IT asset intelligent management system and implementation method thereof
By combining intelligent analysis and prediction subsystems, lifecycle management subsystems, and security and compliance subsystems with big data and machine learning, the system addresses the issues of incomplete asset discovery, data silos, and low operational efficiency in information technology asset management. It achieves automated management and security compliance throughout the entire lifecycle, thereby improving operational efficiency and security compliance levels.
Patent Information
- Application Number
- CN202511639219.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-11
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2045-11-11
AI Technical Summary
Existing technologies in information technology asset management suffer from problems such as incomplete asset discovery, severe data silos, insufficient lifecycle management, low operation and maintenance efficiency, prominent compliance risks, and insufficient intelligence, making it difficult to achieve end-to-end consistent modeling and closed-loop automation.
It employs intelligent analysis and prediction subsystems, lifecycle management subsystems, and security and compliance subsystems, combined with big data and machine learning, to perform full lifecycle management and real-time security and compliance detection through asset topology maps, utilizes graph databases to build a unified asset relationship model, provides resource capacity prediction, anomaly detection, and risk trend insights, and integrates with external systems through standardized interfaces.
It enables full-stack asset discovery and unified modeling across local, cloud, container, and edge environments, supports automated management throughout the entire lifecycle, improves operational efficiency and security compliance, provides intelligent decision support and open extensibility, and solves problems such as incomplete asset lists, data silos, low operational efficiency, and prominent compliance risks.
Smart Images

Figure CN121094722B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information processing, in particular to an IT (information technology) asset intelligent management system and an implementation method thereof. BACKGROUND
[0002] With the expansion of enterprise informatization scale and the popularity of hybrid cloud or multi-cloud environment, the types and quantities of information technology assets are growing explosively, and the assets are distributed among local computer rooms, edge nodes, virtual machines, container orchestration platforms, and public cloud services. Traditional manual inventory and management methods based on tables or decentralized systems cannot meet the requirements of modern operation and governance, and there are the following typical problems: incomplete discovery and inventory, weak asset automatic discovery capability, and blind spots such as short life cycle instances of containers, temporary resources on the cloud, and edge devices, resulting in inaccurate inventory. Data islands and inconsistencies: different systems, configuration management databases, monitoring, work orders, configuration management, and financial systems have different data formats and perspectives, making it difficult to model and synchronize. Life cycle management is difficult, and the full life cycle of assets from procurement, deployment, change, maintenance to scrap lacks automatic processes and traceability, and manual processes are time-consuming and prone to errors. Configuration and compliance risks: configuration drift, unauthorized software, and patch lag make it difficult to discover and handle security and compliance issues in a timely manner. Insufficient operation automation capability: daily inspection, patch distribution, and configuration change rely on manual operation, which is low in efficiency and poor in repeatability. Visualization and decision support are lacking: managers lack intelligent analysis capabilities such as capacity planning, cost attribution, and risk prediction based on historical and real-time data. Lack of flexibility and scalability: in the face of large-scale, diversified assets and frequent changes in the environment, existing systems have bottlenecks in scalability, access to third-party application programming interfaces, and real-time processing capabilities.
[0003] Existing configuration management databases, asset management, or IT service management products provide some functions, but they often focus on a certain link and cannot achieve consistent modeling and closed-loop automation from end to end; in addition, rule-based alarm systems have high false positive or false negative rates in complex scenarios, and lack intelligent judgment based on behavior or trends. Therefore, there is an urgent need for an information technology asset intelligent management platform and implementation method that can unify asset discovery and modeling, support multi-source data fusion, have automated operation and security compliance capabilities, and achieve predictive maintenance and decision support through data-driven and artificial intelligence technology, to improve operation efficiency, reduce risks, and optimize asset use and cost.
[0004] Prior art one, disclosed as CN120765199A, discloses an enterprise data asset intelligent management system for server research and development manufacturing, which includes a data asset access module for obtaining initial information of the enterprise data asset to be managed; a multi-dimensional feature extraction module for extracting content, structure and semantic features of the data asset; an intelligent classification processing module for multi-dimensional classification processing to obtain classification results; a dynamic storage management module for generating storage strategies; and an application service output module for executing application service output and displaying results. Although it realizes efficient access, comprehensive feature extraction, scientific classification, dynamic storage management and convenient application service output of enterprise data assets in the server research and development manufacturing process, and improves the management level and utilization value of enterprise data assets; but it cannot effectively manage the infrastructure assets such as physical devices, virtual machines, containers and cloud services that constitute information technology services, and does not have the ability to automatically operate and real-time security control these infrastructure assets.
[0005] Prior art two, disclosed as CN120046889A, discloses an intelligent IT asset management system, which includes: a configuration asset management module for automatically collecting IT asset information in the network and establishing a complete configuration item relationship model, supporting dependency relationship mapping and impact analysis between configuration items; a service desk management module for establishing a service directory, defining processing flow, response time and service level agreement, automatically classifying and prioritizing received service requests through an intelligent classification engine, and assigning them to appropriate processing personnel according to preset rules; a contract supplier management module for full life cycle management of suppliers and contracts; an IT service financial module for multi-dimensional budget management and fine management of IT costs; a multi-tenant management module for realizing entity separation and permission control. Although it solves the problems of traditional IT asset management systems in asset tracking, service management, cost control, etc., and provides a complete IT service management solution for enterprises; but its asset discovery method may be relatively traditional and does not explicitly cover containers, cloud service APIs, edge devices and other modern hybrid infrastructures. The "configuration item relationship model" established may be a relatively static or flat relationship model, rather than the dynamic, deep correlation topological graph based on the graph database in the present application, which can more intuitively and accurately express complex service dependency relationships. In addition, prior art two focuses on service flow, financial and supplier management, and lacks the ability to predict and optimize capacity, cost, risk and abnormalities based on machine learning. Its management method is biased towards post-processing and process control, rather than intelligent prediction and proactive intervention.
[0006] The prior art three, disclosed as CN117952558A, discloses an intelligent information asset management method and device. The intelligent information asset management method and device first establishes a scientific and technological database to accumulate scientific and technological basic information and business information. A shared database is established by data centers of each business department of a company, and each data center gathers all scientific and technological basic information and business information. The data centers of each business department of the company share newly collected data to a shared platform through the shared database. The department business systems of each business department of the company obtain information from the shared database according to business needs. Although the company-level information system is provided, the scientific and technological data can be circulated, shared and used, the work burden of business personnel is reduced, and the department work efficiency is greatly improved. However, the discovery, modeling, life cycle and security compliance state of the information technology asset itself are not concerned, the asset concept is more inclined to information data rather than information technology infrastructure. Meanwhile, the architecture is designed around the internal data sharing of the company, and lacks the ability of deep and bidirectional integration with external heterogeneous systems through standardized API, which is easy to form new data islands.
[0007] At present, the prior art one, the prior art two and the prior art three have problems of incomplete information technology asset discovery, serious data island, insufficient life cycle management, low operation and maintenance efficiency, prominent compliance risk, insufficient intelligence and poor expansibility. Therefore, the present application provides an IT asset intelligent management system and an implementation method thereof. SUMMARY
[0008] In order to solve the above technical problems, the present application provides an IT asset intelligent management system, which comprises:
[0009] An intelligent analysis and prediction subsystem is used for processing and analyzing historical and real-time operation data obtained from life cycle management, security compliance and the like based on an asset topology map, and outputting resource capacity prediction, abnormality detection, cost optimization suggestion and risk trend insight results and prediction indexes;
[0010] A life cycle management subsystem is used for performing full life cycle state tracking and management from asset procurement, deployment, operation, change, maintenance to recycling and scrapping, and driving an automated operation workflow through a strategy engine to realize closed-loop management of information technology asset states;
[0011] A security and compliance subsystem is used for real-time detection and analysis based on an asset topology map and information technology asset states through a compliance strategy library to identify configuration drift, unauthorized change and security compliance states, and generate alarms, repair suggestions or execute automated repair strategies.
[0012] Optionally, the security and compliance subsystem comprises:
[0013] A compliance posture mirror building component is configured to define static asset relationships of an asset topology map and a dependency network as an immutable review framework; real-time configuration data, operation parameters and security attributes contained in an information technology asset state are filled into the review framework according to corresponding asset entity units; the configuration data defines an expected security baseline of the information technology asset, and the operation parameters reflect an actual operation state; and a compliance posture mirror is built.
[0014] A policy consistency deduction component is configured to perform logical deduction on each policy rule in a compliance policy library in a global context built by the compliance posture mirror, identify deep violations and associated risks in a single information technology asset inspection, and generate a compliance deviation event set describing a deviation asset, a deviation type, a violated policy item and an impact range in the topology.
[0015] A classification disposal instruction generation component is configured to perform risk rating and disposal path decision according to the keyness of each information technology asset in the compliance deviation event set in the asset topology map, the severity level of the deviation itself and available automated repair scripts.
[0016] Optionally, the policy consistency deduction component comprises:
[0017] A policy inspection context building sub-component is configured to perform semantic analysis on the policy rules, each policy rule is converted into an executable policy inspection context, and the policy inspection context comprises a logical judgment condition of the policy and defines a specific path and a relationship type in the asset topology map required for performing inspection; and the policy rule is instantiated as a policy inspection context for directional exploration on the specific data entity of the compliance posture mirror.
[0018] An associated influence network analysis sub-component is configured to perform deep traversal and logical judgment on the compliance posture mirror, and when an initial policy deviation is identified on a certain information technology asset, the initial policy deviation is taken as a starting point, and a dynamic deduction of associated security influences caused by the initial policy deviation is performed according to the dependencies and connection relationships defined in the compliance posture mirror, so as to generate an associated influence network centering on the initial policy deviation and outlining potential influence paths and ranges.
[0019] A compliance deviation event synthesis sub-component is configured to perform multi-dimensional feature packaging on an asset identifier, a specific type and a violated policy item of the initial policy deviation and an impact range described by the associated influence network, so as to form a compliance deviation event containing a complete context.
[0020] Optionally, the associated influence network analysis sub-component comprises:
[0021] a risk propagation path discovery module, configured to start from the initial policy deviation asset according to the relationship types in the compliance posture mirror, perform graph traversal, define the conduction possibility and strength for each relationship type, identify all potential paths through which the risk may be conducted via various relationship chains starting from the initial policy deviation asset, and generate a set of risk propagation paths;
[0022] an influence range dynamic definition module, configured to perform influence assessment on all information technology assets covered by the risk propagation paths, calculate an affected degree score according to a pre-defined criticality level of each information technology asset in the compliance posture mirror, and an associated strength and path length of the initial policy deviation, filter all covered information technology assets according to a preset risk tolerance threshold, and determine, as an influence target of the current deviation, an asset whose affected degree score exceeds the risk tolerance threshold;
[0023] a correlation influence network synthesis module, configured to take the initial policy deviation asset as a root node, the risk propagation paths as edges, and assets in the dynamic influence range as vertices, construct an influence relationship subgraph, and obtain a correlation influence network with the initial policy deviation as a center and outlining a potential influence path and an accurate range.
