Asset identification method and device, electronic equipment and storage medium
Patent Information
- Application Number
- CN202380100267.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-26
- Publication Date
- 2026-02-13
AI Technical Summary
It is difficult to obtain detailed information on OT assets and IoT assets in industrial Ethernet in prior art, affecting security monitoring and threat assessment.
By obtaining network traffic related to the asset equipment to be recognized, the identification information is extracted, and the identification results containing the application scenario description are generated based on the identification information. This method is applicable to protocols that support standard format recognition information, as well as protocols that do not support standard formats. The identification information is obtained through means such as feature groups and scene matching rules, field mapping relationships, etc.
A detailed identification of OT assets and IoT assets are realized, and wealth of identification results are provided to facilitate users to understand assets, deepen their awareness of assets, and support security analysis and influence evaluation.
Smart Images

Figure CN121532994A_ABST
Abstract
Description
Asset identification method, device, electronic device and storage medium Technical Field
[0001] The present invention relates to the field of asset management technology, and in particular to an asset identification method, device, electronic device and storage medium. Background Art
[0002] Many Internet of Things (IoT) assets (also known as devices) are connected to Industrial Ethernet networks in Operational Technology (OT) systems. Detailed information about these assets is crucial for OT security monitoring, for example, to analyze system risks and assess threat impacts.
[0003] However, due to the different performances of various assets and the widespread use of many protocols, it is currently difficult to obtain detailed information on assets (e.g., OT assets and / or IoT assets).
[0004] Summary of the Invention
[0005] The embodiments of the present invention provide an asset identification method, device, electronic device, and storage medium.
[0006] An asset identification method, comprising:
[0007] Obtain network traffic related to the asset device to be identified;
[0008] Based on the network traffic, obtaining identification information of the asset device to be identified;
[0009] Based on the identification information, an identification result of the asset device to be identified is generated, wherein the identification result includes an application scenario description of the asset device to be identified.
[0010] Therefore, identification information is extracted from the network traffic related to the asset device to be identified, and identification results containing application scenario descriptions are generated based on the identification information. The identification results are richer, which makes it easier for users to understand the assets in detail, deepens the user's understanding of the assets, and is conducive to security analysis and impact assessment.
[0011] In one embodiment, the asset device to be identified is an OT device and / or an IoT device;
[0012] The obtaining of network traffic related to the asset device to be identified includes:
[0013] The mirrored traffic of the network traffic flowing through the switch within a predetermined time is obtained via a monitoring port on the switch connected to the OT device and / or IoT device.
[0014] Therefore, mirroring traffic through a switch can easily capture the network traffic of OT devices and / or IoT devices.
[0015] In one embodiment, obtaining the identification information of the asset device to be identified includes: when the protocol type of the network traffic supports the definition of identification information with a standard format, extracting the identification information from the field interval corresponding to the predetermined type in the network traffic, wherein the identification information has the standard format, and the standard format includes an application scenario identification field, a location identification field and a purpose identification field; generating the identification result of the asset device to be identified based on the identification information includes: matching the first content in the application scenario identification field with a predefined application scenario mapping relationship to determine the application scenario description of the asset device to be identified corresponding to the first content; matching the second content in the location identification field with a predefined location mapping relationship to determine the location description of the asset device to be identified corresponding to the second content; matching the third content in the purpose identification field with a predefined purpose mapping relationship to determine the purpose description of the asset device to be identified corresponding to the content in the purpose identification field.
[0016] Therefore, for network traffic that supports identification information in a standard format, identification results including an application scenario description, a location description, and a usage description can be easily obtained based on the identification information.
[0017] In one embodiment, obtaining identification information of the asset device to be identified includes: when the protocol type of the network traffic does not support the definition of identification information in a standard format, extracting a feature group of the network traffic; generating an identification result of the asset device to be identified based on the identification information includes: determining an application scenario description of the asset device to be identified based on a matching result between the feature group and a predetermined scenario matching rule.
[0018] It can be seen that for network traffic that does not support identification information in a standard format, the application scenario description can be determined through the matching results of the feature group and the predetermined scenario matching rules.
[0019] In one embodiment, obtaining identification information of the asset device to be identified includes: when the protocol type of the network traffic does not support the definition of identification information with a standard format and is contained in a predetermined field interval mapping relationship, querying the field interval mapping relationship based on the protocol type to determine the location field interval and purpose field interval corresponding to the protocol type, wherein the location field interval is adapted to store the location description of the asset device to be identified, and the purpose field interval is adapted to store the purpose description of the asset device to be identified; generating the identification result of the asset device to be identified based on the identification information includes: extracting the location description from the location field interval; extracting the purpose description from the purpose field interval.
[0020] Therefore, for network traffic that does not support identification information in a standard format, the purpose description and location description can be conveniently extracted through the field interval mapping relationship.
[0021] In one embodiment, the scene matching rule is generated in a manner including at least one of the following:
[0022] generating the scene matching rule based on a combination of at least two features in the feature group;
[0023] generating the scene matching rule based on a combination of at least two features in the feature group and keywords in the location description;
[0024] generating the scenario matching rule based on a combination of at least two features in the feature group and keywords in the usage description;
[0025] The feature group includes at least two of the following features: network address; program identification; public flags in network traffic; transmission control protocol port status; user datagram protocol port status.
