Method and system for automatically discovering and managing oil field information assets

Through flow reduction and active detection, the assets of the oil field industrial control system are identified, combined with fingerprint library matching and vulnerability detection, the problem of asset management difficulties in the oil field industrial control system is solved, automatic discovery and management is realized, and safety and efficiency are improved.

CN120429862APending Publication Date: 2025-08-05PETROCHINA CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202410161204.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-02-05
Publication Date
2025-08-05

Smart Images

  • Figure CN120429862A_ABST
    Figure CN120429862A_ABST
Patent Text Reader

Abstract

The invention provides an oil field information asset automatic discovery and management method and system, and the method comprises the steps: carrying out the flow reduction, carrying out the active detection, carrying out the asset identification label marking of all types of attribute information and components of assets according to the asset information and feature information obtained through the active detection and flow reduction, and carrying out the asset marking. And for unidentified assets found by active detection and flow reduction scanning, inputting corresponding information of the unidentified assets according to the asset identification tag, and carrying out security monitoring on the identified asset information. And the asset information is fed back to the security platform, and the found asset information is compared with alarm information in the security platform, so that non-asset alarm information and alarm information inconsistent with the asset category are removed, and the security platform is assisted to remove invalid information. Through flow reduction and active detection, docking of various network products and automatic identification of asset information in the existing network, asset management ecology of part of third-party products can be integrated, information islands can be broken through, and a clear asset ledger can be established.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of oilfield information networks, and in particular relates to an automatic discovery and management method and system for oilfield information assets. Background Art

[0002] With the explosive growth of cloud, big data, and IoT devices, network architecture has undergone significant changes, and the importance of asset management has gradually become prominent. Typically, asset discovery (detection) requires fingerprinting of hosts or application systems within a certain range (identifying operating system versions, open ports, provided services, and service versions). Automatic detection and scanning are used to discover unknown (unmanaged) asset functions, scan multiple ports of network assets, and obtain asset information of network assets. This allows the identification of network assets to be scanned and the management of assets. Active and passive asset discovery (active network host detection, port detection scanning, hardware characteristics and version information detection) generally includes asset types such as hosts, network devices, security devices, databases, middleware, application components, and terminals. Passive detection methods involve collecting traffic from the target network and analyzing application layer protocols such as HTTP, FTP, and SMT in the traffic, thereby achieving passive detection of network asset information.

[0003] Security issues in industrial control systems in the oilfield industry can be categorized into three aspects: asset status, security threats, and production failures. First, industrial control systems encompass assets such as controllers, hosts, servers, network equipment, RTUs, DCSs, PLCs, industrial computers, cameras, and printers. IT assets include terminal devices such as Windows terminals, Linux terminals, trusted computing terminals, mobile terminals, servers, and virtual machines, as well as common IoT devices such as network printers, IP phones, video conferencing systems, network cameras, IP cameras, and access control systems. These device assets present numerous challenges, including long lifecycles, diverse vendors, dispersed deployments, and a lack of asset record management. Second, industrial control systems are outdated and prone to numerous N-day vulnerabilities, making them vulnerable to security threats such as penetration attacks, botnets, and virus transmission. Finally, the production process of industrial control systems is prone to abnormal events such as equipment failures, abnormal operations, and illegal commands. Summary of the Invention

[0004] The purpose of the present invention is to provide an oilfield information asset automatic discovery and management method and system, to discover various types of assets used in an enterprise intranet and to protect the assets.

[0005] The purpose of the present invention is achieved by the following technical means: obtaining characteristic information, accessing through mirrored traffic, obtaining target traffic data packets in the network, traversing the target data packets, and searching for characteristic information;

[0006] Obtain asset information and actively detect the device's open ports, scan the device's port services, system devices, and business applications, obtain asset fingerprint information, and match the device fingerprint characteristics with the fingerprint database to obtain device type information;

[0007] Identify asset categories. Based on the asset information and feature information obtained through active detection and traffic restoration, determine the protocol type of the target data packet's application layer according to the preset feature information and protocol type correspondence table. Determine the asset category based on the feature library information base and the protocol used. Label the asset's various attribute information and components with asset identification tags.

