Asset abnormity monitoring method and system based on flow audit

By combining periodic mapping and traffic monitoring models, asset points are dynamically updated, and network assets are monitored non-intrusively using passive traffic analysis. This solves the problems of identifying unknown assets and abnormal behavior in existing technologies, and achieves efficient and accurate network asset monitoring and anomaly early warning.

CN121887432APending Publication Date: 2026-04-17HUANENG INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUANENG INFORMATION TECH CO LTD
Filing Date
2025-11-27
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing technologies struggle to identify unknown assets and highly concealed internal anomalies in real-time and with high accuracy in network asset monitoring, and frequent scanning can interfere with network performance.

Method used

By periodically mapping each network node and dynamically updating asset points, and combining this with a pre-set traffic monitoring model, an audit sub-model for asset points is constructed. Passive traffic analysis is used to monitor network assets non-intrusively, and anomaly diagnosis is performed based on the anchored baseline of each asset point.

Benefits of technology

It improves the monitoring efficiency and anomaly warning capabilities of network assets, reduces the false alarm rate, and accurately identifies abnormal states of network assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887432A_ABST
    Figure CN121887432A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network asset monitoring, in particular to an asset anomaly monitoring method and system based on flow audit. Comprising the steps of setting a plurality of data nodes according to a network structure, and obtaining a surveying and mapping flow packet of each data node according to a preset surveying and mapping time node; generating a plurality of asset points based on all the strategy traffic packets, and constructing a traffic auditing model according to a preset traffic monitoring model and all the asset points; and obtaining a feedback data packet of each data node, and generating an abnormal risk value of each asset point according to the traffic auditing model and all the feedback data packets. By periodically surveying and mapping each network node and combining with a preset flow monitoring model, an auditing sub-model of each asset point is quickly established, the monitoring and early warning efficiency of the abnormal risk of each asset point is improved, and all network assets are monitored without invasion through passive flow analysis, so that the monitoring and early warning efficiency of the abnormal risk of each asset point is improved. Meanwhile, abnormity diagnosis is carried out according to the anchoring base line of each asset point, and the abnormal state of the network assets is accurately identified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network asset monitoring technology, and in particular to an asset anomaly monitoring method and system based on traffic auditing. Background Technology

[0002] As enterprises deepen their digital transformation, the number and forms of network assets are surging and diversifying, posing a severe challenge to asset security management. Comprehensive and real-time monitoring of asset dynamics and accurate identification of anomalies have become core requirements for network security operations and maintenance.

[0003] In existing technologies, the discovery and monitoring of internal assets mainly rely on two methods: one is active scanning technology, which discovers online assets through periodic or triggered network scans (such as ICMP and port scans). However, this method has obvious drawbacks: frequent scanning can interfere with network performance and business systems, and it cannot detect the brief online or offline behavior of assets during scanning intervals, resulting in poor real-time performance.

[0004] The second approach is passive discovery technology based on traffic analysis. This method infers asset information by analyzing the communication packets within mirrored network traffic. However, current implementations are mostly limited to monitoring fixed behavioral profiles of known assets or relying on preset static rules for matching and alerting. This method heavily depends on prior knowledge and lacks effective identification capabilities for highly concealed internal anomalies such as the sudden appearance of unregistered "unknown assets" in the enterprise network or legitimate assets performing unconventional business operations. Summary of the Invention

[0005] The purpose of this application is to provide a method and system for monitoring asset anomalies based on traffic auditing, in order to solve the above-mentioned technical problems and improve the monitoring efficiency and anomaly early warning capabilities of network assets.

[0006] In some embodiments of this application, by periodically mapping each network node and dynamically updating asset points, and by combining a preset traffic monitoring model to quickly build an audit sub-model for each asset point, the efficiency of monitoring and early warning of abnormal risks of each asset point is improved, while effectively monitoring unknown and temporary assets is achieved.

[0007] In some embodiments of this application, passive traffic analysis is used to monitor all network assets non-intrusively, and anomaly diagnosis is performed based on the anchored baseline of each asset point to reduce false alarm rate and accurately identify abnormal states of network assets.

