Address management method, program product, electronic equipment and storage medium

By collecting and analyzing the multi-dimensional traffic characteristics of IP addresses in the data center, judging the degree of deviation from the historical mean, and isolating risk IP addresses, the shortcomings of IP address security management in the existing technology are solved, and efficient risk management and security improvement are achieved.

CN120498876APending Publication Date: 2025-08-15ZHENGZHOU YUNHAI INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510872914.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the management of IP addresses in data centers, the prior art ignores the security behavior and risk management of IP during use, making it difficult to effectively realize the risk management of IP addresses and improve security.

Method used

By collecting traffic data from the target device, performing multi-dimensional traffic characteristics analysis of Internet protocol addresses, determining the degree of deviation from the historical mean, isolating the IP address when it exceeds the security deviation, and updating the historical mean of traffic characteristics.

Benefits of technology

Accurate isolation of IP addresses with security risks is achieved, the security and reliability of IP addresses are improved, and the misjudgment rate is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498876A_ABST
    Figure CN120498876A_ABST
Patent Text Reader

Abstract

The invention discloses an address management method, a program product, electronic equipment and a storage medium, and relates to the technical field of computers, and the method comprises the steps: collecting traffic data of target equipment; based on the traffic data, performing feature analysis on each Internet protocol address in the traffic data to obtain respective multi-dimensional traffic features of each Internet protocol address; for any internet protocol address in the flow data, judging whether the deviation degree between the multi-dimensional flow characteristic of the internet protocol address and the historical mean value of the flow characteristic of each dimension of the internet protocol address exceeds a preset security deviation degree or not; if yes, isolating the internet protocol address; and if not, updating the historical mean value of the traffic characteristics of each dimension of the Internet protocol address based on the multi-dimension traffic characteristics of the Internet protocol address. By applying the scheme of the invention, the IP address with the security risk can be isolated, the reliability is very high, and the misjudgment rate is relatively low.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to an address management method, program product, electronic device, and storage medium. Background Art

[0002] With the popularization of cloud computing and big data, the number of server, container, and virtual machine instances in data centers continues to grow rapidly. Under this trend, the management of IP addresses (Internet Protocol Addresses), the core identifier for identifying resources at the network layer, and their management throughout their life cycle, including allocation, usage, monitoring, and recycling, is becoming increasingly difficult.

[0003] Currently, mainstream data center IP management methods are still centered around IP address management systems (IPAM) and configuration management databases (CMDBs). These systems typically maintain IP resource status through static registration, manual inventory, or a combination of scripting tools. These management approaches focus primarily on ensuring "matching and remembering"—that is, they manage static IP address allocation and archiving, but neglect security behavior and risk management during the IP lifecycle.

[0004] In summary, how to effectively implement risk management of IP addresses and improve security is a technical problem that those skilled in the art urgently need to solve. Summary of the Invention

[0005] The present application provides an address management method, program product, electronic device, and storage medium to effectively implement risk management of IP addresses and improve security.

[0006] This application provides an address management method, including:

[0007] Collect traffic data of target devices;

[0008] Based on the traffic data, performing feature analysis on each Internet Protocol address in the traffic data to obtain multi-dimensional traffic features of each Internet Protocol address;

[0009] For any Internet Protocol address in the traffic data, determining whether a degree of deviation between the multi-dimensional traffic characteristics of the Internet Protocol address and a historical average of the traffic characteristics of each dimension of the Internet Protocol address exceeds a preset safety deviation degree;

[0010] If so, isolating said Internet Protocol address;

[0011] If not, based on the multi-dimensional traffic characteristics of the Internet Protocol address, the historical average of the traffic characteristics of each dimension of the Internet Protocol address is updated.

[0012] The present application also provides an electronic device, comprising:

[0013] memory for storing computer programs;

[0014] A processor is used to implement the steps of the address management method as described above when executing the computer program.

[0015] The present application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of the address management method described above are implemented.

[0016] The present application also provides a computer program product, including a computer program, which implements the steps of the address management method described above when executed by a processor.

[0017] In the solution of the present application, the flow data of the target device can be collected, and the collection of the full amount of flow data can usually be achieved through data probes. In order to ensure the reliability of the analysis, it is not based on a single indicator, but based on the flow data, the characteristics of each Internet Protocol address in the flow data are analyzed to obtain the multi-dimensional flow characteristics of each Internet Protocol address. For any Internet Protocol address in the flow data, the solution of the present application will determine whether the degree of deviation between the multi-dimensional flow characteristics of the Internet Protocol address and the historical mean of the flow characteristics of each dimension of the Internet Protocol address exceeds the preset safety deviation level. It can be understood that under normal circumstances, even if the flow characteristics of some dimensions of the Internet Protocol address in the flow data collected this time are different from the historical mean of the flow characteristics of the dimension, the overall degree of deviation usually does not exceed the preset safety deviation level. At this time, the historical mean of the flow characteristics of each dimension of the Internet Protocol address can be updated based on the multi-dimensional flow characteristics of the Internet Protocol address obtained this time. If the situation exceeds the preset safety deviation level, it means that the Internet Protocol address has a security risk, so the solution of the present application will isolate the Internet Protocol address.

