Asset information identification method and computing device

The unified identification of network logs through the matching rules and identification models corresponding to the target type is solved, and the problem of insufficient diversity and comprehensive asset identification in the existing technology is achieved, diversified and comprehensive asset information identification is improved, and the recognition efficiency and accuracy are improved.

CN120474734APending Publication Date: 2025-08-12HENAN QINWEI DIGITAL TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510400631.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

In the prior art, targeted identification tools are needed for different types of network assets, resulting in insufficient diversity and comprehensive asset identification, and each identification tool can only effectively obtain specific types of asset information.

Method used

The network log is uniformly identified through the matching rules corresponding to the target type, and the sub-model and data model in the identification model are used to match the network logs in a rule to identify the asset information of multiple types of network assets.

Benefits of technology

It realizes diversified and comprehensive identification of asset information, reduces the need to adopt targeted tools for different types of assets, and improves identification efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474734A_ABST
    Figure CN120474734A_ABST
Patent Text Reader

Abstract

The invention discloses an asset information identification method and computing equipment, and relates to the technical field of computers. The asset information identification method comprises the following steps: acquiring a weblog of a target network system; the target network system includes a network asset. And performing rule matching on the weblog by using a matching rule corresponding to the target type, and identifying asset information of network assets of the target type in the target network system. Wherein the target types are multiple types. The matching rule corresponding to the target type is used for identifying features of the asset information of the target type. Targeted recognition tools do not need to be adopted for different assets, and diversification and comprehensiveness of asset information recognition are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to an asset information identification method and computing device. Background Art

[0002] In the digital age, cybersecurity threats are ever-present and increasingly complex and subtle. This requires strengthening the security capabilities of network assets. Asset analysis, as a key component, is of paramount importance. Asset identification is the foundation of asset analysis.

[0003] Currently, targeted identification tools are required for each type of network asset (such as network devices, domain names, APIs, IP addresses, or network services). Each type of network asset requires its own identification tool to identify the asset information for that type of network asset. However, different types of network assets require specific identification tools, and each identification tool is often limited in its ability to effectively capture information about only specific types of assets. This results in a lack of diversity and comprehensiveness in asset identification. Summary of the Invention

[0004] The embodiments of the present application provide an asset information identification method and computing device, thereby achieving diversified and comprehensive asset information identification.

[0005] In a first aspect, an embodiment of the present application provides an asset information identification method, which includes: obtaining a network log of a target network system, wherein the target network system includes network assets; performing rule matching on the network log using matching rules corresponding to target types to identify asset information of network assets of a target type in the target network system; the target type is the type of network assets, and there are multiple target types, each of which has a corresponding matching rule.

[0006] In this way, since the target type of network assets covers various types of network assets (such as network equipment, domain names, APIs, IPs or network services, etc.), the data is more comprehensive. In addition, the network logs are fully identified through the matching rules corresponding to the target type to obtain the asset information of the target type. In this way, there is no need to use targeted identification tools for different types of assets, thereby realizing the diversification and comprehensiveness of asset information identification.

[0007] In one possible implementation, matching network logs using matching rules corresponding to target types to identify asset information of network assets of a target type in a target network system includes: inputting the network logs into a recognition model, and obtaining the target type asset information output by the recognition model. The recognition model is configured to identify asset information of multiple types of network assets from the network logs using multiple matching rules corresponding to multiple types.

[0008] In this way, by using multiple matching rules through the identification model, the network logs corresponding to the multiple types of network assets are matched according to the rules, and the asset information of the target type of network assets is identified, thereby further realizing the diversification and comprehensiveness of asset information identification.

[0009] In a possible implementation, the identification model includes a sub-model corresponding to each type, and the sub-model corresponding to each type is used to identify asset information of the corresponding type of network assets from the network log using a corresponding matching rule.

[0010] In this way, since each sub-model can use the corresponding matching rules to identify network logs, manual intervention can be reduced, thereby more accurately extracting asset information of the corresponding type of network assets, thereby improving the efficiency and accuracy of network asset identification.

[0011] In one possible implementation, rule matching is performed on network logs using matching rules corresponding to a target type. The method further includes: obtaining an identification task, wherein the identification task indicates that the type of the network asset to be identified is the target type. Rule matching on the network logs using matching rules corresponding to the target type includes: inputting the network logs into a target sub-model within the identification model, and obtaining asset information of the target type network asset output by the target sub-model; the target sub-model corresponds to the target type.

[0012] Thus, before inputting the network log into the recognition model, the type of network asset to be identified—that is, the target type—is considered, specifically, the type of asset information to be identified in the network log. After determining the target type, the network log is then input into the target sub-model corresponding to the target type, allowing the target sub-model to identify the asset information of the target type of network assets from the network log using the corresponding matching rules. In this way, through the use of the specific target sub-model, the asset information of the target type of network assets can be identified from the network log, achieving accurate and efficient identification of the asset information of the target type of network assets.

[0013] In a possible implementation, the sub-model included in the identification model is a data model DM established according to the characteristics of the corresponding type of asset information.

[0014] In this way, the computing power of the data model is leveraged to parse the input network logs in real time, obtaining the corresponding feature information of the network logs. Based on the characteristics of the corresponding asset information, the target type of asset information can be identified from the network logs. For example, information with the same characteristics as the target type of asset information can be filtered out from the feature information to obtain the target type of asset information, thereby improving the accuracy of asset information identification. During this process, the data model may involve computational operations such as data type conversion, timestamp processing, feature combination (such as generating new features), feature selection, and dimensionality reduction (such as reducing the number of features).

