IP asset detection and identification method and system

By adjusting communication delay and port status based on server status information and communication logs, and identifying and clustering related IP devices, the problem of low IP asset detection efficiency is solved, and accurate identification and resource optimization are achieved.

CN120768784APending Publication Date: 2025-10-10INFORMATION & COMM BRANCH OF STATE GRID JIANGSU ELECTRIC POWER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510928135.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-07
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

The existing technology has low efficiency in IP asset detection and is difficult to achieve accurate identification, especially in the case of complex forwarding relationships and repeated IPs, which leads to waste of communication resources and security risks.

Method used

By incorporating normally connected IP devices into the asset library based on server status information and communication logs, adjusting communication delay and port status, and using the reply information of the routing device to determine the IP asset of the next-hop device, and clustering by associating the communication logs of IP devices, an IP access pointer cluster is constructed to identify proxy routing.

Benefits of technology

It achieves accurate identification of IP assets, improves detection efficiency, optimizes network configuration, reduces resource waste and improves security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768784A_ABST
    Figure CN120768784A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an IP asset detection and identification method and system. The method comprises the following steps: bringing a first to-be-detected IP device in a normal connection state with a server into an IP asset library; for the second to-be-detected IP equipment, adjusting communication time delay based on the communication rate and each subnet scanning clock, and enabling a communication port of the server to serve as a flicker window to enter a flicker occupation state; after the routing equipment in the IP equipment to be detected detects the communication delay, the communication port state of the next-hop equipment is determined based on reply information of the next-hop equipment, and whether the IP of the next-hop equipment is included in the IP asset library or not is determined based on the flicker window of the server and the communication port state; and detecting associated IP equipment among the subnets, forming an IP access pointer cluster based on a second communication log of the associated IP equipment, performing clustering, and taking a clustering result as a proxy route to be included in the IP asset library. According to the technical scheme, accurate identification of the IP assets can be realized, and the detection efficiency of the IP assets is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to an IP asset detection and identification method and system. Background Art

[0002] IP asset detection refers to the process of scanning and identifying asset information related to Internet Protocol (IP) addresses. The identified objects include IP entities such as servers, routing devices, API endpoints, and cloud services.

[0003] Due to the expansion of server services, IP devices are updated rapidly. While some IP services have been offline, these devices remain active on servers, creating low-quality assets. This not only occupies communication resources on existing servers but also poses security risks. However, servers connect to numerous IP segments, and scanning each address in the segment sequentially takes a long time. Using forwarding algorithms to shorten the scanning process requires routers to perform multi-hop forwarding, which reduces the efficiency of IP asset detection.

[0004] In addition, IP devices often have complex forwarding relationships. Some routing devices establish an actual connection with the server by receiving signals forwarded by internal and external devices, and should also be counted as part of the IP assets. The existence of duplicate IPs, bridges, IP firewalls, etc. also makes IP asset detection more complicated, making it difficult to accurately identify IP assets. Summary of the Invention

[0005] In view of this, the present invention provides an IP asset detection and identification method and system, which can achieve accurate identification of IP assets and improve the detection efficiency of IP assets.

[0006] According to one aspect of the present invention, an embodiment of the present invention provides an IP asset detection and identification method, which is applied to an IP asset detection and identification system. The method includes:

[0007] Adding a first IP device to be detected that is in a normal connection state with the server into the IP asset library based on the server status information and the first communication log;

[0008] For the second IP device to be detected, obtaining the communication rate of the server to each subnet, and adjusting the communication delay between the server and each subnet based on the communication rate and a pre-configured scan clock of each subnet, so that the communication port of the server facing each subnet enters an occupied flashing state as a flashing window; wherein each subnet may include multiple IP devices to be detected;

[0009] After the routing device in the second IP device to be detected detects the communication delay, it sends a connection signal to the next-hop device, determines the communication port status of the next-hop device based on the reply information of the connection signal, and determines whether the IP address of the next-hop device is included in the IP asset library based on the flashing window of the server and the communication port status of the next-hop device;

[0010] Detect the associated IP devices between each of the subnets, form an IP access pointer cluster based on the second communication log of the associated IP device, cluster the IP access pointer cluster, and incorporate the clustering results into the IP asset library as a proxy route.

[0011] According to another aspect of the present invention, an embodiment of the present invention further provides an IP asset detection and identification system, the system comprising:

[0012] A message detection module, configured to add a first IP device to be detected that is in a normal connection state with the server into an IP asset library based on the server status information and the first communication log;

[0013] a communication delay adjustment module, configured to obtain, for a second IP device to be detected, a communication rate of the server to each subnet, and adjust the communication delay between the server and each subnet based on the communication rate and a pre-configured scan clock of each subnet, so that the communication port of the server facing each subnet enters an occupied flashing state as a flashing window; wherein each subnet may include multiple IP devices to be detected;

[0014] a window status identification module, configured to, after the routing device in the second IP device to be detected detects the communication delay, send a connection signal to the next-hop device, determine the communication port status of the next-hop device based on the reply information of the connection signal, and determine whether the IP address of the next-hop device is included in the IP asset library based on the flashing window of the server and the communication port status of the next-hop device;

[0015] The edge computing module is used to detect the associated IP devices between each of the subnets, form an IP access pointer cluster based on the second communication log of the associated IP device, cluster the IP access pointer cluster, and incorporate the clustering results into the IP asset library as a proxy route.

