whose VPC codes do not exist in the cloud asset mapping table, perform information field integrity verification and uniqueness verification on the first asset information of all the remaining cloud hosts, and retain the cloud hosts that pass the verification as the cloud temporary asset library. For each cloud host in the cloud temporary asset library, generate a first unique key based on its VPC code, main IP, and server unique ID, and then check whether there is a cloud host corresponding to the first unique key in the cloud asset table. If it exists, update the asset status information in the cloud asset table according to the corresponding first asset information. If it does not exist, create a new cloud host in the cloud asset table, and trigger a responsible person matching task. Based on the creator field of the cloud host, match the corresponding person in the personnel information table as the asset responsible person of the cloud host, and at the same time determine the organization to which the asset responsible person belongs.

[0059] It should be noted that in the above hybrid cloud environment, multi-platform interface docking and real-time data acquisition are required. The cloud platform docking method is as follows: Docking the public cloud and private cloud platforms through the standardized RESTful API or OAuth 2.0 protocol, and regularly pulling the metadata of cloud host instances, including instance ID, public / private IP, VPC code (vpccode), operating system type, security group policy, and creator label (requiring employees to fill in the same personnel ID as in the personnel system when creating cloud hosts), etc. The local terminal device integration method is as follows: Call the interface of the terminal security management system platform (which can be any enterprise internal software system for managing local terminals, such as Tianqing V10) to batch obtain information such as the terminal IP, device type, MAC address, hardware serial number, software version, and responsible person of the terminal device. The data format is unified as JSON and transmitted through HTTPS encryption. The data obtained above may be repeated, and data caching and deduplication are required. For example, Redis can be used to cache temporary data, and deduplication is performed through the unique key (IP + MAC) to avoid duplicate records from being stored in the database.

[0060] S3. Obtain all local terminals owned by the target enterprise organization in real time from the management system of the local terminal, and extract the second asset information of each local terminal; for each local terminal, first match the responsible person in the local asset mapping table. If the responsible person is not matched, hang the local terminal under the root organization; then check whether each local terminal exists in the local asset table. If it does not exist, create a new local terminal. Finally, trigger an asynchronously executed dynamic binding task for the terminal asset responsibility chain for each local terminal, perform log collision through the MAC address of the local terminal and the network authentication system log. If the collision is successful, update the asset responsible person and user information of the newly created local terminal in the local asset table, and the local terminal will be updated from the root organization to the organization where the responsible person is located.

[0061] In an embodiment of the present invention, the specific implementation method of the above S3 is as follows:

[0062] Obtain all local terminals owned by the target enterprise organization in real time from the management system of the local terminal as a local temporary asset library, and extract the second asset information of each local terminal. The second asset information includes terminal IP, MAC address, and device type; for each local terminal in the local temporary asset library, first match the responsible person in the local asset mapping table based on the terminal IP or MAC address of each local terminal. If the responsible person is matched, further match the organization to which the responsible person belongs from the personnel information table and mount the local terminal under the corresponding responsible person. If the responsible person is not matched, mount the local terminal under the root organization; then, generate a second unique key for each local terminal based on its terminal IP, MAC address, and device type, and then check whether there is a local terminal corresponding to the second unique key in the local asset table. If it exists, update the asset status information in the local asset table according to the corresponding second asset information. If it does not exist, create a new local terminal in the local asset table. After each local terminal completes the search operation in the local asset table, trigger an asynchronously executed dynamic binding task for the terminal asset responsibility chain, perform log collision through the MAC address of the local terminal and the network authentication system log. If the collision is successful, update the asset responsible person and user information of the newly created local terminal in the local asset table, and the organization to which the local terminal belongs will be updated from the root organization to the organization where the responsible person is located.

[0063] In the above steps, mounting the local terminal under the root organization is a fallback mechanism. For example, for terminal assets for which the responsible person is not matched, a root organization "unassigned terminal group" can be created on the department hierarchy tree. The responsible person of the local terminal on the root organization can be updated manually or through subsequent log collision.

[0064] In an embodiment of the present invention, the above-mentioned dynamic binding task of the terminal asset responsibility chain is implemented through the network authentication system log data in the network authentication server of the enterprise organization. The network authentication server of the enterprise organization is an authentication operation required when the local terminals inside the enterprise access the internal network. During this process, the login account and login password need to be input. The login account of each employee is unique, and at the same time, the MAC address of each terminal device is also unique. Therefore, the personnel can be determined based on this login account, and the MAC address is used to match the information with the local asset table. The specific execution method of the above-mentioned dynamic binding task of the terminal asset responsibility chain is as follows:

[0065] First, regularly obtain the network authentication system log data from the network authentication server of the enterprise organization, and parse and extract data from the network authentication system log. The extracted fields include timestamp, MAC address, login account, logged-in terminal IP, and log type;

[0066] Then, perform collision matching on the MAC address in the network authentication system log with the MAC address in the local asset table; each local terminal in the local asset table obtains the latest network authentication system log with the same MAC address through collision matching as the source log required for information update;

[0067] Finally, for each local terminal in the local asset table that matches the source log, extract the unique login account of each person input during network authentication in the source log, and use this login account to match the corresponding person in the personnel information table. Then, determine whether there is an asset responsible person field for this local terminal in the local asset table. If it exists, add the matched person as the asset user of this local terminal in the local asset table, and update the asset status information in the local asset table using the timestamp and log type in the source log. If it does not exist, add the matched person as both the asset responsible person and the asset user of this local terminal in the local asset table, and update the asset status information in the local asset table using the timestamp and log type in the source log.

[0068] In addition, since network assets will be updated to a certain extent due to the expiration of the service life or other reasons, in the above S2 and S3, mark the cloud assets and terminal assets that have been inactive for a long time based on the preset aging rules, and further notify the administrator to confirm the asset status, and delete the corresponding assets after determining that they are no longer in use.

[0069] In another embodiment of the present invention, the personnel information table can be synchronously updated in real time from the enterprise personnel system. The personnel information table can be decomposed into an organization table recording department organization information and a user table recording personnel information.