[0024] Optionally, the influence range dynamic definition module comprises:
[0025] a criticality quantification matrix construction submodule, configured to map a pre-defined criticality level of each information technology asset in the compliance posture mirror into a criticality quantification matrix; the criticality quantification matrix assigns a quantified criticality base value to each information technology asset, reflecting the inherent importance of the information technology asset in a static environment;
[0026] a propagation attenuation factor calculation submodule, configured to calculate a propagation attenuation factor for each information technology asset on each specific path in the risk propagation paths; the correlation strength and the path length are fused to calculate the propagation attenuation factor of the information technology asset on the risk propagation path, and the value is between 0 and 1;
[0027] an affected degree score submodule, configured to multiply the corresponding criticality base value in the criticality quantification matrix by the calculated propagation attenuation factor for each information technology asset in the coverage range of the risk propagation paths, and obtain an affected degree score of the information technology asset.
[0028] Optionally, the propagation attenuation factor calculation submodule comprises:
[0029] a relationship type weight allocation unit configured to assign an initial relationship type weight to each type of relationship according to the semantic definition of the connection relationship between the information technology assets in the compliance posture mirror, the relationship type weight representing the inherent difficulty of risk transmission through the relationship channel;
[0030] a path attenuation coefficient calculation unit configured to consider the path length, i.e., the number of hops, of a specific path from the initial deviation asset to the target asset in the risk transmission path, and calculate a path attenuation coefficient using a non-linear attenuation;
[0031] a transmission attenuation factor fusion unit configured to fuse a final quantitative value between 0 and 1, i.e., a transmission attenuation factor, based on the relationship type weight and using the path attenuation coefficient as a non-linear adjuster.
[0032] Optionally, the path attenuation coefficient calculation unit comprises:
[0033] a path attenuation base calculation sub-unit configured to map the integer path length to a path attenuation base between 0 and 1;
[0034] a dynamic attenuation gradient generation sub-unit configured to analyze the historical stability of the current transmission path and generate a dynamic attenuation gradient as an adjustment variable according to the historical stability;
[0035] a path attenuation coefficient synthesis sub-unit configured to read the path attenuation base value generated by the path attenuation base calculation process and load the dynamic attenuation gradient parameter generated by the dynamic attenuation gradient generation process; input the path attenuation base as a base value into the coefficient synthesis and inject the dynamic attenuation gradient as a correction parameter; multiply the value of the dynamic attenuation gradient by a preset gradient influence factor to obtain an actual correction amount; subtract the actual correction amount from the value of the path attenuation base to obtain an intermediate result; perform numerical range constraint processing on the intermediate result to ensure that its value falls within the interval of zero to one; if the intermediate result is less than zero, set it to zero; if the intermediate result is greater than one, set it to one to obtain the path attenuation coefficient.
[0036] Optionally, it further comprises an asset discovery subsystem configured to obtain multi-source raw asset data in the information technology environment through various automatic detection technologies; and output a standardized asset list through a feature comparison and deduplication fusion program;
[0037] a unified modeling subsystem configured to construct a unified asset relationship data model using a graph database based on the standardized asset list; and form an asset topology map by processing the association and dependence between the information technology assets.
[0038] Optionally, an interface and extension subsystem is further included, which is used for outputting the asset topology map, information technology asset state, compliance state and insight results and prediction indicators to external systems such as configuration management databases, monitoring and ticket systems through standardized RESTful API, gRPC and Webhook interfaces, and performing comprehensive rendering and graphical display to output the asset topology map, health score and trend prediction interactive view through a Web interface or a mobile terminal; and receiving external system instructions to realize bidirectional data synchronization and function extension with the external system ecosystem.
[0039] The application provides an implementation method of an IT asset intelligent management system, which comprises the following steps:
[0040] Raw asset data is collected through agentless scanning, agent-based collection and cloud service API collection; the data is cleaned and standardized based on feature comparison and deduplication fusion to generate a structured asset list; an asset relationship model is constructed using graph database technology, a visual asset topology map is formed through correlation analysis, and a complete asset relationship view is established;
[0041] The asset topology map and operation data, including real-time state, historical records and compliance information, are integrated; multi-dimensional analysis is performed using a big data platform and machine learning to realize anomaly detection, capacity prediction, cost evaluation and risk analysis; and quantifiable decision indicators are output, including resource capacity prediction reports, anomaly detection alarms, cost optimization suggestions and risk trend early warnings;
[0042] Data such as asset topology, real-time state and analysis indicators are aggregated and encapsulated through standardized interfaces; integration with external platforms is realized, and visual display is performed through a Web and a mobile terminal to support interactive query of asset topology maps, health score and trend prediction views.
[0043] The application realizes global visibility and unified management: cross-local, cloud, container and edge full-stack asset discovery and unified modeling are realized to solve the problems of incomplete asset list and data silos. Full life cycle closed-loop management is realized: full-process automatic management of assets from procurement to scrapping is realized to improve operation and maintenance efficiency and traceability. Automated operation and maintenance and compliance guarantee are realized: through policy-driven automated inspection, patch distribution and compliance repair, the risk of manual operation is reduced, and the level of safety and compliance is improved. Open extension and high availability are realized: the platform adopts an open interface and a microservice architecture, can flexibly interface with third-party systems, and adapts to high concurrency demands in large-scale environments. Through the above scheme, the information technology asset management is intelligentized, automated and safety-compliant, and the efficiency and reliability of information technology operation and governance are significantly improved.
[0044] Other features and advantages of the present application will be set forth in the description that follows, and in part will be apparent from the description, or can be learned by practice of the application. The purposes and other advantages of the present application will be realized and attained by the structure particularly pointed out in the written description and claims hereof as well as the appended drawings.
[0045] The technical solutions of the present application are described in further detail below with the help of the accompanying drawings and examples. BRIEF DESCRIPTION OF DRAWINGS
[0046] The accompanying drawings are included to provide a further understanding of the present application and are incorporated in and constitute a part of the specification, illustrate embodiments of the present application and are used to explain the present application, but are not intended to limit the present application. In the drawings:
[0047] Figure 1 It is the block diagram of the IT asset intelligent management system in the embodiment 1 of the present application;
[0048] Figure 2 It is the schematic diagram of the IT asset intelligent management system in the embodiment 1 of the present application;
[0049] Figure 3 It is the block diagram of the intelligent analysis and prediction subsystem in the embodiment 4 of the present application;
[0050] Figure 4 It is the block diagram of the life cycle management subsystem in the embodiment 6 of the present application;
[0051] Figure 5 It is the block diagram of the security and compliance subsystem in the embodiment 8 of the present application;
[0052] Figure 6 It is the flow chart of the implementation method of the IT asset intelligent management system in the embodiment 14 of the present application. DETAILED DESCRIPTION
[0053] The preferred embodiments of the present application are described below with the help of the accompanying drawings, and it should be understood that the preferred embodiments described herein are only used to explain and illustrate the present application, and are not intended to limit the present application.
[0054] The terms used in the embodiments of the present application are merely for the purpose of describing the specific embodiments, and are not intended to limit the embodiments of the present application. The singular forms "a", "an" and "the" used in the embodiments of the present application are also intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein means and includes any or all possible combinations of one or more associated listed items.
[0055] The following description refers to the accompanying drawings. Unless otherwise noted, same or similar components in different drawings have same or similar reference numerals. Embodiments described in the following examples do not represent all embodiments consistent with the application. Instead, they are merely examples of apparatuses and methods consistent with some aspects of the application. In the description of the application, it is to be understood that the terms "first", "second", "third", etc. are used merely as labels, and are not necessarily to be taken literally or with a fixed meaning. The above terms are not necessarily used consistently throughout the description, but are used for the sake of clarity to distinguish between different elements or steps in the embodiments of the application.
[0056] Embodiment 1: As shown in the following table, the embodiments of the present application provide an IT asset intelligent management system, comprising: Figure 1
[0057] An asset discovery subsystem is configured to obtain multi-source raw asset data in an information technology environment through various automatic detection technologies such as agentless scanning, agent collection, cloud service API, and container orchestration API; and output a standardized asset list through feature comparison and deduplication fusion program.
[0058] A unified modeling subsystem is configured to construct a unified asset relationship data model using a graph database based on the standardized asset list; and form an asset topology graph by processing the correlation and dependency between information technology assets.
[0059] An intelligent analysis and prediction subsystem is configured to process and analyze historical and real-time operation data obtained from lifecycle management and security compliance based on the asset topology graph, and output insight results and prediction indicators such as resource capacity prediction, anomaly detection, cost optimization suggestions, and risk trends.
[0060] A lifecycle management subsystem is configured to perform full lifecycle state tracking and management from asset procurement, deployment, operation, change, maintenance to recycling and scrapping; and realize closed-loop management of information technology asset status by driving automated operation workflow through a policy engine.
[0061] A security and compliance subsystem is configured to perform real-time detection and analysis based on the asset topology graph and information technology asset status through a compliance policy library, identify configuration drift, unauthorized changes, and security compliance status, and generate alarms, repair suggestions, or execute automated repair strategies.
[0062] An interface and extension subsystem is configured to output the asset topology map, information technology asset state, compliance state, and insight results and prediction indicators to external systems such as a configuration management database, a monitoring and ticket system, and the like through standardized RESTful API, gRPC, and Webhook interfaces, and to perform comprehensive rendering and graphical display, and output interactive views such as an asset topology map, a health score, and trend prediction through a web interface or a mobile terminal. The interface and extension subsystem is also configured to receive external system instructions, and to realize bidirectional data synchronization and function extension with an external system ecosystem.