[0008] In some embodiments of this application, a method for monitoring asset anomalies based on traffic auditing is provided, including: Multiple data nodes are set according to the network structure, and the mapping traffic packets of each data node are obtained according to the preset mapping time nodes. Multiple asset points are generated based on all policy traffic packages, and a traffic audit model is constructed based on the preset traffic monitoring model and all asset points; Obtain feedback data packets from each data node, and generate abnormal risk values ​​for each asset point based on the traffic audit model and all feedback data packets.

[0009] In some embodiments of this application, a preset traffic monitoring model is included, including: Set multiple asset classes; Establish an asset class sequence A, A=(a1, a2, ..., a... i …a n ), where a i Let i be the i-th asset class; n is the number of asset classes; Establish a baseline index series B, B = (b1, b2, ..., bb) i …b m ), where b i Let m be the i-th baseline indicator; m is the number of baseline indicators. Based on the asset category series A, a is set sequentially. i For the target asset class; Construct monitoring sub-models for the target asset class; Construct monitoring sub-models for each asset class in sequence; A flow monitoring model is generated based on all monitoring sub-models.

[0010] In some embodiments of this application, a monitoring sub-model for the target asset class is constructed, including: Generate audit correlation values ​​between the target asset class and each baseline metric; Establish an audit correlation value sequence W, W = (w1, w2, ... w i …w m ), where w i The i-th audit correlation value; m is the number of baseline indicators; Preset audit correlation threshold W1; If w i >W1, set the i-th baseline indicator as the correlation indicator of the target asset class; Get all related metrics; A monitoring sub-model for the target asset class is constructed based on all relevant indicators.

[0011] In some embodiments of this application, a traffic auditing model is constructed, including: Establish an asset point sequence C, C=(c1, c2, ..., c2). i …c r ), where c i Let r be the i-th asset point; r is the number of asset points. Based on the abnormal setting of asset point column C, c is set. i For target asset points; Generate similarity values ​​for the target asset and each asset class; The monitoring sub-model corresponding to the asset class with the highest value among all similar values ​​is set as the first-level monitoring model; Based on the primary monitoring model, a primary baseline indicator series B1 is constructed for the target asset point, B1=(b 11 ,b 12 …b 1i …b 1n1 ), where b 1i is the i-th primary baseline indicator of the target asset point; n1 is the number of primary baseline indicators of the target asset point; Generate associated traffic packages for the target asset points based on all surveyed traffic packages; Set the anchor baseline for each primary baseline indicator based on the associated traffic package; Construct an audit sub-model for the target asset point based on all anchored baselines; Set up audit sub-models for each asset point in sequence.

[0012] In some embodiments of this application, the construction of the traffic auditing model further includes: Based on the asset point sequence C, set c sequentially. i For the asset points to be compared; Generate the association interaction value d between the target asset point and the asset point to be compared; d=[ β i *v i ]; Where θ1 is the number of related indicators; β i is the influence factor of the i-th correlation indicator; vi is the reference value of the i-th correlation indicator generated based on the target asset point and the asset point to be compared; Generate the target asset point and the associated interaction values ​​of each asset point in sequence; Establish a sequence of related interactive values ​​D, D=(d1,d2…d i …d r ), where d i is the association interaction value between the target asset point and the i-th asset point; r is the number of asset points; Preset the threshold value D1 for related interaction values; If d i >D1, set the i-th asset point as the associated asset point of the target asset point; Construct a related sub-table for the target asset point based on all its associated asset points; Construct related sub-tables for each asset point in sequence; Construct a relational model based on all related sub-tables; A flow audit model is constructed based on all audit sub-models and related models.

[0013] In some embodiments of this application, the generation of abnormal risk values ​​includes: Based on the asset point sequence c, set c sequentially. i For the asset points to be audited; The feedback data packets of each data node are obtained according to the preset monitoring time nodes; Generate a related monitoring package for the asset points to be audited based on all feedback data packets; Generate anomaly risk values ​​f for the asset points to be audited based on the associated monitoring packages; Preset anomaly risk threshold F1; If f > F1, generate a first-level early warning instruction for the asset points to be audited; Abnormal risk values ​​for each asset point are generated sequentially.