[0070] The organization table synchronization method is as follows: Full department data is synchronized from the enterprise HR system daily, building a multi-level organization tree. This data is stored in the organization management table. Fields include the HR system department ID (depat_id), the system_org primary key (org_id), the department name (depat_name), the department number (depat_code), and the superior department number (sup_depat_code). The user table synchronization method is as follows: Full user data is synchronized from the enterprise HR system daily, building a multi-level organization tree. Fields include the staff number (staff_code), staff name (staff_name), department number (depart_code), email address (email), mobile phone number (cellphone), creation time (create_time), and update time (update_time).

[0071] The scheduled task for synchronizing the user table and the organization table can be the same scheduled task. Organization synchronization is processed first, and user synchronization is processed later.

[0072] In another embodiment of the present invention, after each network asset in the aforementioned cloud asset table and local asset table is associated with an asset owner, the organization to which the asset owner belongs is determined in the latest personnel information table, thereby attaching each network asset to the corresponding organization. This invention synchronizes the organizational structure of the enterprise personnel system, enabling real-time updates of asset owners and users, and can provide favorable auxiliary conditions for threat alert discovery, notification, and disposal. When a network asset displays alarm information, disposal information, or other information that requires notification, the corresponding asset owner or organization leader is notified via a preset notification method.

[0073] In another embodiment of the present invention, based on the same inventive concept, a system for automatic synchronization of network asset data and dynamic binding of responsibility chains is provided. The system includes the following functional modules:

[0074] An information table acquisition module is used to obtain the cloud asset mapping table, cloud asset table, local asset mapping table, local asset table and personnel information table that are pre-built and maintained for the target enterprise organization;

[0075] The cloud platform synchronization and binding module is used to obtain the full amount of cloud asset data owned by the target enterprise organization from the public cloud platform and the private cloud platform in real time and extract the primary asset information of each cloud host. It retains the cloud hosts that exist in the cloud asset mapping table and have complete and unique primary asset information, and continues to check whether they exist in the cloud asset table. If so, their asset status information is directly updated. If not, a new cloud host is created in the cloud asset table and the corresponding person is matched in the personnel information table based on the creator field of the cloud host as the person in charge of the cloud host.

[0076] A local terminal synchronization and binding module is used to obtain all local terminals owned by a target enterprise organization in real time from the management system of the local terminal and extract the second asset information of each local terminal. For each local terminal, first match the responsible person in the local asset mapping table. If the responsible person is not matched, hang the local terminal to the root organization. Then, check whether each local terminal exists in the local asset table. If it does not exist, create a new local terminal. Finally, trigger an asynchronous terminal asset responsibility chain dynamic binding task for each local terminal. Through log collision between the MAC address of the local terminal and the network authentication system log, if the collision is successful, update the asset responsible person and user information of the newly created local terminal in the local asset table, and the organization to which the local terminal belongs will be updated from the root organization to the organization where the responsible person is located.

[0077] The above method for realizing automatic synchronization of network asset data and dynamic binding of the responsibility chain will be applied to a specific case below to show the specific network architecture for realizing this method and the specific implementation process of the method.

[0078] Embodiment

[0079] As Figure 1 shown, it is the network architecture diagram relied on by the method for realizing automatic synchronization of network asset data and dynamic binding of the responsibility chain in the embodiment of the present invention. In this embodiment, the network architecture includes the personnel system, the network authentication system, manual asset entry, asset scanning equipment, private cloud assets, public cloud assets, and asset information entry of the terminal security management system. In terms of associating and docking devices and systems, the log alarm device, the automatic linkage orchestration system, the SMS platform, the OA office automation system, and the disposal device are docked. The specific operation process is as follows: The security operation platform first synchronizes the organizational structure and user information of the personnel system, as well as the user information of the network authentication system. Then, the assets of the private cloud assets, public cloud assets, and terminal security management system are automatically synchronized to the security operation platform through the interface. Of course, theoretically, in addition to these automatic assets, the assets discovered by the asset scanning equipment and the assets sorted out manually can also be entered, without limitation. At this time, the cloud assets will automatically fill in the asset responsible person and be affiliated to the corresponding organization according to the asset responsible person; the terminal assets supplement the asset responsible person, user and other information according to the MAC collision. When the security operation platform accesses the logs and alarms, it can associate the corresponding asset information with the IP in the alarm. For the alarm information that needs to be disposed of, it will be sent to the automatic linkage orchestration system, and this system will send the alarm IP to the disposal device for disposal (the network authentication system directly logs off the account; the egress load balancing device bans the IP; the firewall bans the IP, etc.). Once the disposal is successful, the corresponding user will be notified by SMS, email or OA.

[0080] The following will detail the specific steps of the method for automatic synchronization of network asset data and dynamic binding of the responsibility chain in this embodiment.

[0081] S1. Obtain the cloud asset mapping table, cloud asset table, local asset mapping table, local asset table, and personnel information table that are pre-constructed and maintained for the target enterprise organization. The initial construction and maintenance methods of these information tables are as described above.

[0082] S2. Dynamically bind the cloud asset synchronization process and the responsibility chain

[0083] As Figure 2 shown, it is the flowchart of cloud asset synchronization and dynamic binding of the responsibility chain of the method of the present invention. This process method includes the following steps:

[0084] Step S201: Regularly obtain the full amount of asset data from the private cloud and the public cloud

[0085] The technical implementation method of this step is as follows: The system regularly calls the asset query services of the private cloud (such as VMware vSphere, OpenStack) and the public cloud platform (such as Alibaba Cloud) through the standardized RESTful API interface every day to obtain the full amount of asset data (cloud hosts such as cloud servers and cloud virtual machines). The core fields include: VPC code (vpccode), public cloud IP, private cloud IP, operating system type, security group configuration, responsible person, etc. Data format: JSON or XML, and it is transmitted through HTTPS encryption to ensure data security.