[0016] The technical scheme of the embodiment of the present application, by including the first to-be-probed IP device in a normal connection state with the server into an IP asset library; for the second to-be-probed IP device, adjusting the communication time delay based on the communication rate and the subnet scanning clock, so that the communication port of the server enters the occupied flashing state as a flashing window; after the routing device in the second to-be-probed IP device detects the communication time delay, determining the communication port state of the next hop device based on the reply information of the next hop device, and determining whether the IP of the next hop device is included in the IP asset library based on the flashing window and the communication port state of the server; detecting the associated IP devices between subnets, constructing an IP access pointer cluster based on the second communication log of the associated IP devices, and after clustering, including the clustering result as a proxy route into the IP asset library. The above technical scheme can realize accurate identification of IP assets and improve the detection efficiency of IP assets.

[0017] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.

[0019] Figure 1 A flow chart of an IP asset detection and identification method provided by an embodiment of the present application;

[0020] Figure 2 A flow chart of another IP asset detection and identification method provided by an embodiment of the present application;

[0021] Figure 3 A structural block diagram of an IP asset detection and identification system provided by an embodiment of the present application;

[0022] Figure 4 Another structural diagram of an IP asset detection and identification system provided by an embodiment of the present application. DETAILED DESCRIPTION

[0023] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0024] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0025] In one embodiment, Figure 1 This is a flow chart of an IP asset detection and identification method provided by an embodiment of the present invention. This embodiment is applicable to situations where IP assets are detected and identified. The method can be executed by an IP asset detection and identification system. Figure 1 As shown, the method includes:

[0026] S110 : Based on the status information of the server and the first communication log, a first IP device to be detected that is in a normal connection state with the server is added to the IP asset library.

[0027] The first IP device to be detected refers to an IP device to be detected that has been historically connected to the server, i.e., an IP device that has been directly connected to the server as known based on communication records. In this embodiment, the first IP device to be detected that is normally connected to the server can be included in the IP asset library based on the server status information and the first communication log.

[0028] In this embodiment, the status information includes at least: port status, routing connection status and data transmission status; the first communication log refers to the log information recorded by the server for direct communication with other IP devices, and the first communication log may include communication records between the server and the IP device.

[0029] In this embodiment, the status information of the server is obtained, and the first communication log recorded by the server in the existing network environment is parsed, and the communication record recorded in the first communication log can be obtained. Therefore, the first IP device to be detected connected to the server can be determined based on the communication record, and the IP address, subnet number, port number and other information of the first IP device to be detected can be recorded. Then, a corresponding communication message (for example, an ICMP message or a TCP message) is sent to the first IP device to be detected to detect the online status of the IP device directly connected to the server (for example, a host device). After sending the corresponding communication message, as long as a reply message from one or more IP devices in the first IP device to be detected is received within a fixed preset time period, it can be determined that the IP device that replied to the message is normally connected to the server, and the normally connected IP device is included in the asset library and stored according to the subnet number of the IP device. It should be noted that the first IP device to be detected in this embodiment may include but is not limited to a host device and a routing device.

[0030] S120. For the second IP device to be detected, obtain the communication rate of the server to each subnet, adjust the communication delay between the server and each subnet based on the communication rate and the pre-configured scan clock of each subnet, so that the communication port of the server facing each subnet enters the occupied flashing state as a flashing window.

[0031] The second IP device to be detected may include an IP device to be detected that is offline when connected to the server, and other possible IP device assets, which may be understood as some unknown IP assets to be detected.

[0032] Each subnet may include multiple second IP devices to be detected. The second devices to be detected may also include routing devices and host devices. It can be understood that a router used for forwarding is also an IP asset.

[0033] In this embodiment, subnets are the subnets connected to the server. Subnets divide a large network into multiple smaller logical networks by dividing the network and host bits of an IP address (using a subnet mask or CIDR prefix). Each IP device must belong to a specific subnet. Within the same subnet, devices communicate directly by resolving MAC addresses using ARP. Messages between different subnets must be sent to the default gateway and forwarded by the router according to the routing table.

[0034] In this embodiment, the server has a certain communication rate for each subnet. After obtaining the server's communication rate for each subnet, this communication rate can be used as a decay rate to generate a test function that decays over time. Since each subnet has an independent scan time, at the beginning of each subnet's scan time, the server can input the current scan time into the test function at fixed intervals, using the output value as the communication delay. This causes the communication port between the server and the subnet to be occupied for the length of the communication delay, and the occupied communication port to flash. This occupied communication port can also be referred to as a flashing window. It should be noted that since each subnet has an independent scan clock, the scan clocks of each subnet do not overlap. This means that scans are performed at intervals, and different subnets cannot be scanned simultaneously.

[0035] S130. After the routing device in the second IP device to be detected detects the communication delay, it sends a connection signal to the next-hop device, and determines the communication port status of the next-hop device based on the reply information of the connection signal, and determines whether the IP of the next-hop device is included in the IP asset library based on the flashing window of the server and the communication port status of the next-hop device.

[0036] Among them, the routing device can also be called a router. The router can send the data packet to the corresponding next-hop device according to the configured routing table. In this embodiment, the next-hop device can be understood as an IP device directly connected to the router. The directly connected device can also be a host device or a router.