[0008] Asset tagging: For unidentified asset categories discovered through active detection and traffic restoration scanning, the corresponding information of the unidentified assets is entered according to the asset identification tags.

[0009] Security monitoring: Based on the identified asset information, the system conducts vulnerability detection on the assets, detecting vulnerability risks, configuration risks, weak password risks, and Web plaintext transmission risks in the assets, providing reference for management personnel to make decisions;

[0010] Asset management feeds asset information back to the security platform. By comparing the discovered asset information with the alarm information in the security platform, alarm information about non-assets and alarm information that does not match the asset category is removed.

[0011] The characteristic information includes asset IP, host name, asset ownership, branch, identification method, operating system, open services and ports, and asset type.

[0012] The asset identification tag includes asset name, open port, operating system, MAC address, manufacturer name and firmware version.

[0013] During active detection, if the industrial equipment and the scanning equipment belong to the same network, assets are discovered by sending ARP broadcast packets. The frequency of broadcast packets and the scanning period should be controlled to control the number and frequency of broadcast packets. This will reduce the frequency of network interruptions and prevent downtime for industrial control equipment with limited network data packet processing capabilities within the industrial network.

[0014] If industrial equipment and scanning devices need to communicate through routing, discover assets by sending ICMP packets, obtain the IP / MAC forwarding table of the corresponding switch through SNMP to obtain asset details, and control the packet sending frequency, size, and scanning cycle to control the number and length of scanned data packets. Only respond to network data packets of a specific size for security devices, and adjust the scan data length to meet the requirements of the security device to allow it to respond.

[0015] It also continuously monitors the access events of devices in the network through traffic analysis, subnet broadcast monitoring, network facility linkage, and DHCP linkage. After discovering new device access events, it obtains device information and adds asset identification tags.

[0016] The scanning of device port services, system devices and business applications specifically includes, for port services, performing host survival detection, discovering surviving hosts, and performing port open detection on surviving hosts;

[0017] For system devices, the device type and database are identified through the TCP / IP protocol stack. The device manufacturer is identified through regular matching of banner information, return body information, and operating system type. Fingerprint recognition technology is used for detection to identify the operating system type and version.

[0018] For business applications, fingerprint detection is used to identify WEB service languages, WEB containers, WEB front-end frameworks, WEB applications, and development frameworks.

[0019] An oilfield information asset automatic discovery and management system, comprising:

[0020] The traffic restoration module obtains the target traffic data packets in the network through mirrored traffic access, traverses the target data packets, searches for feature information, and determines the protocol type of the target data packet's application layer based on the preset feature information and protocol type correspondence table. The asset category is determined based on the feature library information base and the protocol used.

[0021] The active detection module actively detects the open ports of the device, scans the device port services, system devices and business applications, obtains asset fingerprint information, and matches the device fingerprint characteristics with the fingerprint database to obtain device type information;

[0022] The asset tagging module adds asset identification tags to various attribute information and components of assets based on asset information and feature information obtained through active detection and traffic restoration;

[0023] The security monitoring module performs vulnerability detection on assets based on identified asset information, detecting vulnerability risks, configuration risks, weak password risks, and Web plaintext transmission risks in assets;

[0024] The asset management module classifies assets according to asset identification tags, divides asset scenarios according to IP segments and devices, categorizes and counts assets, and uploads risks detected by the security monitoring module to the host computer for management personnel's reference. It also feeds back asset information to the security platform. By comparing the discovered asset information with the alarm information in the security platform, it removes alarm information related to non-assets and alarm information that does not match the asset category.

[0025] The beneficial effects of the present invention are:

[0026] 1. Through traffic restoration and active detection, it connects to various network products and automatically identifies asset information in the existing network. It can integrate the asset management ecosystem of some third-party products, break through information silos, and establish a clear asset ledger.

