Network asset counterfeit detection method and device
By generating candidate identifiers with multi-feature fusion and calculating the counterfeiting difficulty score, the most stable and difficult-to-forge asset master identifier is selected. Combined with historical and current network feature metadata, identity detection is performed, which solves the problem of inaccurate counterfeiting identification caused by the over-reliance on static rules for network asset identity verification information, and achieves accurate identification of counterfeit assets.
Patent Information
- Application Number
- CN202511306698.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-12
- Publication Date
- 2025-11-14
AI Technical Summary
In existing technologies, the authentication information for network assets relies excessively on static rules, making it difficult to accurately identify counterfeit network assets.
By generating candidate identifiers that incorporate multiple features, including static features, topological features, certificate fingerprints, and behavioral fingerprints, a counterfeiting difficulty score is calculated. The most stable and difficult-to-forge asset master identifier is selected, and identity detection is performed by combining historical and current network feature metadata.
It improves the accuracy of identifying counterfeit network assets, solves the problems of unstable identification and easy forgery in dynamic networks, and achieves accurate identification of counterfeit assets.
Smart Images

Figure CN120956513A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of internet security detection technology, and in particular to a method and apparatus for detecting network asset spoofing. Background Technology
[0002] Network assets refer to the sum of all hardware devices, software applications, data resources, and digital services (such as cloud services and domain names) owned by an enterprise or individual that can access the network. They are core objects in cyberspace that have value and need to be identified, managed, and protected. They are also the foundation of modern organizational operations and network security defense. The unique identification of asset identity is a prerequisite for intrusion detection, access control, and compliance auditing.
[0003] In related technologies, the over-reliance on static rules for identity verification information of network assets makes existing single-dimensional, fixed identity verification information extremely easy to counterfeit, thus making it difficult to accurately identify counterfeited network assets.
[0004] Therefore, there is an urgent need for a method and device for detecting network asset spoofing to solve the above-mentioned technical problems. Summary of the Invention
[0005] This invention provides a method and apparatus for detecting counterfeit network assets, which can improve the accuracy of identifying counterfeit network assets in related technologies. The technical solution is as follows: On the one hand, a method for detecting network asset spoofing is provided, the method comprising: Obtain network feature metadata of the asset to be detected after standardization and missing data processing; Based on the network feature metadata, a fusion candidate identifier is generated for verifying the identity information of the asset to be detected; wherein, the fusion candidate identifier includes static features, topology features, certificate fingerprints, and behavioral fingerprints; The counterfeiting difficulty score of each fusion candidate identifier is calculated based on the preset normalization index, and the asset master identifier used to represent the unique identity information of the asset to be detected is determined based on the calculation results. By utilizing the network feature metadata of the asset under the historical state and the network feature metadata of the current state, the main identifier of the asset is used to perform identity detection to determine whether the asset has been counterfeited.
[0006] On the other hand, a network asset spoofing detection device is provided, the device comprising: The acquisition module is used to acquire network feature metadata of the asset to be detected after standardization and missing data processing. The generation module is used to generate a fusion candidate identifier for verifying the identity information of the asset to be detected based on the network feature metadata; wherein, the fusion candidate identifier includes static features, topology features, certificate fingerprints and behavioral fingerprints; The determination module is used to calculate the counterfeiting difficulty score of each fusion candidate identifier according to the preset normalization index, and determine the asset master identifier used to represent the unique identity information of the asset to be detected among the fusion candidate identifiers based on the calculation results. The judgment module is used to perform identity detection on the main identifier of the asset by using the network feature metadata of the asset in the historical state and the network feature metadata in the current state, so as to determine whether the asset has been counterfeited.
[0007] On the other hand, a computer device is provided, the computer device including a memory and a processor, the memory for storing computer programs, and the processor for executing the computer programs stored in the memory to implement the steps of the network asset spoofing detection method described above.
[0008] On the other hand, a computer-readable storage medium is provided, wherein a computer program is stored therein, and when the computer program is executed by a processor, it implements the steps of the network asset spoofing detection method described above.
[0009] On the other hand, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the network asset spoofing detection method described above.
[0010] The technical solution provided by this invention can bring at least the following beneficial effects: It generates candidate identifiers based on different feature data of network assets through multi-feature fusion; then, it determines the score of each candidate identifier from three perspectives: stability, availability, and device type, and selects the one with the highest score as the asset's main identifier; finally, by comparing the identifier information at the current time and historical times, it obtains the counterfeit detection result of the asset to be detected. This method can solve the problems of unstable identification, easy forgery, and high false alarm rates in existing technologies in dynamic networks, achieving accurate identification of counterfeit assets. Attached Figure Description
[0011] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0012] Figure 1 This is a flowchart of a network asset spoofing detection method provided by an embodiment of the present invention; Figure 2 This is a structural diagram of a network asset spoofing detection device provided in an embodiment of the present invention; Figure 3 This is a hardware architecture diagram of a computer device provided in an embodiment of the present invention. Detailed Implementation
[0013] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0014] As mentioned earlier, existing network asset detection typically relies on static identifiers such as IP addresses that can be changed or forged, or uses only a single-dimensional service fingerprint or device model. This makes network assets easy to counterfeit during application and counterfeit assets difficult to detect.
