Hierarchical organization hidden asset quantity estimation method and device

By extracting access records from large hierarchical organizations and using random high-order port connections and rDNS service queries, the addresses of hidden assets can be identified and confirmed. This solves the problem that upper-level organizations have difficulty detecting assets protected by firewalls, and enables accurate estimation of hidden assets and network security management.

CN121967259APending Publication Date: 2026-05-01RICHFIT INFORMATION TECH +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
RICHFIT INFORMATION TECH
Filing Date
2024-10-29
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In large hierarchical organizations, it is difficult for higher-level organizations to accurately detect the number of hidden assets protected by firewalls, resulting in a lack of information transparency and complexity in security management. Existing technical methods also suffer from problems such as false inflation and difficulty in distinguishing service traffic.

Method used

By extracting access records from the device, suspected hidden addresses are identified. Random high-number port connections and rDNS service queries are used to identify and confirm hidden asset addresses. The number of hidden assets is calculated by combining access records from multiple time periods, eliminating firewall interference and improving identification accuracy.

Benefits of technology

Effectively estimate the size of hidden assets, improve network security management capabilities, reduce misjudgments, optimize resource allocation, enhance security protection, and provide accurate asset views and dynamic monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967259A_ABST
    Figure CN121967259A_ABST
Patent Text Reader

Abstract

The invention discloses a hierarchical organization hidden asset quantity estimation method and device, and the method comprises the steps: extracting a plurality of access records corresponding to each equipment end in a hierarchical organization in a first preset time period, and comparing the access records with a recorded asset list, thereby obtaining a plurality of suspected hidden addresses; for each suspected hidden address, sending a connection request, judging whether the suspected hidden address can be accessed, further requesting to connect a plurality of random high-order ports of an adjacent IP address of the suspected hidden address according to an access result, and determining a plurality of first hidden asset addresses; for each first hidden asset address, querying a domain name record through an rDNS service, determining an associated IP address of the first hidden asset address according to a query result, and determining the associated IP address as a second hidden asset address; and obtaining a determined hidden asset address in combination with the first hidden asset address and the second hidden asset address. According to the method, the hidden assets in the hierarchical organization can be estimated, and the blind area behind the firewall can be ascertained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method and apparatus for estimating the amount of hidden assets in a hierarchical organization. Background Technology

[0002] In large, hierarchical organizations, such as education systems and corporations, the conflict between the autonomy of subordinate organizations and the overall security strategy is a common problem. Taking a corporation as an example, its subsidiaries typically establish information systems and formulate corresponding security standards based on their own business needs and actual circumstances. While this bottom-up approach can improve the management capabilities of subordinate organizations regarding their own assets, it may also lead to the upper-level organization being unable to effectively implement a unified security policy.

[0003] At the same time, due to the differences in business models, network architectures and security needs among subordinate organizations, higher-level organizations face great challenges in formulating common security standards, which often conflict with the standards of subordinate organizations, resulting in a situation of "fragmented security standards".

[0004] In asset management, higher-level organizations typically require subordinate organizations to report IT asset information, including servers, storage devices, personal computers, network equipment (such as routers, switches, and firewalls), mobile devices (such as mobile phones and tablets), and other IT infrastructure. However, to prevent excessive interference from higher-level organizations in their operations, subordinate organizations often choose to report only those OT assets that can be easily accessed from the internet or internal LAN. This practice results in many actual assets being hidden in private networks and protected by firewalls. While this protection measure can safeguard the internal assets of subordinate organizations to some extent, it also prevents higher-level organizations from obtaining accurate asset information through conventional network probing methods, leading to a lack of information transparency. Summary of the Invention

[0005] To determine the number of hidden assets within a hierarchical organization, this invention provides a method and apparatus for estimating the number of hidden assets in a hierarchical organization.

[0006] In a first aspect, embodiments of the present invention provide a method for estimating the quantity of hidden assets in a hierarchical organization, which may include:

[0007] Extract multiple access records corresponding to each device within the hierarchical organization during the first preset time period;

[0008] Based on the multiple access records corresponding to each device, and compared with the obtained list of registered assets, multiple suspected hidden addresses were obtained.

[0009] For each suspected hidden address, request a connection to the suspected hidden address and determine whether the suspected hidden address can be accessed;

[0010] If so, then request to connect to multiple random high-order ports of the adjacent IP addresses of the suspected hidden address. If the returned information is abnormal, determine that the suspected hidden address is the first hidden asset address.

[0011] If not, the suspected hidden address is determined to be the first hidden asset address;

[0012] For each first hidden asset address, the domain name record is queried through rDNS service in the local area network where the first hidden asset address is located, the query result is obtained, and the associated IP address of the first hidden asset address is determined based on the query result, and the associated IP address is determined as the second hidden asset address.

[0013] By combining the first hidden asset address and the second hidden asset address, the hidden asset address is determined.

