A covert asset discovery method and system based on traffic monitoring and luring
By monitoring network traffic to establish a communication behavior profile and generating probing commands, and mimicking asset communication patterns to send probe messages, this technology solves the problems of incomplete asset discovery and data incompatibility in existing technologies, enabling accurate identification of hidden assets and timely response to risks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- XI AN JIAOTONG UNIV
- Filing Date
- 2026-04-08
- Publication Date
- 2026-07-10
AI Technical Summary
Existing asset discovery technologies suffer from incomplete coverage, high false negative rates, and data incompatibility, making it difficult to achieve comprehensive and accurate identification of internal assets and timely response to risks, thus failing to meet the actual needs of cybersecurity management.
By monitoring network traffic to establish a communication behavior profile, combining it with Internet mapping data to screen hidden assets, generating probing commands, sending inducing probe messages by mimicking the communication patterns familiar to the assets, and updating the asset's survival status based on the probe response results.
Significantly enhances the comprehensive coverage and accurate identification capabilities of asset discovery, reduces the risk of underreporting, eliminates security blind spots, enables timely risk response, and meets the needs of cybersecurity management.
Smart Images

Figure CN122120006B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security management technology, and in particular relates to a method and system for discovering hidden assets based on traffic monitoring and probing. Background Technology
[0002] In the field of network security management, the comprehensive and accurate discovery and identification of internal assets such as servers, terminals, and network devices is the core foundation for building an effective security defense system, directly determining the effectiveness of subsequent security protection, risk management, and emergency response. As network architectures become increasingly complex, the number and form of internal assets are surging and diversifying, highlighting the growing importance of asset discovery technologies. Currently, mainstream asset discovery technologies are mainly divided into two categories: active scanning and passive monitoring. Active scanning technology sends a large number of standard probe packets into the network and detects asset information based on the feedback results; passive monitoring technology analyzes existing network communication traffic to infer the assets present within the network. Both technologies have their own application scenarios and together constitute the core technology system of current asset discovery.
[0003] Existing asset discovery technologies all have significant limitations, making it difficult to achieve comprehensive coverage and accurate identification of internal assets. Active scanning technologies exhibit distinctive detection characteristics, making them easily intercepted by network firewalls, intrusion detection systems, and other security devices, resulting in incomplete detection results and an inability to effectively discover "silent assets" configured not to respond to general requests. While passive monitoring technologies offer the advantage of stealth detection, they rely entirely on the asset's own proactive communication behavior, posing a serious risk of missed detections for devices that are inactive for extended periods or only respond under specific conditions. This leads to a widespread existence of unmanaged "silent assets" in the network, creating security blind spots. Furthermore, existing technical solutions are fragmented, with inconsistencies frequently existing between internal scanning data, asset management system records, and external internet mapping data, forming "data silos." This makes it difficult for security personnel to automatically distinguish between normal asset changes and potential risks, resulting in delayed risk response.
[0004] It is evident that existing asset discovery technologies suffer from incomplete coverage, high false negative rates, and data incompatibility, making it impossible to achieve comprehensive and accurate identification of internal assets and timely response to risks, thus failing to meet the actual needs of cybersecurity management. Summary of the Invention
[0005] This invention provides a method and system for discovering hidden assets based on traffic monitoring and probing. This method can effectively solve the problems of incomplete coverage, high false negative rate and data incompatibility in existing asset discovery technologies. It can achieve comprehensive and accurate identification of internal assets and timely response to risks, and can meet the actual needs of network security management.
[0006] To achieve the above objectives, the present invention adopts the following technical solution:
[0007] A method for discovering hidden assets based on traffic monitoring and probing, applied to a central analysis and management platform, includes:
[0008] Obtain communication behavior profiles for each network entity in the target network; wherein, the communication behavior profile for each network entity is obtained by monitoring network traffic, and the communication behavior profile is used to characterize the historical communication habits of the corresponding network entity.
[0009] Based on communication behavior profiles and pre-stored Internet mapping data, covert assets are screened from all network entities, and corresponding decoy instructions are generated for the covert assets. The decoy instructions are used to guide the probe nodes to imitate the communication patterns familiar to the covert assets, construct and send induced probe messages to the covert assets.
[0010] The asset survival status of the target network is updated based on the probe response results fed back by the probe nodes.
[0011] Furthermore, before obtaining the communication behavior profiles corresponding to each network entity in the target network, the process also includes:
[0012] Based on the monitored network traffic, a continuously updated communication behavior profile is created for each network entity. The specific steps are as follows:
[0013] The network traffic of the service port to be monitored is copied, and the copied network traffic is sent to the monitoring port of the probe node, so that the probe node can obtain the network traffic and perform the following steps based on the network traffic:
[0014] The original network packets in the network traffic are decoded and reassembled to obtain the reassembled session stream;
[0015] Communication behavior features are extracted from the reconstructed session stream and stored in a structured manner to establish a communication behavior profile for each network entity; wherein, the communication behavior features include basic communication profile, application layer identity fingerprint, and spatiotemporal activity pattern.
[0016] Furthermore, the process of filtering hidden assets from all network entities based on communication behavior profiling files and pre-stored Internet mapping data includes the execution of two parallel tasks, as detailed below:
[0017] Task 1: Automatically check the last communication time in the communication behavior profile of each network entity: If the last communication time of a network entity is more than a first preset time away from the current time, then mark this network entity as a long-term silent network entity; send test network connectivity data packets and connection establishment confirmation data packets to the long-term silent network entity respectively. If no response is received within a second preset time, then determine that this long-term silent network entity is an internal silent asset.
[0018] Task 2: Based on pre-stored Internet mapping data, query the asset information corresponding to all active public network entities in the communication behavior profiling file; compare the asset information with the communication behavior profiling file. If any of the following conditions exist, determine that the network entity is an external exposure surface and an unknown asset, as follows:
[0019] Scenario 1: The network entity was found to have an open port, but there were no communication records for this port in the communication behavior profile within the past third preset time period;
[0020] Scenario 2: The port service of this network entity is inconsistent with that in the communication behavior profile file;
[0021] Network entities that are identified as internal silent assets and external exposed or unknown assets are filtered out from all network entities to obtain hidden assets.
