A method and apparatus for topology generation and asset management based on connectivity baselines

CN122845430APending Publication Date: 2026-09-29CHINA UNITECHS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610838787.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-11
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0005]为解决传统SOC无法直观展示资产间互访关系以评估威胁影响面,以及未纳管资产识别和归属研判依赖人工、效率低下的问题,本发明提供一种基于连接基线的拓扑生成及资产管理方法及装置

Benefits of technology

[0036]1、本发明通过采集主机的实时网络连接信息,自动构建资产间的访问拓扑,使安全运营人员能够清晰看到与事件主机存在通信关系的所有周边主机,当发生安全事件时可快速定位影响范围,对周边主机实施策略阻断。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845430A_ABST
    Figure CN122845430A_ABST
Patent Text Reader

Abstract

This invention discloses a method and apparatus for topology generation and asset management based on a connection baseline. The method includes: collecting network connection information of hosts to generate network connection records between local assets and external assets; determining whether connections in the network connection records are abnormal connections based on a preset network connection baseline; drawing a network connection topology map based on the network connection records and highlighting abnormal connections; identifying external IPs not associated with known asset IDs as unmanaged assets; and generating and dispatching disposal tasks for abnormal connections and unmanaged assets. The method and apparatus can automatically construct business topologies and identify unmanaged assets, quickly locate affected hosts during security incidents, effectively analyze the threat impact, and significantly improve the efficiency of discovering and claiming unmanaged assets, thereby enhancing proactive defense capabilities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method and apparatus for topology generation and asset management based on connection baselines, applicable to the analysis of asset threat impact and the automatic identification and disposal of unmanaged assets in a Security Operations Center (SOC) platform. Background Technology

[0002] With the rapid development of enterprise informatization, communication between hosts, servers, and application systems in the network is becoming increasingly frequent and complex. Security Operations Center (SOC) platforms are responsible for managing security assets and related threat handling, requiring a comprehensive analysis of the threats to assets and their impact. However, traditional SOC platforms typically only handle threats to a single asset, making it difficult to analyze the potential spread of the threat to other related assets, thus failing to effectively assess the threat's impact.

[0003] Meanwhile, in daily security operations, it is frequently observed that unmanaged assets (i.e., ownerless assets) are communicating with managed hosts. Currently, the identification of these unmanaged assets relies primarily on manual assessment and work order assignment by operations personnel, a time-consuming, inefficient process prone to omissions. Furthermore, when a major security incident occurs on a host, it is often only discovered after the host has already been compromised. The lack of early identification methods for abnormal communication behavior makes it impossible to quickly locate surrounding hosts connected to the compromised host, hindering timely isolation measures and allowing the security incident to continue to escalate and spread.

[0004] Therefore, there is an urgent need for a technical solution that can automatically sort out the host service topology, establish communication baselines, and efficiently identify and handle unmanaged assets. Summary of the Invention

[0005] To address the issues that traditional System-on-Chip (SOC) systems cannot intuitively display inter-asset access relationships to assess threat impact, and that the identification and attribution determination of unmanaged assets rely on manual processes and are inefficient, this invention provides a topology generation and asset management method and apparatus based on connectivity baselines.

[0006] To achieve the above objectives, the present invention adopts the following technical solution:

[0007] In one embodiment of the present invention, a topology generation and asset management method based on connectivity baselines is proposed, the method comprising:

[0008] Collect network connection information of hosts within the target network. The network connection information includes at least the local IP, external IP, protocol, and port.

[0009] Generate network connection records between the local asset and external assets based on the network connection information;

[0010] Based on a pre-established network connection baseline, it is determined whether the connections in the network connection records are abnormal connections; wherein, the network connection baseline includes allowed normal connection conditions;

[0011] Draw a network connection topology diagram based on the network connection records, and highlight the connections that are identified as abnormal connections in the network connection topology diagram.

[0012] External IPs in the network connection records that are not associated with a known asset ID are identified as unmanaged assets;

[0013] Disposal tasks are generated for the abnormal connections and the unmanaged assets, and then assigned to the corresponding responsible persons.

[0014] Furthermore, the steps for establishing the network connectivity baseline include:

[0015] The generated network connection records will be displayed;

[0016] The system receives the marking operation of the network connection records displayed by the operators, and adds the records marked as having a normal connection, along with their local IP, external IP, protocol, and port, to the network connection baseline.

[0017] Further, the step of drawing a network connection topology map based on the network connection records includes:

[0018] Using the local IP address as the central node and the external IP addresses as edge nodes, a star topology is constructed based on the network connection records.

[0019] Connections that are not within the network connectivity baseline are highlighted with red lines to emphasize abnormal connections.

[0020] The node in the network connection topology diagram displays the asset ownership information of the corresponding IP address.

[0021] Furthermore, after identifying external IPs not associated with known asset IDs as unmanaged assets, the method further includes: separately marking the nodes corresponding to the unmanaged assets in the network connection topology diagram.

[0022] Furthermore, the task of handling the abnormal connection generation includes:

[0023] The abnormal connection information is dispatched to the local asset manager to confirm whether the abnormal connection is a normal service. If it is confirmed to be normal, the abnormal connection is added to the network connection baseline. If it is confirmed to be abnormal, an interception action is triggered.

[0024] Furthermore, the disposal task generated from the unmanaged assets includes:

[0025] The unmanaged asset information is assigned to the asset manager on this end, so that the manager can designate a suspected responsible party based on business relationships; and the work order is then forwarded to the suspected responsible party, who will complete the asset management.