[0014] In one or more optional embodiments of this application, if the request to connect to multiple random high-order ports of the adjacent IP addresses of the suspected hidden address returns abnormal information, and the suspected hidden address is identified as the first hidden asset address, the following steps are included:

[0015] Request connections to multiple random high-order ports of adjacent IP addresses of the suspected hidden address. If all random high-order ports can be connected, the suspected hidden address is identified as the first hidden asset address.

[0016] In one or more optional embodiments of this application, after determining that the suspected hidden address is the first hidden asset address, the method further includes:

[0017] Path exploration is performed on the first hidden asset address;

[0018] During the path exploration process, if the exploration request terminates at an intermediate IP address, then that intermediate IP address is identified as the firewall of the first hidden asset address.

[0019] During path exploration, if the exploration request does not receive a response on multiple consecutive intermediate IP addresses, the first intermediate IP address that does not receive a response is identified as the firewall of the first hidden asset address.

[0020] In one or more optional embodiments of this application, the step of querying domain name records through rDNS service in the local area network where the first hidden asset address is located for each first hidden asset address, obtaining query results, determining the associated IP address of the first hidden asset address based on the query results, and determining the associated IP address as the second hidden asset address includes:

[0021] For each first hidden asset address, the domain name record is queried through the rDNS service in the local area network to obtain the query result;

[0022] Based on the query results, determine whether the domain name record of the first hidden asset address can be obtained;

[0023] If so, then search the local area network for associated IP addresses belonging to the same main domain as the domain name record, and determine the associated IP address as the second hidden asset address;

[0024] If not, then all subnet IP addresses with domain name records in the local area network will be identified as the second hidden asset addresses.

[0025] In one or more optional embodiments of this application, the access record includes an IP address and a port;

[0026] The process involves comparing multiple access records corresponding to each device with the obtained list of registered assets to obtain multiple suspected hidden addresses, including:

[0027] Based on the multiple access records corresponding to each device, check whether there are multiple devices accessing the same IP address or port to obtain a duplicate access address dataset.

[0028] The dataset of repeated access addresses was compared with the list of registered assets to identify several suspected hidden addresses.

[0029] In one or more optional embodiments of this application, the access record includes time information;

[0030] After identifying multiple suspected hidden addresses, the process also includes:

[0031] Based on the multiple access records corresponding to each device and the time information of each access record, access records outside of working hours are retrieved, and the IP address of the access record is identified as a suspected hidden address.

[0032] In one or more optional embodiments of this application, after the concealed asset real estate is identified, the following steps are further included:

[0033] Extract multiple access records corresponding to each device within the hierarchical organization during the second preset time period, re-execute the process to determine the hidden asset address, query the number of determined hidden asset addresses that appear simultaneously in both the first and second preset time periods, and calculate the number of hidden assets, including:

[0034] Extract multiple access records corresponding to each device within the hierarchical organization during the second preset time period, re-execute the process to determine the hidden asset address, query the number of determined hidden asset addresses that appear simultaneously in both the first and second preset time periods, and calculate the number of determined hidden assets based on the following formula:

[0035]

[0036] In the formula, H represents the number of identified hidden asset addresses within the first preset time period, K represents the number of identified hidden asset addresses within the second preset time period, and J represents the number of identified hidden asset addresses that appear simultaneously in both the first and second preset time periods.

[0037] Secondly, embodiments of the present invention provide a device for estimating the quantity of hidden assets in a hierarchical organization, which may include:

[0038] The first extraction module is used to extract multiple access records corresponding to each device in the hierarchical organization within a first preset time period.

[0039] The first filtering module is used to compare multiple access records corresponding to each device with the obtained list of registered assets to obtain multiple suspected hidden addresses;

[0040] The second filtering module is used to request a connection to each suspected hidden address, determine whether the suspected hidden address can be accessed; if yes, execute the third filtering module; if no, execute the fourth filtering module.

[0041] The third filtering module requests multiple random high-order ports of the adjacent IP addresses of the suspected hidden address when the suspected hidden address can be accessed. If the returned information is abnormal, the suspected hidden address is determined to be the first hidden asset address.

[0042] The fourth filtering module determines the suspected hidden address as the first hidden asset address when the suspected hidden address cannot be accessed.

[0043] The first query module is used to query the domain name record in the local area network where the first hidden asset address is located through rDNS service for each first hidden asset address, obtain the query result, determine the associated IP address of the first hidden asset address based on the query result, and determine the associated IP address as the second hidden asset address.

[0044] The first combining module is used to combine the first hidden asset address and the second hidden asset address to obtain the determined hidden asset address.

[0045] Thirdly, embodiments of the present invention provide a computer-readable storage medium having a computer program / instruction stored thereon, which, when executed by a processor, implements the hierarchical organization hidden asset quantity estimation method described above.

[0046] Fourthly, embodiments of the present invention provide a computer program product, including a computer program / instruction, which, when executed by a processor, implements the hierarchical organization hidden asset quantity estimation method described above.

[0047] Fifthly, embodiments of the present invention provide a computer device, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the hierarchical organization hidden asset quantity estimation method as described above.