[0015] Based on this, the concept of the present invention is to generate multiple candidate identifiers by fusing multiple features, and to select the main identifier of the asset that represents the unique identity information of the asset through scoring for counterfeit detection, thereby improving the detection accuracy of counterfeit assets.
[0016] The following describes the specific implementation of the above concept.
[0017] Please refer to Figure 1 The present invention provides a method for detecting network asset spoofing, the method comprising: Step 100: Obtain network feature metadata of the asset to be detected after standardization and missing data processing; Step 102: Generate a fusion candidate identifier for verifying the identity information of the asset to be detected based on the network feature metadata; wherein, the fusion candidate identifier includes static features, topology features, certificate fingerprints and behavioral fingerprints; Step 104: Calculate the counterfeiting difficulty score of each fusion candidate identifier according to the preset normalization index, and determine the asset master identifier used to represent the unique identity information of the asset to be detected among the fusion candidate identifiers based on the calculation results. Step 106: Using the network feature metadata of the asset under the historical state and the network feature metadata under the current state, perform identity detection on the asset master identifier to determine whether the asset has been counterfeited.
[0018] In this embodiment of the invention, candidate identifiers based on multi-feature fusion are generated according to different characteristic data of network assets. Then, the score of each candidate identifier is determined from three perspectives: stability, availability, and device type, and the highest-scoring candidate identifier is selected as the primary identifier of the asset. Finally, by comparing the identifier information at the current moment and historical moments, the counterfeit detection result of the asset to be detected is obtained. This method can solve the problems of unstable identification, easy forgery, and high false alarm rates in existing technologies in dynamic networks, achieving accurate identification of counterfeit assets.
[0019] The following description Figure 1 The execution method for each step is shown.
[0020] First, for step 100, obtain the network feature metadata of the asset to be detected after standardization and missing data processing.
[0021] In this embodiment of the invention, the network feature metadata of the asset to be detected can be collected through non-intrusive scanning, detection and system docking. The collection side needs to perform standardization and missing data processing (removing whitespace, unifying capitalization, and adding field placeholders "-"), and record time information such as first_seen, last_seen, and observed_at.
[0022] The collected network feature metadata includes basic network information, service characteristics, hardware and software information, topology characteristics, and behavioral characteristics. Specifically: Basic network information: IP address, MAC address, VLAN ID, gateway, routing path, OUI; Service characteristics: open ports / protocols, application fingerprints (HTTP Banner, SSH HostKey fingerprint, TLS certificate information, SMB / NetBIOS, database handshake information, etc.); Hardware and software information: manufacturer, device model, firmware / OS version, serial number / CPU ID (if available); Topology characteristics: switch ID, physical port, uplink device, link layer path; Behavioral characteristics: communication peer, protocol usage ratio, session periodicity, domain name category distribution, etc.
[0023] The candidate identifiers in subsequent steps are generated based on these feature metadata.
[0024] Then, for step 102, a fusion candidate identifier is generated based on the network feature metadata to verify the identity information of the asset to be detected.
[0025] Existing anti-counterfeiting technologies for network assets typically rely on static identifiers such as IP / MAC addresses, which are variable or easily forged. These are susceptible to impersonation in scenarios involving DHCP, NAT, or ARP spoofing. Furthermore, some anti-counterfeiting identifiers, using only a single-dimensional service fingerprint or device model, are also easily forged at the application layer. In other words, because existing anti-counterfeiting identifiers are too simplistic, the identity information of network assets is extremely easy to counterfeit, much like determining if someone is the same person simply by their name—another person with the same name can easily impersonate the original.
[0026] Considering the shortcomings of existing technologies, this embodiment creatively designs a fusion candidate identifier for verifying the identity information of the asset to be detected. It contains multiple feature information of the network asset. This multi-dimensional identifier includes static features, topological features, certificate fingerprints and behavioral fingerprints. Each candidate identifier is generated around feature metadata with different stability, which greatly increases the difficulty for illegal acts to counterfeit the identifier, just like judging whether it is the same person by a comprehensive feature such as facial features, height, body shape or blood type and genes.
[0027] Specifically, based on the organization ID, device model information, software version information, port information, and service type information, a hash value SNStatic for the static characteristics of the asset to be detected is generated. SNStatic = Hash( OrgID | DeviceModel | FirmwareVersion | Port | ServiceClass ) Wherein, OrgID is the organization ID; DeviceModel is the device model; FirmwareVersion is the software version; Port is the port number; and ServiceClass is the service type.