[0018] It can be seen that the present application solution can isolate Internet Protocol addresses that pose security risks, thereby effectively realizing risk management of IP addresses and improving security. In addition, the present application solution is based on the multi-dimensional traffic characteristics of the IP address, and is combined with the degree of deviation between the historical averages of the traffic characteristics of each dimension of the IP address to make judgments, making it highly reliable and able to accurately discover some difficult-to-identify risk IPs with a low misjudgment rate. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0020] Figure 1 This is a flowchart of an address management method according to a specific embodiment of the present invention;

[0021] Figure 2 This is a schematic diagram of collecting traffic data on a core switch through a data probe in a specific embodiment of the present invention;

[0022] Figure 3 A schematic diagram of the functional division of an address management method in a specific embodiment of the present invention;

[0023] Figure 4 A schematic structural diagram of an electronic device provided in a specific embodiment of the present invention;

[0024] Figure 5 This is a schematic structural diagram of a computer-readable storage medium of the present invention. DETAILED DESCRIPTION

[0025] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0026] It should be noted that, in the description of this application, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. The terms "first," "second," etc., in this application are used to distinguish similar objects, and are not used to describe a particular order or sequence.

[0027] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below in conjunction with the accompanying drawings and specific implementation methods. Figure 1 , Figure 1 This is a flowchart of an implementation method of an address management method provided in a specific embodiment of the present invention. The address management method may include the following steps:

[0028] Step S101: Collect traffic data of the target device.

[0029] Specifically, in actual applications, traffic data of target devices can usually be collected through data probes. The target devices can be set as needed. For example, lightweight traffic probes can be deployed on key nodes such as core switches and virtual distributed switches in data centers. Traffic probes are devices used to collect and analyze network traffic in network monitoring systems. When collecting traffic data, they do not affect the original data transmission. Figure 2 , Figure 2 In the example, traffic data on the core switch is collected through a data probe, that is, the target device is the core switch, which is also the solution commonly used in actual applications.

[0030] The data probe can use the NetFlow v9 protocol that supports high-performance traffic statistics, can be seamlessly connected to the existing network, and has extremely small device load and no blind spots in traffic collection. In other specific implementations, the protocol type used can be adjusted as needed. Figure 2 In the example, the traffic data collected by the data probe can be sent to the cloud management platform for subsequent processing.

[0031] In actual applications, in the cloud management platform, by installing special DHCP and Neutron plug-ins, the policy execution layer of the cloud management platform can directly call the cloud platform interface to dynamically adjust the network configuration, including the allocation, isolation, release of IP addresses, and the issuance of traffic ACLs. This plug-in can adapt to mainstream virtualization environments and achieve unified security policy management across VLANs. In addition, Figure 2 In the example, the database can be connected so that all required data can be written into a time series database (for example, a Prometheus database) for storage.

[0032] It is understandable that, since traffic data is continuous, when collecting traffic data through data probes, the traffic data collected within a certain period of time can be used as the traffic data that needs to be detected in this round, and then the subsequent steps are performed based on these traffic data, and the next round also needs to collect traffic data for a certain period of time as the traffic data that needs to be detected in the next round. For example, in a specific scenario, the certain period of time described here can be specifically set to 30 seconds, that is, the continuous traffic data is segmented and aggregated with 30 seconds as the time granularity. That is to say, in this example, whenever 30 seconds of traffic data is collected through the data probe, the subsequent steps can be performed based on this 30 seconds of traffic data.

[0033] See Figure 3, is a functional division diagram of the address management method of the present application in a specific implementation method, showing the data probe layer, the portrait generation layer, the comparison and analysis layer, the policy execution layer, and the visualization layer. Step S101 can be implemented through the data probe layer, that is, the data probe layer is responsible for the collection of traffic data. In some cases, the data probe layer can also perform preliminary information processing on the traffic data collected by the data probe. For example, after the preliminary information processing, the extracted information may include: IP and port communication, protocol identification, the size and frequency of various data packets, session duration, various login / authentication statuses, and basic fingerprint information of the operating system and terminal type.

[0034] Data probes utilize port mirroring and traffic monitoring technologies to ensure zero disruption to service links during traffic data collection. Furthermore, protocols like NetFlow enable high-speed traffic collection. Data probes can flexibly configure collection granularity (e.g., the 30 seconds described above) and, in some cases, even set filtering policies. This allows for both high-frequency "second-level flushing" and large-scale traffic data collection. Data probes can cross physical and virtual boundaries, ensuring full-scenario coverage for this application solution.

[0035] Step S102: Based on the traffic data, perform feature analysis on each Internet Protocol address in the traffic data to obtain multi-dimensional traffic features of each Internet Protocol address.

[0036] After collecting the traffic data, the profile generation layer can be used to perform feature analysis on the traffic data to obtain the multi-dimensional traffic features of each IP in the traffic data. For example, in the above example, the time granularity is 30 seconds. At this time, step S102 is performed on the traffic data of these 30 seconds to obtain the multi-dimensional traffic features of each IP in these 30 seconds of traffic data.

[0037] The collected traffic data may include multiple data packets (such as ARP, ICMP, TCP, UDP and other types of data packets), and it is understandable that when performing feature analysis of a certain IP address in the traffic data, it is necessary to perform feature analysis of the IP address based on the various data packets belonging to the IP in the traffic data. The specific IP to which a data packet belongs can be determined by the source IP or destination IP of the data packet. In actual applications, this application usually sets the destination IP, that is, for any data packet, the destination IP of the data packet is regarded as the IP of the data packet.