[0014] In some embodiments of this application, the generation of anomaly risk value f for the asset point to be audited includes: f=e*[ η i *s i ]; e=U1*[ µ i *f' i ]; Where e is the abnormality compensation coefficient; n2 is the number of primary baseline indicators for the asset points to be audited; η i The impact factor of the i-th primary baseline indicator of the asset to be audited; s i It is the deviation value generated from the anchor baseline of the i-th primary baseline indicator based on the associated monitoring package; U1 is the preset first conversion coefficient; r1 is the number of associated asset points of the asset point to be audited; µ i f' is the influence factor of the i-th related asset point of the asset point to be audited; i This represents the abnormal flow value of the i-th associated asset point of the asset point to be audited.

[0015] Some embodiments of this application also include: Obtain the mapping traffic packets of each data node at the current mapping time node; Generate an updated evaluation value h based on all surveyed flow packets; h=g*[ k i ]; Where r2 is the number of asset points at the previous surveying time point; k iis the fluctuation value of the anchor baseline of the i-th asset point at the previous surveying time point at the current surveying time point; g is the correction coefficient set based on the number of newly added asset points at the current surveying time point; Preset update evaluation value threshold H1; If h > H1, a first-level update instruction is generated at the current surveying time node.

[0016] In some embodiments of this application, an asset anomaly monitoring system based on traffic auditing is provided, including: The central control unit is used to set up multiple data nodes according to the network structure; The traffic monitoring unit includes multiple monitoring sub-modules, which are located at each data node; The monitoring unit is used to acquire traffic data from each data node; The monitoring unit is also used to generate mapping traffic packets and feedback data packets for each data node; The central control unit includes: The first processing module is used to generate multiple asset points based on all policy traffic packages; The second processing module is used to construct a traffic audit model based on the preset traffic monitoring model and all asset points; The third processing module is used to obtain feedback data packets from each data node and generate abnormal risk values ​​for each asset point based on the traffic audit model and all feedback data packets.

[0017] In some embodiments of this application, the central control unit further includes: The fourth processing module is used to set multiple asset categories; Establish an asset class sequence A, A=(a1, a2, ..., a... i …a n ), where a i Let i be the i-th asset class; n is the number of asset classes; Establish a baseline index series B, B = (b1, b2, ..., bb) i …b m ), where b i Let m be the i-th baseline indicator; m is the number of baseline indicators. Based on the asset category series A, a is set sequentially. i For the target asset class; Construct monitoring sub-models for the target asset class; Construct monitoring sub-models for each asset class in sequence; A flow monitoring model is generated based on all monitoring sub-models.

[0018] Compared with existing technologies, the asset anomaly monitoring method and system based on traffic auditing described in this embodiment have the following advantages: By periodically mapping each network node and dynamically updating asset points, and combining this with a pre-set traffic monitoring model, an audit sub-model for each asset point can be quickly built, improving the efficiency of monitoring and early warning of abnormal risks at each asset point, while also enabling effective monitoring of unknown and temporary assets.

[0019] By using passive traffic analysis, all network assets are monitored non-intrusively. At the same time, anomaly diagnosis is performed based on the anchored baseline of each asset point, reducing the false alarm rate and accurately identifying the abnormal state of network assets. Attached Figure Description

[0020] Figure 1 This is a flowchart illustrating a preferred embodiment of an asset anomaly monitoring method based on traffic auditing in this application. Detailed Implementation

[0021] The specific embodiments of this application will be described in further detail below with reference to the accompanying drawings and examples. The following examples are used to illustrate this application, but are not intended to limit the scope of this application.

[0022] In the description of this application, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application.

[0023] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0024] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.

[0025] like Figure 1As shown in the preferred embodiment of this application, an asset anomaly monitoring method based on traffic auditing includes: S101: Set multiple data nodes according to the network structure, and obtain the mapping traffic packets of each data node according to the preset mapping time nodes; S102: Generate multiple asset points based on all policy traffic packages, and construct a traffic audit model based on the preset traffic monitoring model and all asset points; S103: Obtain feedback data packets from each data node, and generate abnormal risk values ​​for each asset point based on the traffic audit model and all feedback data packets.

[0026] Specifically, the network structure is traversed, and each key network node is set as a data node, where a single data node represents a key network node.