[0048] The beneficial effects of the above-described technical solutions provided in the embodiments of the present invention include at least the following:

[0049] This invention provides a method for estimating the number of hidden assets in a hierarchical organization. The method involves extracting multiple access records corresponding to each device within the hierarchical organization during a first preset time period to identify suspected hidden addresses. By requesting connections to the suspected hidden addresses and the high-order ports of adjacent IP addresses, the hidden asset addresses are determined. Based on the identified hidden asset addresses, domain name records are queried in the local area network to determine the associated IP addresses, which are also identified as hidden asset addresses. Then, during a second preset time period, multiple access records corresponding to each device within the hierarchical organization are extracted to re-determine the hidden asset addresses. Based on the hidden asset addresses determined in the first and second preset time periods, the number of hidden assets is calculated. This method, based on collected network access records, can effectively estimate the scale of hidden IT assets protected by firewalls in various subordinate organizations, identify blind spots in traditional asset detection methods, effectively improve the network security management capabilities of hierarchical organizations, and help enterprises better schedule resources and protect security.

[0050] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings.

[0051] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0052] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0053] Figure 1 A schematic diagram illustrating the steps of the method for estimating the quantity of hidden assets in a hierarchical organization provided in an embodiment of the present invention;

[0054] Figure 2 A framework diagram of the method for estimating the quantity of hidden assets in a hierarchical organization provided in an embodiment of the present invention;

[0055] Figure 3 A schematic diagram of the structure of the hierarchical organization hidden asset quantity estimation device provided in the embodiments of this application. Detailed Implementation

[0056] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.

[0057] The inventors discovered that in existing technologies, higher-level organizations cannot accurately detect the number of assets protected by firewalls. This means there are blind spots in their understanding of the overall asset situation, and the automatic response mechanisms of some firewalls may lead to false inflation of detection results, causing the number of detected IT assets to exceed the actual number of assets, introducing unnecessary complexity to security management. Furthermore, since different subordinate organizations may use the same firewall to penetrate service traffic, higher-level organizations find it difficult to distinguish these traffic flows, making security analysis challenging. Based on this, the inventors, through further research and development, created this invention, providing a method and apparatus for estimating the number of hidden assets in a hierarchical organization.

[0058] Example 1

[0059] Embodiment 1 of this invention provides a method for estimating the quantity of hidden assets in a hierarchical organization, referring to... Figure 1 As shown, the method may include the following steps S101-S107:

[0060] S101: Extract multiple access records corresponding to each device within the hierarchical organization during the first preset time period.

[0061] S102: Based on the multiple access records corresponding to each device, compare them with the obtained list of registered assets to obtain multiple suspected hidden addresses.

[0062] S103: For each suspected hidden address, request a connection to the suspected hidden address and determine whether the suspected hidden address can be accessed: if yes, proceed to step S104; if no, proceed to step S105.

[0063] S104: Request to connect to multiple random high-order ports of the adjacent IP addresses of the suspected hidden address. If the returned information is abnormal, the suspected hidden address is determined to be the first hidden asset address.

[0064] S105: The suspected hidden address has been identified as the primary hidden asset address.

[0065] S106: For each first hidden asset address, query the domain name record in the local area network where the first hidden asset address is located through the rDNS service, obtain the query result, determine the associated IP address of the first hidden asset address based on the query result, and determine the associated IP address as the second hidden asset address.

[0066] S107: Combine the first hidden asset address and the second hidden asset address to obtain the determined hidden asset address.

[0067] This invention provides a method for estimating the number of hidden assets in a hierarchical organization. The method involves extracting multiple access records corresponding to each device within the hierarchical organization during a first preset time period to identify suspected hidden addresses. By requesting connections to the suspected hidden addresses and the high-order ports of adjacent IP addresses, the hidden asset addresses are determined. Based on the identified hidden asset addresses, domain name records are queried in the local area network to determine the associated IP addresses, which are also identified as hidden asset addresses. Then, during a second preset time period, multiple access records corresponding to each device within the hierarchical organization are extracted to re-determine the hidden asset addresses. Based on the hidden asset addresses determined in the first and second preset time periods, the number of hidden assets is calculated. This method, based on collected network access records, can effectively estimate the scale of hidden IT assets protected by firewalls in various subordinate organizations, distinguish fake assets created by firewalls, identify blind spots in traditional asset detection methods, effectively improve the network security management capabilities of hierarchical organizations, and help enterprises better schedule resources and protect security.

[0068] In this embodiment of the application, the method is implemented based on an asset exploration system and a network access data recording tool. The network access data recording tool needs to be pre-installed on all known devices within the hierarchical organization. The network access data recording tool is used to record all access records on the devices.

[0069] When this method is executed, the asset exploration system will send asset exploration requests to the network access data logging tools on all known devices. The network access data logging tools will then submit their access records to the asset exploration system. The asset exploration system can then execute this method based on the access records submitted by the network access data logging tools to obtain the number of hidden assets.

[0070] The network access data recording tool is used to collect and send access records from each device. The asset exploration system encapsulates all the functions of steps S101-S107 described in this method, and can determine the address of the hidden asset based on the access records from each device.

