Service asset automatic management method, device, equipment, medium and product
By acquiring access traffic and combining it with probe requests, the system uses HTTP and HTTPS protocol standards or characteristic bytes to determine the traffic type and stores storage asset data based on response codes. This solves the problem of the large amount of manpower required for traditional scanning to acquire web service assets, achieving automated identification and management and reducing the pressure on operation and maintenance.
Patent Information
- Application Number
- CN202511109117.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-11-07
AI Technical Summary
Existing technologies require significant manpower to acquire web service assets, and network scanning may disrupt normal business operations, increasing the risk to production operations.
By acquiring access traffic and combining it with probe requests, service asset data is automatically identified and obtained. The traffic type is determined using HTTP and HTTPS protocol standards or characteristic bytes, and the service asset data is stored in the database based on the response code.
It enables automatic identification of user web service assets, reducing the burden on customers and operations and maintenance personnel, avoiding the impact of server scanning, and reducing the workload of operations and maintenance.
Smart Images

Figure CN120915767A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computers, and can be applied to the field of financial technology, and particularly relates to a service asset automatic management method, device, equipment, medium and product. BACKGROUND
[0002] At present, the diversification and complexity of the configuration of the web (World Wide Web) application firewall make users and operation and maintenance personnel spend a lot of time and effort in use and maintenance, and there is an urgent need for intelligent functions capable of automatically identifying service user assets, automatically adding configurations and optimizing policies, so as to reduce the pressure on customers and operation and maintenance personnel.
[0003] The existing technology obtains web asset information mainly by network scanning, and cooperates with API (Application Programming Interface) interfaces to collect network assets such as database information and middleware information; and some organizations or companies generally do not want defense-type security products to perform a large amount of scanning on the intranet, and the scanning needs to consume a large amount of manpower for operation and maintenance, and the scanning on the server may affect the normal operation of the business, and increase the production business operation risk.
[0004] Therefore, there is an urgent need for a method for automatically identifying user web service assets to achieve automatic discovery of assets and further reduce the pressure on customers and operation and maintenance personnel. SUMMARY
[0005] The present application provides a service asset automatic management method, device, equipment, medium and product, which solves the problem of consuming a large amount of manpower for obtaining web service assets by scanning, automatically identifies and obtains service asset data by obtaining access traffic and combining with a detection request, realizes automatic identification of user web service assets, and reduces the pressure on customers and operation and maintenance personnel.
[0006] According to an aspect of the present application, a service asset automatic management method is provided, applied to a switch, comprising:
[0007] Obtaining access traffic of a terminal or server intranet and the Internet;
[0008] Analyzing the access traffic to obtain service asset data; the service asset data includes HTTP and HTTPS site and virtual site information;
[0009] Initiating a detection request including the access traffic to a server, and storing the service asset data into a database based on a response code fed back by the server.
[0010] According to another aspect of the present application, there is provided a service asset automatic management apparatus, comprising:
[0011] an acquisition module configured to acquire access traffic of a terminal or a server intranet to the Internet;
[0012] a parsing module configured to parse the access traffic to obtain service asset data; the service asset data comprising HTTP and HTTPS site and virtual site information;
[0013] a storage module configured to initiate a probe request comprising the access traffic to a server, and store the service asset data into a database based on a response code fed back by the server.
[0014] According to another aspect of the present application, there is provided an electronic device, comprising:
[0015] at least one processor; and
[0016] a memory communicatively connected to the at least one processor; wherein
[0017] the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the service asset automatic management method according to any one of the embodiments of the present application.
[0018] According to another aspect of the present application, there is provided a computer readable storage medium storing computer instructions for enabling a processor to perform the service asset automatic management method according to any one of the embodiments of the present application.
[0019] According to another aspect of the present application, there is provided a computer program product comprising a computer program for enabling a processor to perform the service asset automatic management method according to any one of the embodiments of the present application when executed by the processor.