[0037] In this embodiment, after the routing device in the second IP device to be detected detects the communication delay, it starts to send the corresponding ping connection signal to the next-hop device in a constant window, and then receives the reply signal of the connection signal fed back by each next-hop device. If a reply signal is received, it indicates that the sent ping connection signal is a valid signal. If the ping connection signal is not received, the ping signal that does not receive the reply signal is an invalid signal. The time window in which the invalid signal is located is recorded as the unanswered window, which represents that the communication port status of the next-hop IP device is in an occupied state. The unanswered window is then compared with the server flashing window. If the consistency of the comparison result is higher than the preset threshold, the IP of the next-hop device corresponding to the unanswered window is included in the IP asset library. It can be understood that for each subnet, all IP devices in the subnet directly connected to the server are included in the IP asset library.

[0038] S140: Detect associated IP devices between subnets, form IP access pointer clusters based on the second communication logs of the associated IP devices, cluster the IP access pointer clusters, and incorporate the clustering results into the IP asset library as proxy routes.

[0039] The associated IP device can be understood as an IP device associated with each subnet.

[0040] In the embodiment, for each subnet, after all IP devices in the subnet directly connected with the server are included in the IP asset library, the IP devices associated with each subnet can be further detected.

[0041] In the embodiment, each subnet is scanned in turn according to a certain scanning time, and if the communication port state of the IP device of another subnet in the scanning time length of each subnet is in an occupied state, the IP device in the occupied state is determined as the associated IP device of the subnet, which can be understood as that the IP device flashing in the scanning clock of two subnets is recorded as the associated IP device. In the embodiment, after detecting the associated IP device between each subnet, the associated IP device is addressed to determine the routing device connected with the associated IP device, the routing device connected with the associated IP device is taken as the edge device, and the communication log between the associated IP device and the server is parsed using the edge device to obtain a parsing result. Based on the parsing result, a pointer is generated for each communication record in the communication log to form a pointer cluster of the associated IP, so that the proxy routing included in the IP asset library is obtained through clustering.

[0042] The above technical solution of the embodiment of the application can include the first to-be-detected IP device in the IP asset library in a normal connection state with the server, adjust the communication time delay based on the communication rate and the scanning clock of each subnet, so that the communication port of the server enters the occupied flashing state as a flashing window, determine the communication port state of the next-hop device based on the reply information of the next-hop device after the routing device in the second to-be-detected IP device detects the communication time delay, determine whether the IP of the next-hop device is included in the IP asset library based on the flashing window of the server and the communication port state, detect the associated IP device between each subnet, form an IP access pointer cluster based on the second communication log of the associated IP device, and include the clustering result as the proxy routing in the IP asset library after clustering. The above technical solution can realize accurate identification of IP assets and improve the detection efficiency of IP assets.

[0043] In an embodiment, the method further comprises:

[0044] Obtaining parameter information corresponding to the IP asset in the IP asset library, inputting the parameter information into a pre-constructed risk threat model to output a risk value of the IP asset;

[0045] Making a risk protection decision according to the risk value, and cleaning up the invalid IP asset.

[0046] The parameter information may include but is not limited to the value of the IP asset, the confidentiality level, the routing risk value of the connection, and the attack log.

[0047] In this embodiment, the value, confidentiality level, connected route risk value, and attack logs of each IP asset are input into modeling software. A risk threat model is then established according to vulnerability assessment standards. The input of the risk threat model is the IP asset, and the output is the risk value of the IP asset. The modeling software used includes SPSS, EViews, NetLogo, and AnyLogic. Risk protection decisions are then made based on the risk value, and invalid IP assets are cleared. In this embodiment, by inputting parameter information into a pre-built risk threat model to output the risk value of the IP asset, risk protection decisions are made based on the risk value, and invalid IP assets are cleared. This allows for risk-based security configuration updates, better identification and repair of security vulnerabilities, reduction of potential attack surfaces, and improved server security performance.

[0048] In one embodiment, making risk protection decisions and cleaning up invalid IP assets based on the risk value includes:

[0049] Update the server's security configuration based on the risk value to protect against risks;

[0050] Retrieve IP assets with consistent risk values ​​from the asset library and merge them to obtain the merged target IP assets;

[0051] For each target IP asset, those with risk values ​​higher than the preset risk threshold and not related to the business will be cleared.

[0052] In this embodiment, the server's security configuration is updated based on the risk value to protect against risk. For example, the encryption level can be increased when the threat increases. IP assets with consistent risk values ​​are retrieved from the asset library for IP asset merging. IP assets with risk values ​​above a threshold and unrelated to the existing network services are cleared. Finally, the server security configuration is updated based on the risk values ​​of all existing IP assets. IP assets unrelated to the existing network services may include: The existing network service is a communication service for 5G devices, but the server long ago provided services for 2G devices. Consequently, some 2G device IP links may have been forgotten. These are assets unrelated to the existing network services. The purpose of IP discovery is to remove these IP assets.

[0053] In one embodiment, Figure 2A flowchart of another IP asset detection and identification method provided for one embodiment of the present invention. Based on the above embodiments, this embodiment includes a first IP device to be detected that is in a normal connection state with the server based on the server status information and the first communication log into the IP asset library; adjusts the communication delay between the server and each subnet based on the communication rate and the pre-configured scan clock of each subnet, so that the communication port of the server facing each subnet enters an occupied flashing state as a flashing window; determines the communication port status of the next-hop device based on the reply information of the connection signal, and determines whether the IP of the next-hop device is included in the IP asset library based on the flashing window of the server and the communication port status of the next-hop device; and forms an IP access pointer cluster based on the second communication log of the associated IP device, clusters the IP access pointer clusters, and further refines the clustering results as proxy routes and includes them in the IP asset library.