[0063] The working principle and beneficial effects of the technical solution are as follows: the asset discovery subsystem is configured to obtain multi-source raw asset data in an information technology environment through various automatic detection technologies such as agentless scanning, agent-based collection, cloud service API, and container orchestration API; and output a standardized asset list through feature comparison and deduplication fusion procedures; the unified modeling subsystem is configured to construct a unified asset relationship data model using a graph database based on the standardized asset list; form an asset topology map by processing the correlation and dependency between information technology assets; the intelligent analysis and prediction subsystem is configured to process and analyze historical and real-time operation data obtained from lifecycle management and security compliance based on the asset topology map; output insight results and prediction indicators such as resource capacity prediction, anomaly detection, cost optimization suggestions, and risk trends; the lifecycle management subsystem is configured to perform full lifecycle state tracking and management from asset procurement, deployment, operation, change, maintenance, to recycling and scrapping; and drive an automated operation workflow through a policy engine to realize closed-loop management of information technology asset states; the security and compliance subsystem is configured to perform real-time detection and analysis through a compliance policy library based on the asset topology map and information technology asset states, identify configuration drift, unauthorized changes, and security compliance states, generate alarms, repair suggestions, or execute automated repair strategies; and the interface and extension subsystem is configured to output the asset topology map, information technology asset state, compliance state, and insight results and prediction indicators to external systems such as a configuration management database, a monitoring and ticket system, and the like through standardized RESTful API, gRPC, and Webhook interfaces, and to perform comprehensive rendering and graphical display, and output interactive views such as an asset topology map, a health score, and trend prediction through a web interface or a mobile terminal. The interface and extension subsystem is also configured to receive external system instructions, and to realize bidirectional data synchronization and function extension with an external system ecosystem (for specific principles, refer to the description of the foregoing embodiments). Figure 2). The above scheme realizes automatic data collection and standardized processing through multi-source asset discovery technology, and forms a panoramic topology atlas by combining the asset relationship model constructed by the graph database. Based on the atlas and real-time operation data, machine learning algorithms are used to realize resource prediction, anomaly detection and risk analysis, and the asset state closed-loop management is completed relying on the life cycle management module; the security and compliance module dynamically monitors the configuration deviation and illegal behavior through the strategy library, and links to the automatic repair mechanism; the standardized interface system synchronizes asset data, analysis results and control instructions to external systems in both directions, and finally presents the topology relationship, health indicators and trend prediction through the visual interface, forming a collaborative management capability throughout the asset life cycle.
[0064] The embodiment realizes unified discovery and modeling of multi-source heterogeneous assets, adopts hybrid discovery technology, combines Agentless scanning, Agent data acquisition, cloud API and container orchestration API and other means to realize unified discovery across physical machines, virtual machines, containers, cloud services and edge devices. A unified data modeling mechanism is introduced, such as an asset relationship model based on a graph database, to realize dynamic and accurate expression of asset relationships. A full life cycle closed loop management is realized, which links procurement, deployment, configuration, operation, change, maintenance, recycling and scrapping and other links to form a traceable whole process, and supports policy-driven automatic operations such as patch distribution, configuration delivery and asset compliance checking and repair. Intelligent analysis and prediction, using big data and machine learning models to analyze historical performance data and events, realize capacity prediction, fault trend prediction and cost optimization suggestions; support anomaly behavior detection, timely identify unauthorized access, abnormal consumption or security risks. An open architecture and extensible capability is realized, providing standardized interfaces such as RESTful API, Webhook, gRPC, facilitating integration with existing CMDB, monitoring, ticket and financial systems; based on micro-service architecture and containerized deployment, supporting high concurrency and high availability operation in large-scale cluster environment. Visualization and intelligent decision support is realized, providing asset topology graph, life cycle process view, compliance health score and trend prediction chart; managers can make decisions based on the visualization interface and obtain optimization schemes through intelligent recommendations. A security and compliance built-in mechanism is realized, integrating a policy engine to detect real-time configuration compliance of assets, automatically discovering unauthorized devices or illegal changes; providing one-key repair or automatic repair mechanism to improve security and compliance level. Through the above technical features, the embodiment can realize global visibility, automated operation, intelligent decision support and security compliance guarantee of IT assets, effectively solving the following problems of the prior art: incomplete asset discovery: traditional systems rely on manual input or periodic scanning, which is difficult to cover dynamic assets such as cloud, containers and edge nodes, resulting in incomplete and inaccurate inventory. Data is scattered and isolated: there is a lack of unified data model and interface between CMDB, monitoring, ticket and financial systems, and data standards are inconsistent, making it difficult to realize panoramic asset management. Life cycle management is insufficient: existing solutions often only focus on static registration of assets, lacking full-process tracking and automated control from procurement, deployment, operation, change to recycling / scrapping. Low operation efficiency: asset inspection, configuration change, patch distribution and other operations are still mainly manual or semi-automatic, lacking intelligent scheduling and batch closed loop management mechanism. Compliance and security risks are prominent: configuration drift, unauthorized device access, patch update lag and other problems cannot be discovered and warned in real time, which easily leads to security vulnerabilities and compliance risks. Lack of intelligence: most systems use static rules for alarm and analysis, lacking learning of historical data and running behavior, and cannot provide capacity prediction, risk prediction or optimization suggestions.Poor scalability and compatibility: In the face of hybrid clouds, multi-vendors, and multi-type assets, the existing system has obvious deficiencies in heterogeneous data access, mass concurrent processing, and horizontal expansion capabilities.
[0065] The embodiment is used for discovering, modeling, life cycle management, automated operation and maintenance, and security compliance management of information technology assets such as computing devices, network devices, storage, virtualization / container resources, cloud services, software licenses, and configuration items, and realizes intelligent decision support and abnormal prediction combined with data analysis / machine learning capabilities.
[0066] Embodiment 2: On the basis of embodiment 1, the asset discovery subsystem provided by the embodiment of the application comprises:
[0067] A digital gene extraction component is configured to acquire information technology asset data of the detected information technology assets through multiple channels in parallel, and construct a digital gene sequence for each detected information technology asset object; the digital gene sequence is composed of a group of core feature codes, and the core feature codes are authoritative identification information given by different collection channels; for example, a cloud instance unique identification code is acquired and generated from a cloud service API, a container group runtime signature is acquired and generated from a container orchestration API, a hardware fingerprint hash value is acquired and generated from a proxy collector, and a network service interface fingerprint is generated in combination with a network layer;
[0068] A multi-round fusion component is configured to start a multi-round fusion and conflict resolution process using the digital gene sequence; in the first round of fusion, digital gene sequence matching is performed, information technology asset records with the same digital gene sequence are determined as the same information technology asset, and a first merging is performed;
[0069] For information technology asset records that cannot be matched, the next round of fusion is entered, and digital gene fragment similarity calculation and relevance analysis are started, and the relevance weight and credibility of each core feature code in different digital gene sequences are analyzed; for example, when the cloud instance unique identification codes of two information technology asset objects are different, but the hardware fingerprint hash values and network service interface fingerprints are consistent, it can be inferred that they are different virtual instances on the same physical host, and an association is established instead of being simply regarded as two independent information technology assets or being incorrectly merged;
[0070] For records with conflicting attribute information in different data sources, the most credible attribute value is automatically selected and retained according to the preset data source authority level and the confidence of the feature code; through multi-round fusion, a de-duplicated primary information technology asset list is generated;
[0071] A context association component is configured to utilize the dynamically collected network connection relationships, inter-process call chains, and storage mount points, and the like, to pre-associate the assets in the information technology asset inventory with respect to their topological relationships; for example, if it is identified that the network service interface fingerprint of information technology asset A is being connected by information technology asset B, then the service-consumer relationship is taken as a key attribute and attached to the records of the two information technology assets.
[0072] After the topological relationship pre-association is completed, all information technology asset records and their preliminary relationships are subjected to format conversion and attribute mapping, and a standardized information technology asset inventory is output.
[0073] The working principle and beneficial effects of the technical solution are as follows: the digital gene extraction component of the embodiment is used to acquire information technology asset data detected through multiple channels in parallel, and construct a digital gene sequence for each detected information technology asset object; the digital gene sequence is composed of a group of core feature codes, and the core feature codes are authoritative identification information given by different collection channels; for example, a cloud instance unique identification code is acquired and generated from a cloud service API, a container group runtime signature is acquired and generated from a container orchestration API, a hardware fingerprint hash value is acquired and generated from a proxy collector, and a network service interface fingerprint is generated in combination with a network layer; the multi-round fusion component is used to start a multi-round fusion and conflict resolution process by using the digital gene sequence; in the first round of fusion, digital gene sequence matching is performed, information technology asset records with the same digital gene sequence are determined as the same information technology asset, and the first merging is performed; for information technology asset records that cannot be matched, the next round of fusion is entered, digital gene fragment similarity calculation and relevance analysis are started, and the relevance weight and credibility of each core feature code in different digital gene sequences are analyzed; for example, when the cloud instance unique identification codes of two information technology asset objects are different, but the hardware fingerprint hash values and the network service interface fingerprints are consistent, it can be inferred that they are different virtual instances on the same physical host, and an association is established instead of being simply regarded as two independent information technology assets or being incorrectly merged; for records with conflicting attribute information in different data sources, the most credible attribute value is automatically selected and retained according to the preset data source authority level and the confidence of the feature code; through multi-round fusion, a de-duplicated primary information technology asset list is generated; the context association component is used to use the dynamically collected network connection relationship, inter-process call chain and storage mounting point and the like to pre-associate the assets in the information technology asset list in a topological relationship; for example, if it is identified that the network service interface fingerprint of information technology asset A is connected by information technology asset B, the service-consumer relationship is taken as a key attribute and is attached to the records of the two information technology assets; after the topological relationship pre-association is completed, all information technology asset records and their preliminary relationships are subjected to format conversion and attribute mapping, and a standardized information technology asset list is output. The above scheme integrates the three core modules of digital gene extraction, multi-round fusion and context association, realizes comprehensive identification, accurate de-duplication and relationship construction of information technology assets. The digital gene extraction component collects through multiple channels in parallel, constructs a digital gene sequence containing core feature codes for each asset object; the core feature codes come from authoritative data such as cloud instance identification, container group signature, hardware fingerprint and network interface fingerprint, ensuring the comprehensiveness and accuracy of asset identification.The multi-round fusion component implements a hierarchical disambiguation strategy based on digital gene sequences. The first round of fusion achieves efficient deduplication through precise matching. The second round of fusion introduces feature code weight analysis and conflict resolution mechanisms, which can identify complex scenarios such as virtual instances on the same physical host, and avoid false merging or omissions. Through data source authority rating and feature confidence assessment, attribute conflicts are automatically resolved, forming a high-reliability primary asset list. The context association component further utilizes dynamic information such as network connections and process call chains to construct the topology relationship between assets. By identifying service connections, dependency relationships and other interaction modes, the asset list is injected with business context to form a standardized output with semantic association. Finally, through the closed-loop processing of feature collection, conflict resolution and relationship mining, unified governance of asset data is achieved, ensuring wide coverage of asset discovery and improving data quality through multi-dimensional verification, providing a complete, accurate and context-rich data foundation for asset management.