[0020] The technical solution of the embodiments of the present application solves the problem of consuming a large amount of manpower in obtaining web service assets by scanning, and automatically identifies and obtains service asset data by acquiring access traffic and combining probe requests, thereby realizing automatic identification of user web service assets and reducing the pressure on customers and operation and maintenance personnel.
[0021] It should be understood that the content described in this section is not intended to identify key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0022] In order to make the technical solutions in the embodiments of the present application clearer, the accompanying drawings needed in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description only show some embodiments of the present application, and all other embodiments obtained by those of ordinary skill in the art without any creative effort based on the accompanying drawings should fall within the protection scope of the present application.
[0023] Figure 1 is a flow chart of a service asset automatic management method according to an embodiment of the present application;
[0024] Figure 2 is a flow chart of a service asset automatic management method according to an embodiment of the present application;
[0025] Figure 3 is a flow chart of a service asset automatic management method according to an embodiment of the present application;
[0026] Figure 4 is a design diagram of a service asset automatic management method according to an embodiment of the present application;
[0027] Figure 5 is a structural schematic diagram of a service asset automatic management device according to an embodiment of the present application;
[0028] Figure 6 is a structural schematic diagram of an electronic device implementing a service asset automatic management method according to an embodiment of the present application. DETAILED DESCRIPTION
[0029] In order to make the technical solutions in the embodiments of the present application clearer, the accompanying drawings needed in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description only show some embodiments of the present application, and all other embodiments obtained by those of ordinary skill in the art without any creative effort based on the accompanying drawings should fall within the protection scope of the present application.
[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0031] Furthermore, it should be noted that the collection, storage, use, processing, transmission, provision, and disclosure of traffic data packets and the like in the technical solution of this invention all comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0032] Figure 1 This invention provides a flowchart of an automatic service asset management method. This embodiment is applicable to identifying user service assets, particularly for the automatic acquisition of web service assets. The method can be executed by an automatic service asset management device, which can be implemented in hardware and / or software and can be configured in a switch. Figure 1 As shown, the method includes:
[0033] S110: Obtain access traffic between the terminal or server's intranet and the Internet.
[0034] Among them, the terminal is the user terminal access, which can be a user device such as a mobile terminal or a computer terminal; the server intranet is a database server or application cluster; the Internet is a public external network; access traffic can be the data generated when accessing network assets; network assets can be such as websites, servers or applications; access traffic can be network traffic packets, client requests and server responses obtained by HTTP (Hypertext Transfer Protocol) proxies, etc.
[0035] Specifically, it can capture access traffic from terminals accessing the server's intranet or the internet, or access traffic from the server's intranet to the internet.
[0036] Optionally, obtain the intranet access traffic of the terminal or server to the Internet, including:
[0037] Based on the mirroring method, obtain the access traffic between the terminal or server's intranet and the Internet.
[0038] The mirroring mode is a port mirroring technology.
[0039] Specifically, the switch replicates the access traffic between the terminal or server intranet and the Internet through the port mirroring technology, that is, the switch replicates the traffic of the source port and sends it to the designated observation port, specifically, replicates the traffic entering the source port in the port entry direction, replicates the traffic from the source port in the port exit direction, or replicates the traffic in and out at the same time.
[0040] It can be understood that the access traffic between the terminal or server intranet and the Internet is obtained through the port mirroring mode, and compared with the prior art of collecting network assets through network scanning combined with a software development kit or an interface, the port mirroring mode does not need to scan the intranet assets, guarantees the privacy of the defense type security product, and can quickly obtain the in and out traffic, thereby improving the information collection effect of the web server site and virtual site.
[0041] S120, analyzing the access traffic to obtain service asset data; the service asset data includes HTTP and HTTPS site and virtual site information.
[0042] The service asset data is web asset information, including HTTP and HTTPS (Hypertext Transfer Protocol over Secure Socket Layer, secure layer hypertext transfer protocol) site and virtual site information; the site information can be the ip (Internet Protocol) address and port corresponding to the site, or the ip address, port and domain name information.