[0022] Furthermore, the generation of corresponding probe instructions for concealed assets includes:
[0023] For internally dormant assets or externally exposed and unknown assets, corresponding probe commands are generated. These probe commands include a target IP, a simulation protocol, and a feature payload. The target IP is used to specify the IP address of the concealed asset to be probed. The simulation protocol is used to specify the communication protocol for the probe. The feature payload is used to specify the feature string to be filled into the probe message. The feature string originates from the concealed asset's existing historical communication fingerprint in its communication behavior profiling file or from a most common fingerprint database. The most common fingerprint database is generated based on universal network traffic statistics.
[0024] The decoy command is sent to the probe node, so that the probe node can construct a decoy probe message based on the decoy command and send the decoy probe message to the hidden asset.
[0025] Furthermore, the detection node constructs an induced detection message according to the decoy command and sends the induced detection message to the concealed asset, including:
[0026] The decoy execution agent of the probe node receives decoy instructions issued by the central analysis and management platform in real time; wherein, the decoy execution agent runs inside the probe node in each region;
[0027] Query the communication behavior profile based on the target IP address in the probe instruction to obtain the historical communication characteristics of the hidden asset; select the corresponding protocol template in the communication behavior profile based on the simulation protocol in the probe instruction.
[0028] The historical communication characteristics and protocol templates of the concealed assets are populated with preset rules to generate inducible probe messages;
[0029] Send inductive probe messages to the corresponding covert assets.
[0030] Furthermore, in the step of filling the historical communication characteristics and protocol templates of the concealed assets with preset rules to generate an inducible probe message, the preset rules include rules for filling the network layer and transport layer and rules for filling the application layer payload.
[0031] The rules for filling the network layer and transport layer include:
[0032] Obtain the top-ranked IP address from the communication behavior profile of the target concealed asset, and use the top-ranked IP address as the source IP address of the induced probe message;
[0033] Use the target IP address in the probe command as the destination IP address; use the standard destination port corresponding to the emulation protocol in the probe command as the destination port;
[0034] Set the time to live and generate random TCP sequence numbers;
[0035] The rules for application layer load filling are as follows:
[0036] Check the feature payload in the probe command. If the feature payload is not empty, fill the corresponding placeholder in the protocol template with the complete string corresponding to the feature payload. Otherwise, extract the application layer identity fingerprint from the communication behavior profile file corresponding to the target covert asset. If there is no record in the communication behavior profile file corresponding to the target covert asset, select the default value of the corresponding protocol from the global common fingerprint library and fill it.
[0037] Furthermore, the update of the asset liveness status of the target network based on the decoy response results fed back by the probe nodes includes:
[0038] Obtain the decoy response results fed back by the probe node, wherein the decoy response results include a task execution result data packet;
[0039] If the field in the task execution result data packet is a responded field, then the asset survival status of the hidden asset in the target network will be updated to online.
[0040] If the field in the task execution result data packet is a non-responding field, then update the asset survival status of the hidden asset in the target network to offline status.
[0041] The asset's survival status is recorded in the communication behavior profile.
[0042] Furthermore, after updating the asset liveness status of the target network based on the decoy response results fed back by the probe nodes, the process also includes:
[0043] If the asset survival status of the hidden asset in the target network is online, the asset fingerprint information of the hidden asset is extracted from the task execution result data packet, and the application layer identity fingerprint in the communication behavior profile file corresponding to the hidden asset is updated according to the asset fingerprint information.
[0044] If the service port for this communication is discovered for the first time, the port number of this communication port will be added to the historical open port list of the communication behavior profile corresponding to the covert asset, so as to complete the update of the communication behavior profile corresponding to the covert asset.
[0045] Furthermore, after updating the communication behavior profile corresponding to the concealed asset, the process also includes:
[0046] Compare the old and new communication behavior profiles corresponding to the hidden assets to generate comparison results;
[0047] If the comparison result exceeds the preset warning rules, a security alarm event will be generated.
[0048] A covert asset discovery system based on traffic monitoring and decoy detection, applied to a central analysis and management platform, includes:
[0049] The data acquisition module is used to acquire the communication behavior profiles of each network entity in the target network; wherein, the communication behavior profile of each network entity is obtained by monitoring network traffic, and the communication behavior profile is used to characterize the historical communication habits of the corresponding network entity.
[0050] The filtering and generation module is used to filter hidden assets from all network entities based on communication behavior profiles and pre-stored Internet mapping data, and generate corresponding decoy instructions for the hidden assets; wherein, the decoy instructions are used to guide the probe nodes to imitate the communication patterns familiar to the hidden assets, construct and send induced probe messages to the hidden assets.
[0051] The status update module is used to update the asset survival status of the target network based on the probe response results fed back by the probe nodes.
[0052] Compared with the prior art, the present invention has the following beneficial effects:
[0053] This invention provides a method for discovering hidden assets based on traffic monitoring and probing. First, it monitors target network traffic to create communication behavior profiles for each network entity, characterizing its historical communication habits. Then, based on these profiles and pre-stored internet mapping data, it filters hidden assets and generates probing instructions to guide probe nodes to send induced probe messages mimicking the asset's familiar communication patterns. Finally, it updates the asset's liveness status based on the probing feedback. In this method, passive monitoring captures communication patterns non-intrusively, avoiding the interception risks of active scanning. Simultaneously, the probing behavior bypasses firewalls and intrusion detection systems by simulating legitimate behavior, directly probing dormant assets. Furthermore, it integrates internal monitoring data and external mapping data, solving the data fragmentation problem. This method significantly improves the comprehensive coverage and accurate identification capabilities of asset discovery, greatly reduces the risk of missed detections, effectively detects long-term inactive or dormant devices, eliminates security blind spots, and automates the differentiation between normal changes and potential threats through data interoperability, enabling timely risk response and meeting network security management needs. Attached Figure Description
[0054] Figure 1 This invention provides an implementation flowchart of a method for discovering hidden assets based on traffic monitoring and probing.
[0055] Figure 2 A flowchart illustrating the core steps of a method for discovering hidden assets based on traffic monitoring and probing, provided in an embodiment of the present invention;
[0056] Figure 3 This is a schematic diagram of the structure of a covert asset discovery system based on traffic monitoring and probing, provided as an embodiment of the present invention. Detailed Implementation
[0057] To further understand the content of this invention, the invention will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments are merely illustrative and not limiting of the invention.
[0058] The technical terms involved in this invention are explained as follows:
[0059] IP stands for Internet Protocol.