[0074] In the embodiment 1, the unified modeling subsystem provided by the embodiment of the present application comprises:
[0075] The asset entity component is used to receive the standardized asset list, start the asset semantic context analysis process, and assign an entity semantic identity to each information technology asset according to the type attribute, key identifier and topology relationship pre-association information in each information technology asset item in the standardized asset list. The standardized asset list is converted into a set of asset entity units with role definition and potential relationship orientation.
[0076] The type attribute includes physical servers, cloud virtual machines, container clusters, load balancing services, etc. The entity semantic identity not only includes the basic attributes of the information technology asset, but also defines the role played by the information technology asset in the information technology environment and its expected behavior boundary. For example, an asset identified as a database master node will implicitly include potential relationships of being dependent on application servers and storage resources.
[0077] The generation and association component is used to start a multi-dimensional relationship assertion generation process based on the asset entity unit, perform logical reasoning on the attributes and behavior context of the asset entity unit based on predefined business logic rules and infrastructure dependency patterns, and convert the asset entity unit into relationship assertions through the discovery of topology relationship pre-association information. Isolated asset entity units are interconnected through relationship assertions.
[0078] Among them, the logical reasoning is carried out on the properties and behavior context of the asset entity unit; for example, the reasoning engine finds that the network connection target address of an asset entity unit or an application server is consistent with the access endpoint of another asset entity unit or a database service, generates a relationship assertion of access dependency type; at the same time, the topological relationship pre-association information explicitly marked from the discovery subsystem is also processed, which is converted into a relationship assertion of network adjacency or running type;
[0079] The synthesis and topology emergence component is used for fusing all relationship assertions with asset entity units, performing dynamic graph synthesis operation; each asset entity unit is taken as a graph vertex, and each relationship assertion is taken as a graph edge with type and attribute, and is put into a graph database; the built-in graph computing capability of the graph database will actively identify and aggregate discrete points and edges, so that they are self-organized into a mutually related network structure; the internal connectivity of the vertices and edges is rendered by the graph database, and an asset topology graph is generated.
[0080] The working principle and beneficial effects of the above technical solution are: the asset entity component of the embodiment is used to receive the standardized asset list, start the asset semantic context analysis process, and give each information technology asset an entity semantic identity according to the type attribute, key identifier and topological relationship pre-association information of each information technology asset item in the standardized asset list; the standardized asset list is converted into a set of asset entity units with role definition and potential relationship orientation; the type attribute includes physical servers, cloud virtual machines, container clusters, load balancing services, etc.; the entity semantic identity not only includes the basic attributes of the information technology asset, but also defines the role played by the information technology asset in the information technology environment and its expected behavior boundary; for example, an asset identified as a database master node will implicitly include the potential relationship of being dependent on an application server and a storage resource; the generation and association component is used to generate a multi-dimensional relationship assertion generation process based on the asset entity unit, logically infer the attribute and behavior context of the asset entity unit based on predefined business logic rules and infrastructure dependency patterns; at the same time, the asset entity unit is converted into a relationship assertion from the discovery topological relationship pre-association information; the isolated asset entity unit is interconnected through the relationship assertion; the attribute and behavior context of the asset entity unit is logically inferred; for example, the inference engine finds that the network connection target address of an asset entity unit or an application server is consistent with the access endpoint of another asset entity unit or a database service, and generates a relationship assertion of the access dependency type; at the same time, it also processes the topological relationship pre-association information explicitly marked from the discovery subsystem, and converts it into a network adjacency or a relationship assertion running in the same type; the synthesis and topological emergence component is used to fuse all relationship assertions with asset entity units and perform dynamic graph synthesis operations; each asset entity unit is taken as a graph vertex, and each relationship assertion is taken as a graph edge with a type and an attribute, and is placed into a graph database; the built-in graph computing capability of the graph database will actively identify and aggregate discrete points and edges, and make them self-organize into an interconnected network structure; the internal connectivity of the vertices and edges in the graph database is rendered to generate an asset topology graph. The above scheme converts the standardized asset list into asset entity units with role definition and potential relationship orientation through the asset entity component, so that the information technology asset has an entity semantic identity; the generation and association component generates multi-dimensional relationship assertions based on the asset entity unit, and realizes the interconnection of the asset entity unit through logical inference and pre-association information processing; the synthesis and topological emergence component fuses the relationship assertion and the asset entity unit into a dynamic graph, and generates an interconnected asset topology graph through the graph computing capability of the graph database; finally, the complete conversion of the information technology asset from discrete items to semantic entities, from isolated units to relationship interconnection, and from static data to dynamic topology is realized, and an inferable, renderable and computable asset network structure is formed.
[0081] Embodiment 4: As shown in Embodiment 1, on the basis of Embodiment 1, the intelligent analysis and prediction subsystem provided by the embodiment of the application comprises: Figure 3 An environment situation matrix construction component is configured to start multi-modal data fusion, take the static asset relationship and dependency structure defined by the asset topology graph as an invariable coordinate base, inject historical and real-time running data into the coordinate base according to corresponding asset entity units, and construct an environment situation matrix to form data entities.
[0082] The historical and real-time running data comprises performance indicators, configuration change records and compliance state snapshots; the performance data fills the behavior dimension of the information technology asset, and the configuration and compliance data fill the state dimension of the information technology asset.
[0083] A time series pattern mining component is configured to start time series pattern mining based on the constructed environment situation matrix, and a machine learning model synchronously acquires the context environment of the information technology asset in the asset topology graph when analyzing the behavior data of any information technology asset; the model extracts graph-enhanced time series features by jointly learning the topology relationship and time series data embedded in the environment situation matrix; the graph-enhanced time series features reveal deep laws such as resource bottleneck propagation patterns under service dependency paths and security event diffusion paths under network topology.
[0084] The behavior data comprises CPU usage rate trends; when analyzing abnormal performance fluctuations of an application server, the model simultaneously analyzes the states of downstream databases and upstream load balancers having service dependency relationships with the application server, judges whether the fluctuations are isolated events, the starting point of a chain reaction, or a systematic resource competition result.
[0085] A strategy generation and indicator output component is configured to use the mined graph-enhanced time series features to enter a strategy generation stage for intervention, and generate a strategy draft; the strategy draft, together with quantitative prediction indicators and cost trade-off analysis, constitutes insight results and prediction indicators.
[0086] The prediction model of the strategy generation stage outputs a basic conclusion that resources will be exhausted at a certain time or an anomaly is detected once; for capacity prediction, the model outputs a strategy draft for elastic expansion of A and B service nodes before a business peak arrives to ensure core transaction links; for anomaly detection, the model outputs a strategy draft for immediately starting account blocking and checking audit logs of data service C in view of the fact that the suspicious login from the edge node can directly access the core data area; the quantitative prediction indicators comprise expected resource gaps and risk confidence.
[0087]
[0088] The working principle and beneficial effects of the technical solution are: the environmental situation matrix construction component of the embodiment is used to start multi-modal data fusion, and the static asset relationship and dependency structure defined by the asset topology graph are used as an invariable coordinate base; the historical and real-time running data are injected into the coordinate base according to the corresponding asset entity unit; the environmental situation matrix is constructed to form a data entity; wherein the historical and real-time running data include performance indicators, configuration change records and compliance state snapshots; the performance data fill the behavior dimension of the information technology asset, and the configuration and compliance data fill the state dimension of the information technology asset; the time series pattern mining component is used to start time series pattern mining based on the constructed environmental situation matrix, and the machine learning model synchronously obtains the context environment of the information technology asset in the asset topology graph when analyzing the behavior data of any information technology asset; the graph-enhanced time series features are extracted by jointly learning the topological relationship and time series data embedded in the environmental situation matrix; the graph-enhanced time series features reveal deep laws such as resource bottleneck propagation mode under service dependency path and security event diffusion path under network topology; wherein the behavior data includes CPU usage trend; when analyzing the abnormal performance fluctuation of an application server, the model analyzes the states of the downstream database and the upstream load balancer that have service dependency relationship with the application server, judges whether the fluctuation is an isolated event, the starting point of a chain reaction or a systematic resource competition result; the strategy generation and indicator output component is used to enter the strategy generation stage for intervention by using the mined graph-enhanced time series features to generate a strategy draft; the strategy draft, together with the quantitative prediction indicators and cost trade-off analysis, constitutes the insight results and prediction indicators; wherein the prediction model of the strategy generation stage outputs the basic conclusion that the resource will be exhausted at a certain time or an abnormality is detected; for capacity prediction, the model outputs the strategy draft of elastic expansion of A and B service nodes before the arrival of business peak to ensure the core transaction link; for anomaly detection, the model outputs the strategy draft of immediately starting account blocking and checking the audit log of data service C based on the analysis of the attack path, in view of the fact that the edge node can directly access the core data area; the quantitative prediction indicators include expected resource gap and risk confidence. The above scheme fuses the static asset relationship and dynamic running data through the environmental situation matrix construction component to form a unified data entity expression. The time series pattern mining component jointly learns the topological structure and time series data based on graph context perception to extract graph-enhanced time series features that can reflect the resource bottleneck propagation and security event diffusion laws. The strategy generation and indicator output component generates complete insight results including pre-disposal schemes, quantitative indicators and cost analysis based on these features. The components work together to realize a full-chain closed loop from data fusion, law mining to decision support, and finally form a predictive operation and maintenance mechanism with topology perception capability, which can accurately identify systematic risks and give targeted intervention schemes.
[0089] In the embodiment 5, on the basis of the embodiment 4, the timing pattern mining component comprises:
[0090] The graph convolutional time series feature extraction sub-component is used to start the graph convolutional time series feature extraction, and the asset topology graph structure contained in the environment situation matrix is loaded into a graph neural network operation as graph structure priori knowledge. When analyzing the behavior data of the target information technology asset, the contemporaneous behavior data of the directly adjacent information technology assets is aggregated synchronously according to the weight, and a group of graph convolutional time series features are generated.
[0091] The space-time correlation distillation sub-component is used to introduce a time attention mechanism to analyze the time correlation of the graph convolutional time series features, identify time segments similar to the current situation, and generate a space-time correlation summary.
[0092] The time attention mechanism automatically identifies and emphasizes the time segments in the historical data that are similar to the current situation or have caused key events. For example, it is found that the pattern of the current graph convolutional time series features is highly similar to the pattern before a chain collapse of the application server caused by a database bottleneck last month.
[0093] The propagation pattern feature formation sub-component is used to use a lightweight causal discovery model to infer the most likely propagation path and root cause of the anomaly or load based on the space-time correlation summary, and obtain the propagation pattern features of the behavior data.