[0086] The exception handling method of this step is as follows: If the API call fails (such as network timeout, insufficient permissions), enable the exponential backoff retry mechanism (up to 3 times), and record the error log after failure. Perform integrity verification on the returned data (such as missing required fields, incorrect format), mark the invalid data and temporarily store it in a temporary table for manual review.

[0087] Extract the key fields from the private cloud and public cloud management systems, including the VPC number (vpc_code) and the creator account (create_account), and automatically generate the fields of the cloud asset mapping table. The fields include: VPC code (vpc_code), responsible person account (owner_account), which are used to associate cloud assets with the responsible person entity.

[0088] Step S202: Determine whether the vpc_code exists

[0089] Query the VPC code (vpc_code) of each cloud host. If it exists, jump to step S203; if it does not exist, jump to step S204.

[0090] Step S203: Determine whether vpc_code exists in the cloud asset mapping table

[0091] Query the cloud asset mapping table based on the VPC code (vpc_code). If a matching record exists, jump to step S205; if not, jump to step S204.

[0092] Step S204: Discard the data directly

[0093] The execution condition for discarding the data is that the asset does not meet the relevant requirements.

[0094] The operation details for discarding the data are as follows: Store the invalid asset records in the lost asset table, and the fields include the reason for discarding, timestamp, and the original data snapshot. The security operation platform notifies the security administrator to prompt manual verification and supplement the cloud asset mapping relationship table.

[0095] Step S205: Start synchronizing and checking field integrity

[0096] Verify the required fields: Whether the VPC code (vpc_code), primary IP (primary_ip), and server unique ID (server_id) are empty or have incorrect formats (such as IP address format verification).

[0097] Step S206: Determine whether there are duplicate IPs under the same vpc_code

[0098] Check whether there are any within the same VPC code (vpc_code). If so, jump to step S207; otherwise, jump to step S213.

[0099] Step S207: When multiple assets have duplicate IPs under the same VPC code (vpc_code), automatically select the first IP in the list.

[0100] Step S208: Selection rule for the primary IP (primary_id)

[0101] If an asset has multiple IP addresses, by default, select the first valid IP as the primary IP (primary_ip).

[0102] Step S209: Determine whether the primary ID (primary_id) already exists

[0103] Query the database. If the primary ID already exists, jump to step S210; otherwise, jump to step S204.

[0104] Step S210: Verify whether the server unique ID or virtual machine ID is empty

[0105] If it is not empty, jump to step S211; if it is empty, mark it as invalid data and jump to step S204.

[0106] Step S211: Global verification of server ID repeatability

[0107] Check whether the server ID is repeated; if it is repeated, jump to step S212; if it is not repeated, jump to step S213.

[0108] Step S212: Server unique ID selection rule

[0109] If there are multiple IDs for the server, by default, select the first valid ID.

[0110] Step S213: Comprehensive uniqueness verification

[0111] Perform a final uniqueness verification on the VPC code (vpc_code), primary IP (primary_ip), and server ID (server_id) to ensure no conflicts and then prepare for storage.

[0112] Step S214: Asset data enters the temporary library

[0113] Write the asset data that has passed the verification into the temporary database, record the synchronization timestamp, and update the status to "synchronized".

[0114] Step S215: Can the asset responsible person be found through the cloud asset mapping table

[0115] Find the value in the cloud asset mapping table that is the same as the vpc_code of this asset, and assign the responsible person information in the cloud asset mapping table to this cloud asset. According to the responsible person's account (owner_account), query the staff code in the user table and mount the asset under the name of this person. If the responsible person is found, jump to step S216; if the responsible person is not found, jump to step S204.

[0116] Priority rule: The manually configured responsible person information has a higher priority than the automatically synchronized result to ensure management flexibility.

[0117] Step S216: Can the asset be found through the asset relationship unique key

[0118] Definition of the unique key for cloud assets: It consists of the VPC code (vpc_code), primary IP (ip), and MAC address (mac) to form a unique key (such as ip:vpc:vpc-001_192.168.1.100_mac:00:1A:2B:3C:4D_).

[0119] Asset query: Retrieve existing records in the cloud asset table based on the unique key of the cloud asset. If a matching record exists, jump to step S217; if not, jump to step S218.

[0120] Step S217: Call the interface to update the asset information in the cloud asset table

[0121] The update operation is as follows: Call the interface, and the updated fields include the last synchronization time (last_sync_time), online / offline (status), and extended attributes (such as security policies), then jump to step S219.

[0122] Step S218: Call the interface to create a new asset

[0123] The create operation is as follows: Call the interface, insert a new record into the cloud asset table, generate a unique asset serial number, and initialize the responsible person as "unassigned". And automatically trigger the responsible person matching task (asynchronous message queue processing), then jump to step S219.

[0124] Step S219: Delete invalid assets

[0125] Invalidation criteria: The asset has been deleted or deactivated in the cloud platform for more than 30 days. Records that exist in the asset table but are not returned in the full synchronization.

[0126] Deletion strategy: Soft deletion: Mark is_deleted = 1, and retain historical data for audit queries; Physical deletion: For sensitive data (such as assets in a destroyed test environment), perform physical deletion and record the operation log.

[0127] Clean-up task: Start a scheduled task daily to scan and clean up invalid assets and release storage resources.

[0128] The technical implementation method of this step is as follows: Adopt an optimistic locking mechanism to prevent concurrent update conflicts. Ensure the transactionality of data operations to prevent inconsistent states caused by process interruptions. Before committing the database transaction, perform pre-commit checks (such as foreign key constraints, uniqueness verification). If the check fails, roll back the current operation and record the exception log.

[0129] Finally, the security operation platform automatically generates the security operation platform asset attributes according to the corresponding fields of private cloud and public cloud assets, and filters and retains them according to the constraint conditions. Table 1 below shows the specific field conditions of the cloud asset table:

[0130] Table 1 Fields included in the cloud asset table

[0131]

[0132] The key points of the process technology implementation of this S2 step are as follows:

[0133] Process Closed-loop: Complete asset synchronization, responsible person binding, data update and cleaning operations to ensure the consistency between the cloud asset table and the cloud environment; Data Verification: Use regular expressions to verify the IP format. The database unique index prevents duplicate records; Conflict Resolution: The optimistic lock mechanism avoids concurrent update conflicts.