[0027] 2. When assets are discovered, risk detection is performed on the vulnerability of user assets, detecting risks such as vulnerability risks, configuration risks, weak passwords, and Web plaintext transmission in user assets. A clear analysis report is generated to help users quickly obtain the security status of their own assets and discover potential risks, so as to achieve the effect of early prevention and realize three-dimensional asset security protection;

[0028] 3. By feeding asset information back to the security system, the security platform can filter out alarm information that does not belong to internal assets and alarm information that does not match the asset type, thereby assisting the security platform in removing invalid information. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Figure 1 A flowchart of a method for automatically discovering and managing oilfield information assets;

[0030] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. DETAILED DESCRIPTION

[0031] [Example 1]

[0032] like Figure 1 As shown, a method for automatically discovering and managing oilfield information assets includes the following steps:

[0033] Obtain characteristic information, obtain target traffic data packets in the network through mirrored traffic access, traverse the target data packets, and search for characteristic information;

[0034] The characteristic information includes asset IP, host name, asset ownership, branch, identification method, operating system, open services and ports, and asset type.

[0035] Traffic restoration uses mirrored traffic access to identify specific asset information from traffic flow information based on a combination of various network, routing, database, email, and other application protocols, as well as traffic signature libraries. It also integrates SNMP, log information, and agent data to improve the integrity of passive identification data.

[0036] Specifically, the traffic feature determination method is: combining the key business interface traffic of the oilfield core switch, the identification and unpacking matching analysis characteristics of the data packets generated by cameras, PLCs, RTUs, DCSs, industrial computers, etc.

[0037] This includes extracting session metadata from TCP / UDP protocols, and also enabling push through NetFlow data generated by routers and switches. Session metadata records include source IP, source port, destination IP, destination port, protocol type, number of packets, session start time, session end time, etc. Data can also be supplemented based on session metadata, such as source IP country and destination IP country.

[0038] Extract common and key fields from common protocols such as HTTP, DNS, SMB, SMTP, IMAP, MSSQL, DHCP, Kerberos, LDAP, SMB, FTP, TELNET, and SSH to form protocol metadata, such as the version number, URL, HOST, header fields, BODY (specified length), and status code of HTTP protocol requests.

[0039] Obtain asset information and actively detect the device's open ports, scan the device's port services, system devices, and business applications, obtain asset fingerprint information, and match the device fingerprint characteristics with the fingerprint database to obtain device type information;

[0040] Active detection is to perform a customized scan of the network through a scanning probe and identify and store it in the database, while also scanning switches or routers to obtain accurate MAC address information in the ARP table.

[0041] Specifically, the system scans the device's open ports through a port detection program and obtains the device's TCP / IP stack fingerprint characteristics through packet scanning, thereby matching the device's operating system, open services, and other information. By integrating the scanning information from various dimensions and matching it with the built-in rich fingerprint library, the closest device type information is obtained.

[0042] The device has built-in rich device discovery protocols for commonly used industrial network devices. It uses common or proprietary device discovery protocols to scan RTUs, PLCs, industrial terminals, NVRs and other devices, and supports obtaining the accurate type, brand, model, description and other information of the device.

[0043] Through active detection, the device is scanned at three levels: port service (various network protocols), system equipment (operating system, etc.), and business application (various application protocols) to obtain device information. The device type is matched according to the fingerprint library. For example, the matching result of one asset is a camera, and another asset is a PLC.

[0044] By obtaining industrial host health, log audit, and other security equipment asset information as a supplement to passive identification, it is more conducive to users to accurately grasp the production network asset situation.

[0045] Asset identification scope: Covers more than 2,000 mainstream controller models from manufacturers including Siemens, Schneider, Rockwell, GE, ABB, OMRON, MITSUBISHI, HollySys, etc.

[0046] The asset identification tag includes asset name, open port, operating system, MAC address, manufacturer name and firmware version.

[0047] Other asset identification capabilities include industrial terminals such as industrial computers, PLCs, RTUs, and DCS systems, as well as various network devices such as PCs, cameras, and printers. Automatic learning builds unique behavioral asset models, creating an asset whitelist to monitor access by illegal and counterfeit devices. The product supports asset management, including attributes such as manufacturer name, device type, operating system, device model, IP address, MAC address, access location, and custom asset data.

[0048] It also continuously monitors network device access events through traffic analysis, subnet broadcast monitoring, network facility linkage, and DHCP linkage. Upon discovering a new device access event, it obtains device information and tags it with asset identification tags. It immediately detects new device access events and obtains device information.