[0027] Specifically, key network nodes refer to area boundaries (firewalls, intrusion prevention systems, etc.), data convergence points (core switches connecting all data center servers, storage, and applications), and core processing units within the network. Monitoring sub-modules (i.e., traffic collectors) are deployed at each key network node. Full traffic data is collected losslessly via mirroring or probe methods.

[0028] Specifically, the mapping traffic packet includes the full traffic data of each individual data node (including but not limited to flow records such as NetFlow / sFlow / IPFIX, and captured full packet data). By parsing the mapping traffic packet, the source IP, destination IP, source port, destination port, and protocol of the five-tuple are obtained. Based on the parsing results, active IP addresses are automatically identified and set as asset points.

[0029] It is understood that in the above embodiments, by periodically mapping each network node, dynamically updating asset points, and combining a preset traffic monitoring model to quickly build an audit sub-model for each asset point, the efficiency of monitoring and early warning of abnormal risks of each asset point is improved, while effectively monitoring unknown and temporary assets is achieved.

[0030] In a preferred embodiment of this application, the preset traffic monitoring model includes: Set multiple asset classes; Establish an asset class sequence A, A=(a1, a2, ..., a... i …a n ), where a i Let i be the i-th asset class; n is the number of asset classes; Establish a baseline index series B, B = (b1, b2, ..., bb) i …b m ), where b iLet m be the i-th baseline indicator; m is the number of baseline indicators. Based on the asset category series A, a is set sequentially. i For the target asset class; Construct monitoring sub-models for the target asset class; Construct monitoring sub-models for each asset class in sequence; A flow monitoring model is generated based on all monitoring sub-models.

[0031] Specifically, by analyzing the correlation between the target asset class and various baseline indicators, correlation indicators for the target asset class are generated, thereby constructing corresponding monitoring sub-models.

[0032] Specifically, constructing a monitoring sub-model for the target asset class includes: Generate audit correlation values ​​between the target asset class and each baseline metric; Establish an audit correlation value sequence W, W = (w1, w2, ... w i …w m ), where w i The i-th audit correlation value; m is the number of baseline indicators; Preset audit correlation threshold W1; If w i >W1, set the i-th baseline indicator as the correlation indicator of the target asset class; Get all related metrics; A monitoring sub-model for the target asset class is constructed based on all relevant indicators.

[0033] Asset categories include, but are not limited to, databases, physical servers, office equipment, routers, switches, firewalls, wireless access points (production environment servers), business systems, etc., covering all equipment and virtual entities involved in modern enterprise networks.

[0034] Specifically, the audit correlation threshold can be set based on historical parameters. If the audit correlation value of the current baseline indicator is less than the preset audit correlation threshold, it means that the baseline indicator does not have the ability to map abnormal risks of the target asset class.

[0035] Specifically, baseline metrics include, but are not limited to, behavioral timing baselines (regularity of activity time), service access baselines (which services are typically accessed or provided), communication object baselines (which internal / external assets are typically communicated with), and traffic pattern baselines (inbound and outbound bandwidth and number of data packets within a specific time period).

[0036] Specifically, by analyzing the fluctuation status of various baseline indicators when abnormal risks occur in the target asset class, corresponding audit correlation values ​​are generated. The greater the fluctuation status, the larger the corresponding audit correlation value. The mapping relationship between the two can be set according to historical parameters.

[0037] In a preferred embodiment of this application, the traffic auditing model is constructed, including: Establish an asset point sequence C, C=(c1, c2, ..., c2). i …c r ), where c i Let r be the i-th asset point; r is the number of asset points. Based on the abnormal setting of asset point column C, c is set. i For target asset points; Generate similarity values ​​for the target asset and each asset class; The monitoring sub-model corresponding to the asset class with the highest value among all similar values ​​is set as the first-level monitoring model; Based on the primary monitoring model, a primary baseline indicator series B1 is constructed for the target asset point, B1=(b 11 ,b 12 …b 1i …b 1n1 ), where b 1i is the i-th primary baseline indicator of the target asset point; n1 is the number of primary baseline indicators of the target asset point; Generate associated traffic packages for the target asset points based on all surveyed traffic packages; Set the anchor baseline for each primary baseline indicator based on the associated traffic package; Construct an audit sub-model for the target asset point based on all anchored baselines; Set up audit sub-models for each asset point in sequence.