[0134] Asynchronous Processing: Time-consuming operations (such as logging) are executed asynchronously through a message queue (such as Kafka).

[0135] The process value of this step lies in: By means of automated mapping, virtual organization fallback and invalid asset cleaning mechanisms, it solves the core problems such as unclear responsibility attribution and poor data consistency in hybrid cloud asset management; Through automated verification and conflict resolution mechanisms, it reduces manual intervention and ensures the accuracy and consistency of hybrid cloud asset data.

[0136] S3, Local Terminal Asset Synchronization

[0137] As Figure 3 shown, it is the local terminal asset synchronization flowchart of the method of the present invention. This process method includes the following steps:

[0138] Step S301: Regularly obtain the full amount of asset data from the terminal security management system

[0139] The technical implementation method of this step is as follows: The system regularly obtains the full amount of asset data through the API interface of the enterprise internal terminal security management system (such as Tianqing, which needs to be installed on each terminal accessing the enterprise internal communication) every day. The core fields include: computer name, terminal IP (terminal_ip), MAC address (mac), device type (device_type), responsible person label (owner_tag), operating system version (OS_version). Data format: JSON / XML, encrypted transmission through HTTPS.

[0140] The exception handling method of this step is as follows: When the API call fails, enable the retry mechanism (up to 3 times), record the error log and trigger an alarm after failure.

[0141] Step S302: Whether the asset responsible person can be found through the asset mapping table

[0142] Mapping table structure: The fields include terminal IP (terminal_ip), MAC address (mac_address), responsible person ID (owner_id).

[0143] Query logic: Query the mapping table according to the terminal IP or MAC address. If the match is successful, jump to step S303; otherwise, jump to step S304.

[0144] Step S303: Whether the organization matching rule can be found through the responsible person:

[0145] Query the organizational structure table based on the responsible person ID (owner_id) to obtain the department ID (department_id) and organizational hierarchy.

[0146] If no valid organization is matched, jump to step S305 (initialize virtual organization).

[0147] Step S304: "Organization defaults to the root node (-1)"

[0148] This is a fault-tolerant and fail-safe mechanism in asset management. By attaching unmatched assets to a pre-set root node, it ensures data integrity and provides an entry point for subsequent manual or automated processing. This design balances automation efficiency with data controllability and is a core principle of hybrid cloud asset management.

[0149] Data integrity protection: Prevents asset loss due to incomplete mapping rules or data anomalies, ensuring that all assets are owned.

[0150] Improved operation and maintenance efficiency: By centrally managing unallocated assets, manual inspection costs are reduced and a basis for automated corrections (such as timed retry matching) is provided.

[0151] Audit and compliance: The root node serves as a fallback path, recording all unmatched operation logs to meet compliance requirements (such as full lifecycle asset tracking).

[0152] Step S305: Initialize the virtual organization

[0153] Virtual organization creation: A virtual organization ID (such as virt_org_002) is automatically generated, and the name format is "Unassigned-Terminal-{device_type}".

[0154] Set properties: the organization level is the lowest priority and marked as a temporary organization.

[0155] Data persistence: Write virtual organization information into the organizational structure table and associate it with assets, binding the asset ID (asset_id) and organization ID (org_id).

[0156] Step S306: Whether the asset is found by the asset relationship unique key

[0157] Unique key definition: It is composed of the terminal IP (terminal_ip), MAC address (mac_address), and device type (device_type) to form a unique one (ip: 192.168.1.100_mac: 00:1A:2B:3C:4D_type: server).

[0158] Asset query: Retrieve records in the asset table according to the unique key. If a match exists, jump to step S307 (update asset); if not, jump to step S308 (create a new asset).

[0159] Step S307: Call the interface to update the asset

[0160] The update operation is as follows: Call the interface to update the fields: the last synchronization time (last_sync_time), online status (status), and extended attributes (such as security policies). Use optimistic locking to prevent concurrent conflicts.

[0161] Step S308: Call the interface to create a new asset

[0162] The create operation is as follows: Call the interface to insert a new record into the asset table, generate a unique asset ID (asset_id), and initialize the responsible person (owner_id) as "unassigned". Trigger an asynchronous task for responsible person matching.

[0163] Step S309: Clean up invalid assets

[0164] Invalid judgment: The terminal asset has been deleted or offline in the security system for more than 30 days. Records that exist in the asset table but are not returned in the full synchronization.

[0165] Deletion policy: Soft deletion: Mark is_deleted = 1 and retain historical data. Physical deletion: Thoroughly delete sensitive data (such as test equipment) and record the log.

[0166] Scheduled task: Execute the cleanup task regularly every day to release storage resources.

[0167] Finally, the security operation platform automatically generates the security operation platform asset attributes according to the corresponding fields of the terminal security system and records them in the local asset table containing the fields shown in Table 2:

[0168] Fields included in Table 2 local asset table

[0169]

[0170] The key points of the process technology implementation of this S3 step are as follows:

[0171] Data Consistency: Ensure the atomicity of operations through database transactions. Unique indexes prevent duplicate asset records;

[0172] Performance Optimization: Batch processing reduces the number of API calls. Asynchronous logging is implemented through a message queue (such as Kafka);

[0173] Conflict Resolution: The manual review interface supports manual adjustment of the responsible person and organizational affiliation.

[0174] The process value of this step lies in: ensuring the real-time accuracy of terminal asset data through automated synchronization, root organization fallback, and invalid asset cleanup, and improving security operation efficiency and compliance.

[0175] S4. Dynamic Binding of the Terminal Asset Responsibility Chain for Local Terminals

[0176] As Figure 4 shown, it is the flowchart of the dynamic binding of the terminal asset responsibility chain of the method of the present invention. This process method includes the following steps:

[0177] Step S401: syslog Receives Network Authentication System Logs

[0178] Receives raw log data in real time from the authentication server. Listen on a specified port through the syslog protocol and parse the log format. Core field extraction: timestamp, MAC address (mac), login account (account_name), logged-in terminal IP (ip), log type (online / offline).