[0049] Identify asset categories. Based on the asset information and feature information obtained through active detection and traffic restoration, determine the protocol type of the target data packet's application layer according to the preset feature information and protocol type correspondence table. Determine the asset category based on the feature library information base and the protocol used. Label the asset's various attribute information and components with asset identification tags.

[0050] Through the labeling management of various asset attribute information and components, it supports advanced asset retrieval and statistical analysis based on various dimensions of assets.

[0051] Active detection and traffic restoration identify assets and generate an asset baseline, prioritizing the MAC address as the unique identifier. Based on this baseline, the asset's operational status is monitored, covering asset risk, network communication status, operational status changes, and MAC address changes. For network communication monitoring, the system provides a visual graphical interface that intuitively displays network communication relationships between assets and between assets and other network addresses. Other monitored items can be displayed to users in various formats, including tables, charts, and alerts. All static and dynamic asset information can be exported to other platforms.

[0052] Asset tagging: For unidentified asset categories discovered through active detection and traffic restoration scanning, the corresponding information of the unidentified assets is entered according to the asset identification tags.

[0053] Deploying agent-based products on terminals can indeed collect terminal information and report it to system administrators. However, given the enterprise's practical needs, it's not possible to install agents on every type of network asset. Therefore, some assets require second-level administrators to manually enter asset information. For assets with agents installed, the agent automatically uploads information such as the operating system version, patch status, registry keys, terminal program status, and file status on the terminal's directory disk. For assets without agents installed, administrators manually enter asset information by restoring traffic and proactively detecting unidentified assets.

[0054] After active detection, traffic restoration and manual entry, the discovered assets are classified according to preset rules, such as fixed assets, current assets, intangible assets, etc. Asset classification can provide basic data for subsequent asset management.

[0055] By organizing assets and clearing out expired or useless assets, the storage and management costs of oil fields can be reduced.

[0056] After the assets are discovered, it can also provide a decision-making basis for the asset management of the oil field, discover and solve problems in asset management, and improve the asset utilization efficiency and value of the oil field.

[0057] Security monitoring: Based on the identified asset information, the system conducts vulnerability detection on the assets, detecting vulnerability risks, configuration risks, weak password risks, and Web plaintext transmission risks in the assets, providing reference for management personnel to make decisions;

[0058] Through active detection, traffic restoration and manual entry, assets are discovered, IT / OT assets in the entire network are sorted out, and vulnerability testing is performed on the discovered assets to detect vulnerability risks, configuration risks, weak password risks and Web plaintext transmission risks in the assets. Global industrial asset security risks are discovered, and risk information and security information are uploaded to industrial safety equipment centralized management and monitoring platforms, log centralized collection and management systems, threat unified analysis and operations and other security products. By linking various security products, various products feedback effective security information, accurate security strategies, and reasonable security suggestions, which effectively help the oilfield industry to ensure production continuity. While meeting the safety and compliance needs of the oilfield industry, it provides decision-making support for the systematic construction of oilfield industry safety.

[0059] Asset management feeds asset information back to the security platform. By comparing the discovered asset information with the alarm information in the security platform, alarm information about non-assets and alarm information that does not match the asset category is removed.

[0060] For example, the security platform may locate a server as risky, but asset information shows that this server does not exist in the internal assets, indicating that it may be a disguised or false alarm information.

[0061] Or the security platform alarm is that there is a process risk, but according to the feedback of the asset information, the corresponding device is a printer, and the printer does not have a process risk. Therefore, the alarm information does not match the asset type, and it can be determined that the alarm information is wrong. Through the above two methods, users can be assisted in filtering and removing errors in the used security platform alarm information.

[0062] Scanning and probing industrial network equipment assets generally involves Layer 2 and Layer 3 network scanning. Layer 2 scanning involves the industrial equipment and scanning devices being on the same network. Layer 3 scanning involves the industrial equipment and scanning devices requiring routing to communicate. Scanning and probing involves sending data packets to the network segment to be probed and waiting for a response from the device. If a response is received, the IP and MAC address information of the corresponding production equipment asset is detected.