[0060] TCP stands for Transmission Control Protocol.
[0061] UDP: Short for User Datagram Protocol.
[0062] HTTP stands for Hypertext Transfer Protocol.
[0063] HTTPS stands for Hypertext Transfer Protocol Secure.
[0064] SMB stands for Server Message Block.
[0065] SSH stands for Secure Shell, a protocol that provides secure shell access to the environment.
[0066] RDP stands for Remote Desktop Protocol.
[0067] DNS: short for Domain Name System.
[0068] JSON stands for JavaScript Object Notation.
[0069] FOFA: Refers to the Cyberspace Assets Search Engine.
[0070] User-Agent: refers to the user agent.
[0071] SYN: Short for Synchronize, it is the first step in the TCP three-way handshake. The client sends a SYN packet to request the establishment of a connection.
[0072] TTL stands for Time To Live, which is the time to survive.
[0073] ICMP stands for Internet Control Message Protocol.
[0074] API stands for Application Programming Interface.
[0075] SMB Dialect: refers to a specific version of the Server Message Block Protocol.
[0076] libpcap library: is an open-source, cross-platform network packet capture library, short for Library for Packet Capture.
[0077] GUID: Globally Unique Identifier.
[0078] Cookie: A mechanism used on the Internet to store user information.
[0079] Version: An identifier used to identify different iterations or update states of software, hardware, documentation, or other products.
[0080] Host: The host computer.
[0081] Server: refers to the server itself.
[0082] VLAN: short for Virtual Local Area Network.
[0083] ICMP Echo Request packets are a message type in the ICMP protocol used to test the reachability of network devices and measure network latency.
[0084] TCP SYN packet: This is the first packet in the TCP connection establishment process, used to initiate a connection request.
[0085] RESTful API: short for Representational State Transfer Application Programming Interface, is a web application interface designed based on the REST architectural style.
[0086] WebSocket is a network protocol that enables full-duplex, bidirectional communication over a single TCP connection.
[0087] AES-GCM-256 is an encryption scheme that combines the AES-256 symmetric encryption algorithm with the Galois counter authentication encryption mode.
[0088] ID: full name Identification, refers to a unique identifier used to identify and distinguish different individuals or objects.
[0089] UUID stands for Universally Unique Identifier.
[0090] IPv4: short for Internet Protocol version 4, which is the fourth version of the Internet communication protocol.
[0091] As mentioned in the background section, existing methods for discovering hidden assets are fragmented, with internal scanning data, asset management system records, and external internet mapping data often inconsistent, creating "data silos." This makes it difficult for security personnel to automatically distinguish between normal asset changes and potential risks (for example, an internally unregistered device exposing a high-risk port on the public network), resulting in delayed responses.
[0092] To address the aforementioned issues, this embodiment provides a covert asset discovery method based on traffic monitoring and probing. This method can covertly and proactively detect dormant assets and intelligently integrate internal and external multi-source data to achieve continuous, accurate, and closed-loop discovery and monitoring of network assets, thereby completely eliminating asset blind spots and enhancing security situational awareness capabilities. This method aims to solve the problems of poor concealment, ineffectiveness against dormant assets, and fragmented multi-source data in traditional asset discovery techniques. The core concept of this method lies in the deep integration of passive traffic analysis, proactive probing, and external intelligence verification to form a self-learning, adaptive intelligent closed-loop system.
[0093] like Figure 1 As shown in the figure, this embodiment provides a method for discovering hidden assets based on traffic monitoring and probing, which is applied to a central analysis and management platform. The specific steps are as follows:
[0094] Obtain communication behavior profiles for each network entity in the target network; wherein, the communication behavior profile for each network entity is obtained by monitoring network traffic, and the communication behavior profile is used to characterize the historical communication habits of the corresponding network entity.
[0095] Based on communication behavior profiles and pre-stored Internet mapping data, covert assets are screened from all network entities, and corresponding decoy instructions are generated for the covert assets. The decoy instructions are used to guide the probe nodes to imitate the communication patterns familiar to the covert assets, construct and send induced probe messages to the covert assets.
[0096] The asset survival status of the target network is updated based on the probe response results fed back by the probe nodes.
[0097] The hidden asset discovery method based on traffic monitoring and probing provided in this embodiment is based on the following core idea: First, the method collects full traffic losslessly through bypass mirroring and performs in-depth analysis to establish a dynamically updated communication behavior profile for each network entity, accurately depicting the historical communication habits of the network entity. Then, based on the communication behavior profile and combined with comparison with Internet mapping data, the system intelligently identifies two types of targets: assets that have been dormant internally for a long time, and assets whose exposure on the Internet does not match their internal records (external exposure and unknown assets). For these targets, the system does not perform traditional brute-force scanning, but automatically generates highly customized probing instructions based on their historical behavior profile (communication behavior profile). The probing instructions guide the probe node to mimic the communication patterns familiar to the target, constructing and sending induced probe messages disguised as normal business or retransmitted data packets; this probing method can greatly reduce the probability of being identified by security devices. Finally, the system analyzes the probing response results, not only updating the asset liveness status of the target network, but also automatically detecting risks such as abnormal changes in asset fingerprints and exposure of unknown high-risk services, and generating accurate alarms.
[0098] The prediction method provided in this embodiment will be further explained below with reference to the accompanying drawings:
[0099] like Figure 1 As shown, this embodiment provides a method for discovering hidden assets based on traffic monitoring and probing, including:
[0100] Step 1: Network traffic monitoring and communication behavior profiling:
[0101] The core objective of this step is to capture, parse, and extract features from the raw communication packets in the target network environment to create a continuously updated communication behavior profile for each active network entity in the target network (primarily identified by its IP address); this profile serves as the data foundation for subsequent intelligent judgment and probing.
[0102] First, network traffic is collected. Port mirroring is configured on the core switch of the target network to copy the traffic of the service port (source port) that needs to be monitored and send it to the monitoring port (destination port) connected to the traffic collection probe (probe node). The traffic collection probe is a dedicated hardware device deployed in the network management area, whose network interface card receives the copy of the mirrored traffic.