[0043] Specifically, the access traffic obtained by replication is analyzed to obtain the ip address, port and domain name information corresponding to the access traffic.
[0044] In an optional mode of the present application, the HTTP protocol standard or HTTPS characteristic byte can be used to judge the access traffic type, and further based on the traffic type, the bytes in the access traffic are extracted to obtain the ip address, port and domain name information of the access traffic.
[0045] S130, initiating a detection request including the access traffic to the server, and storing the service asset data into the database based on the response code fed back by the server.
[0046] The detection request is an access request to the server to determine whether the current access traffic exists.
[0047] Specifically, a detection request including access traffic is initiated to the server, a response code fed back by the server is acquired, it is judged whether the current access traffic exists based on the response code, if yes, service asset data corresponding to the access traffic is stored into a database.
[0048] It can be understood that, depending on the flexible and reliable web service detection mechanism, available network services can be effectively identified and key information can be stored.
[0049] Optionally, a detection request including access traffic is initiated to the server, and service asset data is stored into a database based on a response code fed back by the server, including:
[0050] A detection request including access traffic is initiated to the server, and a response code is acquired.
[0051] If the response code is a valid value, service asset data corresponding to the access traffic is stored into a database.
[0052] The response code is a response status code of the detection request, used to indicate whether the access traffic can be normally accessed, such as 200, 404, etc.; and the valid value is a valid range value corresponding to the response status code.
[0053] Specifically, a detection request corresponding to access traffic is initiated to the server, and a response status code corresponding to the detection request is captured, when the status code is in a specified range, for example, the response status code is greater than or equal to 200 and less than 400, the IP address, port and domain name information of the access traffic are stored into a database.
[0054] It can be understood that, by combining the detection request to judge the acquired access traffic, the HTTP or HTTPS site and virtual site information corresponding to the access traffic that can be normally accessed are stored, the service asset data is further effectively managed while ensuring the automatic identification of user web service assets, and the information collection accuracy of the site and virtual site of the web server is ensured.
[0055] The embodiment of the application acquires access traffic of a terminal or a server intranet and the Internet, analyzes the access traffic to obtain service asset data, the service asset data includes HTTP and HTTPS site and virtual site information, a detection request including the access traffic is initiated to the server, and the service asset data is stored into a database based on a response code fed back by the server; the above technical solution solves the problem that a lot of manpower is consumed in the traditional acquisition of web service assets through network scanning, avoids the influence of scanning the server on the normal operation of the business, increases the production business operation risk, realizes the automatic identification of user web service assets, and reduces the pressure of customers and operation and maintenance personnel.
[0056] Figure 2 is a flow chart of a service asset automatic management method according to an embodiment of the present application. The embodiment of the present application is based on the above-mentioned embodiment and supplements the service asset data obtained by analyzing the access traffic. It should be noted that the parts not described in detail in the embodiment of the present application can refer to the relevant descriptions of other embodiments, such as Figure 2 as shown in the figure, the method comprises the following steps.
[0057] S210, obtaining the access traffic between the terminal or server intranet and the Internet.
[0058] S220, extracting the fields of the access traffic based on the preset bytes and analyzing the fields to obtain the IP header, the TCP header and the application data.
[0059] The preset bytes are the IP data segment, the TCP (Transmission Control Protocol segment) data segment and the application data segment in the access traffic. The preset bytes can be 46-1500 bytes of the access traffic. The application data includes the APP (Application) header and the user data.
[0060] Specifically, 46-1500 bytes of the access traffic are extracted based on the preset bytes, and the IP header, the TCP header and the application data in the 46-1500 bytes are analyzed.
[0061] S230, performing type judgment on the application data based on the standard protocol or the characteristic byte to obtain a judgment result.
[0062] The standard protocol is the HTTP protocol standard. The characteristic byte is the characteristic byte corresponding to HTTPS, which can be the "TLS (Transport Layer Security)" or "SSL (Secure Sockets Layer)" protocol.