[0015] In a possible implementation manner, the method further includes: assigning a category label indicating the target type to the asset information of the network asset of the target type.

[0016] In this way, the asset information of each target type of network assets can be divided into a category of asset information. By classifying the asset information of the identified target type of network assets, priority sorting and targeted management can be facilitated, such as taking effective security measures and managing risks for each category of asset information.

[0017] In one possible implementation, the method further includes preprocessing the asset information of the target type of network assets to obtain target asset information, wherein the preprocessing includes deduplication and / or cleaning. In this way, the target asset information is made more accurate, complete, and highly usable.

[0018] In a possible implementation, the method further includes: storing asset information of target-type network assets in an asset database according to the target type, thereby improving the availability and effectiveness of the information.

[0019] In a possible implementation, the multiple types include: network devices, domain names, application programming interfaces (APIs), Internet protocol addresses (IPs), and multiple network services.

[0020] In this way, multiple types of network logs can be covered, and the data is more comprehensive, thereby making asset identification more comprehensive.

[0021] In one possible implementation, obtaining a network log of a target network system includes: obtaining a raw network log of the target network system; and converting the raw network log using a data template corresponding to the target type, based on the type of the network asset to be identified as a target type, to obtain the network log. Different types correspond to different data templates, and the data templates are used to convert raw network logs of different formats into a unified format and to convert different field names into a unified name.

[0022] In this way, the original network logs are normalized through the data template corresponding to the target type, so that the network logs of the target network system have the same format and the same naming standard, which makes it easier to identify asset information.

[0023] In a possible implementation, obtaining the original network log of the target network system includes: collecting the original network log on the target object through a probe on the target object in the target network system, where the target object represents the object for which the original network log is to be obtained.

[0024] In a second aspect, embodiments of the present application provide an asset information identification device, comprising: an acquisition module for acquiring network logs of a target network system; the target network system comprising network assets; and an identification module for matching the network logs using matching rules corresponding to target types to identify asset information of target-type network assets in the target network system. The target types may be multiple; the matching rules corresponding to the target types are used to identify characteristics of the asset information of the target types.

[0025] In a third aspect, an embodiment of the present application provides a computing device comprising a processor and a memory; the processor is configured to execute instructions stored in the memory so that the computing device executes the method described above.

[0026] In a fourth aspect, an embodiment of the present application provides a storage medium comprising computer program instructions. When the computer program instructions are executed by a computer, the computer executes the method as described above.

[0027] In a fifth aspect, an embodiment of the present application provides a computer program product, which, when executed on a processor, enables the processor to execute the method described above.

[0028] Among them, the technical effects brought about by any implementation method in the second to fifth aspects can refer to the technical effects brought about by different implementation methods in the first aspect, and will not be repeated here.

[0029] Based on the implementation methods provided in the above aspects, this application can also be further combined to provide more implementation methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 A schematic diagram of an asset information identification system provided in an embodiment of the present application;

[0031] Figure 2 A schematic diagram of a recognition model provided in an embodiment of the present application;

[0032] Figure 3 A schematic diagram of a computing device provided in an embodiment of the present application;

[0033] Figure 4 A flowchart of an asset information identification method provided in an embodiment of the present application;

[0034] Figure 5 A flowchart of another asset information identification method provided in an embodiment of the present application;

[0035] Figure 6 A schematic diagram of the structure of an asset information identification device provided in an embodiment of the present application;

[0036] Figure 7 A schematic diagram of the structure of another computing device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0037] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0038] In the description of this application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship, for example, A / B can represent A or B; "and / or" in this application is merely a description of the association relationship of associated objects, indicating that three relationships may exist, for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural.

[0039] Furthermore, in the description of this application, unless otherwise specified, "plurality" means two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0040] In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design schemes. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.

[0041] The following is an illustrative introduction to the application scenarios of the embodiments of the present application.

[0042] In the digital age, cybersecurity threats are ever-present and increasingly complex and subtle. This requires strengthening the security capabilities of network assets. Asset analysis, as a key component, is of paramount importance. Asset identification is the foundation of asset analysis.

[0043] Network assets can refer to various devices used in computer (or communication) networks, including network equipment (such as servers, routers, switches, firewalls, etc.). Network assets also include intangible assets created and accumulated in the network environment, such as domain names, application programming interfaces (APIs), Internet protocol addresses (IPs), network services, etc.

[0044] Currently, targeted identification tools are required for each type of network asset (such as network devices, domain names, APIs, IP addresses, or network services). Each type of network asset is identified by a corresponding identification tool, which identifies the asset information for that type of network asset. For example, for network devices, the corresponding identification tool scans the device's ports. Specifically, it sends a probe packet to the device and then analyzes the information contained in the response packet returned by the device, such as the IP address, open ports, running services, and device fingerprints, to identify the asset information for that type of network device.

[0045] However, different types of network assets require targeted identification tools, and each identification tool can often only effectively obtain specific types of asset information. For example, the identification tools corresponding to the above-mentioned network device types only identify information such as IP addresses, open ports, running services, device fingerprints, etc., and have certain limitations on domain names related to network devices, API request parameters, etc., which leads to insufficient diversity and comprehensiveness in asset identification.

[0046] In light of this, embodiments of the present application provide an asset information identification method that uniformly identifies the network logs of a target network system using matching rules corresponding to the target type to obtain asset information of the target type. This method, because the target type of network assets encompasses a wide range of network assets, can identify asset information for multiple types of network assets from network logs. This provides more comprehensive data and eliminates the need for specialized identification tools for different types of network assets, achieving diversified and comprehensive asset information identification.