[0054] like Figure 2 As shown, the IP asset detection and identification method in this embodiment may specifically include the following steps:

[0055] S210: Monitor server status information.

[0056] In this embodiment, the server status information is monitored and recorded, wherein the status information at least includes: port status, routing connection status and data transmission status.

[0057] S220, obtaining the first communication log recorded by the server, determining the first IP device to be detected connected to the server based on the status information and the first communication log, and recording the IP address, subnet number, port number and IP device type of the first IP device to be detected.

[0058] Among them, IP device types may include but are not limited to routers, hosts, and auxiliary servers.

[0059] In this embodiment, the first IP device to be detected connected to the server is determined through status information and the first communication log, and the IP address of the first IP device to be detected, the subnet number of the subnet to which it belongs, the port number and the IP device type are recorded. It can be understood that the communication records between the server and the IP device recorded by the server in the existing network environment are parsed, and the first IP device to be detected connected to the server is determined from the communication records in the work log, and the IP address, subnet number, port number and device type of the device are recorded.

[0060] S230: Send a communication message to the first IP device to be detected, and detect the online status of the IP device connected to the server based on the communication message.

[0061] In this embodiment, a communication message is sent to the first IP device to be detected. The communication may include an ICMP or TCP message. The information that may be carried in the message includes but is not limited to a server ID, a ping request, and a timestamp for port scanning. Specifically, an ICMPECHO / TIMESTAMP / NETMASK message, a TCPSYN / ACK data packet and an SCTPINIT data packet are sent to the first IP device to be detected, thereby detecting the online status of the IP device directly connected to the server through the communication message.

[0062] S240. Receive message reply information from each first IP device to be detected within a preset time period, and determine whether the server is in a normal connection state with the first IP device to be detected based on the message reply information, and classify the first IP device to be detected in a normally connected state according to the subnet number of the first IP device to be detected and store it in the IP asset library.

[0063] In this embodiment, after sending a message to the IP device, the message reply information of each first IP device to be detected is received within a preset time length. As long as a data reply is received from the IP device within the fixed time length, it is determined that the IP device is normally connected to the server, and the normally connected IP device is included in the asset library and stored in the IP asset library according to the subnet number of the first IP device to be detected.

[0064] S250 : For the second IP device to be detected, obtain the communication rate of the server to each subnet, and use the communication rate as the fading speed to generate a test function that decays over time.

[0065] In this embodiment, the communication rate of the server to each subnet is obtained, and the communication rate is used as the fading speed to generate a test function that decays over time. The test function is expressed as: G(t) = mod(t / t0)·T max ·e -V·t ; In the formula, G(t) represents the test function, t0 is the test period, mod is the remainder function, t is the current scan time, T max is the maximum delay that the IP devices in each subnet can receive, and V is the communication rate of the server to each subnet.

[0066] S260. At the start of the scanning clock of each subnet, the current scanning time corresponding to each time is used as the input of the test function according to the preset time period, and the output of the test function is used as the communication delay between the server and each subnet.

[0067] In this embodiment, an independent scan clock is set for each subnet, and the scan clocks of each subnet do not overlap with each other. When the scan clock of the subnet starts, the server inputs the current time into the test function at fixed intervals, and uses the output value as the communication delay. This communication delay can be used to detect the flickering window, so that the communication port between the server and the subnet is occupied for the length of the communication delay and enters the flickering state. The window in which the communication port is occupied serves as the flickering window.

[0068] S270. After detecting the communication delay, the routing device in the second IP device to be detected sends a connection signal to the next-hop device and obtains reply information corresponding to the connection signal. The connection signal that receives the reply information is recorded as a valid signal, and the connection signal that does not receive the reply information is recorded as an invalid signal.

[0069] In this embodiment, after the routing device in the IP device to be detected detects the communication delay, it sends a connection signal to the next-hop device and obtains the reply information corresponding to the connection signal. The connection signal that receives the reply information is recorded as a valid signal, and the connection signal that does not receive the reply information is recorded as an invalid signal. It can be understood that after detecting that there is a communication delay on the server port, a ping connection signal is sent to the next-hop IP device with a constant window, and the received reply signal is recorded. The ping signal that does not receive a reply signal is a failed signal, and the time window in which the failed signal is located is recorded as an unanswered window, which means that the communication port of the next-hop IP device is occupied.

[0070] S280: Record the time window where the failure signal is located, and use the time window as the unanswered window.

[0071] In this embodiment, the time window in which the failure signal is located is recorded and used as the unresponsive window, wherein the unresponsive window indicates that the communication port of the next-hop device is in an occupied state.

[0072] S290: Compare the unanswered window with the flashing window of the server to obtain a comparison result.

[0073] In this embodiment, the unanswered window is compared with the flashing window of the server to check whether the unanswered window and the flashing window of the server are both in the flashing state (occupied state). If the consistency of the comparison result is higher than the preset threshold, the IP of the next-hop device corresponding to the unanswered window is included in the IP asset library.

[0074] S2100: If the consistency of the comparison result is higher than a preset threshold, the IP address of the next-hop device corresponding to the unanswered window is added to the IP asset library.