[0038] This application solution requires obtaining the multi-dimensional traffic characteristics of each Internet Protocol address. Of course, the specific dimensions can be set and adjusted according to actual needs, as long as they can effectively reflect the traffic characteristics of the Internet Protocol address. For example, the traffic characteristics may include the maximum packet value, PPS (packets per second), BPS (bytes per second), peak ratio, etc. of the IP address.

[0039] Step S103: For any IP address in the traffic data, determine whether the deviation between the multi-dimensional traffic characteristics of the IP address and the historical average of the traffic characteristics of each dimension of the IP address exceeds a preset safety deviation level. If so, proceed to step S104; if not, proceed to step S105.

[0040] In the present application, for any IP in the traffic data, it is necessary to compare the multi-dimensional traffic characteristics of the IP obtained in this round with the historical mean of the traffic characteristics of each dimension of the IP, that is, to compare the degree of deviation between the two, so as to determine whether the deviation between the two exceeds the preset safety deviation degree. And it can be understood that, under normal circumstances, the traffic characteristics of each dimension of the IP in the traffic data collected in this round should be roughly consistent with the historical mean of the traffic characteristics of the corresponding dimension. Even if the traffic characteristics of some dimensions are different from the historical mean of the traffic characteristics of the dimension, the overall deviation degree will not usually exceed the preset safety deviation degree. It can be achieved through Figure 3 The comparison analysis layer in the example is used to implement the operation of this step.

[0041] When performing the consistency comparison in this step, there can be multiple specific implementation methods for obtaining the degree of deviation, which can effectively reflect the difference between the multi-dimensional traffic characteristics of the IP obtained this time and the historical mean of the traffic characteristics of each dimension of the IP. For example, the deviation parameter S can be obtained by calculation, and the deviation parameter S can effectively reflect the difference between the multi-dimensional traffic characteristics of the IP obtained this time and the historical mean of the traffic characteristics of each dimension of the IP.

[0042] In a specific embodiment of the present invention, step S103 may specifically include:

[0043] For any Internet Protocol address in the traffic data, based on the multi-dimensional traffic characteristics of the Internet Protocol address and the historical average of the traffic characteristics of each dimension of the Internet Protocol address, The calculation method is used to determine the deviation parameter S of the Internet Protocol address;

[0044] Determining whether a deviation parameter S of the Internet Protocol address exceeds a preset first threshold;

[0045] If so, determining whether the degree of deviation between the multi-dimensional traffic characteristics of the Internet Protocol address and the historical mean of the traffic characteristics of each dimension of the Internet Protocol address exceeds a preset safe deviation degree;

[0046] If not, determining whether the deviation between the multi-dimensional traffic characteristics of the Internet Protocol address and the historical mean of the traffic characteristics of each dimension of the Internet Protocol address does not exceed a preset safe deviation level;

[0047] Among them, S is the deviation parameter of the Internet Protocol address, j is the dimension number of the traffic feature, and n is the total number of dimensions of the traffic feature. is the traffic characteristic of the j-th dimension of the Internet Protocol address, is the historical mean of the traffic characteristics of the j-th dimension of the Internet Protocol address, is the maximum value of the historical mean of the traffic characteristics of the j-th dimension of the Internet Protocol address during the update process, is the weight of the traffic feature of the jth dimension corresponding to the Internet Protocol address.

[0048] In this implementation, it can be seen from the calculation method of S that the traffic characteristics of each dimension are taken into account. Therefore, the deviation parameter S obtained in this implementation can very accurately and effectively measure the difference between the multi-dimensional traffic characteristics of the IP obtained this time and the historical average of the traffic characteristics of each dimension of the IP.

[0049] For the traffic characteristics of the jth dimension, It can effectively reflect the current value (that is, the traffic characteristics of the j-th dimension obtained this time) ) and the historical mean ( ) and considering the different importance of traffic features in different dimensions, the deviation ratio needs to be proportional to the weight of the traffic features in that dimension. Multiply them together so that the final deviation parameter S can more accurately reflect the risk level of the IP. In addition, the maximum value of the historical mean during the update process is used to calculate the deviation ratio in the above formula. , so that the obtained deviation ratio is not easy to be too high, which is helpful to reduce the probability of misjudgment to a certain extent.

[0050] In this embodiment, after obtaining the deviation parameter S of the IP, it can be determined whether the deviation parameter S exceeds the preset first threshold. Under normal circumstances, the deviation parameter S obtained this time will not exceed the preset first threshold, which means that the degree of deviation between the multi-dimensional traffic characteristics of the IP address obtained this time and the historical mean of the traffic characteristics of each dimension of the IP address does not exceed the preset safety deviation degree. On the contrary, if the deviation parameter S obtained this time exceeds the preset first threshold, it can be determined that the degree of deviation between the multi-dimensional traffic characteristics of the IP address obtained this time and the historical mean of the traffic characteristics of each dimension of the IP address exceeds the preset safety deviation degree.

[0051] Step S104: Isolate the Internet Protocol address.