[0063] During active detection, if the industrial equipment and the scanning equipment belong to the same network, assets are discovered by sending ARP broadcast packets. The frequency of broadcast packets and the scanning period should be controlled to control the number and frequency of broadcast packets. This will reduce the frequency of network interruptions and prevent downtime for industrial control equipment with limited network data packet processing capabilities within the industrial network.

[0064] If industrial equipment and scanning devices need to communicate through routing, discover assets by sending ICMP packets, obtain the IP / MAC forwarding table of the corresponding switch through SNMP to obtain asset details, and control the packet sending frequency, size, and scanning cycle to control the number and length of scanned data packets. Only respond to network data packets of a specific size for security devices, and adjust the scan data length to meet the requirements of the security device to allow it to respond.

[0065] The scanning of device port services, system devices and business applications specifically includes, for port services, performing host survival detection, discovering surviving hosts, and performing port open detection on surviving hosts;

[0066] For system devices, the device type and database are identified through the TCP / IP protocol stack. The device manufacturer is identified through regular matching of banner information, return body information, and operating system type. Fingerprint recognition technology is used for detection to identify the operating system type and version.

[0067] For business applications, fingerprint detection is used to identify WEB service languages, WEB containers, WEB front-end frameworks, WEB applications, and development frameworks.

[0068] The characteristics of oilfield information assets (RTU, PLC, intelligent monitoring cameras, and network access equipment required for the production network) are profiled from the underlying device system, operating system to the upper-level port services and business applications. This can quickly discover asset types and comprehensively sort out asset fingerprints.

[0069] Assets are divided into three layers from bottom to top: port services, system equipment, and business applications. Detecting these three layers of information assets enables in-depth analysis and profiling of assets. The technical means employed are as follows:

[0070] Ports and services:

[0071] 1) Host survival detection. Use ICMP Echo reply, ICMP timestamp, ARP detection, TCP SYN connection, TCP ACK half-connection, etc. to detect host survival and find surviving hosts;

[0072] 2) Port open detection. Use a variety of mature port scanning technologies to detect and scan host ports, such as TCP SYN scan, TCP connect scan, TCP NULL scan and TCP Maimon scan;

[0073] 3) Service and version detection. For service and version detection, we designed an asset feature database based on the historical asset information of various oilfields. This database serves as the original fingerprint detection library for the oilfield. We initiate empty connection requests to the corresponding ports, obtain banner information, parse the response message, and perform regular expression matching to achieve service detection. Furthermore, we perform service detection by requesting a specific service on a specific port. If the server responds to this request, it indicates that the corresponding service is available.

[0074] System equipment:

[0075] 1) Device type identification. Use the TCP / IP protocol stack to accurately identify the device type. For example, when identifying a Cisco switch, the TCP / IP protocol can be used to identify the device type. If it is Cisco IOS, it can be determined to be a Cisco switch / router.

[0076] 2) Database Identification. Database types can be identified through the TCP / IP protocol stack, such as the commonly used database port. Banner information is used for identification, providing a powerful banner information dictionary for database type identification. In addition, database fingerprint recognition and detection of web service error messages are provided.

[0077] 3) Device manufacturer identification. A variety of technologies are provided for device manufacturer identification, such as banner information, regular expression matching of returned body information, specific operating system type, etc.

[0078] 4) Operating system type identification. Identify the operating system type and version, etc., use fingerprint recognition technology for detection, and provide a powerful fingerprint database, such as:

[0079] a) Make a preliminary judgment based on the basic services provided by the operating system, such as the welcome information, copyright notice, and command response information of FTP, telnet, http, DNS and other servers;

[0080] b) Make judgments based on the subtle differences between operating systems in protocol implementation, such as operating system identification through TTL values and TCP FIN scanning.

[0081] Business Applications:

[0082] Identify web service languages, web containers, web front-end frameworks, web applications, and development frameworks. Provide multi-faceted fingerprint detection for upper-level business applications, such as header detection, body regular expression matching, URL MD5 comparison, 404 page detection, and fixed directory pages. This allows for fingerprint detection of business applications and supports a vast library of web fingerprint detections.