[0075] In this embodiment, if the consistency of the comparison result is higher than a preset threshold, that is, the unresponsive window is consistent with the server flashing window, the IP of the next-hop device corresponding to the unresponsive window is included in the IP asset library.

[0076] S2110. Scan each subnet in sequence according to a preset scanning time. If the communication port status of an IP device in another subnet is occupied within the scanning time of each subnet, determine that the IP device in the occupied state is the associated IP device corresponding to the subnet.

[0077] The preset scan time is the scan time of the customized device.

[0078] In this embodiment, each subnet is scanned in sequence according to a preset scanning time. If the communication port status of the IP device in other subnets is in an occupied state within the scanning time length of each subnet, the IP device in the occupied state is determined to be the associated IP device corresponding to the subnet. For example, there are two subnets, and these two subnets are scanned in sequence. The communication port status of two IP devices is in an occupied state, that is, a flashing state, within the scanning time length of subnet 1. At this time, when scanning subnet 2, if the communication port status of one or more IP devices in subnet 2 is in an occupied state within the scanning clock of subnet 1, the IP devices in subnet 2 and the IP devices in subnet 1 are associated IP devices.

[0079] S2120: Address the associated IP device to determine the routing device connected to the associated IP device.

[0080] In this embodiment, the associated IP device is addressed to determine the routing device connected to the associated IP device. Specifically, a ping command is sent to each flashing IP, that is, the IP whose communication port status is occupied, and after obtaining the corresponding address, it is broadcast to obtain a routing response to determine the routing device connected to the associated IP device.

[0081] S2130: Use the routing device connected to the associated IP device as an edge device, and use the edge device to parse the communication log between the associated IP device and the server to obtain a parsing result.

[0082] In this embodiment, the routing device connected to the associated IP device is used as an edge device, and the edge device is used to parse the communication log between the associated IP device and the server to obtain a parsing result, wherein the parsing result at least includes: the amount of communication data generated during each communication process, the network segment and subnet number of the communication address. Specifically, the communication log between the relevant IP and the server is parsed to obtain the amount of communication data, the network segment and subnet number of the communication address during each communication process.

[0083] S2140, using the communication data volume as the length, the network segment and subnet number of the communication address as the horizontal and vertical directions of the pointer respectively, generates a corresponding virtual pointer for the communication record generated by each communication log, and organizes each virtual pointer into an IP access pointer cluster corresponding to the associated IP device.

[0084] In this embodiment, a virtual pointer is generated for each communication log entry, using the communication data volume as the length and the network segment and subnet number of the communication address as the horizontal and vertical directions of the pointer, respectively. Each virtual pointer is then grouped into an IP access pointer cluster corresponding to the associated IP device. For example, each time a host communicates with a server, a communication log entry is generated on the host, and a virtual pointer is generated for each communication log entry.

[0085] S2150: Cluster the IP access pointer clusters using edge devices, and add all virtual pointers in the cluster to obtain a cluster pointer.

[0086] In this embodiment, when clustering is performed, one of the pointers in the pointer cluster is determined to represent the pointing of the entire pointer cluster, where the pointing represents the network segment and subnet number, and then all virtual pointers in the cluster are added together to obtain a cluster pointer.

[0087] S2160: Determine the cluster standard deviation based on the cluster pointer, and include the network segments within the cluster standard deviation and with communication data volume higher than a preset threshold into the IP asset library as proxy routes.

[0088] In this embodiment, the cluster standard deviation is determined based on the cluster pointer, and network segments within the cluster standard deviation and with communication data volume higher than a preset threshold are included in the IP asset library as proxy routes. This can be understood as recording network segment addresses within the cluster standard deviation of the cluster pointer and with communication data volume higher than the threshold as proxy routes and included in the asset library. The cluster standard deviation is expressed as: Where s is the cluster standard deviation, n is the number of pointers in the pointer cluster, Wi represents the i-th pointer, and E is the cluster pointer.

[0089] For example, the known IP of the server is in two subnets, and it is found that the routing response frequency of the IP device in the two subnets is consistent with the flashing frequency of the server. The address 192.162.101.023 of the IP device is taken as the conflicting IP. The communication log of the conflicting IP is parsed, and it is found that there are communication records between the conflicting IP and the two IP addresses. The communication data volume is 20GB and 5GB respectively. The addresses are 192.162.210.001 and 192.162.140.011 respectively. The clustering result (clustering address) is 192.162.190.000, and the clustering range is 30. The IP address 192.162.210.001 in the clustering range is included in the IP assets.

[0090] The above technical solution of the embodiment of the present invention uses the communication rate of the server to each subnet and uses the communication rate as the fading speed to generate a test function that decays over time. At the beginning of the scanning clock of each subnet, the current scanning time corresponding to each time is used as the input of the test function according to the preset time period, and the output of the test function is used as the communication delay between the server and each subnet. After the routing device in the second IP device to be detected detects the communication delay, it sends a connection signal to the next hop device and obtains the reply information corresponding to the connection signal. The connection signal that receives the reply information is recorded as a valid signal, and the connection signal that does not receive the reply information is recorded as a failed signal. The time window in which the failed signal is located is recorded, and the time window is recorded. The unanswered window is used as the unanswered window, and the unanswered window is compared with the server's flashing window to obtain a comparison result. If the consistency of the comparison result is higher than the preset threshold, the IP of the next-hop device corresponding to the unanswered window is included in the IP asset library. By generating a periodic test function that decays over time, the communication delay of the server is flashed according to the test function, and a probe message is sent to the known IP in the subnet and the clock is set. The IP with the same unanswered window and flashing window is identified as a server asset. The data timing is used as the unique fingerprint for IP identification, which saves the server time of scanning IPs in sequence, helps to quickly discover hidden IP assets, optimize network configuration, and reduce IP resource waste.