[0026] Therefore, by generating scene matching rules in a variety of ways, the applicability and richness of scene matching rules are improved.
[0027] In one embodiment, it includes:
[0028] When the protocol type of the network traffic does not support the definition of identification information in a standard format and is not included in the field interval mapping relationship: based on a predetermined location description keyword, determine the location field interval for storing the location description from the network traffic; based on a predetermined purpose keyword, determine the purpose field interval for storing the purpose description from the network traffic; in the field interval mapping relationship, add a mapping relationship between the location field interval and the purpose field interval and the protocol type.
[0029] It can be seen that for protocol types not recorded in the field interval mapping relationship, the purpose field interval and location field interval can be parsed, and the mapping relationship of the protocol type can be added to the field interval mapping relationship, thereby automatically expanding the field interval mapping relationship.
[0030] An asset identification device, comprising:
[0031] A traffic acquisition module is used to acquire network traffic related to the asset device to be identified;
[0032] An information acquisition module, configured to extract identification information of the asset device to be identified from the network traffic;
[0033] A generating module is configured to generate an identification result of the asset device to be identified based on the identification information, wherein the identification result includes an application scenario description of the asset device to be identified.
[0034] Therefore, identification information is extracted from the network traffic related to the asset device to be identified, and identification results containing application scenario descriptions are generated based on the identification information. The identification results are richer, which makes it easier for users to understand the assets in detail, deepens the user's understanding of the assets, and is conducive to security analysis and impact assessment.
[0035] In one embodiment, the asset device to be identified is an OT device and / or an IoT device;
[0036] The traffic acquisition module is used to obtain the mirror traffic of the network traffic flowing through the switch within a predetermined time via the monitoring port on the switch connected to the OT device and / or IoT.
[0037] Therefore, mirroring traffic through a switch can easily capture the network traffic of OT devices and / or IoT devices.
[0038] In one embodiment, the information acquisition module is used to obtain the identification information from the field interval corresponding to the predetermined type in the network traffic when the protocol type of the network traffic supports the definition of identification information with a standard format, wherein the identification information has the standard format, and the standard format includes an application scenario identification field, a location identification field and a purpose identification field; the generation module is used to match the first content in the application scenario identification field with a predefined application scenario mapping relationship to determine the application scenario description of the asset device to be identified corresponding to the first content; match the second content in the location identification field with a predefined location mapping relationship to determine the location description of the asset device to be identified corresponding to the second content; match the third content in the purpose identification field with a predefined purpose mapping relationship to determine the purpose description of the asset device to be identified corresponding to the content in the purpose identification field.
[0039] Therefore, for network traffic that supports identification information in a standard format, identification results including an application scenario description, a location description, and a usage description can be easily obtained based on the identification information.
[0040] In one embodiment, the information acquisition module is used to extract the feature group of the network traffic when the protocol type of the network traffic does not support the definition of identification information in a standard format; the generation module is used to determine the application scenario description of the asset device to be identified based on the matching result of the feature group with the predetermined scenario matching rule.
[0041] It can be seen that for network traffic that does not support identification information in a standard format, the application scenario description can be determined through the matching results of the feature group and the predetermined scenario matching rules.
[0042] In one embodiment, the information acquisition module is used to query the field interval mapping relationship based on the protocol type when the protocol type of the network traffic does not support the definition of identification information with a standard format and is contained in a predetermined field interval mapping relationship, so as to determine the location field interval and purpose field interval corresponding to the protocol type, wherein the location field interval is adapted to store the location description of the asset device to be identified, and the purpose field interval is adapted to store the purpose description of the asset device to be identified; the generation module is used to extract the location description from the location field interval; and extract the purpose description from the purpose field interval.
[0043] Therefore, for network traffic that does not support identification information in a standard format, the purpose description and location description can be conveniently extracted through the field interval mapping relationship.
[0044] In one embodiment, the scene matching rule is generated in a manner including at least one of the following:
[0045] generating the scene matching rule based on a combination of at least two features in the feature group;
[0046] generating the scene matching rule based on a combination of at least two features in the feature group and keywords in the location description;
[0047] generating the scenario matching rule based on a combination of at least two features in the feature group and keywords in the usage description;
[0048] The feature group includes at least two of the following features: network address; program identification; public flags in network traffic; transmission control protocol port status; user datagram protocol port status.
[0049] Therefore, by generating scene matching rules in a variety of ways, the applicability and richness of scene matching rules are improved.
[0050] In one embodiment, the information acquisition module is used to, when the protocol type of the network traffic does not support the definition of identification information in a standard format and is not included in the field interval mapping relationship: based on a predetermined location description keyword, determine the location field interval for storing the location description from the network traffic; based on a predetermined purpose keyword, determine the purpose field interval for storing the purpose description from the network traffic; in the field interval mapping relationship, add a mapping relationship between the location field interval and the purpose field interval and the protocol type.
[0051] It can be seen that for protocol types that are not recorded in the current field interval mapping relationship, the purpose field interval and location field interval can be parsed, and the mapping relationship of the protocol type can be added to the field interval mapping relationship, thereby realizing automatic expansion of the field interval mapping relationship.
[0052] An electronic device, comprising:
[0053] processor;
[0054] a memory for storing executable instructions of the processor;
[0055] The processor is configured to read the executable instructions from the memory and execute the executable instructions to implement any one of the above asset identification methods.