[0047] In some embodiments, in the method provided by the embodiments of the present application, first, the network log of the target network system is obtained; the target network system includes network assets. Then, the network log is matched with the matching rules corresponding to the target type to identify the asset information of the target type network assets in the target network system (hereinafter referred to as the asset information of the target type). Among them, the target type is of multiple types, and the matching rules corresponding to the target type are used to identify the characteristics of the asset information of the target type. Since the network assets of the target type include multiple types of network assets (such as network devices, domain names, APIs, IPs or network services, etc.), the data is more comprehensive, and the network assets in the target network system are uniformly identified through the matching rules corresponding to the target type to obtain the asset information of the target type. In this way, there is no need to use targeted identification tools for different types of assets, thereby realizing the diversification and comprehensiveness of asset information identification.

[0048] The following is an exemplary introduction to the system architecture of the embodiment of the present application.

[0049] like Figure 1 As shown, an embodiment of the present application provides an asset information identification system, which includes:

[0050] The acquisition module can be used to obtain the network logs of the target network system.

[0051] The identification module can be used to perform rule matching on the network log using the matching rules corresponding to the target type, and identify the asset information of the network assets of the target type in the target network system.

[0052] The target network system includes network assets. The target type is the type of network asset, which can be of multiple types. The matching rule corresponding to the target type is used to identify asset information of the target type. Each target type has a corresponding matching rule.

[0053] Exemplarily, the multiple types include multiple types of network devices, domain names, APIs, IPs, and network services. Specifically, the network devices include servers and / or other network devices (such as routers, switches, or firewalls, etc.).

[0054] In some embodiments, the acquisition module includes a data template management unit, in which one or more data templates are stored.

[0055] In one implementation, the acquiring module acquires the network log of the target network system including: acquiring the original network log of the target network system, converting the original network log using a data template corresponding to the target type based on the type of the network asset to be identified as the target type, and acquiring the network log.

[0056] Different types correspond to different data templates. The data templates are used to convert original network logs of different formats into a unified format and to convert different field names into the same name.

[0057] In one implementation, the acquisition module acquires raw network logs from the target network system from probes deployed on target objects. The target object represents the object for which the raw network logs are to be acquired, such as one or more of an operating system, a network device, an IDS, or a database operating system. The probes are used to collect the raw network logs from the target objects. Specifically, the raw network logs are first collected by the probes on the target objects for each target object, and then acquired by the acquisition module from the probes on each target object.

[0058] In some embodiments, the asset information identification system may further include an assignment module for assigning a category label indicating the target type to the asset information of the target type.

[0059] In some embodiments, the asset information identification system further includes an identification model, which is used to identify various types of asset information from network logs using various matching rules corresponding to various types.

[0060] In one implementation, the recognition model includes a sub-model corresponding to each type, and the sub-model corresponding to each type is used to identify asset information of the corresponding type from the network log using a corresponding matching rule.

[0061] Optionally, the sub-model included in the identification model is a data model DM established according to the characteristics of the corresponding type of asset information.

[0062] For example, the characteristics of the asset information are pre-defined and pre-stored in the memory of the sub-model corresponding to the corresponding type. In this way, the characteristics of the asset information can be relatively important information for the corresponding type, so that the asset information identified based on the characteristics of the asset information is more important, thereby improving the effectiveness of the asset information.

[0063] For example, pre-defined asset information features include the following: Network device asset information features may specifically include server asset information features and / or other network device asset information features (e.g., firewalls). Server asset information features may include IP, port, operating system, and other features, such as dip, port, http, ssh, server, and CPU. Asset information features of other network device types (e.g., firewalls) may include IP, device serial number, hard disk, and network card, such as dip, device_serial_number, hard_disk, and network_card. Domain asset information features may include domain name, port, protocol, and IP, such as host, port, http_host, protocol, http_domain, dport, dip, app_protocol, and data_distime. API asset information features may include request method, URI address, URL address, server IP, server domain name, and request parameters, such as method, uri, dst_ip, host, content_type, is_ipv6, and device_sn. The characteristics of IP-type asset information may include IP and port numbers, such as dip, port, etc. The characteristics of network service-type asset information may include network service-related processes, such as host, port, protocol, and app_protocol.

[0064] Furthermore, if the recognition model employs pre-defined asset information features, the first consideration is the type of network asset to be identified, also known as the target type. Specifically, the type of asset information to be identified in the network log is considered. After determining the target type, the network log is then fed into the target sub-model corresponding to the target type. The target sub-model then uses the corresponding matching rules to identify the asset information corresponding to the target type from the network log.

[0065] Furthermore, when the features of the network assets to be identified are consistent with the features of the asset information pre-stored in the target sub-model, the asset information corresponding to the features is extracted from the assets to be identified, thereby identifying the asset information corresponding to the target type from the network log.

[0066] Exemplarily, the sub-model is also used to detect updates to the features of asset information corresponding to the corresponding type, and when the features of the asset information corresponding to the corresponding type are updated, reload the updated features of the asset information. In this way, when the features of the asset information are updated, the features of the asset information in the sub-model's memory can be updated in real time, so that the corresponding asset information features deployed by the sub-model are up to date, thereby improving the accuracy of asset information recognition.