[0091] In the embodiment of the application, by sequentially scanning each subnet according to a preset time, in the case that the communication port state of the IP device of other subnets exists in the occupied state within the scanning time length of each subnet, the IP device in the occupied state is determined as the associated IP device corresponding to the subnet, the associated IP device is addressed to determine that the routing device connected with the associated IP device is used as the edge device, and the communication log between the associated IP device and the server is parsed using the edge device to obtain a parsing result, the communication record generated by each communication log is generated into a corresponding virtual pointer, each virtual pointer is composed into an IP access pointer cluster corresponding to the associated IP device, the IP access pointer cluster is clustered by using the edge device, all virtual pointers in the cluster are added to obtain a cluster pointer, the cluster standard deviation is determined according to the cluster pointer, and the network segment located in the cluster standard deviation and having a communication data volume higher than a preset threshold is taken as a proxy routing and included in the IP asset library. The proxy routing of the related IP can be determined by discovering the clock flicker across the subnet, obtaining the routing communication log of the related IP, taking the communication data volume as the length, generating the pointer cluster of the related IP pointing to the routing address, and performing cluster clustering, thereby improving the security and operation efficiency of the server.

[0092] In an embodiment, Figure 3 A structural block diagram of an IP asset detection and identification system is provided for an embodiment of the application. The system is suitable for the case of detecting and identifying IP assets. The system can be implemented by hardware / software. The system can be configured in an electronic device to implement an IP asset detection and identification method in an embodiment of the application. As shown in the figure, the system includes a message detection module 310, a communication time delay adjustment module 320, a window state identification module 330, and an edge computing module 340. Figure 3

[0093] The message detection module 310 is configured to include a first to-be-detected IP device in an IP asset library based on the state information of a server and a first communication log, wherein the first to-be-detected IP device is in a normal connection state with the server.

[0094] The communication time delay adjustment module 320 is configured to obtain the communication rate of the server for each subnet for a second to-be-detected IP device, adjust the communication time delay of the server for each subnet based on the communication rate and the preconfigured scanning clock of each subnet, and make the communication port of the server facing each subnet enter an occupied flicker state as a flicker window. Each of the subnets can include a plurality of to-be-detected IP devices.

[0095] ​The window status identification module 330 is configured to send a connection signal to the next-hop device after the routing device in the second IP device to be detected detects the communication delay, determine the communication port status of the next-hop device based on the reply information of the connection signal, and determine whether the IP address of the next-hop device is included in the IP asset library based on the flashing window of the server and the communication port status of the next-hop device;

[0096] The edge computing module 340 is used to detect the associated IP devices between each of the subnets, form an IP access pointer cluster based on the second communication log of the associated IP device, cluster the IP access pointer cluster, and incorporate the clustering results into the IP asset library as a proxy route.

[0097] In an embodiment of the present invention, the message detection module includes the first IP device to be detected that is in a normal connection state with the server into the IP asset library; the communication delay adjustment module adjusts the communication delay for the second IP device to be detected based on the communication rate and the scanning clock of each subnet, so that the communication port of the server enters the occupied flashing state as a flashing window; the window state identification module determines the communication port state of the next-hop device based on the reply information of the next-hop device after the routing device in the IP device to be detected detects the communication delay, and determines whether the IP of the next-hop device is included in the IP asset library based on the flashing window and communication port state of the server; the edge computing module detects the associated IP devices between each subnet, forms an IP access pointer cluster based on the second communication log of the associated IP device, and includes the clustering result as a proxy route into the IP asset library after clustering. The above technical solution can realize the accurate identification of IP assets and improve the detection efficiency of IP assets.

[0098] In one embodiment, the system further includes:

[0099] a risk assessment module, configured to obtain parameter information corresponding to the IP assets in the IP asset library, input the parameter information into a pre-built risk threat model, and output a risk value of the IP assets;

[0100] The security decision module is used to make risk protection decisions and clean up invalid IP assets based on the risk value.

[0101] In one embodiment, the security decision module further includes:

[0102] a risk protection unit, configured to update a security configuration of the server according to the risk value to perform risk protection;

[0103] An IP asset merging unit, configured to retrieve IP assets with consistent risk values ​​from the asset library, merge the IP assets, and obtain a merged target IP asset;

[0104] The asset cleanup unit is used to clean up the target IP assets whose risk values ​​are higher than a preset risk threshold and are not related to the business.

[0105] In one embodiment, the message detection module 310 includes:

[0106] A status monitoring unit, configured to monitor the status information of the server; wherein the status information includes at least: port status, routing connection status, and data transmission status;

[0107] a first IP device to be detected determining unit, configured to obtain a first communication log recorded by the server, determine a first IP device to be detected connected to the server based on the status information and the first communication log, and record an IP address, a subnet number of a subnet to which the first IP device to be detected belongs, a port number, and an IP device type;

[0108] An IP device online status determining unit, configured to send a communication message to the first IP device to be detected, and detect the online status of the IP device connected to the server based on the communication message;

[0109] The first IP device asset determination unit is used to receive message reply information from each of the first IP devices to be detected within a preset time period, and determine whether the server is in a normal connection state with the first IP device to be detected based on the message reply information, and classify the first IP devices to be detected in a normally connected state according to the subnet number of the first IP device to be detected and store them in the IP asset library.