[0052] For any Internet Protocol address in the traffic data, if the degree of deviation between the multi-dimensional traffic characteristics of the Internet Protocol address and the historical mean of the traffic characteristics of each dimension of the Internet Protocol address exceeds the preset safety deviation degree, it means that the IP address has a security risk. And for such a risk, the present application solution will isolate the IP address. For example, after the comparison and analysis layer determines that the IP address has a security risk, it can immediately generate a security event and write the security event to the pending event queue based on information such as the event type, threat level, and business impact. Subsequently, the policy execution layer reads the pending security event from the pending event queue, and then, according to the pre-set automated processing strategy, automatically calls various interfaces and control measures to complete the processing of the risky IP. Specifically, due to the risk of the IP, specifically the degree of deviation between the multi-dimensional traffic characteristics of the IP address and the historical mean of the traffic characteristics of each dimension of the IP address, isolating the risky IP is a more appropriate treatment method, that is, the policy execution layer can isolate the risky IP address.

[0053] Step S105: Based on the multi-dimensional traffic characteristics of the Internet Protocol address, the historical mean of the traffic characteristics of each dimension of the Internet Protocol address is updated.

[0054] For any Internet Protocol address in the traffic data, if the degree of deviation between the multi-dimensional traffic characteristics of the Internet Protocol address and the historical average of the traffic characteristics of each dimension of the Internet Protocol address does not exceed the preset safety deviation level, then the historical average of the traffic characteristics of each dimension of the Internet Protocol address can be updated normally based on the multi-dimensional traffic characteristics of the Internet Protocol address obtained this time.

[0055] In a specific embodiment of the present invention, step S104 may specifically include:

[0056] Migrate the Internet Protocol address to the quarantine zone by modifying the virtual local area network (VLAN) or access permissions of the Internet Protocol address.

[0057] In this implementation, when isolating an IP address, the IP address can be relocated to the isolation zone by modifying its VLAN or access permissions, thereby isolating the IP address and preventing the IP address from spreading risks to the core business area. Furthermore, this implementation allows for isolation by modifying the IP address's VLAN or access permissions, ensuring the flexibility of the isolation operation implemented by the present application.

[0058] In a specific embodiment of the present invention, after isolating the Internet Protocol address, the following steps may also be included:

[0059] Perform risk checks on Internet Protocol addresses using pre-set risk check rules;

[0060] If the risk check passes, the quarantine of the Internet Protocol address is lifted.

[0061] In actual applications, the policy execution layer can conduct a risk review of the isolated Internet Protocol addresses, that is, the risk review of the Internet Protocol addresses can be performed through preset risk review rules. Of course, the content of the specific risk review rules can be set according to actual needs. For example, the risk IP address can be more comprehensively tested in combination with other information. For example, the historical behavior of the IP address can be comprehensively analyzed to complete the risk review. For example, the risk review can be based on the black and white lists, that is, the preset risk review rules can be used to determine whether the isolated IP address is a whitelisted IP. If so, it is determined that the risk review has passed and the isolation of the IP address can be cancelled.

[0062] In addition to automatic verification, manual verification is also supported, that is, the preset risk verification rules can be for receiving the verification pass instruction sent by the staff, at which time the system can determine that the IP address has passed the risk verification.

[0063] In this implementation, isolated IP addresses can be further reviewed to further ensure the accuracy of the solution. That is, by using pre-set risk verification rules, the Internet Protocol address is risk-checked. If the risk verification passes, the isolation of the IP address can be lifted, and it can be allocated to the healthy business resource pool so that it can be allocated and used normally.

[0064] In a specific embodiment of the present invention, it may further include:

[0065] For any Internet Protocol address in the first address pool, when the idle time of the Internet Protocol address reaches an idle time threshold, reclaiming the Internet Protocol address;

[0066] The first address pool represents an address set consisting of used Internet Protocol addresses.

[0067] In the above, risky IP addresses are isolated based on the degree of deviation between the multi-dimensional traffic characteristics of the IP address and the historical average of the traffic characteristics of each dimension. This implementation method further takes into account that some IP addresses, although not risky IP addresses, are idle for a long time, resulting in resource waste. In this case, they can be automatically recycled.

[0068] In traditional solutions, it is easy for IP addresses that have not been used for a long time to be forgotten and zombie processes to be mounted for a long time. Usually, they rely on manual inspections to handle them, which are slow to respond, incomplete, and inefficient.

[0069] In this implementation, the first address pool represents an address set consisting of used IP addresses. For any IP address in the first address pool, its idle time will be calculated. If its idle time reaches the idle time threshold, it can be determined that the IP address has been occupied but has not been active recently, that is, it has been idle for a long time, and the IP address can be reclaimed.

[0070] The specific calculation method of the idle time can be set according to actual needs. For example, in a specific embodiment of the present invention, the idle time of the Internet Protocol address is calculated by T idle =T now -L gets the idle time;

[0071] Among them, T idle It represents the idle time of Internet Protocol address, T now It represents the current timestamp, L represents the timestamp of the most recent activity of the Internet Protocol address, and the update condition of L is: the Internet Protocol address is detected from the traffic data.

[0072] In this implementation, for any IP address, the current timestamp T now Subtract the timestamp L of the last activity of the IP address to easily get the idle time T of the IP address. idle . In addition, it should be noted that the update condition of L is: the IP address is detected from the traffic data. For example, in the above example, the feature analysis of the traffic data of these 30 seconds is performed with a time granularity of 30 seconds. It can be understood that every time 30 seconds of traffic data is obtained, the IP address of each data packet in the 30 seconds of traffic data can be updated.