[0067] For example, Figure 2 As shown, a schematic diagram of an identification model is provided. The identification model includes one or more of a first sub-model, a second sub-model, a third sub-model, a fourth sub-model, and a fifth sub-model. Among them, the first sub-model is a sub-model corresponding to the network device type, which is a data model established according to the characteristics of the asset information of the network device type, that is, it stores the characteristics of the asset information of the network device type. The second sub-model is a sub-model corresponding to the domain name type, which is a data model established according to the characteristics of the asset information of the domain name type, that is, it stores the characteristics of the asset information of the domain name type. The third sub-model is a sub-model corresponding to the API type, which is a data model established according to the characteristics of the asset information of the API type, that is, it stores the characteristics of the asset information of the API type. The fourth sub-model is a sub-model corresponding to the IP type, which is a data model established according to the characteristics of the asset information of the IP type, that is, it stores the characteristics of the asset information of the IP type. The fifth sub-model is a sub-model corresponding to the network service type, which is a data model established according to the characteristics of the asset information of the network service type, that is, it stores the characteristics of the asset information of the network service type.

[0068] In some embodiments, the asset information identification system can be deployed on the same computing device or on different computing devices.

[0069] In the embodiments of the present application, the computing device may specifically be a network device. The network device may include a server, etc. The server may be a single physical server, or two or more physical servers sharing different responsibilities that collaborate to implement the various server functions. When the computing device comprises multiple servers, the scheduling system is a server cluster with high availability.

[0070] Illustratively, the server may be a blade server, a high-density server, a rack server, a tower server, or the like.

[0071] The hardware of the computing device includes a processor, a basic input / output system (BIOS) chip, an out-of-band controller, and memory, while the software mainly includes the BIOS, an out-of-band management module, and an operating system (OS). Figure 3 shown.

[0072] The processor may include a central processing unit (CPU), which includes one or more CPU cores. The CPU's data processing operations are all performed by the CPU cores. The more CPU cores a CPU includes, the faster the data processing speed. In an embodiment of the present application, the processor in the computing device acts as a scheduler to execute the above-mentioned workflow scheduling method.

[0073] The BIOS chip is a chip installed on the motherboard that initializes and detects various hardware components during the computer's startup process. The BIOS chip includes a flash memory area.

[0074] The out-of-band management module is located in the out-of-band controller, and the operating system is located in the processor.

[0075] An out-of-band management module can be a management unit for non-business modules. For example, an out-of-band management module can remotely maintain and manage a computing device through a dedicated data channel. This out-of-band management module is completely independent of the computing device's operating system and can communicate with the BIOS and operating system through the computing device's out-of-band management interface.

[0076] Exemplarily, the out-of-band management module may include a management unit for the computing device's operating status, a management system in a management chip, a baseboard management controller (BMC) for the computing device, a system management module (SMM), etc. It should be noted that the embodiments of the present application do not limit the specific form of the out-of-band management module, and the above description is merely an example.

[0077] The operating system (OS) is a computer program that manages and controls the hardware and software resources of a computing device. Any other software must be supported by the OS to run. After a computing device is powered on, the BIOS first performs a series of operations, including self-tests and initialization, and then boots the OS, allowing the user to use the computing device normally.

[0078] BIOS is a set of programs embedded in the BIOS chip on the motherboard of a computing device. The main function of BIOS is to provide the lowest-level and most direct hardware settings and control for the computing device.

[0079] Memory, also known as internal storage or main memory, is installed in memory slots on the motherboard of a computing device.

[0080] It should be noted that the embodiments of the present application do not limit the device form of the computing device, and the above is only an exemplary description.

[0081] It should be noted that the system architecture and application scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new application scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0082] For ease of understanding, the asset information identification method provided in the embodiment of the present application is exemplarily introduced below in combination with the above system architecture and accompanying drawings.

[0083] like Figure 4 As shown, an embodiment of the present application provides an asset information identification method, which can be executed by a computing device deployed in an asset information identification system. The method includes:

[0084] S401, obtaining the network log of the target network system.

[0085] The target network system includes network assets.

[0086] For example, the target network system may be a computer (or communication) network system for which asset information needs to be identified.

[0087] Exemplarily, the target network system includes multiple types of network assets, including multiple types of network devices, domain names, APIs, IPs, and network services.

[0088] In one implementation, network logs are used to record important information such as various operations, events, and anomalies within the target network system. Network logs can specifically include one or more of operating system logs, network device logs (including firewall logs), intrusion detection system (IDS) logs, and database logs. Specifically, operating system logs originate from the operating system. Network device logs originate from network devices. IDS logs originate from the IDS. Database logs originate from the database management system. By integrating logs from multiple sources, data becomes more comprehensive.

[0089] Exemplarily, operating system logs specifically include system error and alarm logs, first password alarm logs, and first server alarm logs. The system error and alarm logs record alarms for system hardware failures, software errors, insufficient system resources, and other warnings, such as memory overflows, excessive CPU usage, and board failures. The first password alarm log records password-related operations during user login, such as account lockouts triggered by multiple incorrect password attempts. The first server alarm log records alarms for server hardware failures, insufficient system resources, and other warnings.

[0090] For example, network device logs specifically include firewall logs, second server alarm logs, first full-flow alarm logs, and first API alarm logs. The second server alarm log records the connection status between the server and external devices, such as network interruptions and packet loss. The first full-flow alarm log records anomalies in network traffic passing through network devices, such as sudden surges in traffic, abnormal traffic sources or directions, etc. The first API alarm log records anomalies in API access at the network level, such as a large number of abnormal requests to the API from a specific IP address, causing network congestion.

[0091] Exemplarily, firewall logs specifically include a second password warning log, a second full-flow warning log, and a second API warning log. The second password warning log records abnormal login behaviors such as password guessing attempts by external parties through the firewall, such as frequent failed login attempts from specific IP addresses. The second full-flow warning log records traffic that violates security policies or abnormal traffic discovered by the firewall when monitoring network traffic. The second API warning log records API access information that violates the security policies set by the firewall, such as access from unauthorized IP addresses.