[0103] After receiving the raw network packets, the traffic acquisition probe immediately parses and analyzes them locally, without relying on remote processing. This process consists of two steps:
[0104] 1. Protocol Decoding and Session Reassembly: Analysis software (e.g., developed based on the libpcap library) decodes the binary packets layer by layer, stripping the Ethernet frame header, identifying the IP protocol version, and parsing the TCP / UDP header. The system logically reassembles the packets into a complete session stream based on the "five-tuple"—source IP address, destination IP address, source port number, destination port number, and transport layer protocol.
[0105] 2. Communication Behavior Feature Extraction: For each source IP address, three types of features are extracted from the sessions it initiates and stored in a structured manner:
[0106] (1) Basic communication profile (five-tuple statistics): Record the 20 most frequently used destination IP addresses, the 10 most frequently used destination port numbers, and the 3 most commonly used transport layer protocols (such as TCP and UDP) of this IP, and count the number of sessions and the total number of bytes.
[0107] (2) Application Layer Identity Fingerprint: For common application protocols, specific identification fields are extracted from their message payloads. The specific extracted fields are shown in Table 1:
[0108] Table 1 lists the specific fields extracted from the message payload.
[0109]
[0110] It should be noted that Table 1 shows examples of common protocols, and the system supports expanding the recognizable protocol types by updating the parsing rule base.
[0111] (3) Spatiotemporal activity pattern: Record the hourly period during which the IP address communicates most frequently in the last 24 hours; calculate the average size of the data packets it sends (in bytes); if regular communication with the same target is detected with a period of more than 10 seconds and an error within ±1 second, record this heartbeat interval.
[0112] In this embodiment, the traffic acquisition probe maintains a communication behavior profile for each active IP address (active network entity). This profile is a JSON structured data file with the IP address as a unique index, containing all the aforementioned characteristics. Every 5 minutes, the traffic acquisition probe uploads all newly added or updated communication behavior profile data from the past 5 minutes to the central analysis and management platform deployed in the data center via the management VLAN network using a proprietary binary protocol based on TCP.
[0113] Step 2: Identification of concealed targets (concealed assets) and generation of decoy strategies:
[0114] This step is executed on the central analysis and management platform. The strategy engine of the central analysis and management platform performs scanning and analysis based on the network-wide "communication behavior profile files" gathered in step one, and outputs probing commands that need to be implemented.
[0115] First, asset status comparison and initial target screening are performed. The strategy engine combines internal files (communication behavior profiling files) and external data (Internet mapping data) to execute the following two parallel scanning tasks to discover two types of suspicious targets:
[0116] 1. Internal Silent Asset Discovery: The policy engine automatically executes every 24 hours, checking the "Last Communication Time" field in each IP address file. If an IP address's last communication time is more than 168 hours ago, it is immediately marked as a "long-term silent IP." The policy engine immediately sends an ICMP Echo Request packet and a TCP SYN packet to each of these IPs using the platform's built-in scanning module (the destination port is the IP's historically most frequently used port; if no record is found, port 80 is used). If no response is received within 3 seconds, the IP is determined to be a "silent asset requiring probing," meaning the network entity is identified as an internal silent asset.
[0117] 2. External Exposure Surface and Unknown Asset Discovery. The policy engine executes automatically every 12 hours. It compiles a list of all active public IP addresses (excluding the private address ranges 10.0.0.0 / 8, 172.16.0.0 / 12, and 192.168.0.0 / 16) from the communication behavior profiling file. Then, it queries the asset information of these IPs on the internet in batches by calling the public RESTful API provided by the FOFA platform. The API returns data including the domain name associated with the IP, open ports, and service banners. The policy engine compares the FOFA query results with the internal files. If any of the following conditions are found, the IP or newly discovered port is marked as an "unknown / exposed asset requiring probing," i.e., an external exposure surface and unknown asset:
[0118] (1) Unknown port: FOFA shows that a certain IP has opened a certain port, but the internal files have no communication records for this port in the past 7 days.
[0119] (2) Unknown service: FOFA shows that a certain IP has a port service that is inconsistent with the internal file. For example, the service banner on port 22 is SSH-2.0-OpenSSH_8.1, but there is no corresponding SSH fingerprint record for port 22 of this IP in the internal file.
[0120] For example, for each type of target IP discovered by the above tasks, the policy engine generates a structured probe instruction, which mainly includes the following three defined parts:
[0121] 1. Target IP: Clearly specify the target IP address that needs to be probed.
[0122] 2. Emulation Protocol: Specifies which protocol to emulate for probing. The selection logic is:
[0123] For "silent assets requiring probing," the most recently successfully recorded protocol is selected from the application layer identity fingerprint of the IP's own historical archives as the emulation protocol. If no historical fingerprint is available, the HTTP protocol template is used by default.
[0124] For "unknown / exposed assets that need to be probed", the determination is based on the source of discovery:
[0125] (1) If triggered by a new port discovered in Task 2, the general protocol corresponding to the port is used directly (port 22 corresponds to SSH, port 3389 corresponds to RDP, port 445 corresponds to SMB, port 53 corresponds to DNS, and ports 80 / 443 correspond to HTTP / HTTPS).
[0126] (2) If triggered by a new service banner discovered in Task 2, the protocol indicated by the banner shall be used (SSH-2.0 corresponds to SSH, RDP corresponds to RDP). If there is no common protocol corresponding to the port, the HTTP protocol template shall be used by default.
[0127] 3. Feature Payload: The instruction explicitly specifies the specific feature string to be filled into the probe data packet. The selection of this string comes from the following sources:
[0128] For targets with their own historical communication fingerprints (most "silent assets"), the corresponding protocol fingerprint recorded in their communication behavior profile is used directly. For example, if an HTTP template is used for an IP, the User-Agent recorded in its communication behavior profile is filled in: Mozilla / 5.0 (Windows NT 10.0; Win64; x64)...
[0129] For targets without their own historical communication fingerprints (mainly referring to newly discovered ports or services in the "unknown / exposed assets"), a pre-built, static "most common fingerprint database" generated from general network traffic is used. For example, for the SSH protocol, the most frequently occurring string "SSH-2.0-OpenSSH_9.6p1 version" is used.
[0130] In this embodiment, the generated probing instructions are placed into an in-memory task queue maintained by the central analysis and management platform. The "probing execution agent," deployed on traffic collection probes in various regions, receives task instructions pushed by the platform in real time from target IPs belonging to its managed network segment via a persistent, encrypted WebSocket long connection (all instructions and response data are transmitted using AES-GCM-256 encryption. The key is dynamically rotated using a short-term token issued by the platform, updated every 30 minutes).