[0179] Step S402: Save Logs into the Database

[0180] Structurally store the raw logs in the database. Database table design: fields include log ID (log_id), timestamp, MAC address (mac), login account (account_name), logged-in terminal IP (ip), log type (online / offline). Storage method: batch insertion (such as every 5 seconds), and optimize query efficiency through indexes (such as create indexes on mac and timestamp).

[0181] Step S403: Query the Terminal Asset Table According to the MAC Field

[0182] Associate terminal asset information through the MAC address in the network authentication system log (collide the MAC address in the terminal asset table with the MAC address in the network authentication system log). Obtain the asset ID (asset_id), login account (account_name), device status (status), etc. from the network authentication system log.

[0183] Step S404: Query the user table according to the logged-in account

[0184] Query the staff code in the user table of the personnel system of the security operation platform through the logged-in account (account_name) in the network authentication system. Retrieve the records that match the logged-in account (account_name) field from the user table, and obtain the staff name (staf_name), department code (depat_code), etc.

[0185] Step S405: Determine whether the asset responsible person is empty

[0186] Determine whether there is information about the responsible person for the assets in the terminal asset table. If the responsible person is empty, jump to S406; if the responsible person is not empty, jump to S409.

[0187] Step S406: Determine the log type (online / offline)

[0188] Process according to the branch processing logic of the log operation type. If the operation type is online, jump to S407; if the operation type is offline, jump to S408.

[0189] Step S407 (online log): Update the asset information

[0190] Supplement the logged-in account (account_name) and logged-in name (name) in the network authentication system as

[0191] The responsible person account (owner_account) and responsible person name (owner_name) in the terminal asset table; at the same time, as the user account (user_account) and user name (user_name) in the terminal asset table.

[0192] Update fields: responsible person account (owner_account), responsible person name (owner_name), user account (user_account), user name (user_name), last online time (last_online_time), set the asset status to "online" (status = online), and set the last offline time to empty (last_offline_time = NULL).

[0193] The technical implementation method of this step is as follows: Database transactions ensure atomicity, and optimistic locks prevent concurrent conflicts.

[0194] Step S408 (offline log): Update the asset information

[0195] Supplement the login account (account_name) and login name (name) in the network authentication system as

[0196] the responsible person's account (owner_account) and responsible person's name (owner_name) in the terminal asset list; at the same time, serve as the user's account (user_account) and user's name (user_name) in the terminal asset list.

[0197] Update fields: responsible person's account (owner_account), responsible person's name (owner_name), user's account (user_account), user's name (user_name), last offline time (last_offline_time), and retain the original value of the asset status (extra logical judgment is required if it is "offline").

[0198] The technical implementation method of this step is as follows: Only update the necessary fields to avoid overwriting the online status history record.

[0199] Step S409: Judge the log type (login / logout)

[0200] Perform branch processing logic according to the log operation type. If the operation type is login, jump to S410; if the operation type is logout, jump to S411.

[0201] Step S410 (login log): Update asset information

[0202] Use the login account (account_name) and login name (name) in the network authentication system as the user's account (user_account) and user's name (user_name) in the terminal asset list.

[0203] Update fields: user's account (user_account), user's name (user_name), last login time (last_online_time), set the asset status to "online" (status = online), and set the last offline time to null (last_offline_time = NULL).

[0204] The technical implementation method of this step is as follows: Database transactions ensure atomicity, and optimistic locks prevent concurrent conflicts.

[0205] Step S411 (logout log): Update asset information

[0206] Use the login account (account_name) and login name (name) in the network authentication system as the user account (user_account) and user name (user_name) in the terminal asset table.

[0207] Update fields: user account (user_account), user name (user_name), last offline time (last_offline_time), and keep the original value for the asset status (extra logical judgment is required for "offline").

[0208] The technical implementation method of this step is as follows: Only update necessary fields to avoid overwriting the online status history.

[0209] The key points of the process technology implementation in this step S4 are as follows:

[0210] Data correlation: Implement three-way binding of device-user-asset through MAC address and account;

[0211] Exception handling: Log abnormal records for unmatched MAC or account;

[0212] Support manual intervention interface to correct incorrect associations.

[0213] Performance optimization: Use caching (such as Redis) to store frequently queried asset and user information; Update the database in batches to reduce I / O pressure.

[0214] The process value of this step S4 is reflected in the following aspects:

[0215] Real-time: Ensure timely synchronization of asset status and users through log streaming processing;

[0216] Responsibility traceability: Clearly define the device user and responsible person to meet the requirements of security audit;

[0217] Resource optimization: Automatically clean up invalid session data to reduce storage redundancy.

[0218] S5. Synchronous update of the personnel information table and the enterprise personnel system

[0219] As Figure 5 shown, it is the personnel system synchronization flow chart of the method of the present invention, and this flow method includes the following steps:

[0220] Step S501: Regularly pull the full volume of organizational data from the personnel system

[0221] Retrieve the latest organizational structure data from the personnel system at a fixed time every day. Data pulling: Obtain all data through the API interface. The core fields include organization code (org_code), organization name (org_name), parent organization code (parent_org_code), etc., and create a temporary organization table. Data format: JSON / XML, and it is transmitted encrypted via HTTPS. The exception handling method for this step is as follows: When the API call fails, enable the retry mechanism (up to 3 times), and record the error log after failure.

[0222] Step S502: Determine whether the organization code (org_code) already exists

[0223] Check whether the current organization code already exists in the organization table of the security operation platform. If it exists, jump to step S503; if not, jump to step S504.

[0224] Step S503: Save to the temporary organization table

[0225] Temporarily store the pulled data in a temporary table to avoid directly operating on the production table. Table structure: Align with the fields of the personnel system, and add a synchronization timestamp (sync_time) to mark the batch. Storage strategy: Insert in batches, and use database transactions to ensure data integrity.