[0092] For example, the IDS log may specifically include a third password alarm log, a third full-flow alarm log, and a third API alarm log. The third password alarm log records abnormal behaviors such as brute force cracking of system passwords detected by the intrusion detection system. The third full-flow alarm log records intrusions or abnormal activities in the entire network traffic detected by the intrusion detection system. The third API alarm log records attacks against APIs detected by the intrusion detection system, such as malicious parameter tampering.

[0093] Exemplarily, the database log includes a database alarm log, which records abnormalities of the database management system itself.

[0094] In some embodiments, obtaining the network log of the target network system includes obtaining the original network log of the target network system, converting the original network log using a data template corresponding to the target type based on the type of the network asset to be identified as the target type, and obtaining the network log.

[0095] The data template is used to convert original network logs of different formats into the same format, and different field names into the same name.

[0096] In the embodiment of the present application, the original network log is normalized by using a data template corresponding to the target type, so that the network log of the target network system has the same format and the same naming standard, which is more convenient for identifying asset information.

[0097] In one implementation, the network log is in JSON format. It is understood that the original network log format can be one or more of text, XML, JSON, and syslog formats. Using the data template, the original network log format is converted to JSON. This facilitates parsing and processing of the network log.

[0098] For example, a data template converts different field names into a single name, meaning that different fields of the same object are named uniformly. For example, server aliases (such as "host" and "server") are converted to a single "server." This standardized naming improves the accuracy and efficiency of asset information identification.

[0099] Exemplarily, the original network log includes one or more of an original operating system log, an original network device log, an original IDS log, and an original database log. It is understood that the original operating system log, the original network device log, the original IDS log, and the original database log are respectively the original operating system log, network device log, IDS log, and database log that have not been processed by the data template. In other words, the original operating system log, the original network device log, the original IDS log, and the original database log are consistent with the information recorded in the operating system log, the network device log, the IDS log, and the database log, respectively.

[0100] Exemplarily, obtaining raw network logs from a target network system includes obtaining raw network logs from a probe deployed on a target object. The target object represents the object for which raw network logs are to be obtained, such as one or more of an operating system, a network device, an IDS, and a database operating system. The probe is configured to collect raw network logs from the target object.

[0101] In one implementation, the target type is user-specified. That is, regardless of the source of the target network system's original network logs or the specific information they contain, the original network logs are normalized using the corresponding data template based on the user-specified target type, thus better meeting the user's actual needs.

[0102] In another implementation, the target type is determined based on the original network log. Specifically, the target type can be determined based on the source of the original network log (such as an operating system, network equipment, IDS, or database operating system, etc.). It is understandable that the focus of original network logs from different sources may be different. For example, the original network log derived from the operating system may pay more attention to the network equipment type, IP type, API type, etc., while the original network log derived from the network equipment may pay more attention to the API type, IP type, API type, network equipment type, network service type, etc. Therefore, the target type determined based on the original network log, thereby determining the corresponding data template, is more adapted to and consistent with the content of the original network log.

[0103] For example, if the original network log includes an original operating system log, the target type may be one or more of a network device type, an IP type, an API type, a domain name type, and a network service type, wherein the network device type may specifically be a server type.

[0104] For example, if the original network log includes an original network device log, the target type may be one or more of an API type, an IP type, a domain name type, a network device type, and a network service type. Specifically, the network device type may be other network device types.

[0105] Exemplarily, if the original network log includes an original IDS log, the target type may be one or more of an API type, an IP type, a network device type, a domain name type, and a network service type.

[0106] Exemplarily, if the original network log includes an original database log, the target type may be one or more of a network device type, a domain name type, an API type, an IP type, and a network service type.

[0107] It should be noted that if the original network log includes multiple logs, the target type may be a combination of types corresponding to the logs.

[0108] In one implementation, different types correspond to different data templates. In this way, since each type focuses on different points, using the corresponding data template can accurately and efficiently organize the corresponding type of data information to meet the diverse needs of different scenarios.

[0109] Exemplarily, the data template corresponding to the server type includes IP, port, operating system, etc. The data template corresponding to other network device types (such as firewalls) includes IP, device serial number, hard disk, network card, etc. The data template corresponding to the domain name type includes domain name-related attribute information, such as domain name, port, protocol, IP, etc. The data template corresponding to the API type includes API-related request methods, uniform resource identifier (URI) address, uniform resource locator (URL) address, server IP, server domain name, request parameters, etc. The data template corresponding to the IP type includes IP and port number, etc. The data template corresponding to the network service type includes network service-related processes, etc. That is to say, through the data template, the original network logs in different formats are uniformly converted into JSON format, and different names are unified into the same name. In addition, the network assets of server type include IP, port, operating system and other information; the network assets of other network device types include IP, device serial number, hard disk, network card and other information; the network assets of API type include API-related request methods, URI address, URL address, server IP, server domain name, request parameters and other information; the network assets of IP type include IP and port number and other information; the network assets of network service type include network service-related processes and other information.

[0110] In the embodiment of the present application, since different data templates include different attributes (such as IP, port, etc.), it is possible to focus on the key points corresponding to different types and to organize the corresponding types of data information more accurately and efficiently.

[0111] S402 : performing rule matching on the network log using the matching rule corresponding to the target type, and identifying asset information of the network assets of the target type in the target network system.

[0112] There are multiple target types. The matching rules corresponding to the target types are used to identify asset information of the target types. The target type is the type of network asset, and each target type has a corresponding matching rule.