[0131] Step 3: Construction and delivery of the guided detection package:
[0132] The decoy command generated in step two is issued by the central analysis and management platform and received by the decoy execution agent. The decoy execution agent runs inside the traffic acquisition probes in each region and is responsible for the final construction, sending and initial listening of the decoy probe packet.
[0133] The probe execution agent receives probe commands in real time through a long-lived WebSocket connection established with its central analysis and management platform. Upon receiving a probe command, the probe execution agent immediately performs two resource preparations locally:
[0134] 1. Load Protocol Templates: The proxy accesses the local "protocol template library". This library is a configuration file stored in JSON format, which defines six binary structure templates for protocol messages by default, including byte offsets, default values, and dynamically populated "placeholders" for each field. The definitions of these six templates and their key populated fields are shown in Table 2:
[0135] Table 2 lists the six templates and their corresponding key fillable fields.
[0136]
[0137] It should be noted that, in addition to the templates mentioned above, the system supports updating the probe agent's configuration file to insert new protocol templates to expand the detection capabilities.
[0138] 2. Query Feature Data: Based on the "target IP" in the probe command, the probe execution agent queries the locally stored "Communication Behavior Profile" database (continuously updated by step one) to obtain the historical communication characteristics of the target IP. Simultaneously, the agent maintains a "Global Common Fingerprint Database," which stores the most common fingerprint string for each protocol, statistically derived from historical traffic, as the default value when there are no historical records.
[0139] Based on the "Emulation Protocol" field specified in the probe instruction, the agent selects the corresponding protocol template from the template library and fills it in according to the following defined rules to generate a complete network packet to be sent:
[0140] 1. Network layer and transport layer padding:
[0141] Source IP Address: The probe execution agent selects the top-ranked IP address from the target IP's historical archive of "20 Most Frequently Communicating Destination IP Addresses" as the source IP for this probe packet. If the list is empty, it uses one of the probe's own idle IP addresses.
[0142] Destination IP and Port: Use the "target IP" specified in the command and the standard destination port corresponding to the protocol. Common standard ports for these protocols are: HTTP 80, HTTPS 443, SSH 22, SMB 445, RDP 3389, and DNS 53. For basic TCP SYN probes or probes targeting non-standard ports, use the target port explicitly specified in the command or policy.
[0143] TTL (Time to Live): Set to 64 to simulate the typical hop count in an internal network. This value has no unit and is an 8-bit field in the IP header that represents the maximum number of router hops a data packet is allowed to traverse in the network. 64 is a typical initial value for LAN devices.
[0144] TCP sequence number: Generate a 32-bit random integer. The generation method is: take the lower 32 bits of the current system timestamp (in seconds), and XOR it with a fixed random seed.
[0145] 2. Application layer load filling:
[0146] (1) Prioritize the use of instruction payloads. Probe execution agent checks the "feature payload" field in the instruction. If the field is not empty, the complete string provided by the field is used to fill the corresponding placeholder in the protocol template.
[0147] (2) Next, use historical fingerprints. If the “feature payload” field is empty, extract it from the “application layer identity fingerprint” of the target historical file queried locally, depending on the protocol type.
[0148] (3) Finally, use the global fingerprint. If there is no record in the file, the default value of the corresponding protocol is taken from the "Global Common Fingerprint Library" to fill it.
[0149] After the probe message is constructed, the probe execution agent sends the probe message (probe packet) to the target through the AF_PACKET raw socket (an interface provided by the Linux kernel that allows applications to directly read and write link layer frames).
[0150] Sending control: To avoid being identified as a scan storm, the probe execution agent forcibly inserts a fixed delay of 500 milliseconds between two sending actions to reduce the sending rate.
[0151] Listening and Capturing: After sending, the probe execution agent immediately starts a packet capture session on the same network card for 5 seconds, setting the Berkeley packet filtering rule to "capture all packets from the target IP address and whose destination port is the source port of the local machine".
[0152] Initial Response Assessment and Encapsulation: Within a 5-second listening window, if any matching packet is captured, the probe execution agent immediately marks it as "response received" and encapsulates the key network layer and transport layer fields of the response into a "response packet." Fields include: source IP, destination IP, source port, destination port, transport layer protocol, TCP flags, or ICMP type / code. If the response contains application layer data, the first 64 bytes of that application layer data are also recorded. If no packet is captured within 5 seconds, it is marked as "no response."
[0153] In this embodiment, regardless of whether a response is received, the probe execution agent will report the task execution result (probe response result) to the central analysis and management platform in real time via a separate HTTPS API interface after the task is completed (i.e., after sending and listening for 5 seconds). The reported data structure is a JSON object, and the meaning, data type, and value rules of each field are strictly defined as follows:
[0154] 1. task_id: String type. This refers to the unique identifier corresponding to this probing task. This ID is created by the central analysis and management platform when generating the probing command and is issued along with the command. Its value is a globally unique string conforming to the UUID version 4 standard.
[0155] 2. target_ip: String type. This refers to the Internet Protocol address of the target device targeted by this probing mission, directly derived from the "Target IP" field in the probing command. Its value is a standard IPv4 address dotted decimal string.
[0156] 3. status: String type. Represents the final status of whether the probing mission received a valid network response from the target IP. This field has only two definite enumeration values: responded (indicating that a response packet conforming to the filtering rules from the target IP was successfully captured within a 5-second listening window after sending the probing packet) or no_response (indicating that no response packet conforming to the filtering rules from the target IP was captured within a 5-second listening window).
[0157] 4. `response_raw_packet`: Object type or null. When the status is "responded", this field is an object used to encapsulate key parsing information of the response message; when the status is "no_response", this field is null (i.e., if a response is received, this field contains a binary digest or key fields of the response message; if there is no response, this field is empty). When this field is an object, it will contain the following subfields:
[0158] (1) src_ip (string type): The source IP address of the response message, i.e. the destination IP.
[0159] (2) dst_port (integer type): The destination port number of the response message, i.e. the source port used when the probe execution agent sends the message.
[0160] (3) protocol (string type): the transport layer protocol of the response message, with a value of "TCP", "UDP" or "ICMP".
[0161] (4) flags_or_type (string type): Control flags for the transport or network layer. For TCP responses, this records the TCP flag combination; for ICMP responses, this records the ICMP type and code.