[0038] Specifically, all initial traffic data packets are filtered and analyzed to obtain traffic data related to the target asset point (i.e., data that passes through or is associated with the target asset point), and traffic packets associated with the target asset point are generated based on the filtering results.

[0039] Specifically, by analyzing the associated traffic packages, the baseline status with the largest proportion of each primary baseline indicator in the associated traffic package is generated, and this baseline is set as the anchor baseline. Based on all anchor baselines, an audit sub-model for the target asset point is generated.

[0040] Specifically, the higher the similarity value, the stronger the monitoring sub-model of that asset class is at detecting and warning of abnormal states of the target asset.

[0041] Specifically, building a traffic auditing model also includes: Based on the asset point sequence C, set c sequentially. i For the asset points to be compared; Generate the association interaction value d between the target asset point and the asset point to be compared; d=[ β i *v i ]; Where θ1 is the number of related indicators; β i is the influence factor of the i-th correlation indicator; vi is the reference value of the i-th correlation indicator generated based on the target asset point and the asset point to be compared; Generate the target asset point and the associated interaction values ​​of each asset point in sequence; Establish a sequence of related interactive values ​​D, D=(d1,d2…d i …d r ), where d i is the association interaction value between the target asset point and the i-th asset point; r is the number of asset points; Preset the threshold value D1 for related interaction values; If d i >D1, set the i-th asset point as the associated asset point of the target asset point; Construct a related sub-table for the target asset point based on all its associated asset points; Construct related sub-tables for each asset point in sequence; Construct a relational model based on all related sub-tables; A flow audit model is constructed based on all audit sub-models and related models.

[0042] Specifically, the correlation interaction value threshold can be set based on historical parameters. When the correlation interaction value exceeds the preset correlation interaction value threshold, it indicates that there is a risk interference between the asset point to be compared and the target asset point, that is, when an asset point experiences operational risk, it will interfere with the operational status of the other asset.

[0043] Specifically, correlation indicators include, but are not limited to, parameters reflecting the interaction status between the target asset and the asset to be compared, such as interaction frequency, interaction volume, and data similarity. By quantifying each correlation indicator, all correlation indicators are made to be within the same value range. Furthermore, the influence factor of each correlation indicator can be set according to its correlation with the interaction status between the two asset points. The greater the correlation, the greater the reference value of the corresponding influence factor.

[0044] Specifically, the higher the reference value of each related indicator, the closer the interaction between the two asset points.

[0045] It is understood that in the above embodiments, an audit sub-model for each asset point is quickly built based on a preset traffic monitoring model, which improves the efficiency of monitoring and early warning of abnormal risks at each asset point, and at the same time enables effective monitoring of unknown and temporary assets.

[0046] In a preferred embodiment of this application, generating anomaly risk values ​​includes: Based on the asset point sequence c, set c sequentially. i For the asset points to be audited; The feedback data packets of each data node are obtained according to the preset monitoring time nodes; Generate a related monitoring package for the asset points to be audited based on all feedback data packets; Generate anomaly risk values ​​f for the asset points to be audited based on the associated monitoring packages; Preset anomaly risk threshold F1; If f > F1, generate a first-level early warning instruction for the asset points to be audited; Abnormal risk values ​​for each asset point are generated sequentially.

[0047] Specifically, the abnormal risk threshold can be set based on historical parameters. If the abnormal risk value of the asset to be audited is greater than the preset abnormal risk threshold, it indicates that there is an abnormal risk in the asset to be audited. A first-level warning instruction should be generated in a timely manner to carry out further maintenance and risk handling operations to ensure the security of network assets.

[0048] Specifically, the feedback data packet is all traffic data collected by the corresponding data node within a single monitoring period (a monitoring period is between two adjacent monitoring time nodes).