[0073] The specific value of the idle time threshold can be set and adjusted as needed. For example, it can be set to 7 days. That is, for an IP address that has been used, if there is no data packet of this IP address in the traffic data obtained within 7 days, the L of this IP address will never be updated, resulting in the loss of data through T now -L calculated T idle If it is longer than 7 days, the IP address will be determined to be a long-term idle IP address and will be recycled.

[0074] Furthermore, in a specific embodiment of the present invention, the idle duration threshold is a dynamically set idle duration threshold, and the value of the idle duration threshold is negatively correlated with U;

[0075] Here, U represents the number of used Internet Protocol addresses and its proportion in the total number of Internet Protocol addresses.

[0076] In this implementation, the value of the idle time threshold can be dynamically adjusted. U represents the number of used Internet Protocol addresses and its proportion in the total number of Internet Protocol addresses, which can be expressed as U=N1 / N2. Here, N2 is the total number of IP addresses, including used IP addresses and unused IP addresses, and here, N1 is the number of used IP addresses. The value of the idle time threshold is negatively correlated with U. It can be understood that the larger the value of U, the fewer unused IPs, that is, the tighter the remaining IP resources, so it is necessary to lower the value of the idle time threshold so that the recovery of inactive IPs can be accelerated. Correspondingly, the smaller the value of U, the more unused IPs, that is, the more sufficient the remaining IP resources, so the value of the idle time threshold can be appropriately increased to avoid excessive recovery.

[0077] For example, in one scenario, when U is greater than 85%, the idle duration threshold is set to a first idle duration threshold with a smaller value, and when U is not greater than 85%, the idle duration threshold is set to a second idle duration threshold with a larger value.

[0078] In a specific embodiment of the present invention, it may further include:

[0079] Determine, based on the traffic data, usage behavior parameter information of each Internet Protocol address in the traffic data;

[0080] For any Internet Protocol address in the traffic data, determine whether the Internet Protocol address has a port anomaly based on the usage behavior parameter information of the Internet Protocol address;

[0081] If yes, execute the preset port exception handling measures.

[0082] In the above, based on the degree of deviation between the multi-dimensional traffic characteristics of the IP address and the historical mean of the traffic characteristics of each dimension, the risk IP is isolated. This implementation method further takes into account that some IPs have port anomalies, but it is necessary to analyze the usage behavior of the IP to determine, that is, the traffic characteristics of the IP address cannot reflect all the characteristics of the IP. In this implementation method, based on the traffic data, the usage behavior parameter information of each IP address in the traffic data will also be determined, and then based on the usage behavior parameter information of the IP address, it is judged whether the IP address has port anomalies. If so, it is necessary to execute the preset port anomaly handling measures. The specific operation content of the port anomaly handling measures can be set according to actual needs. Only the abnormal port of the IP address can be processed, or the entire IP address can be processed. For example, the IP address can be isolated, or the traffic of the IP address can be restricted, or only the traffic of the abnormal port under the IP address can be restricted.

[0083] The specific content of the usage behavior parameter information can be set according to actual needs, for example, it may include protocol stack type, port distribution, number of new connections per unit time, number of failures, response delay, access destination and other usage behavior parameters.

[0084] In addition, there are many specific implementations for determining whether an Internet Protocol address has a port anomaly. Generally, the port connection status can be analyzed based on the usage behavior parameter information of the Internet Protocol address to determine whether the port is abnormal. For example, in a specific embodiment of the present invention, for any Internet Protocol address in the traffic data, based on the usage behavior parameter information of the Internet Protocol address, determining whether the Internet Protocol address has a port anomaly can specifically include:

[0085] For any Internet Protocol address in the traffic data, based on the usage behavior parameter information of the Internet Protocol address, The calculation method is to determine the port abnormality P of each port of the Internet Protocol address;

[0086] Determining whether a port abnormality degree P of at least one port of the Internet Protocol address is greater than a preset port abnormality degree threshold;

[0087] If so, it is determined that the Internet Protocol address port is abnormal;

[0088] If not, then determine that the Internet Protocol address port is not abnormal;

[0089] Where P is the port abnormality of a single port of the Internet Protocol address, C is the real-time connection number of the port of the Internet Protocol address, and A is the average of the historical connection number of the port of the Internet Protocol address. is the standard deviation of the historical number of connections to the port of the Internet Protocol address, A preset constant greater than 0.

[0090] In this implementation, for each port of the IP address, you can The calculation method is used to calculate the port abnormality degree P of the port of the IP address. It is a preset constant greater than 0, which is a very small constant to prevent the denominator from being 0. In other words, and The calculation results are generally consistent. For any port of the IP address, it is necessary to subtract the mean value A of the historical connection count of the port from the real-time connection count C of the port obtained based on the current traffic data, and then divide it by the standard deviation of the historical connection count of the port. With the minimum constant The sum of is used to obtain the port abnormality P of the port.

[0091] Under normal circumstances, the port abnormality degree P of each port of the IP address should not be greater than the preset port abnormality degree threshold. In this case, it can be determined that the port of the IP address is not abnormal. Correspondingly, if the port abnormality degree P of at least one port is greater than the preset port abnormality degree threshold, it can be determined that the port of the IP address is abnormal. Of course, as described above, when executing the port abnormality handling measures, the specific operation content can be set according to actual needs. It can be processed only for the abnormal ports of the IP address, or for the entire IP address.