[0063] Specifically, the application data is analyzed based on the standard protocol to determine whether it contains the HTTP request / response line, the HTTP request / response header and the HTTP request / response body. Or, it is determined based on the characteristic byte whether the TCP part of the application data contains the "TLS" or "SSL" characteristic byte.
[0064] S240, determining the traffic type of the access traffic based on the judgment result. The traffic type includes HTTP traffic or HTTPS traffic,
[0065] Specifically, according to the judgment result, if the application data contains HTTP request / response line, HTTP request / response header, HTTP request / response body, the traffic type of the access traffic is HTTP traffic; if the TCP part of the application data contains "TLS" or "SSL" characteristic bytes, the traffic type of the access traffic is HTTPS traffic.
[0066] It can be understood that the http protocol standard or the https characteristic byte is used to judge whether the access traffic is http traffic and https traffic, and compared with the prior art of judging the access traffic type through the port, the accuracy and comprehensiveness of the access traffic type judgment are higher.
[0067] S250, the service asset data is obtained by parsing the access traffic based on the traffic type.
[0068] Among them, the service asset data corresponding to the access traffic is obtained by parsing the access traffic according to the traffic type, which can be an IP address, a port and a domain name.
[0069] Optionally, the service asset data is obtained by parsing the access traffic based on the traffic type, including:
[0070] If the traffic type is HTTP traffic, the IP field, the port field and the domain name field in the access traffic are extracted;
[0071] The IP field, the port field and the domain name field are subjected to hash operation to obtain a target hash value, and the target hash value is taken as the service asset data.
[0072] Specifically, if the traffic type of the access traffic is HTTP traffic, the IP field, the port field and the domain name field in the access traffic are extracted, and the IP field, the port field and the domain name field are subjected to hash operation to obtain a target hash value, and the target hash value is taken as the service asset data.
[0073] It can be understood that the service asset data is obtained in advance for subsequent rapid access data. When a large amount of access traffic needs to be identified corresponding service asset data, it can be subjected to hash operation and cached by using a hash table, so as to quickly find all service asset data corresponding to the access traffic according to a certain service asset data of the access traffic.
[0074] S260, a detection request including the access traffic is initiated to the server, and the service asset data is stored into the database based on the response code fed back by the server.
[0075] Specifically, while the service asset data of the access traffic is cached, a probe request including the access traffic is initiated to the server, and according to a response code fed back, if the response code is a valid value, it indicates that the access traffic is valid, and then the service asset data of the access traffic can be found from the service asset data based on the IP address in the access traffic.
[0076] In an optional mode of the present application, the service asset data is cached in a hash structure, and then the corresponding port field and domain name field can be found based on the IP field of the access traffic, or the corresponding domain name field can be found based on the IP field and the port field of the access traffic, or the corresponding IP field and port field can be found based on the domain name field of the access traffic, which is not limited in the present application.
[0077] In the present application, the HTTP protocol standard or the HTTPS characteristic byte is used to judge the traffic type of the extracted application data, which ensures the accuracy of the type judgment and is more comprehensive compared with the port judgment.
[0078] Figure 3 is a flow chart of a service asset automatic management method according to an embodiment of the present application, which supplements the method for analyzing the access traffic with the HTTPS traffic to obtain the service asset data based on the above-mentioned embodiments. Figure 3 The method comprises the following steps:
[0079] S310, access traffic between a terminal or a server intranet and the Internet is obtained.
[0080] S320, fields of the access traffic are extracted based on a preset byte, and an IP header, a TCP header and application data are obtained by analyzing the fields.
[0081] S330, the application data is judged based on a standard protocol or a characteristic byte to obtain a judgment result.
[0082] S340, the traffic type of the access traffic is determined based on the judgment result, and the traffic type includes HTTP traffic or HTTPS traffic.
[0083] S350, if the traffic type of the access traffic is the HTTPS traffic, then the to-be-analyzed field, the IP field and the port field in the access traffic are extracted, and the to-be-analyzed field is analyzed.