[0049] Specifically, generating the abnormal risk value f for the asset points to be audited includes: f=e*[ η i *s i ]; e=U1*[ µ i *f' i ]; Where e is the abnormality compensation coefficient; n2 is the number of primary baseline indicators for the asset points to be audited; η i The impact factor of the i-th primary baseline indicator of the asset to be audited; s i It is the deviation value generated from the anchor baseline of the i-th primary baseline indicator based on the associated monitoring package; U1 is the preset first conversion coefficient; r1 is the number of associated asset points of the asset point to be audited; µ i f' is the influence factor of the i-th related asset point of the asset point to be audited; i This represents the abnormal flow value of the i-th associated asset point of the asset point to be audited.

[0050] Specifically, the higher the abnormal risk value of the asset to be audited, the greater the possibility that the asset to be audited has abnormal risks.

[0051] Specifically, the real-time baseline status of each primary baseline indicator is generated based on the associated monitoring package. The real-time baseline status is compared with the corresponding anchored baseline, and the corresponding deviation value is set according to the degree of difference between the two. The greater the difference, the greater the corresponding deviation value. The mapping relationship between the two can be set according to historical parameters.

[0052] Specifically, the impact factors of each primary baseline indicator are set based on the audit correlation value of the asset category corresponding to the audited asset point. The larger the audit correlation value, the larger the reference value of the corresponding impact factor. The mapping relationship between the two can be set based on historical parameters.

[0053] Specifically, the generation rules for traffic anomalies at each associated asset point correspond to the anomaly risk value f. η i *s i [Partially identical]

[0054] Specifically, the impact factor of each related asset point can be set according to its correlation value with the audited asset point. The mapping relationship between the two can be set according to historical parameters. The larger the correlation value, the larger the value of the corresponding impact factor.

[0055] Specifically, by presetting a first conversion coefficient, the anomaly compensation coefficient is made to be within a preset value range, and [ µ i *f' i The larger the value of ], the larger the corresponding abnormal compensation coefficient e will be. The mapping relationship between the two can be set according to historical parameters, and the value of the abnormal compensation coefficient e is always greater than 1.

[0056] In a preferred embodiment of this application, it further includes: Obtain the mapping traffic packets of each data node at the current mapping time node; Generate an updated evaluation value h based on all surveyed flow packets; h=g*[ k i ]; Where r2 is the number of asset points at the previous surveying time point; k i is the fluctuation value of the anchor baseline of the i-th asset point at the previous surveying time point at the current surveying time point; g is the correction coefficient set based on the number of newly added asset points at the current surveying time point; Preset update evaluation value threshold H1; If h > H1, a first-level update instruction is generated at the current surveying time node.

[0057] Specifically, the fluctuation value of the anchoring baseline is set according to the difference between the anchoring baselines generated at two surveying time points. The greater the difference, the greater the corresponding fluctuation value. The mapping relationship between the two can be set according to historical parameters.

[0058] Specifically, the more new asset points are added, the larger the reference value of the corresponding correction coefficient will be. The mapping relationship between the two can be set according to historical parameters, and the value of the correction coefficient is always greater than 1.

[0059] Specifically, the update evaluation value threshold can be set based on historical parameters. When the real-time update evaluation value exceeds the update evaluation value threshold, the traffic audit model needs to be rebuilt according to the first-level update instruction, and the anchoring baseline of each asset point needs to be dynamically adjusted to reduce the false alarm rate and accurately identify the abnormal state of network assets.

[0060] In another preferred embodiment of the asset anomaly monitoring method based on traffic auditing based on any of the above preferred embodiments, this preferred embodiment provides an asset anomaly monitoring system based on traffic auditing, comprising: The central control unit is used to set up multiple data nodes according to the network structure; The traffic monitoring unit includes multiple monitoring sub-modules, which are set up at each data node; The monitoring unit is used to acquire traffic data from each data node; The monitoring unit is also used to generate mapping traffic packets and feedback data packets for each data node; The central control unit includes: The first processing module is used to generate multiple asset points based on all policy traffic packages; The second processing module is used to construct a traffic audit model based on the preset traffic monitoring model and all asset points; The third processing module is used to obtain feedback data packets from each data node and generate abnormal risk values ​​for each asset point based on the traffic audit model and all feedback data packets.