[0071] Asset exploration systems and network access data logging tools can be implemented on common operating system platforms (such as Linux and Windows), developed using various programming languages ​​(such as C++, Java, and Go), and stored in databases (such as MySQL, PostgreSQL, and MongoDB) to record access records and other information. In order to improve exploration efficiency and coverage, asset exploration systems and network access data logging tools can be implemented on a distributed architecture, enabling real-time collection and processing of massive amounts of network data through collaboration among subordinate organizations.

[0072] In step S101 above, multiple access records corresponding to each device in the hierarchical organization within the first preset time period are extracted.

[0073] Specifically, it could be that, based on the asset exploration system, an asset exploration request is sent to all known devices within the hierarchical organization, specifying the time period for the required data as the first preset time period, such as from 00:00 on October 1, 2024 to 24:00 on October 7, 2024.

[0074] Then, the network access data recording tool on all known devices within the hierarchical organization will return multiple access records for each device within the first preset time period. Each access record includes the IP address, port, and time information of the target network access.

[0075] The device side can include servers, personal computers, workstations, and mobile devices in IT assets.

[0076] It is important to note that not every access record includes port data. For example, if the network protocol corresponding to the access record (such as ICMP) does not use ports, then its access record will not contain port data.

[0077] In this embodiment, step S101 ensures the acquisition of comprehensive network activity data, providing accurate foundational information for subsequent analysis. By collecting access records, abnormal network behavior is detected, laying the groundwork for determining the addresses of hidden assets.

[0078] In step S102 above, multiple access records corresponding to each device are compared with the obtained list of registered assets to obtain multiple suspected hidden addresses. Specifically, this includes the following steps S1021-S1023:

[0079] S1021: Based on the multiple access records corresponding to each device, check whether there are multiple devices accessing the same IP address or port, and obtain the duplicate access address dataset.

[0080] Specifically, it can be done by checking whether there are multiple different devices accessing the same IP address or port based on the multiple access records corresponding to each device and the IP address and port information of each access record, and forming a duplicate access address dataset based on the IP address and port data that are accessed repeatedly.

[0081] It should be noted that a single duplicate access address in the duplicate access address dataset may contain only the IP address, or it may contain both the IP address and port data.

[0082] S1022: Compare the dataset of repeated access addresses with the list of registered assets to identify multiple suspected hidden addresses.

[0083] Specifically, this can be done by comparing the duplicate access address dataset with the list of registered assets. If a certain IP address or port in the duplicate access address dataset does not exist in the list of registered assets, then the IP address and port in the duplicate access address dataset are identified as suspected hidden addresses.

[0084] The asset filing list is a list of IT assets that have been registered or filed by the superior organization in the hierarchical organization, which includes the IP addresses and port data of all known devices.

[0085] In this embodiment of the application, step S1022 above can effectively distinguish between known legal assets and unknown potential hidden assets by comparing them with the list of registered assets, which helps to narrow the scope of subsequent investigations and improve efficiency.

[0086] S1023: Based on multiple access records corresponding to each device and the time information of each access record, retrieve access records outside of working hours and determine the IP address of the access record as a suspected hidden address.

[0087] Specifically, it can be done by retrieving access records outside of working hours, such as from 10 PM to 4 AM the next day, based on multiple access records corresponding to each device and the time information of each access record, and then identifying the IP address and port of the access record as a suspected hidden address.

[0088] In this embodiment of the application, the operation of determining the suspected hidden address performed in step S102 above, by combining all device terminals for correlation analysis, initially identifies the hidden assets and solves the limitation of traditional network detection methods that are difficult to penetrate firewalls.

[0089] In step S103 above, for each suspected hidden address, a request is made to connect to the suspected hidden address, and it is determined whether the suspected hidden address can be accessed: if yes, step S104 is executed; if no, step S105 is executed.

[0090] Specifically, for each suspected hidden address, the asset detection component will attempt to request a connection to the suspected hidden address to determine whether the suspected hidden address can be accessed. If so, it means that the asset detection component has successfully connected to the suspected hidden address, and then step S104 is executed to further attempt to connect to the adjacent IP address and high-order port of the suspected hidden address to explore whether the successful connection of the suspected hidden address is a false impression created by the firewall; if not, it means that the suspected hidden address cannot be accessed (including interruption, reset, etc.), and then step S105 is executed to determine that the suspected hidden address is a hidden asset address.

[0091] In step S104 above, multiple random high-order ports of the adjacent IP addresses of the suspected hidden address are requested for connection. If the returned information is abnormal, the suspected hidden address is determined to be the first hidden asset address. Specifically, this includes the following steps S1041-S1043:

[0092] S1041: Request connections to multiple adjacent IP addresses of the suspected hidden address.

[0093] For example, if the suspected hidden IP address is 10.10.10.10, then the adjacent IP addresses could be 10.10.10.8, 10.10.10.9, 10.10.10.11, and 10.10.10.12.