[0162] (5) app_data_preview (string type or null): If the response message contains an application layer payload, this field records the first 128 bytes of the payload as a string encoded by Base64 (an encoding scheme based on 64 printable characters); if it does not contain an application layer payload, this field is null.
[0163] 5. timestamp: String type. Represents the absolute timestamp of the completion of this probing task, taken as the system time 5 seconds after the probing agent ended its listening.
[0164] Step 4: Response Analysis and Asset Status Update
[0165] This step is the feedback phase, completing the asset discovery loop. This step is implemented on the central analysis and management platform. After receiving the probing responses from each probe, the central analysis and management platform analyzes them, updates the communication behavior profiling database accordingly, and triggers alarms.
[0166] The central analysis and management platform continuously monitors the HTTPS API service endpoint, receives and parses the JSON-formatted "task execution result" data packet reported in step three in real time, and makes the final determination of the asset's survival status based on the status field, according to the following rules:
[0167] Rule 1: Asset survival status update.
[0168] If the status field value of the result is "responded", then the asset corresponding to the target_ip (target IP address) is immediately determined to be in an "online" state.
[0169] If the status field value is "no_response", then the asset is considered to be in an "offline" state.
[0170] 2. Rule 2: Extraction of asset fingerprint information.
[0171] When a hidden asset is determined to be "online", the central analysis and management platform will further parse the response_details object in the "task execution result" data packet.
[0172] Based on the protocol used in this probing mission (which can be obtained through a related query in the mission history), keyword matching was performed on the first 128 bytes of the Base64 decoded application layer data (response_details.app_data_preview field) to extract asset fingerprints. The extraction rules are as follows:
[0173] 1. If the protocol is HTTP / HTTPS, search for the Server: response header in the data and extract the server software identification string that follows it.
[0174] 2. If the protocol is SSH, the first 32 bytes after the application layer data is decoded are directly recorded as the SSH server version fingerprint.
[0175] 3. If the protocol is SMB, search for the byte sequence related to SMB Dialect in the application layer data, parse and record the negotiated SMB protocol version number.
[0176] 4. If the protocol is RDP, search for the RDP protocol negotiation response in the application layer data and extract its version or identification information.
[0177] 5. If the protocol is DNS, then resolve the DNS response message and attempt to extract the server software identifier contained therein.
[0178] Based on the judgment and extraction results, the platform performs an update operation on the communication behavior profiling database, forming a new profiling version. The update logic is as follows: Locate the communication behavior profiling file corresponding to the target_ip. Update the "Last Communication Time" field in the IP communication behavior profiling file to the timestamp byte in the result data packet. Update the "Asset Liveness Status" field in the IP communication behavior profiling file to the result of this judgment ("Online" or "Offline"). If this probing task discovers a new service fingerprint, add the fingerprint information to the "Application Layer Identity Fingerprint" object of the IP communication behavior profiling file. If the service port is discovered for the first time, add the port number to the "Historically Open Ports" list of the IP communication behavior profiling file.
[0179] After the communication behavior profile is updated, the central analysis and management platform immediately compares the old and new versions of the communication behavior profile and generates a security alert event based on preset, deterministic rules. The rules are as follows:
[0180] Rule 1: Alert for Long-Term Offline Assets Returning to Online Status. If an asset's "Asset Liveness Status" changes from "Offline" to "Online," and its last communication time is more than 720 hours from the current time, a "High-Priority Alert" is generated, stating "[IP Address] was detected as online after being silent for more than 30 days." If the last communication time is less than 720 hours but greater than or equal to 168 hours, a "Medium-Priority Alert" is generated, stating "[Target IP] was detected as online after being silent for more than 7 days." If the last communication time is less than 168 hours, a "Low-Priority Alert" is generated, stating "[Target IP] Online Status Changed."
[0181] 2. Rule Two: Alert for Unregistered High-Risk Services. If any of the following service fingerprints are recorded for the first time in an asset's file:
[0182] SSH service fingerprint (port 22);
[0183] Remote Desktop Protocol (RDP) service fingerprint (port 3389);
[0184] Server Message Block (SMB) protocol version (port 445);
[0185] It should be noted that services such as HTTP / HTTPS and DNS are usually more common. Their first detection can be set to a lower priority alert or simply logged according to the organization's policy, and they are not within the scope of this default high-risk alert rule.
[0186] If the IP address is not marked as an authorized management device, a "high priority alarm" will be generated, with the alarm content being "[target IP] discovered an unregistered high-risk service [service name] on port [port number]".
[0187] 3. Rule Three: Asset Service Fingerprint Change Alert. If an existing service in the asset file experiences an unexpected change to the specific fingerprint string in its "Application Layer Identity Fingerprint," and the new fingerprint is not in the asset's baseline database, a "Medium Priority Alert" will be generated. The content will be: "The asset service fingerprint of [Target IP] has changed from [Old Fingerprint] to [New Fingerprint]."
[0188] The platform records the success status of each probe attempt (based on the status field) to optimize subsequent probes. The optimization logic is as follows: the system maintains a "recent success rate" metric for each type of protocol targeting "long-term silent IPs." This metric calculates the percentage of responses received when using this protocol to probe such IPs within the past 24 hours. When the policy engine generates probe instructions in step two, it will prioritize protocol templates with higher "recent success rates."
[0189] Therefore, this embodiment provides a method for discovering covert assets based on traffic monitoring and probing, which has the following advantages compared with existing covert asset discovery methods:
[0190] First, it achieves highly covert active detection: by using the target's own historical communication characteristics to construct detection packets, the detection behavior is integrated into the background traffic, effectively avoiding detection by traditional active scanning.
[0191] Secondly, it can effectively discover dormant assets: by identifying IPs with no traffic for a long time through "behavioral profiling" and using an acceptable method for inducing detection, it solves the fundamental problem that passive monitoring cannot discover inactive assets.
[0192] Third, intelligent judgment through the integration of internal and external data: the internal traffic analysis results are automatically compared with the external cyberspace mapping data to proactively identify assets that are inconsistent with the internal data, thus achieving closed-loop management of asset exposure.
[0193] Fourth, it achieves an automated risk closed loop: from asset discovery and probing verification to status updates and risk alerts, the entire process requires no manual intervention, forming a continuously operating self-optimizing closed loop, which significantly improves the real-time performance and security of asset management.