[0113] For example, the asset information characteristics of a network device type may specifically include the asset information characteristics of a server type and / or the asset information characteristics of other network device types (such as firewalls). The asset information characteristics of a server type may include IP, port, operating system, etc., such as dip, port, http, ssh, server, CPU, etc. The asset information characteristics of other network device types (such as firewalls) may include IP, device serial number, hard disk, network card, etc., such as dip, device_serial_number, hard_disk, network_card, etc.

[0114] Exemplarily, the characteristics of domain name type asset information may include domain name, port, protocol, IP, etc., such as host, port, http_host, protocol, http_domain, dport, dip, app_protocol, data_distime, etc.

[0115] For example, the characteristics of API-type asset information may include request method, URI address, URL address, server IP, server domain name, request parameters, etc., such as method, uri, dst_ip, host, content_type, is_ipv6, device_sn, etc.

[0116] For example, the characteristics of IP-type asset information may include IP and port number, such as dip, port, etc.

[0117] Exemplarily, the characteristics of the asset information of the network service type may include processes related to the network service, such as host, port, protocol, and app_protocol.

[0118] In some embodiments, the network log is matched with the matching rules corresponding to the target type to identify the asset information of the target type network assets in the target network system, including: inputting the network log into the recognition model to obtain the asset information of the target type output by the recognition model.

[0119] The recognition model is used to identify various types of asset information from network logs using various matching rules corresponding to various types.

[0120] In the embodiment of the present application, the recognition model utilizes multiple matching rules to match the network logs corresponding to multiple types of network assets and identify the asset information of the target type, thereby further achieving diversified and comprehensive asset information identification.

[0121] In one implementation, the sub-model included in the recognition model is a data model DM established based on the characteristics of the corresponding type of asset information. In this way, the computing power of the data model is utilized to parse the input network log in real time, obtain the corresponding characteristic information of the network log, and then identify the asset information of the target type from the network log based on the characteristics of the corresponding type of asset information. For example, information with the same characteristics as the target type of asset information is filtered out from the characteristic information, thereby obtaining the target type of asset information and improving the accuracy of asset information recognition. During this process, the data model may involve computational operations such as data type conversion, timestamp processing, feature combination (such as generating new features), feature selection, and dimensionality reduction (such as reducing the number of features).

[0122] In one implementation, the identification model includes a sub-model corresponding to each type. Each sub-model is used to identify asset information of the corresponding type from network logs using the corresponding matching rules. This reduces manual intervention, allowing for more accurate extraction of asset information of the corresponding type and improving the efficiency and accuracy of network asset identification.

[0123] For example, sub-models corresponding to different types (e.g., the first sub-model, the second sub-model, the third sub-model, the fourth sub-model, and the fifth sub-model) deploy the characteristics of the corresponding types of asset information. This allows for accurate identification of corresponding network asset information based on the characteristics of each type of asset information, improving the pertinence and effectiveness of asset information identification.

[0124] In another implementation, the method further includes obtaining a recognition task by using matching rules corresponding to the target type to match the network log. Using the matching rules corresponding to the target type to match the network log includes inputting the network log into a target sub-model within the recognition model and obtaining asset information of the target type output by the target sub-model.

[0125] The identification task indicates that the type of the network asset to be identified is a target type, and the target sub-model corresponds to the target type.

[0126] In this embodiment of the present application, before inputting the network log into the recognition model, the type of network asset to be identified, namely the target type, is considered, specifically, the type of asset information to be identified in the network log. After determining the target type, the network log is then input into the target sub-model corresponding to the target type, so that the target sub-model uses the corresponding matching rules to identify the asset information corresponding to the target type from the network log. In this way, through the specific target sub-model, the asset information corresponding to the target type is identified from the network log, achieving accurate and efficient identification of asset information of the target type.

[0127] In one implementation, obtaining the identification task includes determining the identification task corresponding to the target type based on a preset correspondence. This allows for precise identification of the target type using the preset correspondence, improving identification efficiency and accuracy. Furthermore, the determined identification task better meets user or actual needs, resulting in more accurate and effective identified asset information.

[0128] Exemplarily, the preset correspondence includes: if the target type is a network device type, the identification task corresponding to the target type is a first identification task. If the target type is a domain name type, the identification task corresponding to the target type is a second identification task. If the target type is an API type, the identification task corresponding to the target type is a third identification task. If the target type is an IP type, the identification task corresponding to the target type is a fourth identification task. If the target type is a network service type, the identification task corresponding to the target type is a fifth identification task.

[0129] The first recognition task is to use the first sub-model to identify network device asset information from network logs. The second recognition task is to use the second sub-model to identify domain name asset information from network logs. The third recognition task is to use the third sub-model to identify API asset information from network logs. The fourth recognition task is to use the fourth sub-model to identify IP asset information from network logs. The fifth recognition task is to use the fifth sub-model to identify network service asset information from network logs.

[0130] In this way, by pre-setting specific corresponding relationships, corresponding identification tasks can be matched for different types of network assets to be identified, that is, target types, which can improve the accuracy and efficiency of identifying various types of asset information from network logs, thereby meeting the identification needs of different network assets.

[0131] In one implementation, the method further includes: if the features of the asset information corresponding to the corresponding type are updated, reloading the updated features of the asset information. In this way, when the features of the asset information are updated, the features of the asset information in the sub-model's memory can be updated in real time, so that the features of the corresponding asset information deployed by the sub-model are up to date, thereby improving the accuracy of asset information recognition.

[0132] In one implementation, when the features of the network asset to be identified are consistent with the features of the asset information pre-stored in the target sub-model (that is, the match is successful), the asset information corresponding to the features is extracted from the asset to be identified, so as to identify the asset information corresponding to the target type from the network log.