[0083] An oilfield information asset automatic discovery and management system, comprising:

[0084] The traffic restoration module obtains the target traffic data packets in the network through mirrored traffic access, traverses the target data packets, searches for feature information, and determines the protocol type of the target data packet's application layer based on the preset feature information and protocol type correspondence table. The asset category is determined based on the feature library information base and the protocol used.

[0085] The active detection module actively detects the open ports of the device, scans the device port services, system devices and business applications, obtains asset fingerprint information, and matches the device fingerprint characteristics with the fingerprint database to obtain device type information;

[0086] The asset tagging module adds asset identification tags to various attribute information and components of assets based on asset information and feature information obtained through active detection and traffic restoration;

[0087] The security monitoring module performs vulnerability detection on assets based on identified asset information, detecting vulnerability risks, configuration risks, weak password risks, and Web plaintext transmission risks in assets;

[0088] The asset management module classifies assets according to asset identification tags, divides asset scenarios according to IP segments and devices, categorizes and counts assets, and uploads risks detected by the security monitoring module to the host computer for management personnel's reference. It also feeds back asset information to the security platform. By comparing the discovered asset information with the alarm information in the security platform, it removes alarm information related to non-assets and alarm information that does not match the asset category.

[0089] The asset management module classifies assets through asset identification tags. For example, it classifies and grades various asset information according to asset groups, asset sources, equipment types, operating system types, offline status, destocking status, port opening status, service status, etc., and displays key asset information intuitively in a graphical manner to help enterprises quickly grasp the current status of managed assets and facilitate timely detection of asset problems.

[0090] After an asset is discovered, it is stored in the database of the asset management module. The stored asset information can be queried, edited and managed. The asset information covers multiple dimensions such as hardware information, operating system information, open ports, applications, development frameworks, and responsible persons. This satisfies asset tagging management and asset identification and classification methods for different administrators in various scenarios, such as IP segment asset division, device asset division, and IP device mixed asset division, to solve asset division and asset statistics problems in complex scenarios.

[0091] Set de-warehouse rules to quickly and accurately identify offline assets and zombie assets, provide timely reminders for such assets, and de-warehouse assets according to certain rules to reduce the security risks brought by zombie assets.

[0092] By identifying asset vulnerabilities, we can perceive the vulnerability risks, configuration risks, weak password risks, and Web plaintext transmission risks in assets, continuously monitor assets and provide risk warnings, helping administrators fully understand the security status of their own assets and achieve the effect of early prevention.

[0093] Accurately identify asset risks from the perspectives of vulnerability risk, configuration risk, weak password risk, and Web plaintext transmission risk. Administrators can promptly grasp the status of assets with vulnerability risks and risk levels, understand the vulnerability distribution of all current assets, hot vulnerability issues, and vulnerability trends in the past 30 days, and query the detailed vulnerability status of each asset, helping administrators understand the current vulnerability situation and handling status, so as to adjust asset management strategies in a timely manner.

[0094] Asset information is also fed back to the existing security platform to screen out the alarm information of the security platform. For example, the security platform locates a server as risky, but through asset information, there is no such server in the internal assets, which means that it may be a disguised or false alarm information.

[0095] Or the security platform alarm is that there is a process risk, but according to the feedback of the asset information, the corresponding device is a printer, and the printer does not have a process risk. Therefore, the alarm information does not match the asset type, and it can be determined that the alarm information is wrong. Through the above two methods, users can be assisted in filtering and removing errors in the used security platform alarm information.

Claims

1. A method for automatic discovery and management of oilfield information assets, characterized in that: The following steps are involved: Obtain characteristic information, access the target traffic data packets in the network through mirrored traffic, traverse the target data packets, and search for characteristic information; Obtain asset information and actively detect the device's open ports, scan the device's port services, system devices, and business applications, obtain asset fingerprint information, and match the device fingerprint characteristics with the fingerprint database to obtain device type information; Identify asset categories. Based on the asset information and feature information obtained through active detection and traffic restoration, determine the protocol type of the target data packet's application layer according to the preset feature information and protocol type correspondence table. Determine the asset category based on the feature library information base and the protocol used. Label various asset attributes and components with asset identification tags; Asset tagging: For unidentified asset categories discovered through active detection and traffic restoration scanning, the corresponding information of the unidentified assets is entered according to the asset identification tags. Security monitoring: Based on the identified asset information, the system conducts vulnerability detection on the assets, detecting vulnerability risks, configuration risks, weak password risks, and Web plaintext transmission risks in the assets, providing reference for management personnel to make decisions; Asset management feeds asset information back to the security platform. By comparing the discovered asset information with the alarm information in the security platform, alarm information about non-assets and alarm information that does not match the asset category is removed.