[0094] S1042: If there are adjacent IP addresses that can be connected, then for each of the adjacent IP addresses, request to connect to multiple random high-order ports of the adjacent IP addresses.

[0095] For example, for a connectable adjacent IP address (10.10.10.11), requests are made to connect to a first preset number of ports of that adjacent IP address (10.10.10.11) within a preset high-order range (e.g., 50000-65535).

[0096] S1043: If all random high-order ports can be connected, the suspected hidden address is identified as the first hidden asset address.

[0097] Specifically, if all random high-order ports can be connected, it can be determined that the previous successful connections with the suspected hidden address and adjacent IP addresses were all illusions created by the firewall, and the suspected hidden address can be identified as the first hidden asset address.

[0098] In this embodiment of the application, step S104 above can further verify the authenticity of the suspected hidden address by attempting to connect to a random high-order port, eliminate false alarms caused by firewalls or other security measures, and improve detection accuracy.

[0099] In this embodiment of the application, after determining the first hidden asset address, step S108 can also be executed to determine the firewall address of the first hidden asset address. S108 specifically includes the following steps S1081-S1083:

[0100] S1081: Pathfinding for the first hidden asset address.

[0101] Specifically, the asset detection component can perform path detection on the first hidden asset address by continuously sending short TTL (Time To Live) probe packets to the first hidden asset address to make detection requests, and gradually obtain the IP address of each device (such as router or switch) in the network path leading to the suspicious address.

[0102] In this embodiment of the application, step S1081 above obtains the IP address of each device that passes through the network path leading to the first hidden asset address by continuously sending short TTL probe packets, thus providing basic data for subsequent firewall identification.

[0103] S1082: During path probing, if the probing request terminates at an intermediate IP address, then the firewall that identifies that intermediate IP address as the first hidden asset address.

[0104] Specifically, during path probing, if a probing request terminates at an intermediate IP address and returns an error message (such as interruption or reset), it means that the intermediate IP address has the function of protecting hidden assets. If a firewall blocks the probing request at the intermediate IP address, then the intermediate IP address is marked as the firewall of the first hidden asset address.

[0105] S1083: During path exploration, if the exploration request does not receive a response on multiple consecutive intermediate IP addresses, the first intermediate IP address that does not receive a response will be identified as the firewall for the first hidden asset address.

[0106] Specifically, when a probe request fails to receive a response from a certain IP address, the asset probe component will continue to increase the TTL length and attempt to connect to the next device on the network path. If the probe request fails to receive a response from any of the second preset number of intermediate IP addresses during the path probe process, the first unresponsive intermediate IP address will be identified as the firewall for the first hidden asset address.

[0107] It should be noted that the firewall can be a hardware device or a software device. When implementing this method, those skilled in the art can determine the firewall's IP address as the first hidden asset address according to the actual needs.

[0108] In this embodiment, step S108 uses path probing technology to perform detailed network path analysis on the first hidden asset address, effectively determining the location of the firewall. Specifically, if the probing request terminates at an intermediate IP address and returns an error message, or if there is no response at multiple consecutive intermediate IP addresses, the first unresponsive intermediate IP address can be identified as the firewall. This step not only improves network security and helps enterprises better understand the security protection points in the network structure, but also optimizes resource allocation, reduces the false positive rate, and enhances the accuracy and comprehensiveness of asset management.

[0109] In this embodiment of the application, after determining the first hidden asset address in step S105, step S108 can also be executed to determine the firewall address of the first hidden asset address. The specific operation has been described above and will not be repeated here.

[0110] In this embodiment, steps S103-S105 determine the address of the first hidden asset. By systematically detecting and confirming this address, the system effectively identifies IT assets hidden by firewalls or other security measures, thereby enhancing organizational asset management and information security. Furthermore, using short TTL probe packets for path probing allows for detailed recording of the routers and switches traversed, facilitating a comprehensive understanding of the network structure and security protection points. This method not only improves the efficiency of monitoring and responding to potential network threats but also flexibly adapts to various network environments and security policies, providing crucial information for subsequent security strategy development and network optimization. Simultaneously, identifying the location of firewalls protecting hidden assets further enhances overall network security.

[0111] In step S106 above, for each first hidden asset address, the domain name record is queried through rDNS service in the local area network where the first hidden asset address is located, the query result is obtained, and the associated IP address of the first hidden asset address is determined based on the query result, and the associated IP address is determined as the second hidden asset address. Specifically, this includes the following steps S1061-S1064:

[0112] S1061: For each first hidden asset address, query the domain name record through rDNS service in the local area network to obtain the query result.

[0113] Specifically, for each first hidden asset address, assuming that the first hidden asset address is running in a standard local area network, this method will query the domain name records of the first hidden asset address in the local area network through rDNS (reverse domain name system) service to obtain the query results, which represent whether the domain name records can be found.

[0114] S1062: Based on the query results, determine whether the domain name record of the first hidden asset address can be obtained: if yes, proceed to step S1063; if no, proceed to step S1064.