[0133] The following is an exemplary description of how to match network logs using matching rules corresponding to target types to identify asset information of target types from network logs. For example, part of the network log of the target network system is as follows:

[0134]

[0135]

[0136] The network log of the target network system including the above-mentioned content is input into the recognition model (specifically, the second sub-model, which stores the features of the asset information corresponding to the domain name type, such as host, port, http_host, protocol, etc.), and the asset information of the domain name type output by the second sub-model is obtained. For example, the asset information of the domain name type is as follows:

[0137] {

[0138] "host":"100.32.2.229",

[0139] "protocol":"HTTP",

[0140] "port":80,

[0141] "http_host": "www.testh.com"

[0142] }

[0143] In an embodiment of the present application, a specific implementation method for asset information identification is provided, for example, accurately and efficiently identifying domain name type asset information from the network log of the target network system.

[0144] In some embodiments, the method further includes assigning a category tag indicating the target type to the asset information of the target type. In this way, each target type of asset information can be classified into a category of asset information. By classifying the identified target type of asset information, priority sorting and targeted management can be facilitated, such as implementing effective security measures and risk management for each category of asset information.

[0145] In some embodiments, the method further includes: pre-processing the asset information of the target type to obtain target asset information.

[0146] Preprocessing includes deduplication and / or cleaning.

[0147] In the embodiment of the present application, the asset information of the identified target type is pre-processed to obtain the final target asset information. By further operating the asset information, the target asset information is made more accurate, complete and has higher usability.

[0148] Exemplarily, the above-mentioned cleaning of the target asset information may include filling missing values, deleting erroneous values, or deleting null values. It may also include converting the formats of asset information of different target types into a unified format. This facilitates the formation of target asset information that meets user requirements.

[0149] For example, when deduplicating and cleaning asset information of a target type, the target asset information can be asset information that has been assigned a target type category label, that is, classified asset information. Thus, after the identified asset information is classified and then pre-processed, the final target asset information is obtained. This target asset information can be pushed to the asset business system for easier application (such as asset management).

[0150] In some embodiments, the method further includes storing the asset information of the target type in an asset database according to the target type. In other words, the classified asset information of the target type is stored in the asset database. This facilitates the management of the information in the asset database.

[0151] For example, when the asset information of a target type is updated, the corresponding asset information of the target type in the asset database is also updated. In this way, the information in the asset database is guaranteed to be up to date, thereby improving the availability and effectiveness of the information.

[0152] In other embodiments, the method further includes storing the target asset information in an asset database according to target type. Specifically, after pre-processing the asset information by target type, the target asset information is categorized and stored in the database. This facilitates subsequent use of the target asset information, such as querying, analysis, and management.

[0153] like Figure 5As shown, an embodiment of the present application provides another asset information identification method. The method comprises: first, converting the original network log (of the target network system) into a network log. Secondly, inputting the network log into the recognition model to obtain the target type of asset information (one or more of the corresponding network device type asset information, domain name type asset information, API type asset information, IP type asset information, and network service type asset information) output and classified by the recognition model (specifically one or more of the first sub-model, the second sub-model, the third sub-model, the fourth sub-model, and the fifth sub-model). Then, the target type of asset information is pre-processed to obtain the target asset information. Finally, the target asset information is stored in the asset database.

[0154] In an embodiment of the present application, network logs are derived from operating system logs, network device logs, etc., and the target asset information obtained based on this is stored in an asset database. The target asset information can subsequently be applied to a variety of scenarios, such as asset management, asset analysis (such as target asset information forming an asset map for analysis), etc. Through the application of target asset information (such as asset management or asset analysis), the interactions and dependencies between different assets in terms of business processes, functional implementation, etc. can be demonstrated. In this way, users can not only understand the sources (such as operating systems, network devices, etc.) and relationships of data assets more quickly and accurately, but also understand the subsequent flow, thereby improving the comprehensibility and trustworthiness of asset information.

[0155] like Figure 6 As shown, an embodiment of the present application provides an asset information identification device 200, comprising an acquisition module 21 and an identification module 22. Acquisition module 21 is configured to acquire network logs of a target network system. The target network system includes network assets. Identification module 22 is configured to perform rule matching on the network logs using matching rules corresponding to target types, thereby identifying asset information of network assets of a target type in the target network system. The target types may be multiple types. The matching rules corresponding to the target types are configured to identify characteristics of the asset information of the target types.

[0156] like Figure 7 As shown, an embodiment of the present application provides another computing device 500. The computing device 500 includes a processor 510 (specifically a central processing unit) and a memory 520 for storing processor-executable instructions. When the processor 510 is configured to execute the instructions, the computing device 500 implements the asset information identification method as described above.

[0157] Figure 7 The computing device 500 shown is merely an example and should not limit the functionality and scope of use of the embodiments of the present application.

[0158] Computing device 500 is implemented as a general-purpose computing device. Components of computing device 500 may include, but are not limited to, one or more processors 510, memory 520, a communication bus 540 connecting various system components (including memory 520 and processor 510), and a communication interface 530.

[0159] Communication bus 540 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor or a local bus using any of a variety of bus architectures.

[0160] The structure includes but is not limited to the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnection (PCI) bus.

[0161] The computing device 500 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the computing device, including volatile and non-volatile media, removable and non-removable media.

[0162] The memory 520 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) and / or cache memory. The computing device may further include other removable / non-removable, volatile / non-volatile computer system storage media. Figure 7Not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk"), and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a Compact Disc Read Only Memory (hereinafter referred to as: CD-ROM), a Digital Video Disc Read Only Memory (hereinafter referred to as: DVD-ROM), or other optical media) may be provided. In these cases, each drive can be connected to the communication bus 540 via one or more data medium interfaces. The memory 520 may include at least one program product having a set (e.g., at least one) of program modules that are configured to perform the functions of the various embodiments of the present application.