[0084] The to-be-analyzed field is an SNI (Server Name Indication) field of HTTPS, and the SNI is a data packet containing SNI information in the HTTPS traffic data packet.
[0085] Specifically, when the HTTPS access traffic is obtained, the SNI field, the IP field and the port field in the access traffic are extracted, and the SNI field is parsed, and the domain name information requested by the access traffic can be found through the parsing.
[0086] S360, if the parsing is successful, the domain name field, the IP field and the port field in the parsing result are subjected to hash operation to obtain a first hash value, and the first hash value is taken as the service asset data.
[0087] The first hash value is a hash value of the domain name field, the IP field and the port field subjected to structured storage.
[0088] Specifically, if the SNI field is successfully parsed, the SNI field contains the domain name field, the domain name field, the IP field and the port field are subjected to hash operation to obtain a first hash value, and the first hash value is taken as the service asset data, and the service asset data is data information of the domain name field, the IP field and the port field subjected to hash table structuring.
[0089] S370, if the parsing fails, the IP field and the port field are subjected to hash operation to obtain a second hash value, and the second hash value is taken as the service asset data.
[0090] The second hash value is structured data containing the IP field and the port field.
[0091] Specifically, if the SNI field is not successfully parsed, the current access traffic does not contain domain name information, the IP field and the port field are subjected to hash operation to obtain a second hash value, and the second hash value is taken as the service asset data.
[0092] S380, a detection request including the access traffic is initiated to the server, and the service asset data is stored into the database based on a response code fed back by the server.
[0093] In an optional mode of the present application, a high-performance data packet processing development framework can be used for resolving and storing the access traffic, and the high-performance data packet processing development framework can include an HTTP decoding module, an HTTPS protocol resolving module, an asset discovery module, a database interaction module and a data forwarding module; specifically, the HTTP access traffic is resolved by the HTTP decoding module in the traffic resolving, and the ip-port-domain field information is obtained and cached by using a hash table structure; the HTTPS access traffic is resolved by the HTTPS protocol resolving module, and the ip-port (port) field and SNI information are obtained and cached by using a hash table structure, and the SNI field is further resolved, and the resolved domain name field is cached by using a hash table structure; after the access traffic is resolved, the access traffic is probed according to the rules formulated by the service probing function, and the cached data is filtered according to the response code in the probing result, and the database is updated through the database interaction interface.
[0094] It can be understood that, compared with the processing of access traffic by other architectures, the high-performance data packet processing development framework adopted by the embodiments of the present application bypasses the kernel protocol stack, optimizes hardware access and provides efficient data structures, and thus realizes low-delay and high-throughput data packet processing capability.
[0095] For HTTPS traffic, the embodiments of the present application extract the IP field, the port field and the SNI field, and cache the service asset data based on the resolving result of the SNI field, and obtain the virtual site information by combining the resolving of the SNI field and the service probing for the HTTPS traffic, thereby avoiding the problems caused by scanning and probing to obtain asset information, reducing the risk of scanning for enterprises from the perspective of security risk, greatly reducing the operation and maintenance workload of traditional scanning investment, and helping enterprises to effectively sort out web asset information.
[0096] Figure 4 It is a design drawing of a service asset automatic management method according to the embodiments of the present application.
[0097] When the access traffic is obtained, the HTTP protocol standard and the HTTPS characteristic byte can be used to identify the HTTP traffic or the HTTPS traffic, and whether the current access traffic is HTTPS traffic is determined.
[0098] If the current access traffic is HTTPS traffic, obtain the SNI field, IP field, and port field, and forward the HTTPS data packet; parse the SNI field; if SNI field parsing fails, directly record the IP and port. Insert the data into the database to form the IP-port hash structure corresponding to this access traffic; if SNI field parsing succeeds, obtain the domain field, initiate an HTTPS probe request, and obtain the response status. If the response status value is greater than or equal to 200 and less than 400, record the IP, port, and domain corresponding to this access traffic, and insert the data into the database to form the IP-port-domain hash structure corresponding to this access traffic.