[0028] Generate a hash value SNToop based on the organization ID, switch information, network port information, and VLAN port information to detect the topology characteristics of the asset. SNTopo = Hash( OrgID | SwitchID | IfIndex | VLANID Here, SwitchID represents the switch; IfIndex represents the network port; and VLANID represents the VLAN port.
[0029] Generate the cryptographic hash value (CF) of the asset certificate fingerprint to be tested based on the certificate's public key information, issuer information, and holder information. CF = Fingerprint( TLS PublicKey | Issuer | Subject ) In this context, the TLS PublicKey is the public key in the certificate, used to establish encrypted communication and verify signatures; the Issuer is the certificate issuer (CA); and the Subject is the certificate holder (usually a domain name or organization).
[0030] Based on protocol distribution information, peer type set, and communication cycle information, a fuzzy hash value BF is generated for the behavior fingerprint of the asset to be detected. BF = ssdeep( ProtoDistribution | PeerTypes | Periodicity ) The purpose of behavioral fingerprinting is to use the communication behavior characteristics of assets in the network as unique identifiers for counterfeiting detection and trust calculation.
[0031] Among them, ProtoDistribution represents the protocol distribution, indicating the distribution of communication protocol types and proportions used by the asset within a certain time window (e.g., the past 7 days), for example: TCP: 70%, UDP: 20%, ICMP: 5%, HTTP: 3%, HTTPS: 2%. Because the protocol distribution characteristics of different types of devices (e.g., cameras vs. web servers) vary significantly, the behavioral fingerprint generated based on this metadata is difficult for counterfeiters to completely replicate. PeerTypes is a set of peer types, representing the role / type statistics of peers communicating with this asset. By matching the peer's IP / port fingerprint and asset database, the possible roles of the peers are determined (such as "internal database server" or "external HTTP client"). Since the communication object type of an asset is part of its behavioral characteristics, for example, if a database server mainly communicates with application servers, a sudden surge in communication with external browsers indicates that the current asset may be at risk.
[0032] Periodicity refers to the periodicity of communication behavior, representing the cyclical characteristics of asset communication behavior. This includes factors such as whether packets are sent at fixed time intervals and the distribution of period lengths. It is calculated by statistically analyzing communication time series over a period of time to determine if there are high-frequency fixed intervals (such as heartbeat packets or data synchronization). For example, high periodicity means sending data packets every 60 seconds (such as IoT device heartbeats), while low periodicity means irregular business requests (such as web page visits). Because the communication periodicity pattern is also a device's "behavioral signature," it is very difficult for counterfeiters to completely replicate this data.
[0033] By concatenating and hashing the data from these three dimensions, a unique behavioral DNA is generated. In counterfeit detection, the magnitude of changes in BF (Behavioral Factor) can be used as an important reference. For example, small changes in BF indicate that the device's behavior pattern is stable and it may be a genuine device; large changes indicate that the behavior pattern differs significantly from the historical pattern and may be counterfeited or replaced.
[0034] For step 104, the counterfeiting difficulty score of each fusion candidate identifier is calculated according to the preset normalization index, and the asset master identifier used to represent the unique identity information of the asset to be detected is determined according to the calculation results.
[0035] Considering that the information completeness of different network assets varies, the anti-counterfeiting capabilities of the corresponding generated fusion candidate identifiers are also not entirely the same. For example, asset 1 has more complete static feature information, making it more difficult to counterfeit, while asset 2 has more complete behavioral fingerprint information, making it more difficult to counterfeit. Therefore, this embodiment requires selecting the most stable and least counterfeit identifier for each network asset as its unique identity information, i.e., the asset master identifier.
[0036] The asset master identifier is essentially the "most robust anchor" selected. For example, a certificate fingerprint is chosen instead of a MAC address because the latter is easy to forge, while the former has higher cryptographic strength. Therefore, in this embodiment, the asset master identifier is selected from three aspects: stability, availability, and device priority. The one with the highest comprehensive score in these three aspects is selected from all fusion candidate identifiers, which is the most difficult asset master identifier to forge.
[0037] In this embodiment of the invention, the asset master identifier is determined through the following process: a stability score for candidate identifiers is calculated based on change rate, online coverage, and missing rate indicators; a usability score for candidate identifiers is calculated based on integrity, reproducibility, and anti-counterfeiting indicators; a priority score for candidate identifiers is determined based on the device type of the asset to be detected; a counterfeiting difficulty score for candidate identifiers is calculated based on the stability score, usability score, and priority score, and the candidate identifier corresponding to the highest counterfeiting difficulty score exceeding a preset threshold is determined as the asset master identifier.
[0038] Specifically, the stability score is determined as follows: The change rate index is calculated based on the ratio of the number of times the candidate identifier value changes between two consecutive data collections to the total number of data collection cycles. : Among them, the number of changes refers to the number of times the candidate identifier value changes between two adjacent collections, and the change rate index ranges from [0,1], with lower values indicating greater stability.