[0094] Wherein, it is determined that the performance fluctuation of the current application server has a high probability of being triggered by the delay of the downstream database, rather than its own problem or the upstream load balancer. The conclusion of the reasoning is solidified as a reusable and deep description of the system behavior rule, i.e. the propagation pattern feature. It explicitly reveals the deep rules such as resource bottleneck propagation pattern under service dependency path or security event diffusion path under network topology, and provides decision basis for the strategy generation and index output component.
[0095] The working principle and beneficial effects of the technical solution are as follows: the graph convolution time series feature extraction subcomponent in the embodiment is used to start graph convolution time series feature extraction, and the asset topology graph structure contained in the environmental situation matrix is loaded into a graph neural network operation as graph structure prior knowledge. When analyzing the behavior data of the target information technology asset, the time series behavior data of the directly adjacent information technology assets is aggregated synchronously according to the weight to generate a set of graph convolution time series features. The space-time correlation distillation subcomponent is used to introduce a time attention mechanism to analyze the time correlation of the graph convolution time series features, identify time segments similar to the current situation, and generate a space-time correlation summary. The time attention mechanism automatically identifies and emphasizes time segments in the historical data that are similar to the current situation or that have caused key events. For example, it is found that the pattern of the current graph convolution time series features is highly similar to the pattern before the application server chain collapse caused by the database bottleneck last month. The propagation pattern feature formation subcomponent is used to infer the most possible propagation path and root cause of the anomaly or load based on the space-time correlation summary by using a lightweight causal discovery model, to obtain the propagation pattern feature of the explained behavior data. It is determined that the performance fluctuation of the current application server is most likely triggered by the delay of the downstream database, rather than the problem of the application server itself or the upstream load balancer. The conclusion of the reasoning is solidified as a reusable and deep description of the system behavior rule, that is, the propagation pattern feature. The deep rules such as the resource bottleneck propagation pattern under the service dependency path or the security event diffusion path under the network topology are explicitly revealed, providing decision basis for the strategy generation and index output component. The time series pattern mining component integrates the three subcomponents of graph convolution time series feature extraction, space-time correlation distillation, and propagation pattern feature formation to form a multi-level analysis framework. The graph convolution time series feature extraction subcomponent takes the asset topology structure as the graph structure prior knowledge, synchronously aggregates the behavior data of the target asset and adjacent assets through the graph neural network, and generates time series features with spatial dependency. The space-time correlation distillation subcomponent adopts the time attention mechanism, compares the time segments similar to the current situation in the historical data, and extracts a feature summary with time correlation. The propagation pattern feature formation subcomponent infers the abnormal propagation path and root cause from the space-time correlation summary based on the causal discovery model, and forms a systematic behavior rule description. After the cooperative action of each technical feature, the systematic analysis from the original behavior data to the system behavior rule is realized. By fusing the spatial topology and time dimension information, the recognition accuracy of the abnormal propagation pattern in the complex system is improved. The propagation path analysis based on causal reasoning enhances the positioning ability of the system fault root cause, and the propagation pattern feature formed provides a verifiable decision basis for system optimization and risk prevention and control. Finally, multi-dimensional perception and deep rule mining of the information system running situation are achieved, supporting accurate operation and maintenance decisions and resource scheduling.
[0096] Embodiment 6: as Figure 4As shown, on the basis of Embodiment 1, the lifecycle management subsystem provided by the present embodiment comprises:
[0097] An asset state baseline depiction component is configured to assign an asset state baseline based on the structural position and dependency relationship of the information technology asset record in the asset topology map;
[0098] The asset state baseline comprises a lifecycle phase of the information technology asset, and a performance index range, a compliance configuration standard and an allowed change operation set that should be met to maintain the service function of the information technology asset; for example, for a server in the core transaction link in the topology, the baseline of the running state of the server defines the patch version that must be run, the prohibited configuration modification item and the performance threshold that must be complied with;
[0099] A policy package dynamic binding component is configured to logically match the asset state baseline with a predefined automated operation workflow; each asset state baseline condition is associated with one or more executable policy packages; when it is found through monitoring real-time operation data that the asset state deviates from the baseline, the corresponding repair policy package is dynamically bound to the information technology asset;
[0100] A closed-loop management work order component is configured to start closed-loop management work order generation and feedback according to the repair strategy execution result report; if the repair strategy execution result report indicates that the operation has successfully returned the information technology asset state to the asset state baseline, a record is generated to update the asset state baseline of the information technology asset;
[0101] If the operation fails or cannot completely solve the problem, based on the error information in the repair strategy execution result report and the current asset state baseline, a closed-loop management work order is automatically generated and assigned to the corresponding manual processing team.
[0102] The working principle and beneficial effects of the technical solution are as follows: the asset state baseline description component of the embodiment is used to assign an asset state baseline based on the structural position and dependency relationship of the information technology asset record in the asset topology map; the strategy package dynamic binding component is used to logically match the asset state baseline with a predefined automated operation and maintenance workflow; each asset state baseline condition is associated with one or more executable strategy packages; when it is found through monitoring real-time operation data that the asset state deviates from the baseline, the corresponding repair strategy package is dynamically bound to the information technology asset; the closed-loop management work order component is used to start the closed-loop management work order generation and feedback according to the repair strategy execution result report; if the repair strategy execution result report indicates that the operation has successfully returned the information technology asset state to the asset state baseline, a record is generated and the asset state baseline of the information technology asset is updated. The asset state baseline description component of the above scheme converts isolated asset data into a state model with contextual relationships through topology analysis and dependency mapping; the baseline integrates life cycle phase determination, performance tolerance interval, compliance configuration rules and change constraint conditions to form a quantifiable asset health standard. For example, the version constraint and performance threshold of the core server baseline essentially build a compliance framework for asset operation. The strategy package dynamic binding component establishes a triggering mechanism for baseline conditions and operation and maintenance strategies; through deviation detection of real-time monitoring data and baseline conditions, automatic matching and loading of repair strategies are realized; the dynamic binding relationship enables the system to have a coherent response capability from state perception to intervention execution. The closed-loop management work order component drives the state closed loop through strategy execution feedback; when the repair is successful, the baseline is updated to achieve knowledge sedimentation, and when the execution fails, a precise work order is generated to assign manual processing; both ensure the efficiency of automated processing of routine problems and reserve a manual intervention channel for abnormal scenarios.
[0103] In summary, the embodiment realizes the continuous governance of asset state from perception, decision-making to correction through the cycle architecture of state modeling, strategy triggering and execution feedback. It reduces the dependence on manual judgment, forms a self-improving operation and maintenance system through baseline iteration optimization, and finally achieves the dual goals of reducing operation and maintenance costs and improving system reliability.
[0104] In the embodiment 6, the strategy package dynamic binding component comprises:
[0105] The strategy knowledge graph association subcomponent is used to deconstruct and associate all predefined automated strategy packages; each strategy package is decomposed into describable strategy metadata to form a strategy knowledge graph;
[0106] The matching vector generation subcomponent is configured to, when a real-time state of an information technology asset deviates from an asset state baseline, a deviation event is analyzed, and a structured baseline deviation descriptor is generated; the baseline deviation descriptor is subjected to semantic matching with the policy knowledge graph, an association degree and a fitting degree between the deviation descriptor and policy metadata of each policy are obtained, and a policy package matching vector sorted according to a matching priority is output.
[0107] The context awareness subcomponent is configured to evaluate and adapt a candidate policy in the policy package matching vector in combination with the asset state baseline and a current runtime context.
[0108] The working principle and beneficial effects of the technical solution are as follows: the policy knowledge graph association subcomponent is configured to deconstruct and associate all predefined automated policy packages; each policy package is decomposed into describable policy metadata to form a policy knowledge graph; the matching vector generation subcomponent is configured to, when a real-time state of an information technology asset deviates from an asset state baseline, a deviation event is analyzed, and a structured baseline deviation descriptor is generated; the baseline deviation descriptor is subjected to semantic matching with the policy knowledge graph, an association degree and a fitting degree between the deviation descriptor and policy metadata of each policy are obtained, and a policy package matching vector sorted according to a matching priority is output; and the context awareness subcomponent is configured to evaluate and adapt a candidate policy in the policy package matching vector in combination with the asset state baseline and a current runtime context. The policy package dynamic binding component is configured to deconstruct a predefined automated policy package into a policy knowledge graph, and establish a semantic association network between policy metadata. When a state of an information technology asset deviates from a baseline, a structured baseline deviation descriptor is generated, an association fitting degree with each policy metadata in the policy knowledge graph is calculated through semantic matching, and a policy package matching vector sorted according to a matching priority is formed. A candidate policy is dynamically evaluated and adapted in combination with an asset state baseline and a runtime context; intelligent association between a policy package and an asset running state is achieved, and matching precision is improved; a semantic matching mechanism is used to reduce complexity of manual policy configuration; dynamic adaptation based on a runtime context enhances effectiveness of policy execution; a policy knowledge graph is used to support reuse and combination of policy elements; and response efficiency and processing accuracy of an asset state deviation event are optimized.
[0109] Embodiment 8: as shown in the embodiment 1, on the basis of the embodiment 1, the security and compliance subsystem provided by the embodiment of the application comprises: Figure 5
[0110] The compliance posture mirror building component is used to define the static asset relationship of the asset topology map and the dependency network as an immutable review framework; real-time configuration data, operation parameters and security attributes contained in the information technology asset state are filled into the review framework according to the corresponding asset entity unit; the configuration data defines the expected security baseline of the information technology asset, and the operation parameters reflect the actual running state; and a compliance posture mirror is built.
[0111] The policy consistency deduction component is used to logically deduce each policy rule in the compliance policy library in the global context built by the compliance posture mirror, identify deep violations and associated risks in a single information technology asset inspection, and generate a compliance deviation event set describing the deviation asset, deviation type, violated policy item, and influence range in the topology.
[0112] The classification disposal instruction generation component is used to perform risk rating and disposal path decision according to the keyness of each event in the compliance deviation event set in the asset topology map, the severity level of the deviation itself, and the available automated repair script.
[0113] For deviations with high risk and automated repair conditions, automated repair strategy instructions are generated; for deviations that require manual review or are complex and have a large impact, repair suggestions and alarms with detailed context are generated.