2. The method for automatic discovery and management of oilfield information assets according to claim 1, characterized in that: The characteristic information includes asset IP, host name, asset ownership, branch, identification method, operating system, open services and ports, and asset type.

3. The method for automatic discovery and management of oilfield information assets according to claim 1, characterized in that: The asset identification tag includes asset name, open port, operating system, MAC address, manufacturer name and firmware version.

4. The method for automatic discovery and management of oilfield information assets according to claim 1, characterized in that: During active detection, if the industrial equipment and the scanning equipment belong to the same network, assets are discovered by sending ARP broadcast packets. The frequency of broadcast packets and the scanning period should be controlled to control the number and frequency of broadcast packets. This will reduce the frequency of network interruptions and prevent downtime for industrial control equipment with limited network data packet processing capabilities within the industrial network. If industrial equipment and scanning devices need to communicate through routing, discover assets by sending ICMP packets, obtain the IP / MAC forwarding table of the corresponding switch through SNMP to obtain asset details, and control the packet sending frequency, size, and scanning cycle to control the number and length of scanned data packets. Only respond to network data packets of a specific size for security devices, and adjust the scan data length to meet the requirements of the security device to allow it to respond.

5. The method for automatic discovery and management of oilfield information assets according to claim 1, characterized in that: It also continuously monitors the access events of devices in the network through traffic analysis, subnet broadcast monitoring, network facility linkage, and DHCP linkage. After discovering new device access events, it obtains device information and adds asset identification tags.

6. The method for automatic discovery and management of oilfield information assets according to claim 1, characterized in that: The scanning of device port services, system devices and business applications specifically includes, for port services, performing host survival detection, discovering surviving hosts, and performing port open detection on surviving hosts; For system devices, the device type and database are identified through the TCP / IP protocol stack. The device manufacturer is identified through regular matching of banner information, return body information, and operating system type. Fingerprint recognition technology is used for detection to identify the operating system type and version. For business applications, fingerprint detection is used to identify WEB service languages, WEB containers, WEB front-end frameworks, WEB applications, and development frameworks.

7. The oilfield information asset automatic discovery and management system according to any one of claims 1 to 6, characterized in that: include, The traffic restoration module obtains the target traffic data packets in the network through mirrored traffic access, traverses the target data packets, searches for feature information, and determines the protocol type of the target data packet's application layer based on the preset feature information and protocol type correspondence table. The asset category is determined based on the feature library information base and the protocol used. The active detection module actively detects the open ports of the device, scans the device port services, system devices and business applications, obtains asset fingerprint information, and matches the device fingerprint characteristics with the fingerprint database to obtain device type information; The asset tagging module adds asset identification tags to various attribute information and components of assets based on asset information and feature information obtained through active detection and traffic restoration; The security monitoring module performs vulnerability detection on assets based on identified asset information, detecting vulnerability risks, configuration risks, weak password risks, and Web plaintext transmission risks in assets; The asset management module classifies assets according to asset identification tags, divides asset scenarios according to IP segments and devices, categorizes and counts assets, and uploads risks detected by the security monitoring module to the host computer for management personnel's reference. It also feeds back asset information to the security platform. By comparing the discovered asset information with the alarm information in the security platform, it removes alarm information related to non-assets and alarm information that does not match the asset category.

Citation Information

Cited By

  • Novel data outbound abnormal behavior analysis system and method

    CN121486039A

  • Valve I / O state monitoring terminal

    CN121505801A

  • Dynamic checking method for private network equipment based on ARP (Address Resolution Protocol) table and network fingerprint scanning

    CN121509177A