[0110] In one embodiment, the communication delay adjustment module 320 includes:

[0111] A test function determination unit is used to use the communication rate as the fading speed to generate a test function that decays over time; wherein the test function is expressed as: G(t) = mod(t / t0)·T max ·e -V·t ; In the formula, G(t) represents the test function, t0 is the test period, mod is the remainder function, t is the current scan time, T max is the maximum delay that can be received by the IP device in each subnet, and V is the communication rate of the server to each subnet;

[0112] The delay determination unit is used to start the scanning clock of each subnet, use the corresponding current scanning time as the input of the test function according to a preset time period, and use the output of the test function as the communication delay between the server and each subnet.

[0113] In one embodiment, the window state identification module 330 includes:

[0114] a failure signal determination unit, configured to obtain reply information corresponding to the connection signal, record the connection signal receiving the reply information as a valid signal, and record the connection signal not receiving the reply information as a failure signal;

[0115] an unanswered window determining unit, configured to record a time window in which the failure signal is located, and use the time window as an unanswered window; wherein the unanswered window indicates that the communication port state of the next-hop device is in an occupied state;

[0116] a window status comparison unit, configured to compare the unanswered window with the flashing window of the server to obtain a comparison result;

[0117] The second IP device asset determination unit is configured to add the IP of the next hop device corresponding to the unanswered window into an IP asset library if the consistency of the comparison result is higher than a preset threshold.

[0118] In one embodiment, the edge computing module 340 includes:

[0119] A subnet scanning unit, configured to sequentially scan each of the subnets according to a preset time;

[0120] an associated IP determining unit, configured to, when a communication port state of an IP device in another subnet is in an occupied state within a scanning time length of each subnet, determine that the IP device in the occupied state is an associated IP device corresponding to the subnet;

[0121] a cross-network addressing unit, configured to address the associated IP device to determine a routing device connected to the associated IP device;

[0122] a parsing unit, configured to use a routing device connected to the associated IP device as an edge device, and use the edge device to parse the communication log between the associated IP device and the server to obtain a parsing result; wherein the parsing result includes at least: the amount of communication data generated during each communication process, the network segment and subnet number of the communication address;

[0123] a pointer generating unit, configured to generate a corresponding virtual pointer for each communication record generated by the communication log, using the communication data volume as the length and the network segment and subnet number of the communication address as the horizontal direction and vertical direction of the pointer respectively, and to form an IP access pointer cluster corresponding to the associated IP device with each virtual pointer;

[0124] A pointer clustering unit, configured to cluster the IP access pointer cluster using the edge device, and add all virtual pointers in the cluster to obtain a cluster pointer;

[0125] The third IP device asset determination unit is configured to determine a cluster standard deviation based on the cluster pointer, and include network segments within the cluster standard deviation and with a communication data volume higher than a preset threshold into the IP asset library as proxy routes.

[0126] In one embodiment, the cluster standard deviation is expressed as: Where s is the cluster standard deviation, n is the number of pointers in the pointer cluster, Wi represents the i-th pointer, and E is the cluster pointer.

[0127] In one embodiment, to facilitate a better understanding of the IP asset detection and identification system, Figure 4 This is an architectural diagram of another IP asset detection and identification system provided by an embodiment of the present invention.

[0128] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.

[0129] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. A method for detecting and identifying IP assets, characterized in that: Applied to an IP asset detection and identification system, the method includes: Adding a first IP device to be detected that is in a normal connection state with the server into the IP asset library based on the server status information and the first communication log; For the second IP device to be detected, obtaining the communication rate of the server to each subnet, and adjusting the communication delay between the server and each subnet based on the communication rate and a pre-configured scan clock of each subnet, so that the communication port of the server facing each subnet enters an occupied flashing state as a flashing window; wherein each subnet may include multiple second IP devices to be detected; After the routing device in the second IP device to be detected detects the communication delay, it sends a connection signal to the next-hop device, determines the communication port status of the next-hop device based on the reply information of the connection signal, and determines whether the IP address of the next-hop device is included in the IP asset library based on the flashing window of the server and the communication port status of the next-hop device; Detect the associated IP devices between each of the subnets, form an IP access pointer cluster based on the second communication log of the associated IP device, cluster the IP access pointer cluster, and incorporate the clustering results into the IP asset library as a proxy route.

2. The method according to claim 1, characterized in that The method further comprises: Obtaining parameter information corresponding to the IP assets in the IP asset library, and inputting the parameter information into a pre-built risk threat model to output a risk value of the IP assets; Make risk protection decisions and clean up invalid IP assets based on the risk value.

3. The method according to claim 2, characterized in that The risk protection decision-making based on the risk value and the cleanup of invalid IP assets include: Update the security configuration of the server according to the risk value to perform risk protection; Retrieving IP assets with consistent risk values ​​in the asset library, merging the IP assets to obtain a merged target IP asset; For each of the target IP assets, the target IP assets with risk values ​​higher than the preset risk threshold and not related to the business will be cleared.