[0194] like Figure 3 As shown, this embodiment also provides a covert asset discovery system based on traffic monitoring and probing, including:
[0195] The data acquisition module is used to acquire the communication behavior profiles of each network entity in the target network; wherein, the communication behavior profile of each network entity is obtained by monitoring network traffic, and the communication behavior profile is used to characterize the historical communication habits of the corresponding network entity.
[0196] The filtering and generation module is used to filter hidden assets from all network entities based on communication behavior profiles and pre-stored Internet mapping data, and generate corresponding decoy instructions for the hidden assets; wherein, the decoy instructions are used to guide the probe nodes to imitate the communication patterns familiar to the hidden assets, construct and send induced probe messages to the hidden assets.
[0197] The status update module is used to update the asset survival status of the target network based on the probe response results fed back by the probe nodes.
[0198] The present invention also provides a covert asset discovery device based on traffic monitoring and probing, comprising: a memory for storing a computer program; and a processor for executing the computer program to implement the steps of the covert asset discovery method based on traffic monitoring and probing.
[0199] The present invention also provides a computer program product, including a computer program / instruction that, when executed by a processor, implements the steps of the covert asset discovery method based on traffic monitoring and probing.
[0200] When the processor executes the computer program, it implements the aforementioned steps for discovering covert assets based on traffic monitoring and probing, such as: acquiring communication behavior profiles corresponding to each network entity in the target network; wherein, the communication behavior profile of each network entity is established by monitoring network traffic, and the communication behavior profile is used to characterize the historical communication habits of the corresponding network entity; based on the communication behavior profile and pre-stored Internet mapping data, covert assets are screened from all network entities, and corresponding probing instructions are generated for the covert assets; wherein, the probing instructions are used to guide the probe nodes to imitate the communication patterns familiar to the covert assets, construct and send induced probe messages to the covert assets; and the asset survival status of the target network is updated based on the probing response results fed back by the probe nodes.
[0201] For example, the computer program can be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of performing preset functions, wherein the instruction segments describe the execution process of the computer program in the covert asset discovery device based on traffic monitoring and probing. For example, the computer program can be divided into a data acquisition module, a filtering and generation module, and a status update module; wherein:
[0202] The data acquisition module is used to acquire the communication behavior profiles of each network entity in the target network; wherein, the communication behavior profile of each network entity is obtained by monitoring network traffic, and the communication behavior profile is used to characterize the historical communication habits of the corresponding network entity.
[0203] The filtering and generation module is used to filter hidden assets from all network entities based on communication behavior profiles and pre-stored Internet mapping data, and generate corresponding decoy instructions for the hidden assets; wherein, the decoy instructions are used to guide the probe nodes to imitate the communication patterns familiar to the hidden assets, construct and send induced probe messages to the hidden assets.
[0204] The status update module is used to update the asset survival status of the target network based on the probe response results fed back by the probe nodes.
[0205] The covert asset discovery device based on traffic monitoring and decoy detection can be a computing device such as a desktop computer, laptop, handheld computer, or cloud server. This device may include, but is not limited to, processors and memory. Those skilled in the art will understand that the above examples of covert asset discovery devices based on traffic monitoring and decoy detection do not constitute a limitation on such devices. The device may include more components than described above, or combine certain components, or use different components. For example, the covert asset discovery device based on traffic monitoring and decoy detection may also include input / output devices, network access devices, buses, etc.
[0206] The processor referred to can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor, or any conventional processor. The processor is the control center of the traffic monitoring and decoy-based covert asset discovery device, connecting all parts of the device via various interfaces and lines.
[0207] The memory can be used to store the computer program and / or modules. The processor implements various functions of the covert asset discovery device based on traffic monitoring and probing by running or executing the computer program and / or modules stored in the memory and calling the data stored in the memory.
[0208] The memory may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a function (such as sound playback, image playback, etc.). The data storage area may store data created based on the use of the mobile phone (such as audio data, phonebook, etc.). Furthermore, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disks, RAM, plug-in hard disks, smart media cards (SMC), secure digital cards (SD cards), flash cards, at least one disk storage device, flash memory device, or other volatile solid-state storage devices.
[0209] The present invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the aforementioned method for discovering covert assets based on traffic monitoring and probing.
[0210] If the modules / units of the concealed asset discovery system based on traffic monitoring and probing are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium.
[0211] Based on this understanding, the present invention can implement all or part of the processes in the above-mentioned method for discovering hidden assets based on traffic monitoring and decoys. This can also be accomplished by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium. When executed by a processor, the computer program can implement the steps of the above-mentioned method for discovering hidden assets based on traffic monitoring and decoys. The computer program includes computer program code, which can be in the form of source code, object code, executable file, or a preset intermediate form, etc.
[0212] The computer-readable storage medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0213] It should be noted that the content contained in the computer-readable storage medium may be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable storage medium does not include electrical carrier signals and telecommunication signals.
[0214] The above embodiments are merely one of the implementation methods for achieving the technical solution of the present invention. The scope of protection claimed by the present invention is not limited to this embodiment, but also includes any variations, substitutions and other implementation methods that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention.
[0215] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the present invention.