[0039] The online coverage index is calculated based on the ratio of the number of times a candidate identifier value can be correctly collected within a collection cycle to the total number of collection cycles. : Among them, effective observations indicate that the candidate identifiers can be correctly collected in this period, and the online coverage index ranges from [0,1], with higher values indicating greater stability.
[0040] The missing value rate index is calculated based on the ratio of the number of missing candidate identifier fields to the total number of fields. : This metric is used to measure whether the fields on which the candidate identifier is generated are frequently missing. The value range is [0,1], and the lower the value, the more stable it is.
[0041] Finally, the change rate metric, the online coverage metric, and the missing rate metric are standardized to obtain the stability score S(c): S(c)=normalize((1−change_rate(c))*a+uptime_coverage(c)*b+(1−missing_ratio(c))*c) Where a, b, c ∈ [0,1] and a+b+c=1, with a default value of (0.4, 0.4, 0.2).
[0042] Furthermore, the usability score, used to measure field completeness, reproducibility, and resistance to forgery, is determined as follows: The completeness index Scomp(c) is determined based on the field length, structural validity, and field missing status of the candidate identifier. For example: the score is 0 when a field is missing or null; the score is 0.5 when a field is partially missing (e.g., a certificate lacking an intermediate CA); and the score is 1 when the field is complete and valid.
[0043] The reproducibility index Srepr(c) is calculated based on the ratio of the number of consistent collections of candidate identifier field values to the total number of collections: For example, if the field value is the same 4 times in the past 5 data collections, then Srepr(c) = 0.8.
[0044] A fixed baseline score is determined based on the field type of the candidate identifier, and the anti-counterfeiting index Santi(c) is calculated by combining it with the security detection results. This index first sets a fixed baseline score according to the field type, and then combines it with the security detection to obtain the final score. For example: when the candidate identifier is a public key, certificate, or signature, the baseline score is set to 1 point, and an additional 0.1 points can be added when the certificate chain is valid, with an upper limit of 1 point for the additional score; when it is a hardware serial number (such as SNStatic), the baseline score is 0.9 points, and +0.05 points if it matches the vendor's database; when it is a network topology derived ID (such as SNTopo), the baseline score is 0.7 points, and +0.05 points if it is consistent across multiple links; when it is a field that can be arbitrarily modified (such as Hostname), the baseline score is 0.3 points, with no additional points.
[0045] Finally, the usability score U(c) is calculated based on the weights of the completeness index, the reproducibility index, and the anti-counterfeiting index: U(c)=w1.Scomp(c)+w2.Srepr(c)+w3.Santi(c) Among them, w1, w2, and w3 are weights, and it is recommended to use the default values of 0.3, 0.4, and 0.3, which can be adjusted according to the business scenario.
[0046] For example, suppose there is a candidate TLS certificate for a device. The calculated integrity score is Scomp = 1 (certificate is intact); reproducibility is Srepr = 0.95 (almost identical across multiple samplings); and anti-forgery score is Santi = 1.0 (certificate signature is valid). Substituting these values into the formula above, the usability score is: U(c)=0.3×1+0.4×0.95+0.3×1.0=0.985 This indicates that the label is almost perfect and highly reliable.
[0047] Furthermore, the device type priority of the assets to be detected can be dynamically modified by the administrator and is loaded when the system is running. The default priority scores are: network devices: 1.0; servers: 0.8; terminals: 0.6; IoT / others: 0.4.
[0048] Finally, the total score of the candidate identifiers is calculated based on the stability score, availability score, and priority score. The candidate identifier corresponding to the highest total score that exceeds a preset threshold is determined as the asset master identifier (PID). PID = max( a·S(c) + b·U(c) + c·P(c)) Here, a, b, and c are system parameters, which are only used as relative weights and their specific values are not fixed here.
[0049] For example, consider a set of candidate identifiers for an asset, C = {SNStatic, CF, BF}: SNStatic: S=0.8, U=0.9, type=server(P=0.8), calculated Score=0.85 SNTopo: S=0.7, U=0.75, type=server(P=0.8), calculates Score=0.75. CF: S=0.95, U=0.98, type=server(P=0.8), calculated Score=0.95 BF: S=0.6, U=0.7, type=server(P=0.8), calculated Score=0.67 The CF certificate fingerprint is then ultimately selected as the PID.
[0050] It's worth noting that the asset master identifier, as a candidate identifier, primarily serves to determine the most complete and robust identifier for subsequent counterfeiting detection. In other words, the asset master identifier's score doesn't indicate whether the identifier can be counterfeited, but rather how difficult it is to counterfeit. For example, if a candidate identifier has missing characters, its stability score will decrease. This is because missing characters result in the candidate identifier containing less information, making it easier to counterfeit. Therefore, a scoring system is needed to select the identifier with the highest score—that is, the one with the fewest flaws—and eliminate the remaining unqualified identifiers.