[0115] S1063: Search the local area network for associated IP addresses belonging to the same primary domain name as the domain name record, and determine that the associated IP address is the address of the second hidden asset.

[0116] Specifically, this can be done by searching all IP addresses on the local area network that can retrieve domain name records, resulting in multiple IP addresses on the same subnet. Then, starting with the IP address on the same subnet furthest from the first hidden asset address, it is determined whether the domain name record of the IP address on the same subnet and the first hidden asset address belongs to the same primary domain. If so, the IP address on the same subnet is determined to be an associated IP address of the first hidden asset address. The above steps are repeated until all IP addresses on the same subnet are determined, resulting in multiple associated IP addresses, and all associated IP addresses are determined to be the second hidden asset address.

[0117] S1064: Identify all IP addresses on the same subnet with domain name records in the local area network as the second hidden asset addresses.

[0118] To facilitate understanding of this solution by those skilled in the art, the specific implementation process of step S106 provided in the embodiments of this application is explained more clearly and completely below: The IP address of the first hidden asset address is 10.10.10.10. Assuming that the first hidden asset address is running in a standard Class C network, the address range of a Class C network is 0 to 255. Therefore, the IP addresses in the range of 10.10.10.1 to 10.10.10.254 constitute a complete Class C network. This method will perform rDNS queries on all IP addresses in the range of 10.10.10.1 to 10.10.10.254 to obtain the domain name information corresponding to these IP addresses and determine whether the domain name record of 10.10.10.10 can be obtained.

[0119] If the rDNS query returns a domain name record for 10.10.10.10, and also retrieves domain name records for three other IP addresses on the same subnet: 10.10.10.20, 10.10.10.25, and 10.10.10.31, then the query will first determine whether the domain name of the IP address on the same subnet, 10.10.10.31, which is furthest from the first hidden asset address 10.10.10.10, belongs to the same main domain as the first hidden asset address 10.10.10.10 (hide.main.xyz). If they belong to the same main domain (e.g., the domain of 10.10.10.31 is show.main.xyz), then the IP address in the same subnet is determined to be an associated IP address. If they belong to different main domains (e.g., the domain of 10.10.10.31 is show.notme.xyz), then find the next IP address that is furthest from the first hidden asset address 10.10.10.10, i.e., 10.10.10.25. Repeat the above steps until all IP addresses in the same subnet are identified, resulting in multiple associated IP addresses. All associated IP addresses are then identified as the second hidden asset address.

[0120] If the rDNS query returns no domain name record for 10.10.10.10, but does return domain name records for three IP addresses on the same subnet: 10.10.10.20, 10.10.10.25, and 10.10.10.31, then all IP addresses on the same subnet are identified as the second hidden asset addresses.

[0121] In this embodiment, step S106 above, by querying and confirming the first hidden asset address and its associated IP address, yields multiple second hidden asset addresses, effectively expanding the number of hidden assets and improving the ability to identify potential hidden assets in the network. Utilizing rDNS service to query domain name records can identify other IP addresses sharing the same main domain name as the hidden assets, helping to promptly discover potential security risks and thus improving overall network security. Furthermore, by judging the domain name records of IP addresses within the same subnet and those of the hidden assets one by one, the false positive rate of hidden assets is reduced, achieving systematic hidden asset management. Ultimately, this method not only optimizes resource allocation, enabling enterprises to focus on monitoring and protecting genuine hidden assets, but also provides a clear asset view for subsequent security audits and compliance management.

[0122] In step S107 above, the hidden asset address is determined by combining the first hidden asset address and the second hidden asset address.

[0123] In this embodiment of the application, after obtaining the determined hidden asset address, the method may further include step S109, which specifically includes: extracting multiple access records corresponding to each device in the hierarchical organization within the second preset time period, re-executing the above steps S101-S106 to obtain the determined hidden asset address, querying the number of determined hidden asset addresses that appear simultaneously in the first preset time period and the second preset time period, and calculating the number of hidden assets based on the following formula 1:

[0124]

[0125] In the formula, H represents the number of identified hidden asset addresses in the first preset time period, K represents the number of identified hidden asset addresses in the second preset time period, and J represents the number of identified hidden asset addresses that appear in both the first and second preset time periods, with H>J and K>J.

[0126] The second preset time period can be set based on the first preset time period set in step S101, and the first and second preset time periods must be continuous and of equal length. For example, if the first preset time period is from 00:00 on October 1, 2024 to 24:00 on October 7, 2024, then the second preset time period could be from 00:00 on October 8, 2024 to 24:00 on October 14, 2024.

[0127] In this embodiment, step S109, by repeatedly executing the process of determining the number of hidden assets within two consecutive preset time periods of equal length, effectively verifies the authenticity and continuity of hidden assets, reducing the possibility of misjudgment. Simultaneously, this method can dynamically monitor changes in hidden assets, ensuring the accuracy and timeliness of the identification results. Only hidden asset addresses that appear in both time periods are considered genuinely existing hidden assets. This step not only improves the accuracy of hidden asset identification but also provides a reliable basis for enterprise network security management and resource scheduling.