[0056] A computer-readable storage medium stores computer instructions thereon, wherein when the computer instructions are executed by a processor, the method for identifying attack links based on logs as described in any one of the above items is implemented.
[0057] A computer program product, characterized in that it comprises a computer program, and when the computer program is executed by a processor, it implements the asset identification method as described in any one of the above items. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] The preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings, so that those skilled in the art will understand the above and other features and advantages of the present invention more clearly. In the accompanying drawings:
[0059] FIG1 is a flow chart of an asset identification method according to an embodiment of the present invention.
[0060] FIG2 is an exemplary schematic diagram of obtaining network traffic according to an embodiment of the present invention.
[0061] FIG3 is a first exemplary flow chart of an asset identification process according to an embodiment of the present invention.
[0062] FIG4 is a second exemplary flow chart of an asset identification process according to an embodiment of the present invention.
[0063] FIG5 is a structural diagram of an asset identification device according to an embodiment of the present invention.
[0064] FIG6 is a structural diagram of an electronic device according to an embodiment of the present invention.
[0065] The accompanying drawings are numerals as follows: DETAILED DESCRIPTION
[0066] In order to make the purpose, technical solutions and advantages of the present invention more clear, the present invention is further described in detail with reference to the following examples.
[0067] For the sake of brevity and intuitiveness in description, the solution of the present invention is explained below by describing several representative implementations. A large number of details in the implementations are only used to help understand the solution of the present invention. However, it is obvious that the technical solution of the present invention may not be limited to these details when implemented. In order to avoid unnecessarily obscuring the solution of the present invention, some implementations are not described in detail, but only a framework is given. Hereinafter, "including" means "including but not limited to", and "according to..." means "at least according to..., but not limited to only according to...". Due to the language habits of Chinese, when the number of a component is not specifically specified below, it means that the component can be one or more, or can be understood as at least one.
[0068] Currently, the demand for automatic asset identification (also known as equipment or asset devices) is growing stronger. It's important to note that this requirement exists in IT systems, IoT systems, OT systems, and even IT / OT converged systems. In particular, the need for automatic asset identification is particularly strong in OT, IoT, and IT / OT converged systems, as many key attributes of OT assets cannot be directly accessed. This presents a significant challenge.
[0069] The embodiment of the present invention proposes an asset identification solution based on scenario perception, which directly extracts or indirectly obtains identification information from the network traffic related to the asset device to be identified, and generates an identification result containing an application scenario description based on the identification information, so as to facilitate users to understand the assets in detail, deepen users' understanding of the assets, and facilitate security analysis and impact assessment.
[0070] FIG1 is a flow chart of an asset identification method according to an embodiment of the present invention. As shown in FIG1 , the method includes:
[0071] Step 101: Obtain network traffic related to the asset device to be identified.
[0072] Here, the asset devices to be identified can be IT devices in an IT system, OT devices in an OT system, IT devices in an IT / OT fusion system, OT devices in an IT / OT fusion system, or IoT devices in an IoT system, etc.
[0073] The protocols used for network traffic transmitted between the assets to be identified can include: transmission protocols and communication protocols. Transmission protocols are generally responsible for networking and communication between devices within a subnet; communication protocols are primarily device communication protocols running on TCP / IP, responsible for data exchange and communication between devices over the internet. For example, transmission protocols for network traffic may include: Representational State Transfer (REST) / Hypertext Transfer Protocol (Hypertext Transfer Protocol), Constrained Application Protocol (CoAP), Message Queuing Telemetry Transport (MQTT), Data Distribution Service for Real-Time Systems (DDS), Advanced Message Queuing Protocol (AMQP), Extensible Messaging and Presence Protocol (XMPP), Java Message Service (JMS), and so on. For another example, the communication protocol may be implemented as Industrial Ethernet (PROFINET) protocol, Modbus protocol, BACNet protocol, RS-232 protocol, HART protocol, MPI protocol, RS-485 protocol, and the like.
[0074] In one embodiment, the asset device to be identified is an OT device or an IoT device. Step 101 specifically includes: obtaining, via a monitoring port on a switch connected to the OT device and / or IoT device, mirrored traffic of network traffic flowing through the switch within a predetermined time period.
[0075] Figure 2 is an exemplary schematic diagram of obtaining network traffic according to an embodiment of the present invention. In Figure 2, a first IoT system 10 includes an IoT device 11 and a switch 12 connected to IoT device 11. A second IoT system 20 includes an IoT device 21, a programmable logic controller (PLC) 22 connected to IoT device 21, and a switch 23 connected to PLC 22. An OT system 30 includes an OT device 31 and a switch 32 connected to OT device 31. Switches 12 and 23 are connected to a data collector 14. Switch 32 is connected to a data collector 15. Data collectors 14 and 15 are each connected to an analysis platform 16.
[0076] Through the mirrored traffic port set on switch 12, data collector 14 can obtain the network traffic (both inbound and outbound) of IoT device 11. Through the mirrored traffic port set on switch 23, data collector 15 can obtain the network traffic (both inbound and outbound) of IoT device 21. Through the mirrored traffic port set on switch 32, data collector 15 can obtain the network traffic (both inbound and outbound) of OT device 31. Data collectors 14 and 15 each send the traffic they obtain to analysis platform 16.