[0092] In this implementation, the port abnormality is determined by combining the mean and standard deviation of the historical connection numbers, which has high accuracy and can effectively determine whether the port is abnormal.

[0093] In a specific embodiment of the present invention, it may further include:

[0094] For any Internet Protocol address in the traffic data, determine whether the usage behavior parameter information of the Internet Protocol address complies with any risk scenario rule in the risk scenario rule library;

[0095] If so, the Internet Protocol address is processed based on a preset automated processing strategy.

[0096] This implementation further takes into account that in order to achieve a more comprehensive risk judgment, a risk scenario rule library can be pre-set in the comparison and analysis layer, which may include multiple risk scenario rules. For example, in actual applications, the risk scenario rule library contains hundreds of pre-set risk scenario rules. These risk scenario rules cover typical risk scenarios including IP blacklists and whitelists, authorized port changes, protocol abuse, port brute force attacks, east-west traffic mutations, bandwidth abuse, and long-term idle resources.

[0097] In this implementation, after obtaining the usage behavior parameter information of the IP address, risk judgment is performed through the risk scenario rule library, which can achieve a more comprehensive risk judgment and is also conducive to discovering some more hidden risk IPs, thereby improving the reliability of the present application solution.

[0098] If the IP address meets a risk scenario rule in the risk scenario rule library, the policy execution layer can handle the IP address based on the preset automated processing strategy. For example, if the risk is port drift, incorrect gateway entry, or configuration mismatch, a corrective command can be automatically issued, enabling unattended automatic remediation. For another example, if the risk of unauthorized port exposure occurs, the IP address can be directly isolated.

[0099] In a specific embodiment of the present invention, it may further include:

[0100] Collect log data and / or management data through data probes;

[0101] For any Internet Protocol address in the traffic data, determine whether the usage behavior parameter information of the Internet Protocol address meets any risk scenario rules in the risk scenario rule library, including:

[0102] For any Internet Protocol address in the traffic data, combined with the collected log data and / or management data, determine whether the usage behavior parameter information of the Internet Protocol address complies with any risk scenario rule in the risk scenario rule library.

[0103] This implementation method takes into account that in addition to obtaining traffic data, the data source can also be expanded. Specifically, log data and / or management data can be collected through data probes. Log data is usually selected as system logs, and management data can be pulled through APIs.

[0104] This implementation method expands the data source because it takes into account that for some risk scenarios, risky IPs cannot be well identified only through traffic data. That is to say, for certain risk scenario rules, log data and / or management data are needed to more accurately determine whether the IP poses the risk. Therefore, the data source is expanded in this implementation method, and the collected log data and / or management data can be combined to determine whether the usage behavior parameter information of the Internet Protocol address complies with any risk scenario rule in the risk scenario rule library.

[0105] In a specific embodiment of the present invention, it may further include:

[0106] After isolating the Internet Protocol address, the asset attribute information, risk information, and disposal actions for the Internet Protocol address are filled into a preset display template for display;

[0107] Record asset attribute information, risk information, and disposal actions for Internet Protocol addresses.

[0108] In this implementation, the asset attribute information, risk information, and disposal actions for an IP address can be entered into a preset display template through a visualization layer for display and easy viewing by the user. The asset attribute information for an IP address can include, for example, the business system to which the IP belongs, the actual server room location, the host type (physical / virtual / container), and a description of its usage. Risk information can include, among other things, the specific risk type of the IP. The disposal action refers to the specific action taken against the IP address. In this implementation, since the IP address is isolated, the specific disposal action is to isolate the IP address. In other situations, if other disposal actions are performed on an IP address, the asset attribute information, risk information, and disposal actions for the IP address can also be entered into a preset display template for display and easy viewing by the user, based on the principles of this implementation.

[0109] This implementation also records IP address asset attribute information, risk information, and the actions taken for these IP addresses, enabling user retrieval and backtracking. In practice, this can also record information such as the IP address's service group, VLAN, and functional area, enabling multi-angle filtering and retrieval, facilitating event review, root cause identification, and business transition tracking.

[0110] In a specific embodiment of the present invention, isolating the Internet Protocol address may specifically include:

[0111] Generate a security event that represents the multi-dimensional traffic characteristics of the Internet Protocol address and the degree of deviation between the characteristics and the historical average of the traffic characteristics of each dimension of the Internet Protocol address, and place it in a queue of pending events if the deviation exceeds a preset safety deviation level;

[0112] When reading security events from the pending event queue, isolating Internet Protocol addresses based on the read security events;

[0113] The pending event queue is a queue that sorts security events by priority. For any security event in the pending event queue, the priority of the security event is expressed as . R in this formula represents the priority of the IP address that caused the security incident. When the IP address causes the security incident, the deviation parameter is S, the port anomaly is P, and the number of used Internet Protocol addresses accounts for U in the total number of Internet Protocol addresses. The deviation parameter S reflects the multi-dimensional traffic characteristics of the Internet Protocol address and the degree of deviation from the historical mean of the traffic characteristics of each dimension of the Internet Protocol address. P reflects the degree of abnormality of the port connection. There are many specific calculation methods. For example, S and P can be calculated according to the description of the above implementation method. In addition, when the IP has multiple ports, the maximum value of the port anomaly P of each port can be used as the port anomaly of the IP address required to be used in this formula.