[0114] The working principle and beneficial effects of the technical solution are as follows: the compliance posture mirror image construction component of the embodiment is used to define the static asset relationship of the asset topology graph as an unchanged review framework in combination with the dependency network; the real-time configuration data, operation parameters and security attributes contained in the information technology asset state are filled into the review framework according to the corresponding asset entity unit; the configuration data define the expected security baseline of the information technology asset, and the operation parameters reflect the actual running state; a compliance posture mirror image is constructed; the strategy consistency deduction component is used to logically deduce each policy rule in the compliance policy library in the global context constructed by the compliance posture mirror image, identify deep violations and associated risks in single information technology asset inspection, and generate a compliance deviation event set describing the deviated asset, the deviation type, the violated policy item and the influence range in the topology; the classification disposal instruction generation component is used to make risk rating and disposal path decisions according to the criticality of each event in the compliance deviation event set in the asset topology graph, the severity level of the deviation itself and the available automated repair scripts; for deviations with high risk and automated repair conditions, automated repair strategy instructions are generated; for deviations that need manual review or are complex and have a large impact range, repair suggestions and alarms with detailed context are generated. The security and compliance subsystem of the above scheme realizes full-link closed-loop management through a modular technical architecture. The compliance posture mirror image construction component fuses the static asset topology and dynamic operation data to form a unified asset security state mapping layer and establish an observability basis for configuration baselines and actual running states. The strategy consistency deduction component implements policy rule reasoning on the global posture mirror image, breaks through the limitations of traditional single-point detection, identifies cross-asset linkage violation patterns through topology correlation analysis, and realizes the evolution from surface compliance inspection to deep risk mining. The classification disposal instruction generation component introduces multi-dimensional decision factors to generate a hierarchical response scheme by comprehensively considering asset criticality, risk severity and repair feasibility. It not only ensures the rapid automatic repair of high-risk vulnerabilities, but also supports manual decision-making in complex scenarios through context-enhanced disposal suggestions.
[0115] In summary, the embodiment realizes deep coupling of security policies and operation and maintenance practices, changes compliance management from passive inspection to active governance, and significantly improves overall security level and operation and maintenance efficiency.
[0116] Embodiment 9: Based on embodiment 8, the strategy consistency deduction component provided by the embodiment of the application comprises:
[0117] The policy checking context construction subcomponent is used for semantic analysis of policy rules, each of which is converted into an executable policy checking context containing the logical judgment conditions of the policy and defining the specific path and relationship type in the asset topology graph that needs to be traversed to perform the check; the policy rule is instantiated as a policy checking context that performs targeted exploration on the compliance posture mirror specific data entity;
[0118] The relevance impact network analysis subcomponent is used for deep traversal and logical judgment on the compliance posture mirror. When an initial policy deviation is identified on a certain information technology asset, the information technology asset of the initial policy deviation is taken as the starting point, and the dependence and connection relationship defined in the compliance posture mirror is used to dynamically deduce the relevance security impact caused by the initial policy deviation, generating a relevance impact network that outlines the potential impact path and scope with the initial policy deviation as the center;
[0119] The compliance deviation event synthesis subcomponent is used for multi-dimensional feature packaging of the asset identification, specific type, and violated policy item of the initial policy deviation, and the impact range described by the relevance impact network, forming a compliance deviation event containing complete context.
[0120] The working principle and beneficial effects of the technical solution are as follows: the policy checking context construction subcomponent of the embodiment is used for semantic analysis of a policy rule, each policy rule is converted into an executable policy checking context, a logical judgment condition of the policy is included, and a specific path and a relationship type in an asset topology graph that needs to be traversed for performing checking are defined; the policy rule is instantiated as a policy checking context that performs directional exploration on a compliance posture mirror specific data entity; the correlation influence network analysis subcomponent is used for performing deep traversal and logical judgment on the compliance posture mirror, when an initial policy deviation is identified on a certain information technology asset, the information technology asset of the initial policy deviation is taken as a starting point, a correlation influence network that takes the initial policy deviation as a center and outlines a potential influence path and a range is generated according to a dependency and a connection relationship defined in the compliance posture mirror; and the compliance deviation event synthesis subcomponent is used for multi-dimensional feature packaging of an asset identifier, a specific type, a policy item violated by the initial policy deviation, and an influence range described by the correlation influence network, to form a compliance deviation event including complete context. The policy checking context construction subcomponent of the above scheme converts a text policy into an executable logical judgment condition, clearly defines a checking range and an asset relationship path, and ensures accuracy and operability of policy verification. The correlation influence network analysis subcomponent performs dynamic deduction along a dependency chain from the initial policy deviation based on a topology relationship of the compliance posture mirror, reveals cascading influences that may be caused by a single-point violation, and forms a risk propagation network covering multi-hop correlation nodes. The compliance deviation event synthesis subcomponent performs multi-dimensional feature fusion to structurally package asset attributes, policy clauses and the influence network, and generates a compliance deviation event record including a complete cause-effect chain, thereby providing a decision basis with traceability for risk disposal.
[0121] In summary, the embodiment realizes closed-loop processing from policy analysis, influence deduction to event generation, and effectively improves the perception depth of a compliance state of a complex information system and the coverage dimension of risk assessment.
[0122] In the embodiment 9, the correlation influence network analysis subcomponent comprises:
[0123] The risk propagation path discovery module is configured to perform graph traversal from the initial policy deviation asset according to the relationship types in the compliance posture mirror, define a transmission possibility and a strength for each relationship type, and identify all potential paths through which risks may be transmitted from the initial policy deviation asset via various relationship chains, to generate a set of risk propagation paths.
[0124] The influence range dynamic definition module is configured to perform influence evaluation on all information technology assets covered by the risk propagation path, calculate an influence degree score according to a criticality level of each information technology asset in the compliance posture mirror image, and an associated strength and path length of the initial policy deviation, and filter all covered information technology assets according to a preset risk tolerance threshold, and determine assets with an influence degree score exceeding the risk tolerance threshold as influence targets of the current deviation.
[0125] The correlation influence network synthesis module is configured to take the initial policy deviation asset as a root node, take the risk propagation path as an edge, and take assets in the dynamic influence range as a vertex, construct an influence relationship subgraph, and obtain a correlation influence network with the initial policy deviation as a center and outlining a potential influence path and an accurate range.
[0126] The working principle and beneficial effects of the above technical solution are as follows: The risk propagation path discovery module is configured to start from the initial policy deviation asset according to a relationship type in the compliance posture mirror image, perform graph traversal, define a transmission possibility and strength for each relationship type, identify all potential paths through which risk may be transmitted from the initial policy deviation asset to each type of relationship chain, and generate a set of risk propagation paths. The influence range dynamic definition module is configured to perform influence evaluation on all information technology assets covered by the risk propagation path, calculate an influence degree score according to a criticality level of each information technology asset in the compliance posture mirror image, and an associated strength and path length of the initial policy deviation, and filter all covered information technology assets according to a preset risk tolerance threshold, and determine assets with an influence degree score exceeding the risk tolerance threshold as influence targets of the current deviation. The correlation influence network synthesis module is configured to take the initial policy deviation asset as a root node, take the risk propagation path as an edge, and take assets in the dynamic influence range as a vertex, construct an influence relationship subgraph, and obtain a correlation influence network with the initial policy deviation as a center and outlining a potential influence path and an accurate range. The correlation influence network analysis subassembly of the above solution realizes systematic risk evaluation through the cooperative operation of the three modules. The risk propagation path discovery module starts from the initial policy deviation asset based on the relationship topology of the compliance posture mirror image, performs traversal analysis along the predefined relationship chain, identifies all potential paths through which risk may be transmitted, and quantifies the transmission possibility and strength of each path. The influence range dynamic definition module performs multi-dimensional influence evaluation on assets covered by the path, calculates an influence degree in combination with parameters such as asset criticality level, associated strength, and path distance, and accurately selects target assets actually influenced according to a preset risk threshold. The correlation influence network synthesis module structurally integrates the analysis results, constructs a relationship subgraph with the initial deviation as a root node, the risk path as an edge, and the influenced assets as a vertex, and forms an analysis network completely describing the risk propagation path and the accurate influence range.
[0127] To sum up, the embodiment realizes progressive analysis from path discovery, range definition to network construction, and can systematically reveal the propagation mechanism and influence boundary of single-point compliance deviation in a complex information system, thereby providing a quantitative basis for risk assessment.
[0128] In the embodiment 10, the influence range dynamic definition module comprises:
[0129] The key quantitative matrix construction submodule is used for mapping a key quantitative matrix according to the key level predefined for each information technology asset in the compliance situation mirror; the key quantitative matrix gives each information technology asset a quantitative key base value, reflecting the inherent importance of the information technology asset in the static environment;
[0130] The propagation attenuation factor calculation submodule is used for calculating the propagation attenuation factor of each information technology asset on each specific path in the risk propagation path; the correlation strength and the path length are fused to calculate the propagation attenuation factor of the information technology asset on the risk propagation path, and the value is between 0 and 1;
[0131] The affected degree scoring submodule is used for multiplying the corresponding key base value in the key quantitative matrix by the calculated propagation attenuation factor for each information technology asset in the coverage range of the risk propagation path, and the result is the affected degree score of the information technology asset.
[0132] The working principle and beneficial effects of the technical solution are as follows: the key quantization matrix construction submodule of the embodiment is used to map a key quantization matrix according to the key level predefined for each information technology asset in the compliance posture mirror; the key quantization matrix gives each information technology asset a quantized key base value, reflecting the inherent importance of the information technology asset in the static environment; the propagation attenuation factor calculation submodule is used to calculate the propagation attenuation factor of each information technology asset on each specific path in the risk propagation path; the correlation strength and the path length are fused to calculate the propagation attenuation factor of the information technology asset on the risk propagation path, and the value is between 0 and 1; the affected degree scoring submodule is used to multiply the corresponding key base value in the key quantization matrix by the calculated propagation attenuation factor for each information technology asset in the risk propagation path coverage, and the result is the affected degree score of the information technology asset. The key quantization matrix construction submodule of the above scheme establishes a benchmark reference system for the inherent importance of assets, converts the abstract key level into a calculable quantitative index, and provides a stable numerical basis for evaluation. The propagation attenuation factor calculation submodule dynamically captures the change law of the risk intensity with the propagation distance and the correlation by analyzing the path characteristics in the risk transmission process, and accurately reflects the attenuation characteristics of the risk in the system. The affected degree scoring submodule synthesizes the static key base value and the dynamic propagation attenuation factor to generate a composite evaluation index with the inherent properties of assets and the risk propagation characteristics, and realizes accurate quantization of the risk influence range.
[0133] In summary, the embodiment forms a complete mapping chain from the inherent importance of assets to the actual impact of risks, enabling the system to objectively identify the key risk impact area and provide accurate range definition basis for risk management decisions.
[0134] In the embodiment 11, the propagation attenuation factor calculation submodule comprises:
[0135] The relationship type weight allocation unit is configured to assign an initial relationship type weight to each relationship type according to the semantic definition of the connection relationship between the information technology assets in the compliance posture mirror, and the relationship type weight represents the inherent difficulty of risk transmission in this type of relationship channel.