[0099] If the current access traffic is not HTTPS traffic, then determine whether the current access traffic is HTTP traffic; if not, forward the traffic; if so, directly send a probe to the server, cache the IP, port and domain corresponding to the access traffic, and forward the traffic; obtain the response status, and if the response value is greater than or equal to 200 and less than 400, record the IP, port and domain corresponding to the access traffic, and insert them into the database to form a hash structure of IP-port-domain corresponding to the access traffic.
[0100] Figure 5 This is a schematic diagram of a service asset automatic management device according to an embodiment of the present invention. This embodiment is applicable to situations involving anomaly detection of logs, particularly complex logs. The service asset automatic management device can be implemented in hardware and / or software and can be configured within a switch. Figure 5 As shown, the service asset automatic management device 400 includes an acquisition module 410, a parsing module 420, and a storage module 430;
[0101] The acquisition module 410 is used to acquire the access traffic between the terminal or server's intranet and the Internet.
[0102] The parsing module 420 is used to parse the access traffic to obtain service asset data; the service asset data includes HTTPS and HTTP site and virtual site information;
[0103] Storage module 430 is used to send a probe request to the server, including access traffic, and store service asset data in the database based on the response code returned by the server.
[0104] The embodiment of the application acquires access traffic of a terminal or a server intranet and the Internet, analyzes the access traffic to obtain service asset data, the service asset data including HTTP and HTTPS site and virtual site information, initiates a detection request including the access traffic to a server, and stores the service asset data into a database based on a response code fed back by the server. The above technical solution solves the problem of consuming a large amount of manpower in obtaining web service assets by traditional network scanning, avoids affecting normal business operation by scanning the server, increases production business operation risk, realizes automatic identification of user web service assets, and reduces the pressure on customers and operation and maintenance personnel.
[0105] Optionally, the analysis module 420 includes an extraction unit, a judgment unit, a traffic type determination unit and an analysis unit.
[0106] The extraction unit is configured to extract fields of the access traffic based on preset bytes, and analyze the fields to obtain IP headers, TCP headers and application data.
[0107] The judgment unit is configured to judge the type of the application data based on standard protocols or characteristic bytes to obtain a judgment result.
[0108] The traffic type determination unit is configured to determine the traffic type of the access traffic based on the judgment result; the traffic type includes HTTP traffic or HTTPS traffic.
[0109] The analysis unit is configured to analyze the access traffic based on the traffic type to obtain service asset data.
[0110] Optionally, the analysis unit is specifically configured to, if the traffic type is HTTP traffic, extract IP fields, port fields and domain name fields in the access traffic; perform hash operation on the IP fields, the port fields and the domain name fields to obtain a target hash value, and take the target hash value as the service asset data.
[0111] Optionally, the analysis unit is specifically configured to, if the traffic type of the access traffic is HTTPS traffic, extract to-be-analyzed fields, IP fields and port fields in the access traffic, and analyze the to-be-analyzed fields; if the analysis is successful, perform hash operation on domain name fields, IP fields and port fields in an analysis result to obtain a first hash value, and take the first hash value as the service asset data; if the analysis fails, perform hash operation on the IP fields and the port fields to obtain a second hash value, and take the second hash value as the service asset data.
[0112] Optionally, the storage module 430 is specifically configured to initiate a detection request including the access traffic to a server, and obtain a response code; if the response code is a valid value, store service asset data corresponding to the access traffic into a database.
[0113] Optionally, the acquisition module 410 is specifically configured to acquire, based on a mirror mode, access traffic between a terminal or a server intranet and the Internet.
[0114] The service asset automatic management device provided by the embodiment of the application can execute the service asset automatic management method provided by any embodiment of the application, and has the corresponding function modules and beneficial effects of the execution method.
[0115] According to the embodiment of the application, the application further provides an electronic device, a readable storage medium and a computer program product.
[0116] Figure 6 A structural schematic diagram of an electronic device 10 that can be used to implement embodiments of the application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the applications described and / or claimed in this document.