[0226] Step S504: Update the temporary organization table

[0227] Function: According to the latest data of the personnel system, correct the organization information in the temporary table. If the data in the personnel system is inconsistent with that in the security operation platform (such as a change in the organization name), mark it as needing to be updated. Retain the historical version snapshot in the organization history table to support audit traceability.

[0228] Step S505: Synchronously save to the organization table of the security operation platform

[0229] Synchronize the newly added or updated data in the temporary table to the production table. If the organization code (org_code) already exists, overwrite the old data (such as the organization name and person in charge). Use database transactions to ensure atomicity and avoid data inconsistency caused by partial updates.

[0230] Step S506: Synchronously update the organization's superior-subordinate relationship

[0231] Maintain the hierarchical structure of the organization (such as department attribution relationships). If the organization code (org_code) does not exist, insert a new record and generate a unique organization ID (org_id).

[0232] Step S507: Compare all unretrieved organization data

[0233] Identify redundant data not covered by this synchronization (i.e., organizations that have been deleted in the personnel system but still exist in the security operation platform). Mark all organization codes (org_code) of this synchronization in the temporary table. Query the organization codes (org_code) that have not been marked from the organization table in the security operation platform and determine them as data to be cleaned. Generate a list of data to be deleted.

[0234] Step S508: Delete data from the temporary organization table

[0235] Clean the data in the temporary table and release storage resources. Execute the TRUNCATE or DELETE operation to empty the temp_org_table. Record the cleaning operation log.

[0236] Clean the expired organization records in the security operation platform. Soft delete: Mark is_deleted = 1 and retain historical data; Physical delete: Completely remove test or invalid organizations. Scheduled task: Execute the cleaning task daily to avoid data redundancy.

[0237] Step S509: Pull all user data from the personnel system again

[0238] Function: Obtain all user data from the personnel system. Data pulling: Obtain data through the API interface. The core fields include user ID (user_id), name, organization code (org_code), mobile phone number (mobile phone number), email, etc., and create a temporary user table. Data format: JSON / XML, encrypted transmission through HTTPS. The exception handling method for this step is as follows: When the API call fails, enable the retry mechanism (up to 3 times). After failure, record the error log and trigger an alarm (such as email notification to the operation and maintenance).

[0239] Step S510: Whether the user exists in the temporary user table

[0240] Check whether the current user already exists in the user table of the temporary database. Yes (exists), jump to Step S511; No (does not exist), jump to Step S512.

[0241] Step S511: Judge whether the user information has changed

[0242] Compare the personnel system data with the user table in the security operation platform to detect whether the user information has been updated. Basis for change: Based on the difference in the timestamp (last_modified_time) or key fields (such as department, position). Yes (there is a change), jump to Step S513; No (no change): Jump to Step S514.

[0243] Step S512: Save to the temporary user table

[0244] Function: Insert new user data into the temporary table. If the user ID does not exist, insert a new record and generate a unique user ID (or database auto-increment ID).

[0245] Step S515: Update the temporary user table

[0246] Update the new user data from the personnel system to the temporary table. Match the records according to the user ID (user_id) and overwrite the old data (such as department, position). Write the data before the change to the user history table, recording the operator and time.

[0247] Step S514: Do nothing

[0248] Step S515: Delete redundant user data in the security operation platform

[0249] Clean up the users in the security operation platform user table that no longer exist in the personnel system. Through a full comparison of user IDs, find the records that exist in the security operation platform but are missing in the temporary table.

[0250] Soft delete, mark is_deleted = 1, retain historical data; physical delete, completely remove test users. Transaction control: Ensure the atomicity of the delete operation to avoid data inconsistency caused by partial deletion.

[0251] Step S516: Compare whether the user information has changed

[0252] Finally, verify the data consistency between the temporary user table and the security operation platform user table. Yes (there are differences), jump to S517; No (consistent): The process ends.

[0253] Step S517: Update the security operation platform user information table

[0254] Synchronize the changed data in the temporary table to the production table. Match the production table records according to the user ID and update the fields (such as department, position, status). Insert new users into the production table and initialize permissions (such as default roles). Batch processing (1000 records per batch) to reduce I / O pressure through transactions.

[0255] Finally, the security operation platform obtains the organization table shown in Table 3 and the user table shown in Table 4, and the two tables constitute the personnel information table.

[0256] Fields included in Table 3, the organization table

[0257] Field Name Field Meaning Whether Mandatory id Primary Key Auto-Increment Yes depat_id Personnel System Department ID Yes org_id system_org Primary Key No depat_name Department Name Yes depat_code Department Number Yes sup_depat_code Superior Department Number Yes dept_update Personnel System Update Yes activation Whether Enabled Yes create_time Creation Time Yes update_time Update Time Yes

[0258] Fields included in Table 4, the user table

[0259] Field Name Field Meaning Whether Mandatory id Primary Key Auto-Increment Yes staf_code Staff Number Yes staf_name Staff Name Yes depart_code Department Number Yes email Email No cellphone Mobile Phone Number No create_time Creation Time Yes update_time Update Time Yes

[0260] The key implementation points of the process technology in this S5 step are as follows:

[0261] Data consistency:

[0262] Prevent duplicate insert or update conflicts through database transactions and unique indexes; use optimistic locks (version number fields) to handle concurrent scenarios;

[0263] Performance optimization: Use paging queries (1000 records per page) for full - volume comparison to reduce memory occupancy; use batch processing for hierarchical relationship updates to avoid individual operations;

[0264] Cache mechanism: Cache high - frequency query fields (such as user IDs) in the cache, and set the cache expiration time to 10 minutes;

[0265] Exception handling: Roll back the transaction when synchronization fails, and record detailed error logs (such as conflicting fields, exception stack traces); provide an interface for manual intervention to support manual data correction.

[0266] The process value of this S5 step is reflected in the following aspects:

[0267] Data real - time performance: Ensure that the personnel data in the security operation platform is consistent with the organizational structure / user information in the personnel system, and support scenarios such as permission allocation and auditing.