[0077] The above exemplary descriptions of the protocol for transmitting network traffic and specific examples of obtaining network traffic are provided. Those skilled in the art will appreciate that such descriptions are merely exemplary and are not intended to limit the scope of protection of the embodiments of the present invention.
[0078] Step 102: Based on the network traffic, obtain identification information of the asset device to be identified.
[0079] For example, in the architecture shown in FIG2 , step 102 may be specifically performed by the analysis platform 16. Here, through traffic parsing, the identification information of the asset device to be identified can be directly extracted from the network traffic, or indirectly obtained based on the attributes of the network traffic. The identification information is information used to generate the identification result of the asset device to be identified. For example:
[0080] (1) When the protocol type supports the definition of identification information with a standard format, the identification information is specifically implemented as a combination field with a standard format. In these protocol types, a new definition of a combination field with a standard format is added. For example, the protocol types that can add the definition of a combination field may include: PROFINET protocol, Modbus protocol, BACNet protocol, RS-232 protocol, HART protocol, MPI protocol and RS-485 protocol, etc. The combination field may specifically include: an application scenario identification field, a location identification field and a purpose identification field. Among them, the content in the application scenario identification field is used to characterize the application scenario of the asset device to be identified, such as being implemented as a string corresponding to the application scenario description; the content in the location identification field is used to characterize the location of the asset device to be identified, such as being implemented as a string corresponding to the location description; the content in the purpose identification field is used to characterize the purpose of the asset device to be identified, such as being implemented as a string corresponding to the purpose description. The specific content in the application scenario identification field, the location identification field and the purpose identification field can be filled in by the user during the startup or initialization process of the asset device to be identified. The combination field can be set to a fixed position (the fixed position facilitates quick location of identification information) of a predetermined type of message in the predetermined type of communication protocol, such as in the payload portion of the message. For example, for the PROFINET protocol, the combination field can be located in the payload portion of the handshake message; for the BACnet protocol, the combination field can be located in the payload portion of the Who-is message. Preferably, the combination field of the identification information in the standard format can also include other fields for identifying asset attributes. For example, these asset attributes can include: system name, system purpose, subsystem purpose, asset device model, etc. Accordingly, the specific content of these asset attribute fields can be filled in by the user during the startup or initialization process of the asset device to be identified.
[0081] (2) When the protocol type of network traffic does not support the definition of identification information with a standard format, that is, there is no new definition of a combination field with a standard format in the protocol type, the identification information can be implemented as follows: (a): Feature group of network traffic: The features in the feature group can be implemented as: network address; program identifier; public flag in network traffic; Transmission Control Protocol port status; User Datagram Protocol port status, etc. (b): Location field interval and purpose field interval corresponding to the protocol type, wherein the location field interval is adapted to store the location description of the asset device to be identified, and the purpose field interval is adapted to store the purpose description of the asset device to be identified. Specifically, the public flag can include at least one of the following: (1) Time to Live (TTL): TTL specifies the maximum number of network segments allowed to pass before the IP packet is discarded by the router. For example, in the IPv4 packet header, TTL is an 8-bit field, which is located in the 9th byte of the IPv4 packet. (2) Window size: (WinSize): The TCP header contains the window size field, which actually refers to the window of the receiving end, that is, the receiving window, which is used to inform the sending end of the amount of data it can receive, thereby achieving the purpose of flow control. (3) Do Not Fragment (DF) bit: DF bit: 1 indicates no fragmentation, 0 indicates fragmentation. (4) Maximum Message Size (MSS): MMS is an option of the TCP protocol. It is used by the sender and receiver to negotiate the maximum data length (excluding the segment header) that each segment can carry during communication when the TCP connection is established. (5) Window Scaling Factor (WinScale): WinScale is located in the Options field of the TCP packet header and represents the multiple by which the window can be magnified. Similarly, the protocol types that do not have a newly added combination field with a standard format can include: PROFINET protocol, Modbus protocol, BACNet protocol, RS-232 protocol, HART protocol, MPI protocol and RS-485 protocol, etc.
[0082] Step 103: Generate an identification result of the asset device to be identified based on the identification information, wherein the identification result includes an application scenario description of the asset device to be identified.
[0083] In one embodiment, step 102 specifically includes: when the protocol type of the network traffic supports the definition of identification information with a standard format, extracting identification information from a field interval corresponding to a predetermined type in the network traffic, wherein the identification information has a standard format, and the standard format includes an application scenario identification field, a location identification field, and a purpose identification field; step 103 specifically includes: matching the first content in the application scenario identification field with a predefined application scenario mapping relationship to determine an application scenario description of the asset device to be identified corresponding to the first content; matching the second content in the location identification field with a predefined location mapping relationship to determine a location description of the asset device to be identified corresponding to the second content; matching the third content in the purpose identification field with a predefined purpose mapping relationship to determine a purpose description of the asset device to be identified corresponding to the content in the purpose identification field. In this embodiment, the standard format of the identification information and the specific storage location (i.e., field interval) of the identification information in the traffic message are predefined. The first content in the application scenario identification field can be matched with a predefined application scenario mapping relationship to determine the application scenario description, and the second content in the location identification field can be matched with a predefined location mapping relationship to determine the location description of the asset equipment to be identified; the third content in the purpose identification field can be matched with a predefined purpose mapping relationship to determine the purpose description. The identification result includes an application scenario description, a location description, and a purpose description. Similarly, when the combination field of the standard format identification information also includes other fields for identifying asset attributes (such as: system name, system purpose, subsystem purpose, asset equipment model, etc.), the application scenario mapping relationship correspondingly includes the corresponding attribute description, so that the corresponding asset attribute description can be determined based on the content of these asset attributes, and the asset attribute description can be attached to the identification result.