[0061] In a preferred embodiment of this application, the central control unit further includes: The fourth processing module is used to set multiple asset categories; Establish an asset class sequence A, A=(a1, a2, ..., a... i …a n ), where a i Let i be the i-th asset class; n is the number of asset classes; Establish a baseline index series B, B = (b1, b2, ..., bb) i …bm ), where b i Let m be the i-th baseline indicator; m is the number of baseline indicators. Based on the asset category series A, a is set sequentially. i For the target asset class; Construct monitoring sub-models for the target asset class; Construct monitoring sub-models for each asset class in sequence; A flow monitoring model is generated based on all monitoring sub-models.

[0062] Based on the first concept of this application, by periodically mapping each network node and dynamically updating asset points, and by combining a preset traffic monitoring model to quickly build an audit sub-model for each asset point, the efficiency of monitoring and early warning of abnormal risks of each asset point is improved, while also enabling effective monitoring of unknown and temporary assets.

[0063] According to the second concept of this application, all network assets are monitored non-intrusively through passive traffic analysis, and anomaly diagnosis is performed based on the anchored baseline of each asset point to reduce the false alarm rate and accurately identify the abnormal state of network assets.

[0064] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and substitutions can be made without departing from the technical principles of this application, and these improvements and substitutions should also be considered within the scope of protection of this application.

Claims

1. A method for monitoring asset anomalies based on traffic auditing, characterized in that, include: Multiple data nodes are set according to the network structure, and the mapping traffic packets of each data node are obtained according to the preset mapping time nodes. Multiple asset points are generated based on all policy traffic packages, and a traffic audit model is constructed based on the preset traffic monitoring model and all asset points; Obtain feedback data packets from each data node, and generate abnormal risk values ​​for each asset point based on the traffic audit model and all feedback data packets.

2. The asset anomaly monitoring method based on traffic auditing as described in claim 1, characterized in that, Preset traffic monitoring models include: Set multiple asset classes; Establish an asset class sequence A, A=(a1, a2, ..., a... i …a n ), where a i Let i be the i-th asset class; n is the number of asset classes; Establish a baseline index series B, B = (b1, b2, ..., bb) i …b m ), where b i Let m be the i-th baseline indicator; m is the number of baseline indicators. Based on the asset category series A, a is set sequentially. i For the target asset class; Construct monitoring sub-models for the target asset class; Construct monitoring sub-models for each asset class in sequence; A flow monitoring model is generated based on all monitoring sub-models.

3. The asset anomaly monitoring method based on traffic auditing as described in claim 2, characterized in that, Construct a monitoring sub-model for the target asset class, including: Generate audit correlation values ​​between the target asset class and each baseline metric; Establish an audit correlation value sequence W, W = (w1, w2, ... w i …w m ), where w i Let be the i-th audit correlation value; m is the number of baseline indicators; Preset audit correlation threshold W1; If w i >W1, set the i-th baseline indicator as the correlation indicator of the target asset class; Get all related metrics; A monitoring sub-model for the target asset class is constructed based on all relevant indicators.

4. The asset anomaly monitoring method based on traffic auditing as described in claim 3, characterized in that, Constructing a traffic auditing model includes: Establish an asset point sequence C, C=(c1, c2, ..., c2). i …c r ), where c i Let r be the i-th asset point; r is the number of asset points. Based on the abnormal setting of asset point column C, c is set. i For target asset points; Generate similarity values ​​for the target asset and each asset class; The monitoring sub-model corresponding to the asset class with the highest value among all similar values ​​is set as the first-level monitoring model; Based on the primary monitoring model, a primary baseline indicator series B1 is constructed for the target asset point, B1=(b 11 ,b 12 …b 1i …b 1n1 ), where b 1i is the i-th primary baseline indicator of the target asset point; n1 is the number of primary baseline indicators of the target asset point; Generate associated traffic packages for the target asset points based on all surveyed traffic packages; Set the anchor baseline for each primary baseline indicator based on the associated traffic package; Construct an audit sub-model for the target asset point based on all anchored baselines; Set up audit sub-models for each asset point in sequence.