[0114] This implementation allows for the creation of a security event when an IP address needs to be addressed, placing it in a pending event queue. This event can then be retrieved from the pending event queue and processed, effectively addressing the IP address targeted by the security event. Furthermore, the pending event queue prioritizes security events, allowing higher-risk IP addresses to be addressed first. These are weighted coefficients, reflecting the impact of S, P, and U on priority. It's understandable that if an IP's S and P are large, security incidents caused by that IP will be given a higher priority. A smaller U indicates that there are many unused IPs, and traffic is generally not busy at this time, so security incidents caused by those IPs can also be prioritized.

[0115] In addition, it can be understood that in this embodiment, a security event is generated that represents the multi-dimensional traffic characteristics of the Internet Protocol address, the degree of deviation between the multi-dimensional traffic characteristics of the Internet Protocol address and the historical mean of the traffic characteristics of each dimension of the Internet Protocol address, and exceeds the preset safety deviation degree, and is placed in the queue of pending events. In the above embodiment, other risk assessments and disposals can also be performed on the IP address. For example, when it is determined that the usage behavior parameter information of the IP address meets any risk scenario rule in the risk scenario rule library, a security event can also be generated and placed in the queue of pending events. At this time, the security event indicates that the usage behavior parameter information of the IP address meets a certain risk scenario rule in the risk scenario rule library. When it is determined that a certain IP address port is abnormal, a security event can also be generated and placed in the queue of pending events. At this time, the security event indicates that the IP address port is abnormal. When the idle time of a certain IP address reaches the idle time threshold and the IP address needs to be recycled, a security event can also be generated and placed in the queue of pending events. At this time, the security event indicates that the IP address needs to be recycled.

[0116] In practice, each security incident can be assigned a globally unique serial number, enabling full process monitoring. For example, if no receipt of a critical action is received within 15 minutes, the system can automatically escalate the alert level and proactively send it to operations and maintenance personnel via multiple channels, such as SMS and email, for manual processing. Furthermore, resolved security incidents can be archived for subsequent use and statistical analysis.

[0117] In the solution of the present application, the flow data of the target device can be collected, and the collection of the full amount of flow data can usually be achieved through data probes. In order to ensure the reliability of the analysis, it is not based on a single indicator, but based on the flow data, the characteristics of each Internet Protocol address in the flow data are analyzed to obtain the multi-dimensional flow characteristics of each Internet Protocol address. For any Internet Protocol address in the flow data, the solution of the present application will determine whether the degree of deviation between the multi-dimensional flow characteristics of the Internet Protocol address and the historical mean of the flow characteristics of each dimension of the Internet Protocol address exceeds the preset safety deviation level. It can be understood that under normal circumstances, even if the flow characteristics of some dimensions of the Internet Protocol address in the flow data collected this time are different from the historical mean of the flow characteristics of the dimension, the overall degree of deviation usually does not exceed the preset safety deviation level. At this time, the historical mean of the flow characteristics of each dimension of the Internet Protocol address can be updated based on the multi-dimensional flow characteristics of the Internet Protocol address obtained this time. If the situation exceeds the preset safety deviation level, it means that the Internet Protocol address has a security risk, so the solution of the present application will isolate the Internet Protocol address.

[0118] It can be seen that the present application solution can isolate Internet Protocol addresses that pose security risks, thereby effectively realizing risk management of IP addresses and improving security. In addition, the present application solution is based on the multi-dimensional traffic characteristics of the IP address, and is combined with the degree of deviation between the historical averages of the traffic characteristics of each dimension of the IP address to make judgments, making it highly reliable and able to accurately discover some difficult-to-identify risk IPs with a low misjudgment rate.

[0119] Corresponding to the above method embodiments, embodiments of the present invention further provide an electronic device, a computer-readable storage medium, and a computer program product, which may refer to each other in correspondence with the above.

[0120] See also Figure 4 As shown, the electronic device may include:

[0121] Memory 401, used for storing computer programs;

[0122] The processor 402 is configured to execute a computer program to implement the steps of the address management method in any of the above embodiments.

[0123] The computer program product includes a computer program / instruction, which implements the steps of the address management method in any of the above embodiments when executed by a processor.

[0124] See Figure 5 The computer-readable storage medium 50 stores a computer program 51. When executed by a processor, the computer program 51 implements the steps of the address management method described in any of the above embodiments. The computer-readable storage medium 50 herein includes random access memory (RAM), internal memory, read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, removable disks, or any other form of storage medium known in the art.

[0125] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0126] The above describes in detail an address management method, program product, electronic device, and storage medium provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only intended to help understand the method and core ideas of the present application. It should be noted that, for those skilled in the art, without departing from the principles of the present application, several improvements and modifications may be made to the present application, and these improvements and modifications also fall within the scope of protection of the present application.

Claims

1. An address management method, characterized in that: include: Collect traffic data of target devices; Based on the traffic data, performing feature analysis on each Internet Protocol address in the traffic data to obtain multi-dimensional traffic features of each Internet Protocol address; For any Internet Protocol address in the traffic data, determining whether a degree of deviation between the multi-dimensional traffic characteristics of the Internet Protocol address and a historical average of the traffic characteristics of each dimension of the Internet Protocol address exceeds a preset safety deviation degree; If so, isolating said Internet Protocol address; If not, based on the multi-dimensional traffic characteristics of the Internet Protocol address, the historical average of the traffic characteristics of each dimension of the Internet Protocol address is updated.