[0084] Therefore, for network traffic that supports the definition of identification information having a standard format, an identification result including an application scenario description, a location description, and a usage description can be easily obtained based on the identification information.
[0085] Table 1 lists typical examples of identification information in a standard format. The standard format includes an application scenario identification field, a location identification field, and a purpose identification field. The application scenario identification field is named "pre-string"; the location identification field consists of two parts: building location and room location; and the purpose identification field consists of two parts: device purpose and device number.
[0086] Table 1
[0087] Table 2 lists an example of the correspondence between the leading string and the scenario description. For example, when the leading string of the identification information is "A0", based on Table 2, it is determined that the application scenario of the asset equipment is the building control scenario.
[0088] Table 2
[0089] Table 3 lists an example of the correspondence between the value of the building location field and the building description. For example, when the string in the building location field in the identification information is "B1", it can be determined that the asset equipment is located in building number 1.
[0090] Table 3
[0091] Table 4 lists an example of the correspondence between the values of the room location field and the room location description. For example, when the character string in the location building field in the identification information is "R101", it can be determined that the asset equipment is located in room number 101.
[0092] Table 4
[0093] Table 5 lists an example of the correspondence between the value of the device usage field and the device usage description. For example, when the character string in the device usage field in the identification information is "T", it can be determined that the asset device is a temperature sensor.
[0094] Table 5
[0095] Assuming that the specific content of the identification information that conforms to the above standard format is: "A0_B1_R101_T_001", based on the above Tables 1 to 5, the identification results shown in Table 6 can be obtained.
[0096] Table 6
[0097] The above exemplary descriptions are typical examples of identification information in a standard format and generation of identification results. Those skilled in the art will appreciate that such descriptions are merely exemplary and are not intended to limit the scope of protection of the embodiments of the present invention.
[0098] In one embodiment, step 102 specifically includes: when the protocol type of the network traffic does not support the definition of identification information in a standard format (that is, the protocol type does not include an extended field definition for identification information in a standard format), extracting a feature group of the network traffic; and generating an identification result for the asset device to be identified based on the identification information in step 103 specifically includes: determining the application scenario of the asset device to be identified based on the matching result of the feature group with a predetermined scenario matching rule. It can be seen that for network traffic that does not support the definition of identification information in a standard format, the application scenario description can be determined based on the matching result of the feature group with the predetermined scenario matching rule.
[0099] In one embodiment, the scene matching rule is generated by:
[0100] (1) Generate scene matching rules based on the combination of at least two features in the feature group;
[0101] (2) generating a scene matching rule based on a combination of at least two features in the feature group and keywords in the location description;
[0102] (3) generating a scene matching rule based on the combination of at least two features in the feature group and the keywords in the usage description;
[0103] The feature group includes at least two of the following features: network address; program identifier; common flags in network traffic; TCP port status; and UDP port status. A method for generating scenario matching rules can be determined based on prior knowledge. The generated scenario matching rules can be validated, for example, based on the valid value range of a field variable.
[0104] Example (1): A scenario matching rule generated based on the combination of TCP port status and program identifier is as follows: When the status of TCP port number 445 is open and the program identifier indicates that the traffic-related application is WinCC software, the matching scenario is: chemical distributed control scenario. In this example, directly generating scenario matching rules based on the combination of features in the feature group has the advantage of convenient implementation.
[0105] Example (2): The scenario matching rule generated based on the TCP port status, program identifier, and keywords in the usage description can be exemplified as follows: when the TCP port number 445 is open, the program identifier indicates that the traffic-related application is WinCC software, and the keywords in the usage description include "reactor," "electrolyzer," or "crystallization equipment," then the matching scenario is: chemical distributed control scenario. In this example, generating scenario matching rules based on the feature combination in the feature group and the usage description keywords has the advantage of being easy to implement.
[0106] Example (3): A scenario matching rule generated based on the TCP port status, program identifier, and keywords in the location description can be exemplified as follows: when the TCP port number 445 is open, the program identifier indicates that the traffic-related application is WinCC software, and the keywords in the location description include "mixing workshop," "separation workshop," "purification workshop," or "storage tank," then the matching scenario is: chemical distributed control scenario. In this example, generating scenario matching rules based on the feature combination in the feature group and the location description keywords can generate more accurate rules.
[0107] In one embodiment, obtaining identification information of the asset device to be identified includes: when the protocol type of the network traffic does not support the definition of identification information with a standard format and is contained in a predetermined field interval mapping relationship, querying the field interval mapping relationship based on the protocol type to determine the location field interval and purpose field interval corresponding to the protocol type, wherein the location field interval is adapted to store the location description of the asset device to be identified, and the purpose field interval is adapted to store the purpose description of the asset device to be identified; based on the identification information, generating the identification result of the asset device to be identified includes: extracting the location description from the location field interval; extracting the purpose description from the purpose field interval. Therefore, for network traffic whose protocol type does not conform to the predetermined type, the purpose description and location description can be conveniently extracted through the field interval mapping relationship. Therefore, for network traffic that does not support identification information with a standard format, the purpose description and location description can be conveniently extracted through the field interval mapping relationship.