[0117] As shown in Figure 6 The electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which are communicatively connected to the at least one processor 11, wherein the memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0118] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, a speaker, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0119] The processor 11 can be various general and / or special purpose processing components having processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 performs various methods and processes described above, such as the service asset automatic management method.
[0120] In some embodiments, the service asset automatic management method can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded onto the RAM 13 and executed by the processor 11, one or more steps of the service asset automatic management method described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to perform the service asset automatic management method by any other appropriate means, such as by means of firmware.
[0121] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a programmable logic device (PLD), a computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0122] Computer programs used to implement the methods of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the computer program, when executed by the processor of the machine, implements the functions / acts specified in the flowcharts and / or block diagrams. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a stand-alone software package, and partially on a machine or a remote machine or a server.
[0123] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. A computer-readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of a machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0124] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0125] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0126] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and dedicated virtual service.
[0127] It should be understood that the various forms of flow shown above can be used to reorder, add or delete steps. For example, each step described in the present application can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solutions of the present application can be achieved, which is not limited herein.
[0128] The above detailed description does not constitute a limitation on the scope of protection of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A service asset automatic management method characterized by, Applied to a switch, comprising: Obtaining access traffic of a terminal or a server intranet and the Internet; Parsing the access traffic to obtain service asset data; the service asset data includes HTTP and HTTPS site and virtual site information; Initiating a probe request including the access traffic to a server, and storing the service asset data into a database based on a response code fed back by the server.
2. The method of claim 1, wherein, The parsing the access traffic to obtain service asset data, comprising: Extracting fields of the access traffic based on preset bytes, and parsing the fields to obtain IP header, TCP header and application data; Judging the application data based on standard protocol or characteristic bytes to obtain a judgment result; Determining a traffic type of the access traffic based on the judgment result; the traffic type includes HTTP traffic or HTTPS traffic; Parsing the access traffic based on the traffic type to obtain service asset data.
3. The method of claim 2, wherein, The parsing the access traffic based on the traffic type to obtain service asset data, comprising: If the traffic type is HTTP traffic, extracting IP field, port field and domain name field in the access traffic; Hashing the IP field, the port field and the domain name field to obtain a target hash value, and taking the target hash value as service asset data.
4. The method of claim 2, wherein, The parsing the access traffic based on the traffic type to obtain service asset data, comprising: If the traffic type of the access traffic is HTTPS traffic, extracting a to-be-parsed field, IP field and port field in the access traffic, and parsing the to-be-parsed field; If the parsing is successful, hashing a domain name field in the parsing result, the IP field and the port field to obtain a first hash value, and taking the first hash value as service asset data; If the parsing fails, hashing the IP field and the port field to obtain a second hash value, and taking the second hash value as service asset data.
5. The method of claim 1, wherein, The initiating a probe request including the access traffic to a server, and storing the service asset data into a database based on a response code fed back by the server, comprising: Initiating a probe request including the access traffic to a server, and obtaining a response code; If the response code is a valid value, storing the service asset data corresponding to the access traffic into a database.
6. The method of claim 1, wherein, The obtaining access traffic of a terminal or a server intranet and the Internet, comprising: Obtaining access traffic of a terminal or a server intranet and the Internet based on a mirror mode.
7. A service asset automatic management apparatus characterized by comprising: Comprising: An obtaining module, configured to obtain access traffic of a terminal or a server intranet and the Internet; A parsing module, configured to parse the access traffic to obtain service asset data; The service asset data includes https and http site and virtual site information; A storage module, configured to initiate a probe request including the access traffic to a server, and store the service asset data into a database based on a response code fed back by the server.
8. An electronic device, comprising: The electronic device comprises: At least one processor; and a memory connected with the at least one processor in communication; wherein The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the service asset automatic management method in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions for causing the processor to implement the service asset automatic management method in any one of claims 1-6 when executed.
10. A computer program product, characterised in that, The computer program product comprises a computer program which, when executed by a processor, implements the service asset automatic management method according to any one of claims 1-6.