[0051] Furthermore, the determined primary identifier is not completely fixed. Instead, the PID selection process is re-executed every time an asset scan identifies the same asset. For example, if a server's original PID is the Certificate Fingerprint (CF), but the certificate is changed after it is migrated to a cloud environment, the new candidate identifier is: SNStatic=0.7, SNTopo=0.8, CF_new=0.95. The system automatically switches the PID to the higher-scoring CF_new to maintain the security and continuity of the identity.
[0052] Meanwhile, since the weights in the PID determination formula are not fixed but adjustable, when a drastic change in network topology is detected: parameter b (topology feature weight) is automatically increased; when certificate forgery attacks increase: parameter a (cryptographic feature weight) is automatically increased, thus ensuring that the final selected PID is always the most secure and reliable identity verification.
[0053] Finally, if the set of candidate identifiers is empty or the scores of all candidate identifiers do not meet the preset threshold standard, then PID=UNKNOWN is marked and the manual verification process begins.
[0054] For step 106, the network feature metadata of the asset under the historical state and the network feature metadata under the current state are used to perform identity detection on the main identifier of the asset to determine whether the asset has been counterfeited.
[0055] In this embodiment of the invention, to avoid insufficient accuracy in detecting whether network assets are counterfeited in scenarios such as virtual machine cloning, VLAN migration, cloud migration, and massive IoT terminals, the asset counterfeiting detection process, in addition to detecting the asset's main identifier to complete the identity verification of the network asset, also needs to perform further topology and behavior verification, including: Identity consistency: Compare the historical state PID with the current state PID (same / different / missing).
[0056] Topology consistency: Compare the historical state Topo with the current state Topo (same switch port / VLAN / uplink path, etc.).
[0057] Behavioral similarity: sim(historical state BF, current state BF), using similarity such as Jaccard / Cosine, output [0,1].
[0058] In other words, when topological features are selected as the main asset identifier, behavioral fingerprints need to be selected for further detection in order to improve the accuracy of the detection results; when behavioral fingerprints are selected as the main asset identifier, topological features need to be selected for further detection; and when other identifiers are selected as the main asset identifier, topological and behavioral detection needs to be completed through topological features and behavioral fingerprints.
[0059] The verification results include: When the IP address, main identifier, and topological characteristics of the asset to be detected are the same and the behavioral similarity is higher than the first set value, it is determined that the asset to be detected has not been counterfeited. When the IP addresses of the assets to be detected are different, but the asset main identifier and topological characteristics are the same and the behavioral similarity is higher than the second set value, it is determined that the assets to be detected have undergone asset migration or address change. When the IP address of the assets to be detected is the same, but the main identifier and topological features of the assets are different and the behavioral similarity is lower than the third set value, the assets to be detected are judged to be suspected counterfeit assets. When the historical asset master identifier of the asset to be tested is missing, the asset to be tested is determined to be an asset to be confirmed or a newly added asset.
[0060] Furthermore, in this embodiment, if the asset detection result is determined to be a suspected counterfeit asset, its multi-dimensional quantitative score needs to be calculated, and the suspected counterfeit asset is managed in a graded manner based on the score result.
[0061] Specifically, a multi-dimensional quantitative score L, used to characterize the degree of asset counterfeiting, is first calculated based on the identity conflict degree, topology drift strength, behavioral difference degree, certificate conflict degree, service set mutation degree, policy violation degree, and abnormal lifecycle of the suspected counterfeit asset. L=normalize(w1·I+w2·T+w3·B+w4·K+w5·S+w6·R+w7·A) The components in the formula are defined as follows: I (IdentityConflict): Identity Conflict Level. A higher value is used when the PID changes but there are no reasonable change records; a lower value is used when only the Banner changes.
[0062] T (TopologyDrift): Topology drift intensity. The higher value is taken when the same PID appears on multiple physical ports / VLANs within the same time window.
[0063] B (Behavior Divergence): Behavioral Divergence, B=1-sim(BF(O),BF(H)).
[0064] K (Key / CertMismatch): Certificate / HostKey conflict degree (public key fingerprint change, certificate chain anomaly, inconsistency between issuer and device manufacturer).
[0065] S (ServiceSetShift): Service set mutation degree (Jaccard difference of open ports / protocol sets).
[0066] R (RuleViolations): Policy violations (blacklisted vendors, illegal OUI ranges, etc.), binary or segmented.
[0067] A (AssetLifecycleAnomaly): Lifecycle anomaly (first time abnormal reset, abnormal offline / online cycle).
[0068] w1…w7: are configurable weights (the specific values are not fixed in this disclosure), normalize(·) will linearly normalize the weighted result to [0,1].