[0108] Validation checks can be performed on the location description and purpose description, such as validating the location description and purpose description based on the valid value range of the field variable.
[0109] FIG3 is an exemplary schematic diagram of an asset identification process according to an embodiment of the present invention. As shown in FIG3 , the process includes:
[0110] Step 301: Acquire network traffic related to the asset device to be identified. The protocol type of the network traffic does not support the definition of identification information with a standard format, and the protocol type of the network traffic is recorded in the field interval mapping relationship.
[0111] Step 302: extracting a feature group of the network traffic, and determining a description of the application scenario of the asset device to be identified based on a matching result between the feature group and a predetermined scenario matching rule.
[0112] Step 303: Query the field interval mapping relationship based on the protocol type to determine the location field interval and usage field interval corresponding to the protocol type.
[0113] Step 304: Read the location description from the location field interval, and read the purpose description from the purpose field interval.
[0114] Step 305: Determine whether the location description and / or purpose description has passed verification. If so (corresponding to the "Y" branch), execute step 306; otherwise (corresponding to the "N" branch), execute step 307.
[0115] Step 306: Display the recognition results including the usage description, location description and application scenario description, and exit this process.
[0116] Step 307: Display the recognition result including the application scenario description and exit this process.
[0117] In one embodiment, it includes: when the protocol type of the network traffic does not support the definition of identification information with a standard format and is not included in the field interval mapping relationship: based on a predetermined location description keyword, determining the location field interval for storing the location description from the network traffic; based on a predetermined purpose keyword, determining the purpose field interval for storing the purpose description from the network traffic; in the field interval mapping relationship, adding a mapping relationship between the location field interval and the purpose field interval and the protocol type.
[0118] It can be seen that for protocol types that do not support the definition of identification information with a standard format and are not recorded in the field interval mapping relationship, the purpose field interval and location field interval can be parsed, and the mapping relationship of the protocol type can be added to the field interval mapping relationship, thereby realizing automatic expansion of the field interval mapping relationship.
[0119] FIG4 is a second exemplary flow chart of an asset identification process according to an embodiment of the present invention.
[0120] Step 401: Acquire network traffic related to the asset device to be identified. The protocol type of the network traffic does not support the definition of identification information with a standard format, and the protocol type of the network traffic is not recorded in the field interval mapping relationship.
[0121] Step 402: extracting a feature group of the network traffic, and determining a description of the application scenario of the asset device to be identified based on a matching result between the feature group and a predetermined scenario matching rule.
[0122] Step 403: Based on a predetermined location description keyword, a location field interval for storing location descriptions is determined from the network traffic, and the location description is extracted from this location field interval. For example, the keyword "room number" is searched for in the network traffic content. When the keyword is matched, the location description field is located and the interval of the location field storing the location description is stored. For example, the specific message type to which the location field belongs and the specific position of the location field within that message type are recorded.
[0123] Step 404: Based on the predetermined usage description keyword, a usage field interval for storing the usage description is determined from the network traffic, and the usage description is extracted from this location field interval. For example, if the keyword "temperature sensor" is searched for in the network traffic content, when the keyword is matched, the usage description field is located and the location field interval storing the usage description is stored. For example, the specific message type to which the usage field belongs and the specific location of the usage field within that message type are recorded.
[0124] Step 405: Add a mapping relationship between the location field interval and the usage field interval and the protocol type to the field interval mapping relationship. Therefore, when traffic of the protocol type is encountered again, the location field interval and the usage field interval can be directly determined based on the mapping relationship.
[0125] Step 406: Determine whether the location description and / or purpose description has passed verification. If so (corresponding to the "Y" branch), execute step 407; otherwise (corresponding to the "N" branch), execute step 408.
[0126] Step 407: Display the identification result including the purpose description, location description and application scenario description, and exit this process. Preferably, the identification result may further include attributes such as system name, system purpose, subsystem purpose, asset equipment model, etc.
[0127] Step 408: Display the recognition result including the application scenario description and exit this process.
[0128] FIG5 is a structural diagram of an asset identification device according to an embodiment of the present invention. As shown in FIG5 , the asset identification device 500 includes:
[0129] Traffic acquisition module 501, used to acquire network traffic related to the asset device to be identified;
[0130] An information acquisition module 502 is used to acquire identification information of the asset device to be identified based on network traffic;
[0131] The generating module 503 is configured to generate an identification result of the asset device to be identified based on the identification information, wherein the identification result includes an application scenario description of the asset device to be identified.
[0132] In one embodiment, the asset device to be identified is an OT device and / or an IoT device;
[0133] The traffic acquisition module 501 is used to obtain the mirror traffic of the network traffic flowing through the switch within a predetermined time via the monitoring port on the switch connected to the OT device and / or IoT device.
[0134] In one embodiment, the information acquisition module 502 is used to obtain identification information from a field interval corresponding to a predetermined type in the network traffic when the protocol type of the network traffic supports the definition of identification information with a standard format, wherein the identification information has the standard format, and the standard format includes an application scenario identification field, a location identification field, and a purpose identification field; the generation module 503 is used to match the first content in the application scenario identification field with a predefined application scenario mapping relationship to determine the application scenario description of the asset device to be identified corresponding to the first content; match the second content in the location identification field with a predefined location mapping relationship to determine the location description of the asset device to be identified corresponding to the second content; match the third content in the purpose identification field with a predefined purpose mapping relationship to determine the purpose description of the asset device to be identified corresponding to the content in the purpose identification field.