[0136] The path attenuation coefficient calculation unit is configured to consider the path length, i.e., the hop count, of the specific path from the initial deviation asset to the target asset in the risk propagation path, and calculate a path attenuation coefficient by using a nonlinear attenuation.
[0137] The propagation attenuation factor fusion unit is configured to fuse an initial relationship type weight as a basis and a path attenuation coefficient as a nonlinear adjuster to output a final quantized value between 0 and 1, i.e., the propagation attenuation factor.
[0138] The working principle and beneficial effects of the technical solution are as follows: the relationship type weight distribution unit of the embodiment is used to give an initial relationship type weight to each type of relationship according to the semantic definition of the connection relationship between information technology assets in the compliance situation mirror, and the relationship type weight represents the inherent difficulty of risk transmission in this type of relationship channel; the path attenuation coefficient calculation unit is used to consider the path length, i.e., the number of hops, of the specific path from the initial deviation asset to the target asset in the risk propagation path; a non-linear attenuation is used to calculate the path attenuation coefficient; and the propagation attenuation factor fusion unit is used to fuse an output of a final quantitative value between 0 and 1, i.e., the propagation attenuation factor, based on the relationship type weight and taking the path attenuation coefficient as a non-linear adjuster. The relationship type weight distribution unit of the above scheme quantifies the risk transmission characteristics of different connection relationships, and establishes an initial transmission resistance evaluation benchmark based on asset association semantics. The path attenuation coefficient calculation unit introduces a non-linear attenuation model to accurately depict the dynamics of risk attenuation along the propagation path as the number of hops increases, and avoids the evaluation deviation that may be caused by a linear model. The propagation attenuation factor fusion unit forms a comprehensive attenuation evaluation index with both relationship type characteristics and path topology characteristics through the coupling operation of the weight-based value and the path attenuation coefficient.
[0139] In summary, the embodiment realizes the standardized measurement of risk transmission intensity, provides a quantifiable propagation efficiency parameter for system risk assessment, and supports the accuracy and reliability of risk transmission probability calculation. The influence mechanism of relationship semantic definition and path topology structure on risk propagation is effectively unified, and the evaluation result is ensured to reflect the essential characteristics of asset association and comply with the physical law of risk transmission.
[0140] In the embodiment 12, the path attenuation coefficient calculation unit comprises:
[0141] The path attenuation base calculation sub-unit is configured to map the integer path length into a path attenuation base between 0 and 1; for example, the path attenuation base corresponding to the first hop is 0.6, the second hop is 0.3, the third hop is 0.15, the fourth hop is 0.12, and the fifth hop is 0.11.
[0142] The dynamic attenuation gradient generation sub-unit is configured to analyze the historical stability of the current propagation path, and generate a dynamic attenuation gradient as an adjustment variable according to the historical stability.
[0143] For example, whether the connection relationship between assets on this path has been frequently changed in the past period of time; if the path history stability is high, a smaller dynamic attenuation gradient is generated, allowing the risk to be transmitted further; if the stability is low, a larger dynamic attenuation gradient is generated, intensifying the attenuation of the risk; the dynamic attenuation gradient serves as an adjusting variable for fine-tuning the next step of the synthesis process; the smaller, larger, high, and low of the design can be set according to actual conditions;
[0144] The path attenuation coefficient synthesis subunit is configured to read the path attenuation base value generated by the path attenuation base calculation process, load the dynamic attenuation gradient parameter generated by the dynamic attenuation gradient generation process, input the path attenuation base as a basic value into the coefficient synthesis, and inject the dynamic attenuation gradient as a correction parameter; the path attenuation coefficient synthesis subunit is further configured to multiply the value of the dynamic attenuation gradient by a preset gradient influence factor to obtain an actual correction amount, subtract the actual correction amount from the value of the path attenuation base to obtain an intermediate result, perform numerical range constraint processing on the intermediate result to ensure that the value of the intermediate result falls within the interval of zero to one, set the intermediate result to zero if the intermediate result is less than zero, set the intermediate result to one if the intermediate result is greater than one, and obtain the path attenuation coefficient.
[0145] The working principle and beneficial effects of the technical solution are as follows: the path attenuation base calculation subunit of the embodiment is used to map the integer path length into a path attenuation base between 0 and 1; the dynamic attenuation gradient generation subunit is used to analyze the historical stability of the current propagation path, and generate a dynamic attenuation gradient as a regulating variable according to the historical stability; the path attenuation coefficient synthesis subunit is used to read the path attenuation base value generated by the path attenuation base calculation process, and load the dynamic attenuation gradient parameter generated by the dynamic attenuation gradient generation process; the path attenuation base is input into the coefficient synthesis as a basic value, and the dynamic attenuation gradient is injected as a correction parameter; the value of the dynamic attenuation gradient is multiplied by a preset gradient influence factor to obtain an actual correction amount; the actual correction amount is subtracted from the value of the path attenuation base to obtain an intermediate result; the intermediate result is subjected to numerical range constraint processing to ensure that its value falls within the interval of zero to one; if the intermediate result is less than zero, it is set to zero; if the intermediate result is greater than one, it is set to one to obtain the path attenuation coefficient. The path attenuation coefficient calculation unit of the above scheme realizes dynamic attenuation regulation and control through multi-module cooperation. The path attenuation base calculation subunit maps the integer path length into a standardized base value, establishing a basic attenuation framework. The dynamic attenuation gradient generation subunit generates a gradient parameter according to the historical stability of the propagation path; when the stability is high, a smaller gradient is used to maintain the risk transmission range; when the stability is low, a larger gradient is used to enhance the attenuation effect. The path attenuation coefficient synthesis subunit fuses the base value and the gradient parameter, calculates the actual correction amount through a preset influence factor, and performs interval constraint processing on the synthesis result to ensure that the output value is always within the effective range. The adaptive adjustment of the path attenuation coefficient is realized, which not only retains the basic attenuation characteristics, but also introduces the dynamic stability factor, forming a risk transmission control mechanism with environmental response capability.
[0146] In the embodiments 1-13, the IT asset intelligent management system provided by the present application comprises the following steps: Figure 6 The implementation method of the IT asset intelligent management system provided by the present application comprises the following steps:
[0147] S100: Collecting original asset data through technical means such as agentless scanning, agent collection and cloud service API; cleaning and standardizing the data based on feature comparison and deduplication fusion to generate a structured asset list; constructing an asset relationship model using graph database technology, forming a visual asset topology map through correlation analysis, and establishing a complete asset relationship view;
[0148] S200: Integrate asset topology map and operation data, including real-time status, historical records and compliance information; use big data platform and machine learning for multi-dimensional analysis to realize anomaly detection, capacity prediction, cost evaluation and risk analysis; output quantifiable decision indicators, including resource capacity prediction report, anomaly detection alarm, cost optimization suggestion and risk trend warning;
[0149] S300: Gather asset topology, real-time status and analysis indicators and other data, encapsulate data through standardized interface; realize integration with external platforms such as configuration management database, monitoring system, work order system, etc., and realize visual display through Web and mobile terminal, support interactive query of views such as asset topology graph, health score, trend prediction, etc.
[0150] The working principle and beneficial effects of the above technical solution are: first, the original asset data is collected through agentless scanning, agent collection and cloud service API and other technical means; based on feature comparison and deduplication fusion, the data is cleaned and standardized to generate a structured asset list; the asset relationship model is constructed using graph database technology, and the visual asset topology map is formed through correlation analysis to establish a complete asset relationship view; second, integrate asset topology map and operation data, including real-time status, historical records and compliance information; use big data platform and machine learning for multi-dimensional analysis to realize anomaly detection, capacity prediction, cost evaluation and risk analysis; output quantifiable decision indicators, including resource capacity prediction report, anomaly detection alarm, cost optimization suggestion and risk trend warning; finally, gather asset topology, real-time status and analysis indicators and other data, encapsulate data through standardized interface; realize integration with external platforms such as configuration management database, monitoring system, work order system, etc., and realize visual display through Web and mobile terminal, support interactive query of views such as asset topology graph, health score, trend prediction, etc. The above scheme realizes full-quantity asset coverage through multi-source data collection technology, eliminates data silos by combining standardized processing, and establishes a unified asset information library; the application of graph database technology visualizes asset correlation and realizes accurate mapping of asset dependency relationship. The integration of multi-dimensional data establishes comprehensive analysis capability, and machine learning algorithm realizes the transition from passive monitoring to active prediction; through functions such as anomaly pattern recognition and resource trend prediction, the response speed and management foresight of operation and maintenance are significantly improved. The standardized interface design breaks down the system barriers, realizes seamless connection with the existing operation and maintenance tool chain; cross-platform visual display ensures real-time accessibility of management data, and improves information acquisition efficiency through interactive query.
[0151] In summary, the embodiment realizes the full-process automation of asset management from information collection, intelligent analysis to decision execution, greatly improves asset utilization rate, reduces operation and maintenance cost, and enhances system risk control capability.
[0152] The present embodiments are suitable for use in implementing exemplary electronic devices of the present embodiments.
[0153] The electronic device can include a central processor / microprocessor / master control chip, etc.; a storage medium coupled to the central processor / microprocessor / master control chip, etc., and storing computer executable instructions therein for performing steps of various methods of the present embodiments when executed by the processor.
[0154] The central processor / microprocessor / master control chip, etc. can include, but not limited to, for example, one or more processors or microprocessors, etc.
[0155] The storage medium can include, but not limited to, for example, random access memory (RAM), read only memory (ROM), flash memory, EPROM memory, EEPROM memory, registers, computer storage media (such as hard disks, floppy disks, solid state drives, removable disks, CD-ROMs, DVD-ROMs, Blu-ray discs, etc.).
[0156] In addition, the electronic device can also include (but not limited to) a data bus, an input / output bus / external bus / device bus, etc., a display, and an input / output device (such as a keyboard, a mouse, a speaker, etc.), etc.
[0157] The central processor / microprocessor / master control chip, etc. can communicate with external devices through an I / O bus via a wired or wireless network (not shown).
[0158] The storage medium can also store at least one computer executable instruction for performing steps of various functions and / or methods in the embodiments described in the present technology when executed by the central processor / microprocessor / master control chip, etc.
[0159] In one embodiment, the at least one computer executable instruction can also be compiled or composed into a software product, wherein one or more computer executable instructions are executed by the processor to perform steps of various functions and / or methods in the embodiments described in the present technology.
[0160] Schematic diagram of a computer readable storage medium according to an embodiment of the present embodiments.