[0268] Resource management: Automatically clean up redundant data to reduce storage costs.

[0269] Compliance: Meet the data retention policy through soft deletion and historical snapshots.

[0270] In addition, in the embodiments of the present invention, further linkage notifications and closed - loop handling can be realized in ways such as text messages, emails, and OA notifications. Some implementation methods are specifically introduced below.

[0271] The docking method with the OA system is as follows:

[0272] Interface specification: Implement the docking of the network security integrated operation platform and the OA system through interface docking. The data format is JSON, and the fields include alert ID (alert_id), asset IP (asset_ip), risk level (risk_level), and processing link (action_url). On the one hand, the security operation platform can push linkage disposal information to the OA system to facilitate relevant personnel to process it in a timely manner during daily work.

[0273] Push of to - do tasks: High - risk alerts are pushed to the to - do center of the OA system in real - time, and the responsible person needs to feedback the processing result within 24 hours.

[0274] The docking method with the SMS platform is as follows:

[0275] Docking configuration with the enterprise-specified SMS platform. The SMS sending module automatically sends SMS notifications to relevant personnel. The SMS content format is standardized and key information is complete, ensuring that relevant personnel can receive important security prompt information in a timely manner to assist in quickly responding to security incidents.

[0276] Templatized notification: For example:

Security Alert

[0277] Trigger condition: Dynamically select the notification method according to the alert level (high risk / medium risk / low risk). For high-risk alerts, SMS, email, and OA notifications are sent simultaneously.

[0278] The email system docking method is as follows:

[0279] Docking configuration with the enterprise-specified email system. The email sending module automatically sends email notifications to relevant personnel. The email content format is standardized and key information is complete, ensuring that relevant personnel can receive important security prompt information in a timely manner to assist in quickly responding to security incidents.

[0280] Templatized sender: For example:

Security Alert

[0281] Trigger condition: Dynamically select the notification method according to the alert level (high risk / medium risk / low risk). For high-risk alerts, SMS, email, and OA notifications are sent simultaneously.

[0282] Closed-loop verification and auditing

[0283] After the responsible person has completed the handling, the processing result is fed back through OA (such as "vulnerability has been repaired"). The security administrator updates the asset status and records it in the audit log table (audit_log).

[0284] If not handled within the time limit, the notification is automatically escalated to the superior responsible person, and a weekly report is generated to summarize the unclosed incidents.

[0285] The embodiments described above are only a preferred solution of the present invention, but it is not intended to limit the present invention. Those of ordinary skill in the relevant technical fields can still make various changes and modifications without departing from the spirit and scope of the present invention. Therefore, all technical solutions obtained by adopting equivalent replacements or equivalent transformations fall within the protection scope of the present invention.

Claims

1. A method for automated synchronization of network asset data and dynamic binding of the responsibility chain, where the network assets are located in a hybrid cloud environment composed of public clouds, private clouds, and local terminals, characterized in that Including: S1. Obtain the cloud asset mapping table, cloud asset table, local asset mapping table, and local asset table that are pre-constructed and maintained for the target enterprise organization, and simultaneously synchronize and update the personnel information table containing organizational structure and personnel information at regular intervals; S2. Real-time obtain the full volume of cloud asset data owned by the target enterprise organization from the public cloud platform and private cloud platform, and extract the first asset information of each cloud host. Retain the cloud hosts that exist in the cloud asset mapping table and whose first asset information is complete and unique, and continue to check whether they exist in the cloud asset table. If they exist, directly update their asset status information. If they do not exist, create a new cloud host in the cloud asset table, and match the corresponding personnel based on the creator field of the cloud host in the personnel information table as the responsible person for this cloud host; S3. Real-time obtain all local terminals owned by the target enterprise organization from the management system of the local terminal and extract the second asset information of each local terminal; For each local terminal, first match the responsible person in the local asset mapping table. If the responsible person is not matched, hang this local terminal to the root organization. Then, for each local terminal, check whether it exists in the local asset table. If it does not exist, create a new local terminal. Finally, trigger an asynchronous execution of the terminal asset responsibility chain dynamic binding task for each local terminal. Collide the MAC address of the local terminal with the network authentication system log. If the collision is successful, update the asset responsible person and user information of the newly created local terminal in the local asset table, and this local terminal will be updated from the root organization to the organization where the responsible person is located.

2. The method for automatically synchronizing network asset data and dynamically binding the responsibility chain according to claim 1, wherein The cloud asset mapping table is incrementally updated by pulling data from the public cloud platform and private cloud platform at regular intervals, and the administrator maintains the abnormal data or missing fields; the cloud asset mapping table records the list of cloud hosts owned by the target enterprise organization, and each cloud host needs to record the corresponding VPC code and the responsible person in the table. The VPC code field is a required item, and the responsible person field may be missing. Whenever a cloud host is discarded because the VPC code cannot be found in the cloud asset mapping table, the administrator will be notified to re-maintain the cloud asset mapping table. If the responsible person field is missing, the corresponding personnel will be matched based on the creator field of the cloud host in the personnel information table as the responsible person for this cloud host.

3. The method for automatically synchronizing network asset data and dynamically binding the chain of responsibility as claimed in claim 1, wherein The cloud asset table records the unexpired cloud network asset information owned by the target enterprise organization. Each cloud network asset information includes the asset name, VPC code, main IP, server unique ID, asset responsible person, and asset status information of the cloud host.

4. The method for automated synchronization of network asset data and dynamic binding of the responsibility chain according to claim 1, wherein, The local asset mapping table is pulled from the management system of the local terminal at regular intervals for incremental update, and the administrator maintains the abnormal data or missing fields; the local asset mapping table records the list of local terminals owned by the target enterprise organization, and each local terminal needs to record the corresponding terminal IP, MAC address, asset responsible person, and the department to which the asset responsible person belongs in the table; whenever a local terminal is attached to the root organization and the MAC address of the local terminal fails to collide successfully with the network authentication system log, the administrator will be notified to re-maintain the asset responsible person and the department to which the asset responsible person belongs for this local terminal in the local asset mapping table.