[0069] Determine the corresponding response measures based on the relationship between the calculation results and the preset threshold: If L < τ1: Record and review candidates (no alarm or low-level alarm); If τ1≤L<τ2: Intermediate warning, manual confirmation required; If L≥τ2: Advanced alarm + NAC asset blocking and asset isolation (optional bypass isolation), and trigger forensics.
[0070] τ1 is the first counterfeiting threshold; τ2 is the second counterfeiting threshold. Those skilled in the art can adjust it according to actual needs, and no specific value is limited here.
[0071] The following process is then used to achieve tiered response and evidence collection: Recording / Visualization: Save L, component contributions (I / T / B / ...) and evidence snapshots (fingerprints, topology, behavioral summaries).
[0072] Linked control: Implement blocking / isolation / access degrading through API interfaces with firewalls, switches, and NAC.
[0073] Closed-loop processing: First, the work order is processed and then manually confirmed. Next, it is marked as "legitimate change / counterfeit established / false alarm" and finally fed back to the model (adjusting weights and thresholds).
[0074] The effectiveness and feasibility of the above method are verified by some examples below.
[0075] Terminals connected to the enterprise intranet switch: 1. Asset A was collected: IP=192.168.1.100, VLAN=20, Switch / Port (SW1 / Gi1 / 0 / 24), Open Ports {80,443}; 2. Generate candidates: SNStatic, SNTOPTO, CF (TLS fingerprint), BF (protocol distribution vector); 3. PID Decision: The certificate fingerprint CF history is the most stable and reproducible, so it is selected as PID; 4. In the new observation, the CF remains unchanged, but the IP changes to 192.168.1.120, the topology remains unchanged, and the behavioral similarity is high → this is determined to be asset migration, and L is lower than τ1; 5. If a certain observation shows a change in CF, a topological shift to SW2 / Gi1 / 0 / 10, or a significant decrease in behavioral similarity, it is judged as a suspected counterfeit. If L≥τ2, it is automatically isolated and evidence is collected.
[0076] Virtualized data center VM cloning: 1. Obtain the VM_UUID through the virtualization API and include it in the candidate identifiers; 2. The same VM_UUID appears simultaneously on different host machines and in different topologies, and the HostKey changes → T, K, and I all increase simultaneously; 3. If the score L exceeds the threshold, a high-risk alarm and isolation will be triggered; after confirmation by the administrator, the cloned sample will be added to the blacklist policy.
[0077] IoT camera firmware upgrade: 1. The manufacturer model and certificate fingerprint remain unchanged, only the firmware version and some ports have changed, and the behavioral similarity remains high; 2. PID remains stable, I≈0, B≈0, S is moderate → L is lower than τ1; 3. Automatically marked as "legitimate change" and written to the change log and baseline.
[0078] In summary, the above methods fundamentally alleviate the problem of "single identifiers being volatile / easily forged" by using a candidate identifier set and PID decision-making; the introduction of cross-validation of topology and behavior can maintain stable identification in complex environments such as NAT, VLAN drift, and virtual machine cloning; the credibility score L unifies multi-dimensional evidence into usable action signals, facilitating coordinated control and auditing closed loops; and the methods can be implemented without relying on specific thresholds or performance indicators, with parameters that can be gradually calibrated according to different network environments.
[0079] Please refer to Figure 2 This invention provides a network asset spoofing detection device, which includes: The acquisition module 200 is used to acquire network feature metadata of the asset to be detected after standardization and missing data processing. The generation module 202 is used to generate a fusion candidate identifier for verifying the identity information of the asset to be detected based on the network feature metadata; wherein, the fusion candidate identifier includes static features, topology features, certificate fingerprints and behavioral fingerprints; The determination module 204 is used to calculate the counterfeiting difficulty score of each fusion candidate identifier according to the preset normalization index, and determine the asset master identifier used to represent the unique identity information of the asset to be detected among the fusion candidate identifiers based on the calculation results. The judgment module 206 is used to perform identity detection on the main identifier of the asset by using the network feature metadata of the asset in the historical state and the network feature metadata in the current state, so as to determine whether the asset has been counterfeited.
[0080] In this embodiment of the invention, when the generation module 202 generates a fusion candidate identifier for verifying the identity information of the asset to be detected based on the network feature metadata, it specifically performs the following operations: generating a hash value of the static features of the asset to be detected based on the organization ID, device model information, software version information, port information, and service type information; generating a hash value of the topology features of the asset to be detected based on the organization ID, switch information, network port information, and VLAN port information; generating an encrypted hash value of the certificate fingerprint of the asset to be detected based on the public key information, issuer information, and holder information of the certificate; and generating a fuzzy hash value of the behavioral fingerprint of the asset to be detected based on the protocol distribution information, peer type set, and communication cycle information.