[0161] An instruction, for example, a computer readable instruction, is stored on a non-transitory computer readable storage medium. When the computer readable instruction is executed by a processor, each of the above-described methods can be performed. The non-transitory computer readable storage medium includes, but is not limited to, for example, a volatile memory and / or a non-volatile memory. The volatile memory can include, for example, a random access memory (RAM), a cache, and / or the like. The non-volatile memory can include, for example, a read only memory (ROM), a hard disk, a flash memory, and / or the like. For example, the non-transitory computer readable storage medium can be connected to a computing device such as a computer, and then, when the computing device executes the computer readable instruction stored on the non-transitory computer readable storage medium, each of the above-described methods can be performed.
[0162] It is apparent that a person skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and changes of the present application belong to the scope of equivalents of the present application, they are also intended to be included in the present application.
Claims
1. An intelligent management system for IT assets, characterized in that, Include: The intelligent analysis and prediction subsystem is used to process and analyze asset topology maps and historical and real-time operational data obtained from lifecycle management and security compliance through big data and machine learning. Output results and forecast indicators regarding resource capacity prediction, anomaly detection, cost optimization suggestions, and risk trend insights; The lifecycle management subsystem is used to perform full lifecycle status tracking and management from asset procurement, deployment, operation, change, maintenance to recycling and disposal; and drives automated operation and maintenance workflows through a policy engine to achieve closed-loop management of the status of information technology assets. The security and compliance subsystem is used to perform real-time detection and analysis based on the asset topology map and the status of information technology assets through the compliance policy library, to identify configuration drift, unauthorized changes and security compliance status; generate alarms, remediation suggestions or execute automated remediation strategies; The security and compliance subsystem includes: The compliance posture mirroring component is used to treat the static asset relationships and dependency networks defined by the asset topology map as an immutable review framework; it also uses the real-time configuration data, operating parameters, and security attributes contained in the information technology asset status to correspond to and populate the review framework with the corresponding asset entity units; the configuration data defines the expected security baseline of the information technology assets, and the operating parameters reflect the actual operating status. Build a compliance situation mirror; The strategy consistency deduction component is used to logically deduce each policy rule in the compliance policy library within the global context constructed by the compliance situation mirror, identify deep violations and related risks in the inspection of a single information technology asset, and generate a set of compliance deviation events that describe the deviated assets, deviation types, violated policy entries, and their scope of impact in the topology. The classification and disposal instruction generation component is used to conduct risk rating and disposal path decisions based on the criticality of the IT assets in the asset topology map of each event in the compliance deviation event set, the severity level of the deviation itself, and the available automated remediation scripts.
2. The intelligent IT asset management system as described in claim 1, characterized in that, The strategy consistency inference component includes: The policy inspection context construction sub-component is used to perform semantic parsing of policy rules. Each policy rule is transformed into an executable policy inspection context, which contains the policy's logical judgment conditions and defines the paths and relationship types in the asset topology graph that need to be traversed to perform the inspection. The policy rule is instantiated as a policy inspection context that performs targeted probing on specific data entities in the compliance posture mirror. The Correlation Impact Network Analysis sub-component is used to perform deep traversal and logical judgment on the compliance posture image. When an initial policy deviation is identified on a certain information technology asset, it takes the information technology asset with the initial policy deviation as the starting point and dynamically infers the correlation security impact caused by the initial policy deviation based on the dependency and connection relationship defined in the compliance posture image, generating a correlation impact network that outlines the potential impact path and scope with the initial policy deviation as the center. The compliance deviation event synthesis sub-component is used to encapsulate the asset identifier, specific type, and violated policy entry of the initial policy deviation with the scope of impact described by the correlation influence network in a multi-dimensional feature, forming a compliance deviation event containing a complete context.
3. The intelligent IT asset management system as described in claim 2, characterized in that, The correlation influence network analysis sub-component includes: The risk propagation path discovery module is used to perform graph traversal based on the relationship types in the compliance situation mirror, starting from the initial strategy deviation asset, defining the propagation probability and intensity for each relationship type; identifying all potential pathways from the initial strategy deviation asset where risks may be propagated through various relationship chains, and generating a set of risk propagation paths; The dynamic impact scope definition module is used to assess the impact on all IT assets covered by the risk propagation path. Based on the criticality level of each IT asset in the compliance posture mirror, as well as the correlation strength and path length with the initial strategy deviation, the impact score is calculated. Based on the preset risk tolerance threshold, all covered information technology assets are filtered, and assets whose impact score exceeds the risk tolerance threshold are identified as the targets of this deviation. The correlation influence network synthesis module is used to construct an influence relationship subgraph with the initial strategy deviation asset as the root node, the risk propagation path as the edge, and the assets within the dynamic influence range as the vertices, to obtain a correlation influence network that outlines the potential influence path and precise range with the initial strategy deviation as the center.
4. The intelligent IT asset management system as described in claim 3, characterized in that, The module for dynamically defining the scope of influence includes: The criticality quantification matrix construction submodule is used to map each information technology asset to a criticality quantification matrix based on the predefined criticality level in the compliance situation mirror. The criticality quantification matrix assigns a quantitative criticality base value to each information technology asset, reflecting the inherent importance of the information technology asset in a static environment. The propagation attenuation factor calculation submodule is used to calculate the propagation attenuation factor for each information technology asset on each specific path in the risk propagation path; it integrates the correlation strength and the path length to calculate the propagation attenuation factor of the information technology asset on the risk propagation path, and its value is between 0 and 1. The impact rating submodule is used to multiply the corresponding key base value in the key quantification matrix by the calculated propagation attenuation factor for each information technology asset within the coverage of the risk propagation path, and the result is the impact rating of the information technology asset.
5. The intelligent IT asset management system as described in claim 4, characterized in that, The propagation attenuation factor calculation submodule includes: The relation type weight allocation unit is used to assign an initial relation type weight to each relation type based on the semantic definition of the connection relationship between information technology assets in the compliance situation mirror. The relation type weight represents the inherent difficulty of risk transmission in such relation channels. The path decay coefficient calculation unit is used to calculate the path decay coefficient by considering the path length, i.e. the number of hops, from the initial deviation asset to the target asset in the risk propagation path and using nonlinear decay. The propagation attenuation factor fusion unit is used to fuse a final quantized value between 0 and 1, i.e., the propagation attenuation factor, based on relation type weights and using the path attenuation coefficient as its nonlinear regulator.
6. The intelligent IT asset management system as described in claim 5, characterized in that, The path attenuation coefficient calculation unit includes: The path attenuation basis calculation subunit is used to map integer path lengths to a path attenuation basis between 0 and 1. The dynamic decay gradient generation subunit is used to analyze the historical stability of the current propagation path and generate a dynamic decay gradient as an adjustment variable based on the historical stability. The path attenuation coefficient synthesis subunit is used to read the path attenuation base value generated by the path attenuation base calculation process, and load the dynamic attenuation gradient parameter generated by the dynamic attenuation gradient generation process; the path attenuation base is used as the basic value input into the coefficient synthesis, and the dynamic attenuation gradient is used as the correction parameter. The actual correction amount is obtained by multiplying the value of the dynamic decay gradient by the preset gradient influence factor. The intermediate result is obtained by subtracting the actual correction amount from the path attenuation base value; the intermediate result is then subjected to numerical range constraints to ensure that its value falls within the range of zero to one. If the intermediate result is less than zero, set it to zero; if the intermediate result is greater than one, set it to one, thus obtaining the path attenuation coefficient.
7. The intelligent IT asset management system as described in claim 1, characterized in that, It also includes an asset discovery subsystem, which uses various automated detection technologies to acquire raw asset data from multiple sources in the information technology environment; and outputs a standardized asset list through feature comparison and deduplication fusion procedures. The unified modeling subsystem is used to construct a unified asset relationship data model based on a standardized asset list and using a graph database; it forms an asset topology map by processing the associations and dependencies between information technology assets.
8. The intelligent IT asset management system as described in claim 1, characterized in that, It also includes interfaces and extension subsystems for outputting asset topology maps, IT asset status, compliance status, and insights and predictive indicators to external systems such as configuration management databases, monitoring and ticketing systems via standardized RESTful APIs, gRPC, and Webhook interfaces. It also performs comprehensive rendering and graphical display, outputting interactive views of asset topology maps, health scores, and trend predictions through web interfaces or mobile devices; and receives instructions from external systems to achieve bidirectional data synchronization and functional expansion with the external system ecosystem.
9. A method for implementing an intelligent management system for IT assets, characterized in that, Includes the following steps: Raw asset data is collected through agentless scanning, agent-assisted collection, and cloud service APIs; the data is cleaned and standardized based on feature comparison and deduplication fusion to generate a structured asset list. Utilize graph database technology to construct an asset relationship model, and generate a visualized asset topology map through relationship analysis to establish a complete asset relationship view; Integrate asset topology maps and operational data, including real-time status, historical records, and compliance information; employ big data platforms and machine learning for multi-dimensional analysis to achieve anomaly detection, capacity prediction, cost assessment, and risk analysis; output quantifiable decision indicators, including resource capacity prediction reports, anomaly detection alarms, cost optimization suggestions, and risk trend warnings. It aggregates asset topology, real-time status, and analytical metrics data, and encapsulates the data through standardized interfaces; It integrates with external platforms, provides visualizations via Web and mobile devices, and supports interactive queries of asset topology maps, health scores, and trend prediction views; The compliance posture mirror building component is used to treat the static asset relationships and dependency networks defined by the asset topology map as an immutable review framework; it also uses the real-time configuration data, operating parameters, and security attributes contained in the information technology asset status to correspond to and populate the review framework with the asset entity units corresponding to these data; the configuration data defines the expected security baseline of the information technology assets, and the operating parameters reflect the actual operating status; thus, a compliance posture mirror is constructed. The strategy consistency simulation component is used to logically deduce each policy rule in the compliance policy library within the global context constructed by the compliance situation mirror, identify deep violations and related risks in the inspection of a single information technology asset, and generate a set of compliance deviation events that describe the deviated assets, deviation types, violated policy entries, and their scope of impact in the topology. The classification and disposal instruction generation component is used to conduct risk rating and disposal path decisions based on the criticality of the IT assets in the asset topology map of each event in the compliance deviation event set, the severity level of the deviation itself, and the available automated remediation scripts.
Citation Information
Patent Citations
Intelligent information asset management method and device
CN117952558A
Intelligent IT asset management system
CN120046889A
Enterprise data asset intelligent management system for server research, development and manufacturing
CN120765199A
Asset operation and maintenance decision management platform and management method based on data fusion
CN120217158A