5. The method for automatic synchronization of network asset data and dynamic binding of responsibility chain according to claim 1, characterized in that, The local asset table records the information of the unexpired local terminals owned by the target enterprise organization, and each local terminal information includes the terminal name, terminal IP, MAC address, device type, asset responsible person, and asset status information.

6. The method for automatic synchronization of network asset data and dynamic binding of responsibility chain according to claim 1, characterized in that The specific implementation method of S2 is as follows: Real-time obtain the full amount of cloud asset data owned by the target enterprise organization from the public cloud platform and the private cloud platform, and extract the first asset information of each cloud host. The first asset information includes the creator, VPC code, main IP, and server unique ID; check whether the VPC code of each cloud host exists in the cloud asset mapping table, discard the cloud hosts whose VPC codes do not exist in the cloud asset mapping table, perform information field integrity verification and uniqueness verification on the first asset information of all the remaining cloud hosts, and retain the cloud hosts that pass the verification as the cloud temporary asset library; for each cloud host in the cloud temporary asset library, generate a first unique key based on its VPC code, main IP, and server unique ID, and then check whether there is a cloud host corresponding to this first unique key in the cloud asset table. If it exists, update the asset status information in the cloud asset table according to the corresponding first asset information. If it does not exist, create a new cloud host in the cloud asset table and trigger the responsible person matching task, and match the corresponding person based on the creator field of the cloud host in the personnel information table as the asset responsible person of this cloud host, and at the same time determine the organization to which the asset responsible person belongs.

7. The method for automatic synchronization of network asset data and dynamic binding of responsibility chain according to claim 1, characterized in that, The specific implementation method of S3 is as follows: Real-time obtain all the local terminals owned by the target enterprise organization from the management system of the local terminal as the local temporary asset library, and extract the second asset information of each local terminal. The second asset information includes the terminal IP, MAC address, and device type; for each local terminal in the local temporary asset library, first match the responsible person in the local asset mapping table based on the terminal IP or MAC address of each local terminal. If the responsible person is matched, further match the organization to which the responsible person belongs from the personnel information table and attach this local terminal to the corresponding responsible person. If the responsible person is not matched, attach this local terminal to the root organization; Then, a second unique key is generated for each local terminal based on its terminal IP, MAC address, and device type. Then, a search is performed in the local asset table to determine whether a local terminal corresponding to the second unique key exists. If so, the asset status information in the local asset table is updated according to the corresponding second asset information. If not, a new local terminal is created in the local asset table. After each local terminal completes the search operation in the local asset table, an asynchronous terminal asset responsibility chain dynamic binding task is triggered. The MAC address of the local terminal is used to collide with the network authentication system log. If the collision is successful, the asset responsible person and user information of the newly created local terminal in the local asset table will be updated, and the local terminal will be updated from the root organization to the responsible person's organization.

8. The method for automatic synchronization of network asset data and dynamic binding of the responsibility chain according to claim 1, wherein The specific execution method of the terminal asset responsibility chain dynamic binding task is as follows: First, we periodically obtain network authentication system log data from the enterprise organization's network authentication server and parse and extract data from the network authentication system log. The extracted fields include timestamp, MAC address, login account, login terminal IP, and log type. Then, the MAC address in the network authentication system log is collided with the MAC address in the local asset table; each local terminal in the local asset table obtains the latest network authentication system log with the same MAC address through collision matching as the source log required for information update; Finally, for each local terminal in the local asset table that matches the source log, extract the unique login account of each person entered during network authentication in the source log, and use the login account to match the corresponding person in the personnel information table. Then determine whether the asset responsible person field for the local terminal in the local asset table already exists. If so, add the matched person as the asset user of the local terminal in the local asset table, and use the timestamp and log type in the source log to update the asset status information in the local asset table. If not, add the matched person as both the asset responsible person and asset user of the local terminal in the local asset table, and use the timestamp and log type in the source log to update the asset status information in the local asset table.

9. The method for automatic synchronization of network asset data and dynamic binding of the responsibility chain according to claim 1, characterized in that, After associating each network asset in the cloud asset table and the local asset table with the asset owner, determine the organization to which the asset owner belongs in the latest personnel information table, thereby attaching each network asset to the corresponding organization; When a network asset generates an alarm, disposal information, or other information that requires notification, the corresponding asset manager or organization manager will be notified through the preset notification method.

10. A system for automatic synchronization of network asset data and dynamic binding of the responsibility chain, where the network assets are located in a hybrid cloud environment composed of public clouds, private clouds, and local terminals, and is characterized in that include: The information table acquisition module is used to obtain the cloud asset mapping table, cloud asset table, local asset mapping table, and local asset table that are pre-built and maintained for the target enterprise organization, and to periodically synchronize and update the personnel information table containing organizational structure and personnel information; The cloud platform synchronization and binding module is used to obtain the full amount of cloud asset data owned by the target enterprise organization from the public cloud platform and the private cloud platform in real time, extract the first asset information of each cloud host, retain the cloud hosts that exist in the cloud asset mapping table and whose first asset information is complete and unique, and continue to check whether they exist in the cloud asset table. If they exist, directly update their asset status information. If they do not exist, create a new cloud host in the cloud asset table and match the corresponding person based on the creator field of the cloud host in the personnel information table as the responsible person for the cloud host; The local terminal synchronization and binding module is used to obtain all local terminals owned by the target enterprise organization from the management system of the local terminal in real time and extract the second asset information of each local terminal; For each local terminal, first match the responsible person in the local asset mapping table. If the responsible person is not matched, hang the local terminal to the root organization; then check whether each local terminal exists in the local asset table. If it does not exist, create a new local terminal. Finally, trigger an asynchronous execution of the terminal asset responsibility chain dynamic binding task for each local terminal. Collide the MAC address of the local terminal with the network authentication system log. If the collision is successful, update the asset responsible person and user information of the newly created local terminal in the local asset table, and the local terminal will be updated from the root organization to the organization where the responsible person is located.