Claims
1. A method for discovering hidden assets based on traffic monitoring and probing, applied to a central analysis and management platform, characterized in that, include: Obtain communication behavior profiles for each network entity in the target network; wherein, the communication behavior profile for each network entity is obtained by monitoring network traffic, and the communication behavior profile is used to characterize the historical communication habits of the corresponding network entity. Based on communication behavior profiles and pre-stored Internet mapping data, covert assets are screened from all network entities, and corresponding decoy instructions are generated for the covert assets. The decoy instructions are used to guide the probe nodes to imitate the communication patterns familiar to the covert assets, construct and send induced probe messages to the covert assets. The asset survival status of the target network is updated based on the probing response results fed back by the probe nodes; The process of filtering hidden assets from all network entities based on communication behavior profiling files and pre-stored Internet mapping data includes the execution of two parallel tasks, as detailed below: Task 1: Automatically check the last communication time in the communication behavior profile of each network entity: If the last communication time of a network entity is more than a first preset time away from the current time, then mark this network entity as a long-term silent network entity; send test network connectivity data packets and connection establishment confirmation data packets to the long-term silent network entity respectively. If no response is received within a second preset time, then determine that this long-term silent network entity is an internal silent asset. Task 2: Based on pre-stored Internet mapping data, query the asset information corresponding to all active public network entities in the communication behavior profiling file; compare the asset information with the communication behavior profiling file. If any of the following conditions exist, determine that the network entity is an external exposure surface and an unknown asset, as follows: Scenario 1: The network entity was found to have an open port, but there were no communication records for this port in the communication behavior profile within the past third preset time period; Scenario 2: The port service of this network entity is inconsistent with that in the communication behavior profile file; Network entities that are identified as internal silent assets and external exposed or unknown assets are filtered out from all network entities to obtain hidden assets; The generation of corresponding decoy instructions for concealed assets includes: For internally dormant assets or externally exposed and unknown assets, corresponding probe commands are generated. These probe commands include a target IP, a simulation protocol, and a feature payload. The target IP is used to specify the IP address of the hidden asset to be probed. The simulation protocol is used to specify the communication protocol for the probe. The feature payload is used to specify the feature string to be filled into the probe message. The feature string originates from the hidden asset's existing historical communication fingerprint in its communication behavior profile or from a global common fingerprint database. The global common fingerprint database is generated based on universal network traffic statistics and serves as a default value when there is no historical record. The decoy command is sent to the probe node, so that the probe node can construct a decoy probe message based on the decoy command and send the decoy probe message to the hidden asset.
2. The method for discovering hidden assets based on traffic monitoring and probing according to claim 1, characterized in that, Before obtaining the communication behavior profiles corresponding to each network entity in the target network, the process also includes: Based on the monitored network traffic, a continuously updated communication behavior profile is created for each network entity. The specific steps are as follows: The network traffic of the service port to be monitored is copied, and the copied network traffic is sent to the monitoring port of the probe node, so that the probe node can obtain the network traffic and perform the following steps based on the network traffic: The original network packets in the network traffic are decoded and reassembled to obtain the reassembled session stream; Communication behavior features are extracted from the reconstructed session stream and stored in a structured manner to establish a communication behavior profile for each network entity; wherein, the communication behavior features include basic communication profile, application layer identity fingerprint, and spatiotemporal activity pattern.
3. The method for discovering hidden assets based on traffic monitoring and probing according to claim 1, characterized in that, The detection node constructs a induced detection message according to the decoy command and sends the induced detection message to the concealed asset, including: The decoy execution agent of the probe node receives decoy instructions issued by the central analysis and management platform in real time; wherein, the decoy execution agent runs inside the probe node in each region; Query the communication behavior profile based on the target IP address in the probe instruction to obtain the historical communication characteristics of the hidden asset; select the corresponding protocol template in the communication behavior profile based on the simulation protocol in the probe instruction. The historical communication characteristics and protocol templates of the concealed assets are populated with preset rules to generate inducible probe messages; Send inductive probe messages to the corresponding covert assets.
4. The method for discovering concealed assets based on traffic monitoring and probing according to claim 3, characterized in that, In the step of filling the historical communication characteristics and protocol templates of the concealed assets with preset rules to generate an inducible probe message, the preset rules include rules for filling the network layer and transport layer and rules for filling the application layer payload. The rules for filling the network layer and transport layer include: Obtain the top-ranked IP address from the communication behavior profile of the target concealed asset, and use the top-ranked IP address as the source IP address of the induced probe message; Use the target IP address in the probe command as the destination IP address; use the standard destination port corresponding to the emulation protocol in the probe command as the destination port; Set the time to live and generate random TCP sequence numbers; The rules for application layer load filling are as follows: Check the feature payload in the probe command. If the feature payload is not empty, fill the corresponding placeholder in the protocol template with the complete string corresponding to the feature payload. Otherwise, extract the application layer identity fingerprint from the communication behavior profile file corresponding to the target covert asset. If there is no record in the communication behavior profile file corresponding to the target covert asset, select the default value of the corresponding protocol from the global common fingerprint library and fill it.
5. The method for discovering concealed assets based on traffic monitoring and probing according to claim 1, characterized in that, The update of the asset liveness status of the target network based on the probing response results fed back by the probe nodes includes: Obtain the decoy response results fed back by the probe node, wherein the decoy response results include a task execution result data packet; If the field in the task execution result data packet is a responded field, then the asset survival status of the hidden asset in the target network will be updated to online. If the field in the task execution result data packet is a non-responding field, then update the asset survival status of the hidden asset in the target network to offline status. The asset's survival status is recorded in the communication behavior profile.
6. The method for discovering concealed assets based on traffic monitoring and probing according to claim 1, characterized in that, After updating the asset liveness status of the target network based on the probing response results fed back by the probe nodes, the method further includes: If the asset survival status of the hidden asset in the target network is online, the asset fingerprint information of the hidden asset is extracted from the task execution result data packet, and the application layer identity fingerprint in the communication behavior profile file corresponding to the hidden asset is updated according to the asset fingerprint information. If the service port for this communication is discovered for the first time, the port number of this communication port will be added to the historical open port list of the communication behavior profile corresponding to the covert asset, so as to complete the update of the communication behavior profile corresponding to the covert asset.
7. The method for discovering concealed assets based on traffic monitoring and probing according to claim 6, characterized in that, After updating the communication behavior profile corresponding to the concealed asset, the process also includes: Compare the old and new communication behavior profiles corresponding to the hidden assets to generate comparison results; If the comparison result exceeds the preset warning rules, a security alarm event will be generated.
8. A concealed asset discovery system based on traffic monitoring and decoy detection, applied to a central analysis and management platform, for implementing the concealed asset discovery method based on traffic monitoring and decoy detection as described in any one of claims 1-7, characterized in that, include: The data acquisition module is used to acquire the communication behavior profiles of each network entity in the target network; wherein, the communication behavior profile of each network entity is obtained by monitoring network traffic, and the communication behavior profile is used to characterize the historical communication habits of the corresponding network entity. The filtering and generation module is used to filter hidden assets from all network entities based on communication behavior profiles and pre-stored Internet mapping data, and generate corresponding decoy instructions for the hidden assets; wherein, the decoy instructions are used to guide the probe nodes to imitate the communication patterns familiar to the hidden assets, construct and send induced probe messages to the hidden assets. The status update module is used to update the asset survival status of the target network based on the probe response results fed back by the probe nodes.