2. The address management method according to claim 1, characterized in that: Isolating the Internet Protocol address, including: The Internet Protocol address is migrated to the isolation zone by modifying the virtual local area network or access permission of the Internet Protocol address.

3. The address management method according to claim 1, wherein: Also includes: For any Internet Protocol address in the first address pool, when the idle time of the Internet Protocol address reaches an idle time threshold, reclaiming the Internet Protocol address; The first address pool represents an address set consisting of used Internet Protocol addresses.

4. The address management method according to claim 3, wherein: The idle time of the Internet Protocol address is determined by T idle =T now -L gets the idle time; Among them, T idle It represents the idle time of the Internet Protocol address, T now represents the current timestamp, L represents the timestamp of the most recent activity of the Internet Protocol address, and the update condition of L is: the Internet Protocol address is detected from the traffic data.

5. The address management method according to claim 3, characterized in that: The idle time threshold is a dynamically set idle time threshold, and the value of the idle time threshold is negatively correlated with U; Here, U represents the number of used Internet Protocol addresses and its proportion in the total number of Internet Protocol addresses.

6. The address management method according to claim 1, wherein: After isolating the Internet Protocol address, further comprising: Performing a risk check on the Internet Protocol address using preset risk check rules; If the risk check passes, the quarantine of the Internet Protocol address is lifted.

7. The address management method according to claim 1, characterized in that: Also includes: Determining usage behavior parameter information of each Internet Protocol address in the traffic data based on the traffic data; For any Internet Protocol address in the traffic data, determining whether a port of the Internet Protocol address is abnormal based on usage behavior parameter information of the Internet Protocol address; If yes, execute the preset port exception handling measures.

8. The address management method according to claim 7, characterized in that: For any Internet Protocol address in the traffic data, determining whether a port of the Internet Protocol address is abnormal based on usage behavior parameter information of the Internet Protocol address includes: For any Internet Protocol address in the traffic data, based on the usage behavior parameter information of the Internet Protocol address, Determine the port abnormality degree P of each port of the Internet Protocol address by a calculation method; Determining whether a port abnormality degree P of at least one port of the Internet Protocol address is greater than a preset port abnormality degree threshold; If yes, determining that the Internet Protocol address port is abnormal; If not, determining that the Internet Protocol address port is not abnormal; Wherein, P is the port abnormality of a single port of the Internet Protocol address, C is the real-time connection number of the port of the Internet Protocol address, and A is the average of the historical connection number of the port of the Internet Protocol address. is the standard deviation of the historical number of connections to the port of the Internet Protocol address, A preset constant greater than 0.

9. The address management method according to claim 7, characterized in that: Also includes: For any Internet Protocol address in the traffic data, determining whether usage behavior parameter information of the Internet Protocol address complies with any risk scenario rule in a risk scenario rule library; If so, the Internet Protocol address is handled based on a preset automatic processing strategy.

10. The address management method according to claim 9, characterized in that: Also includes: Collect log data and / or management data through data probes; For any Internet Protocol address in the traffic data, determining whether usage behavior parameter information of the Internet Protocol address complies with any risk scenario rule in a risk scenario rule library includes: For any Internet Protocol address in the traffic data, combined with the collected log data and / or management data, determine whether the usage behavior parameter information of the Internet Protocol address complies with any risk scenario rule in the risk scenario rule library.

11. The address management method according to claim 1, wherein: Also includes: After isolating the Internet Protocol address, the asset attribute information, risk information, and disposal action for the Internet Protocol address are filled into a preset display template for display; Record asset attribute information, risk information, and disposal actions for the Internet Protocol address.

12. The address management method according to any one of claims 1 to 11, characterized in that: For any Internet Protocol address in the traffic data, determining whether a deviation between the multi-dimensional traffic characteristics of the Internet Protocol address and a historical average of the traffic characteristics of each dimension of the Internet Protocol address exceeds a preset safety deviation level includes: For any Internet Protocol address in the traffic data, based on the multi-dimensional traffic characteristics of the Internet Protocol address and the historical average of the traffic characteristics of each dimension of the Internet Protocol address, Determine the deviation parameter S of the Internet Protocol address by a calculation method; Determining whether a deviation parameter S of the Internet Protocol address exceeds a preset first threshold; If so, determining whether the degree of deviation between the multi-dimensional traffic characteristics of the Internet Protocol address and the historical average of the traffic characteristics of each dimension of the Internet Protocol address exceeds a preset safe deviation degree; If not, determining whether the deviation between the multi-dimensional traffic characteristics of the Internet Protocol address and the historical average of the traffic characteristics of each dimension of the Internet Protocol address does not exceed a preset safety deviation level; Wherein, S is the deviation parameter of the Internet Protocol address, j is the dimension number of the traffic feature, and n is the total number of dimensions of the traffic feature. is the traffic characteristic of the j-th dimension of the Internet Protocol address, is the historical mean of the traffic characteristics of the j-th dimension of the Internet Protocol address, is the maximum value of the historical mean value of the traffic feature of the j-th dimension of the Internet Protocol address that has appeared during the update process, is the weight of the traffic feature of the jth dimension corresponding to the Internet Protocol address.

13. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to implement the steps of the address management method according to any one of claims 1 to 12 when executing the computer program.

14. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the address management method according to any one of claims 1 to 12.

15. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the address management method according to any one of claims 1 to 12 are implemented.