4. The method according to claim 1, wherein The step of adding the first IP device to be detected that is in a normal connection state with the server into the IP asset library based on the server status information and the first communication log includes: Monitoring the status information of the server; wherein the status information includes at least: port status, routing connection status and data transmission status; Obtaining a first communication log recorded by the server, determining a first IP device to be detected connected to the server based on the status information and the first communication log, and recording an IP address, a subnet number of a subnet to which the first IP device to be detected belongs, a port number, and an IP device type; Sending a communication message to the first IP device to be detected, and detecting the online status of the IP device connected to the server based on the communication message; Receive message reply information from each of the first IP devices to be detected within a preset time period, and determine whether the server is in a normal connection state with the first IP device to be detected based on the message reply information, and classify the first IP devices to be detected in a normally connected state according to the subnet number of the first IP device to be detected and store them in the IP asset library.

5. The method according to claim 1, characterized in that The adjusting the communication delay between the server and each subnet based on the communication rate and the pre-configured scan clock of each subnet so that the communication port of the server facing each subnet enters an occupied flashing state as a flashing window includes: The communication rate is used as the fading speed to generate a test function that decays over time; wherein the test function is expressed as: G(t) = mod(t / t0)·T max ·e -V·t ; In the formula, G(t) represents the test function, t0 is the test period, mod is the remainder function, t is the current scan time, T max is the maximum delay that can be received by the IP device in each subnet, and V is the communication rate of the server to each subnet; At the start of the scanning clock of each subnet, the current scanning time corresponding to each time is used as the input of the test function according to a preset time period, and the output of the test function is used as the communication delay between the server and each subnet.

6. The method according to claim 1, characterized in that The determining the communication port status of the next-hop device based on the reply information of the connection signal, and determining whether the IP address of the next-hop device is included in the IP asset library based on the flashing window of the server and the communication port status of the next-hop device, includes: Obtaining reply information corresponding to the connection signal, recording the connection signal that receives the reply information as a valid signal, and recording the connection signal that does not receive the reply information as an invalid signal; Recording a time window in which the failure signal is located, and using the time window as an unanswered window; wherein the unanswered window indicates that the communication port state of the next-hop device is in an occupied state; Comparing the unanswered window with the flashing window of the server to obtain a comparison result; If the consistency of the comparison result is higher than a preset threshold, the IP address of the next-hop device corresponding to the unanswered window is included in the IP asset library.

7. The method according to claim 1, characterized in that The detecting of associated IP devices between the subnets, forming IP access pointer clusters based on the second communication logs of the associated IP devices, clustering the IP access pointer clusters, and incorporating the clustering results as proxy routes into the IP asset library includes: Scanning each of the subnets in sequence according to a preset scanning time, and if a communication port status of an IP device in another subnet is in an occupied state within the scanning time length of each subnet, determining that the IP device in the occupied state is an associated IP device corresponding to the subnet; Addressing the associated IP device to determine a routing device connected to the associated IP device; Using a routing device connected to the associated IP device as an edge device, and using the edge device to parse the communication log between the associated IP device and the server to obtain a parsing result; wherein the parsing result includes at least: the amount of communication data generated during each communication process, the network segment and subnet number of the communication address; With the communication data volume as the length, and the network segment and subnet number of the communication address as the horizontal direction and vertical direction of the pointer respectively, a corresponding virtual pointer is generated for each communication record generated by the communication log, and each virtual pointer is combined into an IP access pointer cluster corresponding to the associated IP device; Clustering the IP access pointer cluster using the edge device, and adding all virtual pointers in the cluster to obtain a cluster pointer; The cluster standard deviation is determined according to the cluster pointer, and the network segments within the cluster standard deviation and with the communication data volume higher than a preset threshold are included in the IP asset library as proxy routes.

8. The method according to claim 7, characterized in that The cluster standard deviation is expressed as: Where s is the cluster standard deviation, n is the number of pointers in the pointer cluster, Wi represents the i-th pointer, and E is the cluster pointer.

9. An IP asset detection and identification system, characterized in that: The system includes: a message detection module, a communication delay adjustment module, a window state identification module and an edge computing module; A message detection module, configured to add a first IP device to be detected that is in a normal connection state with the server into an IP asset library based on the server status information and the first communication log; a communication delay adjustment module, configured to obtain, for a second IP device to be detected, a communication rate of the server to each subnet, and adjust the communication delay between the server and each subnet based on the communication rate and a pre-configured scan clock of each subnet, so that the communication port of the server facing each subnet enters an occupied flashing state as a flashing window; wherein each subnet may include multiple IP devices to be detected; a window status identification module, configured to, after the routing device in the second IP device to be detected detects the communication delay, send a connection signal to the next-hop device, determine the communication port status of the next-hop device based on the reply information of the connection signal, and determine whether the IP address of the next-hop device is included in the IP asset library based on the flashing window of the server and the communication port status of the next-hop device; The edge computing module is used to detect the associated IP devices between each of the subnets, form an IP access pointer cluster based on the second communication log of the associated IP device, cluster the IP access pointer cluster, and incorporate the clustering results into the IP asset library as a proxy route.

10. The system according to claim 9, characterized in that The system further includes: a risk assessment module, configured to obtain parameter information corresponding to the IP assets in the IP asset library, input the parameter information into a pre-built risk threat model, and output a risk value of the IP assets; The decision-making module is used to make risk protection decisions and clean up invalid IP assets based on the risk value.