[0081] In this embodiment of the invention, when the determining module 204 calculates the spoofing difficulty score of each fusion candidate identifier according to a preset normalization index, and determines the asset master identifier used to represent the unique identity information of the asset to be detected among the fusion candidate identifiers based on the calculation results, it specifically performs the following operations: calculating the stability score of the candidate identifier based on the change rate index, online coverage index, and missing rate index; calculating the availability score of the candidate identifier based on the integrity index, reproducibility index, and anti-counterfeiting index; determining the priority score of the candidate identifier based on the device type of the asset to be detected; calculating the spoofing difficulty score of the candidate identifier based on the stability score, the availability score, and the priority score, and determining the candidate identifier corresponding to the highest score exceeding a preset threshold in the spoofing difficulty score as the asset master identifier.
[0082] In this embodiment of the invention, when the determining module 204 calculates the stability score of the candidate identifier based on the change rate index, online coverage index, and missing rate index, it specifically performs the following operations: calculating the change rate index based on the ratio of the number of times the candidate identifier value changes between two adjacent collections to the total number of collection cycles; calculating the online coverage index based on the ratio of the number of times the candidate identifier value can be correctly collected in one collection cycle to the total number of collection cycles; calculating the missing rate index based on the ratio of the number of missing fields in the candidate identifier value to the total number of fields; and standardizing the change rate index, the online coverage index, and the missing rate index to obtain the stability score.
[0083] In this embodiment of the invention, when the determining module 204 calculates the availability score of the candidate identifier based on the integrity index, reproducibility index, and anti-counterfeiting index, it specifically performs the following operations: determining the integrity index based on the field length, structural legality, and field missing status of the candidate identifier; calculating the reproducibility index based on the ratio of the number of consistent collections of the candidate identifier's field values to the total number of collections; determining a fixed benchmark score based on the field type of the candidate identifier and calculating the anti-counterfeiting index in conjunction with the security detection results; and calculating the availability score based on the weights of the integrity index, the reproducibility index, and the anti-counterfeiting index.
[0084] In this embodiment of the invention, when the judgment module 206 performs identity detection on the asset master identifier using network feature metadata of the asset under historical state and network feature metadata of the current state to determine whether the asset has been counterfeited, it specifically performs the following operations: when the IP, asset master identifier, and topology features of the asset under test are the same and the behavioral similarity is higher than a first preset value, it is determined that the asset under test has not been counterfeited; when the IP of the asset under test is different, the asset master identifier and topology features are the same and the behavioral similarity is higher than a second preset value, it is determined that the asset under test has undergone asset migration or address change; when the IP of the asset under test is the same, the asset master identifier and topology features are different and the behavioral similarity is lower than a third preset value, it is determined that the asset under test is a suspected counterfeit asset; when the historical asset master identifier of the asset under test is missing, it is determined that the asset under test is an asset to be confirmed or a newly added asset.
[0085] It should be noted that the network asset spoofing detection device provided in the above embodiments is only an example of the division of the above functional modules. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the network asset spoofing detection device and the network asset spoofing detection method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.
[0086] Embodiments of this application also provide a computer device, please refer to... Figure 3 The computer device includes a processor and a memory, the memory storing at least one instruction, at least one program, code set, or instruction set, the at least one instruction, at least one program, code set, or instruction set being loaded and executed by the processor to implement the network asset spoofing detection method provided in the above-described method embodiments.
[0087] Embodiments of this application also provide a computer-readable storage medium storing at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, at least one program, code set, or instruction set is loaded and executed by a processor to implement the network asset spoofing detection method provided in the above-described method embodiments.
[0088] Embodiments of this application also provide a computer program product, which includes a computer program. A processor of a computer device reads the computer program from a computer-readable storage medium and executes the computer program, causing the computer device to perform any of the network asset spoofing detection methods described in the above embodiments.
[0089] For ease of description, the above systems or devices are described separately as various modules or units based on their functions. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware components.
[0090] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.
[0091] Finally, it should be noted that in this document, relational terms such as first, second, third, and fourth are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0092] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A method for detecting network asset spoofing, characterized in that, The method includes: Obtain network feature metadata of the asset to be detected after standardization and missing data processing; Based on the network feature metadata, a fusion candidate identifier is generated for verifying the identity information of the asset to be detected; wherein, the fusion candidate identifier includes static features, topology features, certificate fingerprints, and behavioral fingerprints; The counterfeiting difficulty score of each fusion candidate identifier is calculated based on the preset normalization index, and the asset master identifier used to represent the unique identity information of the asset to be detected is determined based on the calculation results. By utilizing the network feature metadata of the asset under the historical state and the network feature metadata of the current state, the main identifier of the asset is used to perform identity detection to determine whether the asset has been counterfeited.