[0135] In one embodiment, the information acquisition module 502 is used to extract the feature group of the network traffic when the protocol type of the network traffic does not support the definition of identification information with a standard format; the generation module 503 is used to determine the application scenario of the asset device to be identified based on the matching result of the feature group with the predetermined scenario matching rule.
[0136] In one embodiment, the information acquisition module 502 is used to query the predetermined field interval mapping relationship based on the protocol type when the protocol type of the network traffic does not support the definition of identification information with a standard format and is contained in the predetermined field interval mapping relationship to determine the location field interval and purpose field interval corresponding to the protocol type, wherein the location field interval is adapted to store the location description of the asset device to be identified, and the purpose field interval is adapted to store the purpose description of the asset device to be identified; the generation module 503 is used to extract the location description from the location field interval; and extract the purpose description from the purpose field interval.
[0137] In one embodiment, the method for generating scene matching rules includes at least one of the following: generating scene matching rules based on a combination of at least two features in a feature group; generating scene matching rules based on a combination of at least two features in a feature group and keywords in a location description; generating scene matching rules based on a combination of at least two features in a feature group and keywords in a usage description; wherein the feature group includes at least two of the following features: network address; program identifier; common flags in network traffic; TCP port status; UDP port status.
[0138] In one embodiment, the information acquisition module 502 is used to, when the protocol type does not support the definition of identification information in a standard format and is not included in the field interval mapping relationship: based on a predetermined location description keyword, determine the location field interval for storing the location description from the network traffic; based on a predetermined purpose keyword, determine the purpose field interval for storing the purpose description from the network traffic; in the field interval mapping relationship, add a mapping relationship between the location field interval and the purpose field interval and the protocol type.
[0139] The embodiment of the present invention also proposes an electronic device with a processor-memory architecture. Figure 6 is a structural diagram of an electronic device according to an embodiment of the present invention. As shown in Figure 6, the electronic device 600 includes a processor 601, a memory 602, and a computer program stored on the memory 602 and executable on the processor 601. When the computer program is executed by the processor 601, any of the above asset identification methods is implemented. Among them, the memory 602 can be specifically implemented as a variety of storage media such as an electrically erasable programmable read-only memory (EEPROM), a flash memory (Flash memory), and a programmable read-only memory (PROM). The processor 601 can be implemented to include one or more central processing units or one or more field programmable gate arrays, wherein the field programmable gate array integrates one or more central processing unit cores. Specifically, the central processing unit or the central processing unit core can be implemented as a CPU, an MCU, or a DSP, and so on.
[0140] It should be noted that not all steps and modules in the above processes and structure diagrams are required, and certain steps or modules can be omitted based on actual needs. The execution order of the steps is not fixed and can be adjusted as needed. The division of the modules is merely for the convenience of describing the functional division adopted. In actual implementation, a module can be implemented by multiple modules, and the functions of multiple modules can be implemented by the same module. These modules can be located in the same device or in different devices.
[0141] The hardware modules in each embodiment can be implemented mechanically or electronically. For example, a hardware module may include a specially designed permanent circuit or logic device (such as a dedicated processor, such as an FPGA or ASIC) for performing a specific operation. The hardware module may also include a programmable logic device or circuit (such as a general-purpose processor or other programmable processor) temporarily configured by software to perform a specific operation. As for whether to implement the hardware module mechanically, or using a dedicated permanent circuit, or using a temporarily configured circuit (such as configured by software), it can be decided based on cost and time considerations.
[0142] The above are only preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. An asset identification method, characterized in that: include: Obtain (101) network traffic related to the asset device to be identified; Based on the network traffic, obtaining (102) identification information of the asset device to be identified; Based on the identification information, an identification result of the asset device to be identified is generated (103), wherein the identification result includes an application scenario description of the asset device to be identified.
2. The method according to claim 1, characterized in that The asset device to be identified is an operational technology device and / or an Internet of Things device; The obtaining (101) of network traffic related to the asset device to be identified includes: The mirrored traffic of the network traffic flowing through the switch within a predetermined time is obtained via a monitoring port on the switch connected to the operational technology device and / or the Internet of Things device.
3. The method according to claim 1, characterized in that The obtaining (102) identification information of the asset device to be identified comprises: when the protocol type of the network traffic supports the definition of identification information having a standard format, extracting the identification information from a field interval corresponding to the predetermined type in the network traffic, wherein the identification information has the standard format, and the standard format comprises an application scenario identification field, a location identification field, and a purpose identification field; The generating (103) the identification result of the asset device to be identified based on the identification information includes: Matching the first content in the application scenario identification field with a predefined application scenario mapping relationship to determine an application scenario description of the asset device to be identified corresponding to the first content; Matching the second content in the location identification field with a predefined location mapping relationship to determine a location description of the asset device to be identified corresponding to the second content; The third content in the purpose identification field is matched with a predefined purpose mapping relationship to determine a purpose description of the asset device to be identified corresponding to the content in the purpose identification field.
4. The method according to claim 3, characterized in that The obtaining (102) identification information of the asset device to be identified includes: when the protocol type of the network traffic does not support the definition of identification information having a standard format, extracting a feature group of the network traffic; The generating (103) the identification result of the asset device to be identified based on the identification information includes: determining the application scenario description of the asset device to be identified based on the matching result of the feature group and a predetermined scenario matching rule.