[0128] To facilitate understanding of this solution by those skilled in the art, the specific implementation process of the hierarchical organization hidden asset quantity estimation method provided in the embodiments of this application is described more clearly and completely below: Refer to Figure 2The diagram illustrates the process. First, a PC desktop tool submits access records to the asset detection system. This PC desktop tool is the network access data logging tool mentioned above. Then, the asset detection system performs its investigation based on these records. As shown in the diagram, the asset detection system can detect normal asset B using conventional methods, but it cannot identify the hidden asset A protected by a firewall. When employees within the organization access and maintain asset A routinely, the network access data logging tool installed on their devices records and submits their access records. The asset detection system can then determine the IP address of asset A and confirm that asset A is protected by a firewall.

[0129] In this embodiment, the asset detection system can distinguish between offline assets and protected unresponsive assets. Offline assets will directly show "target inaccessible" during the detection process, while protected assets will show "blocked by certain nodes in the network path". This solves the problem of delayed asset information updates and the inability of higher-level organizations to accurately grasp whether an asset is protected or offline (device offline, asset replacement).

[0130] In this embodiment, the method offers several advantages: First, it can distinguish between fake assets caused by firewall auto-response by testing the target and its nearby random uncommon ports, thus identifying the illusion of a fake service caused by auto-response. Second, it can further differentiate between different service traffic passing through the same firewall by analyzing common ports recorded in network access data logging tools to infer the services provided by the hidden assets. Common ports include, for example, HTTP network services typically use port 443, while database services may use ports 3306 or 5432. These combined capabilities enhance the ability to identify and manage hidden assets in the network.

[0131] This method has been implemented in the network security platform of a certain group company. The asset detection system in the group company's network security platform has identified more than 1.6 million assets, of which more than 1.1 million assets have been verified as genuine and valid through comparison of access records by network access data recording tools, while more than 500,000 assets have been determined to be fake / offline assets through access record comparison.

[0132] Example 2

[0133] Based on the same inventive concept, embodiments of the present invention also provide a device for estimating the quantity of hidden assets in a hierarchical organization, referring to... Figure 3 As shown, the device includes:

[0134] The first extraction module 101 is used to extract multiple access records corresponding to each device in the hierarchical organization within a first preset time period.

[0135] The first filtering module 102 is used to compare multiple access records corresponding to each device with the obtained list of registered assets to obtain multiple suspected hidden addresses;

[0136] The second filtering module 103 is used to request a connection to each suspected hidden address, determine whether the suspected hidden address can be accessed; if yes, execute the third filtering module; if no, execute the fourth filtering module.

[0137] The third filtering module 104, when a suspected hidden address can be accessed, requests to connect to multiple random high-order ports of the adjacent IP addresses of the suspected hidden address. If the returned information is abnormal, the suspected hidden address is determined to be a hidden asset address.

[0138] The fourth filtering module 105 determines that the suspected hidden address is a hidden asset address when the suspected hidden address cannot be accessed.

[0139] The first query module 106 is used to query the domain name record in the local area network where the hidden asset address is located through rDNS service for each hidden asset address, obtain the query result, determine the associated IP address of the hidden asset address based on the query result, and determine the associated IP address as the hidden asset address.

[0140] The first calculation module 107 is used to extract multiple access records corresponding to each device in the hierarchical organization within the second preset time period, re-execute the above process of determining the hidden asset address, query the number of hidden asset addresses that appear simultaneously in the first preset time period and the second preset time period, and calculate the number of hidden assets.

[0141] Example 3

[0142] Based on the same inventive concept, embodiments of the present invention also provide a computer-readable storage medium storing a computer program / instruction thereon, which, when executed by a processor, implements the method for estimating the quantity of hierarchical organization hidden assets as described in Embodiment 1 above.

[0143] Example 4

[0144] Based on the same inventive concept, embodiments of the present invention also provide a computer program product, including a computer program / instruction, which, when executed by a processor, implements the method for estimating the quantity of hierarchical organization hidden assets as described in Embodiment 1 above.

[0145] Example 5

[0146] Based on the same inventive concept, this embodiment of the invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory. When the processor executes the computer program, it implements the method for estimating the quantity of hidden assets in a hierarchical organization as described in Embodiment 1 above.

[0147] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0148] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0149] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0150] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0151] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. A method for estimating the quantity of hidden assets in a hierarchical organization, characterized in that, include: Extract multiple access records corresponding to each device within the hierarchical organization during the first preset time period; Based on the multiple access records corresponding to each device, and compared with the obtained list of registered assets, multiple suspected hidden addresses were obtained. For each suspected hidden address, request a connection to the suspected hidden address and determine whether the suspected hidden address can be accessed; If so, then request to connect to multiple random high-order ports of the adjacent IP addresses of the suspected hidden address. If the returned information is abnormal, determine that the suspected hidden address is the first hidden asset address. If not, the suspected hidden address is determined to be the first hidden asset address; For each first hidden asset address, the domain name record is queried through rDNS service in the local area network where the first hidden asset address is located, the query result is obtained, and the associated IP address of the first hidden asset address is determined based on the query result, and the associated IP address is determined as the second hidden asset address. By combining the first hidden asset address and the second hidden asset address, the hidden asset address is determined.