[0163] A program / utility having a set (at least one) of program modules may be stored in memory 520. Such program modules include, but are not limited to, an operating system, one or more application programs, other program modules, and program data, each of which, or some combination thereof, may include an implementation of a network environment. The program modules generally perform the functions and / or methods of the embodiments described herein.

[0164] The computing device 500 may also communicate with one or more external devices (e.g., keyboard, pointing device, display, etc.), one or more devices that enable a user to interact with the computing device, and / or any device that enables the computing device to communicate with one or more other computing devices (e.g., network card, modem, etc.). Such communication may be performed through the communication interface 530. Furthermore, the computing device 500 may also communicate with the network adapter ( Figure 6 The network adapter can communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via the communication bus 540. Figure 7 Not shown, other hardware and / or software modules may be used in conjunction with the computing device 500, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, disk arrays (Redundant Arrays of Independent Drives; hereinafter referred to as: RAID) systems, tape drives, and data backup storage systems.

[0165] The processor 510 executes various functional applications and data processing by running the programs stored in the memory 520, such as implementing the asset information identification method provided in the embodiment of the present application.

[0166] It is understood that the interface connection relationship between the modules illustrated in the embodiments of the present application is merely illustrative and does not constitute a structural limitation on the computing device 500. In other embodiments of the present application, the computing device 500 may also adopt a different interface connection method from the above embodiments, or a combination of multiple interface connection methods.

[0167] It is understandable that, in order to realize the above functions, the above-mentioned computing devices and the like include hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily appreciate that, in combination with the various exemplary units and algorithm steps described in the embodiments disclosed herein, the embodiments of the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the embodiments of the present application.

[0168] The embodiment of the present application can divide the functional modules of the above-mentioned computing device etc. according to the above-mentioned method example. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above-mentioned integrated module can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation.

[0169] An embodiment of the present application also provides a storage medium including computer program instructions. When the computer program instructions are executed by a computer, the computer executes the asset information identification method as described above.

[0170] An embodiment of the present application also provides a computer program product. When the computer program product runs on a processor, the processor executes the asset information identification method provided by the embodiment of the present application.

[0171] The computing device, storage medium or computer program product provided in the embodiments of the present application are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above and will not be repeated here.

[0172] Through the description of the above embodiments, those skilled in the art will clearly understand that for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0173] The functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0174] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as flash memory, mobile hard disk, read-only memory, random access memory, magnetic disk or optical disk.

[0175] The above is only a specific embodiment of the present application, but the scope of protection of this application is not limited to this. Any changes or substitutions within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A method for identifying asset information, characterized in that: include: Obtaining a network log of a target network system, wherein the target network system includes network assets; Performing rule matching on the network log using a matching rule corresponding to the target type to identify asset information of network assets of the target type in the target network system; The target type is a type of network asset. There are multiple target types, and each target type has a corresponding matching rule.

2. The method according to claim 1, characterized in that The performing rule matching on the network log using the matching rule corresponding to the target type to identify the asset information of the network assets of the target type in the target network system includes: The network log is input into the recognition model to obtain the asset information of the target type output by the recognition model; wherein the recognition model is used to use the multiple matching rules corresponding to the multiple types to identify the asset information of the multiple types of network assets from the network log.

3. The method according to claim 2, characterized in that The recognition model includes sub-models corresponding to each type; The sub-model corresponding to each type is used to identify the asset information of the corresponding type of network assets from the network log using the corresponding matching rules.

4. The method according to claim 3, characterized in that The method further comprises: performing rule matching on the network log using a matching rule corresponding to the target type; Acquire an identification task, wherein the identification task indicates that the type of the network asset to be identified is the target type; The performing rule matching on the network log using the matching rule corresponding to the target type includes: The network log is input into the target sub-model in the recognition model to obtain the asset information of the network assets of the target type output by the target sub-model; the target sub-model corresponds to the target type.

5. The method according to claim 3 or 4, characterized in that The sub-models included in the identification model are data models DM established according to the characteristics of the corresponding type of asset information.

6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: A category label indicating the target type is assigned to the asset information of the network asset of the target type.

7. The method according to any one of claims 1 to 6, characterized in that The multiple types include: network devices, domain names, application programming interfaces (APIs), Internet protocol addresses (IPs), and network services.

8. The method according to any one of claims 1 to 7, characterized in that The obtaining of the network log of the target network system includes: Obtaining original network logs of the target network system; According to the type of the network asset to be identified being the target type, the original network log is converted using a data template corresponding to the target type to obtain the network log; wherein different types correspond to different data templates, and the data template is used to uniformly convert original network logs of different formats into the same format, and uniformly convert different field names into the same name.

9. The method according to claim 8, characterized in that The obtaining of the original network log of the target network system includes: The original network log on the target object is collected by a probe on the target object in the target network system, and the target object represents the object for which the original network log is to be obtained.

10. The method according to any one of claims 1 to 9, characterized in that The method further comprises: The asset information of the target type of network assets is preprocessed to obtain target asset information, wherein the preprocessing includes deduplication and / or cleaning.

11. The method according to any one of claims 1 to 10, characterized in that The method further comprises: The asset information of the network assets of the target type is stored in the asset database according to the target type.

12. A computing device, characterized in that The computer comprises a processor and a memory; the processor is configured to execute instructions stored in the memory, so that the computing device executes the method according to any one of claims 1 to 11.