5. The method according to claim 4, characterized in that The obtaining (102) identification information of the asset device to be identified includes: when the protocol type of the network traffic does not support the definition of identification information having a standard format and is included in a predetermined field interval mapping relationship, querying the field interval mapping relationship based on the protocol type to determine a location field interval and a usage field interval corresponding to the protocol type, wherein the location field interval is adapted to store a location description of the asset device to be identified, and the usage field interval is adapted to store a usage description of the asset device to be identified; The generating (103) the identification result of the asset device to be identified based on the identification information includes: Extracting the location description from the location field interval; The purpose description is extracted from the purpose field section.
6. The method according to claim 4, characterized in that The scene matching rule is generated in a manner including at least one of the following: generating the scene matching rule based on a combination of at least two features in the feature group; generating the scene matching rule based on a combination of at least two features in the feature group and a keyword in the location description; generating the scene matching rule based on a combination of at least two features in the feature group and keywords in the usage description; The feature group includes at least two of the following features: network address; program identification; public flags in network traffic; transmission control protocol port status; user datagram protocol port status.
7. The method according to claim 5, characterized in that include: When the protocol type of the network traffic does not support the definition of identification information in a standard format and is not included in the field interval mapping relationship: based on a predetermined location description keyword, determine the location field interval for storing the location description from the network traffic; based on a predetermined purpose keyword, determine the purpose field interval for storing the purpose description from the network traffic; in the field interval mapping relationship, add a mapping relationship between the location field interval and the purpose field interval and the protocol type.
8. An asset identification device, characterized in that: include: A traffic acquisition module (501), used to acquire network traffic related to the asset device to be identified; An information acquisition module (502) is used to acquire identification information of the asset device to be identified based on the network traffic; A generation module (503) is used to generate an identification result of the asset device to be identified based on the identification information, wherein the identification result includes an application scenario description of the asset device to be identified.
9. The device according to claim 8, characterized in that The asset device to be identified is an operational technology device and / or an Internet of Things device; The traffic acquisition module (501) is used to acquire the mirror traffic of the network traffic flowing through the switch within a predetermined time via a monitoring port on the switch connected to the operational technology device and / or the Internet of Things device.
10. The device according to claim 8, characterized in that The information acquisition module (502) is used to acquire the identification information from a field interval corresponding to the predetermined type in the network traffic when the protocol type of the network traffic supports the definition of identification information having a standard format, wherein the identification information has the standard format, and the standard format includes an application scenario identification field, a location identification field, and a purpose identification field; The generating module (503) is used to match the first content in the application scenario identification field with a predefined application scenario mapping relationship to determine an application scenario description of the asset device to be identified corresponding to the first content; Matching the second content in the location identification field with a predefined location mapping relationship to determine a location description of the asset device to be identified corresponding to the second content; The third content in the purpose identification field is matched with a predefined purpose mapping relationship to determine a purpose description of the asset device to be identified corresponding to the content in the purpose identification field.
11. The device according to claim 10, characterized in that The information acquisition module (502) is used to extract a feature group of the network traffic when the protocol type of the network traffic does not support the definition of identification information having a standard format; The generating module (503) is used to determine the application scenario description of the asset device to be identified based on the matching result between the feature group and the predetermined scenario matching rule.
12. The device according to claim 11, characterized in that The information acquisition module (502) is used to query the field interval mapping relationship based on the protocol type to determine the location field interval and usage field interval corresponding to the protocol type when the protocol type of the network traffic does not support the definition of identification information with a standard format and is included in a predetermined field interval mapping relationship, wherein the location field interval is adapted to store the location description of the asset device to be identified, and the usage field interval is adapted to store the usage description of the asset device to be identified; The generating module (503) is used to extract the location description from the location field interval; and extract the usage description from the usage field interval.
13. The device according to claim 11, characterized in that The scene matching rule is generated in a manner including at least one of the following: generating the scene matching rule based on a combination of at least two features in the feature group; generating the scene matching rule based on a combination of at least two features in the feature group and a keyword in the location description; generating the scene matching rule based on a combination of at least two features in the feature group and keywords in the usage description; The feature group includes at least two of the following features: network address; program identification; public flags in network traffic; transmission control protocol port status; user datagram protocol port status.
14. The device according to claim 12, characterized in that The information acquisition module (502) is used to, when the protocol type of the network traffic does not support the definition of identification information in a standard format and is not included in the field interval mapping relationship: based on a predetermined location description keyword, determine the location field interval for storing the location description from the network traffic; based on a predetermined purpose keyword, determine the usage field interval for storing the purpose description from the network traffic; in the field interval mapping relationship, add a mapping relationship between the location field interval and the usage field interval and the protocol type.
15. An electronic device, characterized in that: include: Processor (601); A memory (602), configured to store executable instructions of the processor (601); The processor (601) is used to read the executable instructions from the memory (602) and execute the executable instructions to implement the asset identification method according to any one of claims 1 to 7.
16. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the computer instructions are executed by a processor, the method for identifying attack links based on logs described in any one of claims 1 to 7 is implemented.
17. A computer program product, characterized in that The invention comprises a computer program, which, when executed by a processor, implements the asset identification method according to any one of claims 1 to 7.