2. The method according to claim 1, characterized in that, The request connects to multiple random high-order ports of the adjacent IP addresses of the suspected hidden address. If the returned information is abnormal, the suspected hidden address is identified as the first hidden asset address, including: Request connections to multiple random high-order ports of adjacent IP addresses of the suspected hidden address. If all random high-order ports can be connected, the suspected hidden address is identified as the first hidden asset address.

3. The method according to claim 2, characterized in that, After determining that the suspected hidden address is the address of the first hidden asset, the process also includes: Path exploration is performed on the first hidden asset address; During the path exploration process, if the exploration request terminates at an intermediate IP address, then that intermediate IP address is identified as the firewall of the first hidden asset address. During path exploration, if the exploration request does not receive a response on multiple consecutive intermediate IP addresses, the first intermediate IP address that does not receive a response is identified as the firewall of the first hidden asset address.

4. The method according to claim 1, characterized in that, For each first concealed asset address, the process of querying domain name records in the local area network where the first concealed asset address is located via rDNS service to obtain the query results, determining the associated IP address of the first concealed asset address based on the query results, and identifying the associated IP address as the second concealed asset address includes: For each first hidden asset address, the domain name record is queried through the rDNS service in the local area network to obtain the query result; Based on the query results, determine whether the domain name record of the first hidden asset address can be obtained; If so, then search the local area network for associated IP addresses belonging to the same main domain as the domain name record, and determine the associated IP address as the second hidden asset address; If not, then all subnet IP addresses with domain name records in the local area network will be identified as the second hidden asset addresses.

5. The method according to claim 1, characterized in that, The access records include IP addresses and ports; The process involves comparing multiple access records corresponding to each device with the obtained list of registered assets to obtain multiple suspected hidden addresses, including: Based on the multiple access records corresponding to each device, check whether there are multiple devices accessing the same IP address or port to obtain a duplicate access address dataset. The dataset of repeated access addresses was compared with the list of registered assets to identify several suspected hidden addresses.

6. The method according to claim 1, characterized in that, The access records include time information; After identifying multiple suspected hidden addresses, the process also includes: Based on the multiple access records corresponding to each device and the time information of each access record, access records outside of working hours are retrieved, and the IP address of the access record is identified as a suspected hidden address.

7. The method according to claim 1, characterized in that, After identifying the hidden real estate assets, the following is also included: Extract multiple access records corresponding to each device within the hierarchical organization during the second preset time period, re-execute the process to determine the hidden asset address, query the number of determined hidden asset addresses that appear simultaneously in both the first and second preset time periods, and calculate the number of hidden assets, including: Extract multiple access records corresponding to each device within the hierarchical organization during the second preset time period, re-execute the process to determine the hidden asset address, query the number of determined hidden asset addresses that appear simultaneously in both the first and second preset time periods, and calculate the number of determined hidden assets based on the following formula: In the formula, H represents the number of identified hidden asset addresses within the first preset time period, K represents the number of identified hidden asset addresses within the second preset time period, and J represents the number of identified hidden asset addresses that appear simultaneously in both the first and second preset time periods.

8. A device for estimating the quantity of hidden assets in a hierarchical organization, characterized in that, include: The first extraction module is used to extract multiple access records corresponding to each device in the hierarchical organization within a first preset time period. The first filtering module is used to compare multiple access records corresponding to each device with the obtained list of registered assets to obtain multiple suspected hidden addresses; The second filtering module is used to request a connection to each suspected hidden address and determine whether the suspected hidden address can be accessed. If yes, proceed to the third filtering module; if no, proceed to the fourth filtering module. The third filtering module requests multiple random high-order ports of the adjacent IP addresses of the suspected hidden address when the suspected hidden address can be accessed. If the returned information is abnormal, the suspected hidden address is determined to be the first hidden asset address. The fourth filtering module determines the suspected hidden address as the first hidden asset address when the suspected hidden address cannot be accessed. The first query module is used to query the domain name record in the local area network where the first hidden asset address is located through rDNS service for each first hidden asset address, obtain the query result, determine the associated IP address of the first hidden asset address based on the query result, and determine the associated IP address as the second hidden asset address. The first combining module is used to combine the first hidden asset address and the second hidden asset address to obtain the determined hidden asset address.

9. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When executed by a processor, the computer program / instruction implements the method for estimating the quantity of hidden assets in a hierarchical organization as described in any one of claims 1-7.

10. A computer program product comprising a computer program / instructions, characterized in that, When executed by a processor, the computer program / instruction implements the method for estimating the quantity of hidden assets in a hierarchical organization as described in any one of claims 1-7.

11. A computer device, comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the method for estimating the quantity of hidden assets in a hierarchical organization as described in any one of claims 1-7.