2. The method as described in claim 1, characterized in that, The step of generating a fusion candidate identifier for verifying the identity information of the asset to be detected based on the network feature metadata includes: The hash value of the static characteristics of the asset to be detected is generated based on the organization ID, device model information, software version information, port information, and service type information. Generate hash values for the topology characteristics of the assets to be detected based on the organization ID, switch information, network port information, and VLAN port information; Generate the cryptographic hash value of the certificate fingerprint of the asset to be tested based on the certificate's public key information, issuer information, and holder information; A fuzzy hash value is generated based on the protocol distribution information, the peer type set, and the communication cycle information to generate a fingerprint of the asset behavior to be detected.
3. The method as described in claim 1, characterized in that, The step of calculating the counterfeiting difficulty score of each fusion candidate identifier based on a preset normalization index, and determining the asset master identifier used to represent the unique identity information of the asset to be detected among the fusion candidate identifiers based on the calculation results, includes: The stability score of the candidate identifier is calculated based on the change rate, online coverage, and missing rate indicators. The availability score of the candidate identifier is calculated based on the integrity index, reproducibility index, and anti-counterfeiting index. Based on the type of equipment of the asset to be inspected, the priority score of the candidate identifiers is determined; The counterfeiting difficulty score of the candidate identifier is calculated based on the stability score, the availability score, and the priority score, and the candidate identifier corresponding to the highest score in the counterfeiting difficulty score that exceeds a preset threshold is determined as the asset master identifier.
4. The method as described in claim 3, characterized in that, The stability score of the candidate identifier, calculated based on the change rate, online coverage, and missing rate metrics, includes: The change rate index is calculated based on the ratio of the number of times the candidate identifier value changes between two consecutive collections to the total number of collection cycles. The online coverage rate index is calculated based on the ratio of the number of times a candidate identifier value can be correctly collected within a collection cycle to the total number of collection cycles. The missing rate index is calculated based on the ratio of the number of missing candidate identifier fields to the total number of fields. The change rate metric, the online coverage metric, and the missing rate metric are standardized to obtain the stability score.
5. The method as described in claim 3, characterized in that, The usability score of the candidate identifier, calculated based on the integrity index, reproducibility index, and anti-counterfeiting index, includes: The completeness index is determined based on the field length, structural validity, and field missingness of the candidate identifier; The reproducibility index is calculated based on the ratio of the number of consistent collections of candidate identifier field values to the total number of collections. A fixed baseline score is determined based on the field type of the candidate identifier, and the anti-counterfeiting index is calculated by combining it with the security detection results; The usability score is calculated based on the weights of the completeness index, the reproducibility index, and the anti-counterfeiting index.
6. The method as described in claim 1, characterized in that, The step of using network feature metadata of the asset under test in its historical state and network feature metadata in its current state to perform identity verification on the asset's master identifier to determine whether the asset has been counterfeited includes: When the IP address, main identifier, and topological characteristics of the asset to be detected are the same and the behavioral similarity is higher than the first set value, it is determined that the asset to be detected has not been counterfeited. When the IP addresses of the assets to be detected are different, but the main identifiers and topological features of the assets are the same and the similarity of behavior is higher than the second set value, it is determined that the assets to be detected have undergone asset migration or address change. When the IP address of the assets to be detected is the same, but the main identifier and topological features of the assets are different and the behavioral similarity is lower than the third set value, the assets to be detected are judged to be suspected counterfeit assets. When the historical asset master identifier of the asset to be tested is missing, the asset to be tested is determined to be an asset to be confirmed or a newly added asset.
7. A network asset spoofing detection device, characterized in that, The device includes: The acquisition module is used to acquire network feature metadata of the asset to be detected after standardization and missing data processing. The generation module is used to generate a fusion candidate identifier for verifying the identity information of the asset to be detected based on the network feature metadata; wherein, the fusion candidate identifier includes static features, topology features, certificate fingerprints and behavioral fingerprints; The determination module is used to calculate the counterfeiting difficulty score of each fusion candidate identifier according to the preset normalization index, and determine the asset master identifier used to represent the unique identity information of the asset to be detected among the fusion candidate identifiers based on the calculation results. The judgment module is used to perform identity detection on the main identifier of the asset by using the network feature metadata of the asset in the historical state and the network feature metadata in the current state, so as to determine whether the asset has been counterfeited.
8. A computer device, characterized in that, The computer device includes a memory and a processor. The memory is used to store computer programs, and the processor is used to execute the computer programs stored in the memory to implement the steps of the method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, implements the steps of the method described in any one of claims 1-6.
10. A computer program product, characterized in that, Includes a computer program, which, when executed by a processor, implements the steps of the method according to any one of claims 1-6.
Citation Information
Patent Citations
Method and device for detecting counterfeit website based on website fingerprint
CN115801455A
Asset discovery and management method and device in industrial control environment, equipment and medium
CN116980468A
Video network asset management method, device and equipment based on active scanning
CN117061244A
Authentication method and device based on terminal equipment identifier and storage medium
CN119729472A
Verifying asset identity
US20180337786A1