5. The asset anomaly monitoring method based on traffic auditing as described in claim 4, characterized in that, Building a traffic auditing model also includes: Based on the asset point sequence C, set c sequentially. i For the asset points to be compared; Generate the association interaction value d between the target asset point and the asset point to be compared; d=[ b i *v i ]; Where θ1 is the number of related indicators; β i is the influence factor of the i-th correlation indicator; vi is the reference value of the i-th correlation indicator generated based on the target asset point and the asset point to be compared; Generate the target asset point and the associated interaction values ​​of each asset point in sequence; Establish a sequence of related interactive values ​​D, D=(d1,d2…d i …d r ), where d i is the association interaction value between the target asset point and the i-th asset point; r is the number of asset points; Preset threshold value D1 for related interaction values; If d i >D1, set the i-th asset point as the associated asset point of the target asset point; Construct a related sub-table for the target asset point based on all its associated asset points; Construct related sub-tables for each asset point in sequence; Construct a relational model based on all related sub-tables; A flow audit model is constructed based on all audit sub-models and related models.

6. The asset anomaly monitoring method based on traffic auditing as described in claim 5, characterized in that, Generate abnormal risk values, including: Based on the asset point sequence c, set c sequentially. i For the asset points to be audited; The feedback data packets of each data node are obtained according to the preset monitoring time nodes; Generate a related monitoring package for the asset points to be audited based on all feedback data packets; Generate anomaly risk values ​​f for the asset points to be audited based on the associated monitoring packages; Preset anomaly risk threshold F1; If f > F1, generate a first-level early warning instruction for the asset points to be audited; Abnormal risk values ​​for each asset point are generated sequentially.

7. The asset anomaly monitoring method based on traffic auditing as described in claim 6, characterized in that, Generate the outlier risk value f for the asset points to be audited, including: f=e*[ or i *s i ]; e=U1*[ µ i *f' i ]; Where e is the abnormality compensation coefficient; n2 is the number of primary baseline indicators for the asset points to be audited; η i The impact factor of the i-th primary baseline indicator of the asset to be audited; s i It is the deviation value generated from the anchor baseline of the i-th primary baseline indicator based on the associated monitoring package; U1 is the preset first conversion coefficient; r1 is the number of associated asset points of the asset point to be audited; µ i f' is the influence factor of the i-th related asset point of the asset point to be audited; i This represents the abnormal flow value of the i-th associated asset point of the asset point to be audited.

8. The asset anomaly monitoring method based on traffic auditing as described in claim 7, characterized in that, Also includes: Obtain the mapping traffic packets of each data node at the current mapping time node; Generate an updated evaluation value h based on all surveyed flow packets; h=g*[ k i ]; Where r2 is the number of asset points at the previous surveying time point; k i is the fluctuation value of the anchor baseline of the i-th asset point at the previous surveying time point at the current surveying time point; g is the correction coefficient set based on the number of newly added asset points at the current surveying time point; Preset update evaluation value threshold H1; If h > H1, a first-level update instruction is generated at the current surveying time node.

9. An asset anomaly monitoring system based on traffic auditing, employing the asset anomaly monitoring method based on traffic auditing as described in any one of claims 1-8, characterized in that, include: The central control unit is used to set up multiple data nodes according to the network structure; The traffic monitoring unit includes multiple monitoring sub-modules, which are located at each data node; The monitoring unit is used to acquire traffic data from each data node; The monitoring unit is also used to generate mapping traffic packets and feedback data packets for each data node; The central control unit includes: The first processing module is used to generate multiple asset points based on all policy traffic packages; The second processing module is used to construct a traffic audit model based on the preset traffic monitoring model and all asset points; The third processing module is used to obtain feedback data packets from each data node and generate abnormal risk values ​​for each asset point based on the traffic audit model and all feedback data packets.

10. The asset anomaly monitoring system based on traffic auditing as described in claim 9, characterized in that, The central control unit also includes: The fourth processing module is used to set multiple asset categories; Establish an asset class sequence A, A=(a1, a2, ..., a... i …a n ), where a i Let i be the i-th asset class; n is the number of asset classes; Establish a baseline index series B, B = (b1, b2, ..., bb) i …b m ), where b i Let m be the i-th baseline indicator; m is the number of baseline indicators. Based on the asset category series A, a is set sequentially. i For the target asset class; Construct monitoring sub-models for the target asset class; Construct monitoring sub-models for each asset class in sequence; A flow monitoring model is generated based on all monitoring sub-models.