[0026] In one embodiment of the present invention, a topology generation and asset management device based on a connectivity baseline is also proposed, the device comprising:

[0027] The acquisition module is used to collect network connection information of hosts within the target network. The network connection information includes at least the local IP, external IP, protocol, and port.

[0028] The record generation module is used to generate network connection records between the local asset and external assets based on the network connection information.

[0029] The baseline determination module is used to determine whether a connection in the network connection record is an abnormal connection based on a pre-established network connection baseline; wherein, the network connection baseline includes allowed normal connection conditions;

[0030] The topology drawing module is used to draw a network connection topology diagram based on the network connection records, and to highlight connections that are judged to be abnormal connections in the network connection topology diagram.

[0031] The unmanaged asset identification module is used to identify external IPs in the network connection records that are not associated with a known asset ID as unmanaged assets.

[0032] The disposal module is used to generate disposal tasks for the abnormal connection and the unmanaged assets respectively, and to dispatch them to the corresponding responsible persons.

[0033] In one embodiment of the present invention, a computer device is also proposed, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the topology generation and asset management method based on the connection baseline.

[0034] In one embodiment of the present invention, a computer-readable storage medium is also provided, on which a computer program is stored, which, when executed by a processor, implements the topology generation and asset management method based on the connectivity baseline.

[0035] Beneficial effects:

[0036] 1. This invention automatically constructs the access topology between assets by collecting real-time network connection information of the host, enabling security operations personnel to clearly see all surrounding hosts that have communication relationships with the event host. When a security event occurs, the scope of impact can be quickly located and policy blocking can be implemented on surrounding hosts.

[0037] 2. This invention establishes a network connection baseline and compares the actual connections with the network connection baseline. Access behaviors that exceed the range of the network connection baseline are judged as abnormal, thus realizing the proactive discovery of abnormal access.

[0038] 3. This invention utilizes external IP addresses from network connection records to automatically identify unmanaged assets and assigns suspected ownership to the asset manager through a dispatch process, significantly reducing manual assessment time and improving asset claim efficiency.

[0039] In summary, this invention enables visualized analysis of the threat impact surface, overcoming the shortcomings of traditional SOCs in assessing the scope of threat spread; it automatically identifies unmanaged assets, accelerating the asset management process; and it enhances the early detection and proactive defense capabilities against abnormal access through network connection baseline and topology monitoring. Attached Figure Description

[0040] Figure 1 This is a schematic diagram of the topology generation and asset management method based on the connection baseline of the present invention;

[0041] Figure 2 This is a signaling flowchart of the topology generation and asset management method based on the connection baseline of the present invention;

[0042] Figure 3 This is a schematic diagram of the topology generation and asset management device based on the connection baseline of the present invention;

[0043] Figure 4 This is a schematic diagram of the computer device structure of the present invention. Detailed Implementation

[0044] The principles and spirit of the present invention will now be described with reference to several exemplary embodiments. It should be understood that these embodiments are provided merely to enable those skilled in the art to better understand and implement the present invention, and are not intended to limit the scope of the present invention in any way. Rather, these embodiments are provided to make this disclosure more thorough and complete, and to fully convey the scope of this disclosure to those skilled in the art.

[0045] Those skilled in the art will recognize that embodiments of the present invention can be implemented as an apparatus, device, device, method, or computer program product. Therefore, this disclosure can be specifically implemented in the following forms: entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.

[0046] The principles and spirit of the present invention will be explained in detail below with reference to several representative embodiments.

[0047] Figure 1This is a schematic diagram of the topology generation and asset management method based on the connection baseline of the present invention. Figure 1 As shown, the method includes the following steps:

[0048] Step S1: Collect the network connection information of the host.

[0049] like Figure 2 As shown, in an enterprise's IT environment, host assets are managed by the SOC platform through agent installation or asset ledgers. Management attributes include asset ID, IP address, host ownership organization, and responsible person. For managed hosts, network diagnostic commands (such as the netstat command) are executed periodically via the agent program installed on the host or by remotely logging into the host to collect network connection information. The collected network connection information includes at least: local IP address, protocol, local port, external IP address, external port, process name, and connection status.

[0050] Step S2: Clean the data and generate network connection records.

[0051] like Figure 2 As shown, the collected raw data is parsed, and asset IDs are assigned to both the local IP and external IP. Local IPs generally have corresponding asset IDs, while external IPs may correspond to known asset IDs or may not be matched due to lack of management. Structured network connection records are generated, with fields including: local asset ID, local IP, protocol, local port, external asset ID (can be empty), external IP, external port, process, connection status, connection start time, and connection end time. These records are stored in a database and can be queried and displayed.

[0052] Step S3: Establish network connectivity baseline.

[0053] like Figure 2 As shown, the generated network connection records are displayed on the management page. Security operations personnel then identify the necessary IPs, protocols, and ports for server-external communication based on actual business scenarios. Operations personnel mark connection records representing normal business access and add the marked records and their conditions (local IP, external IP, protocol, port, etc.) to the network connection baseline. Any access behavior not included in the network connection baseline is considered an abnormal connection.

[0054] Step S4: Generate access topology and identify unmanaged assets.

[0055] like Figure 2As shown, based on stored network connection records, connections are constructed starting from the local IP address and ending at external IP addresses. When querying a specific time period or a particular local IP address, a star-shaped topology is displayed using an aggregation method: the local IP address acts as the central node, and the multiple connected external IP addresses serve as surrounding nodes. In the topology diagram, normal connections (within the network connection baseline) are represented by default lines, while abnormal connections are highlighted with red lines. Auxiliary information such as the department to which the IP address belongs can be displayed next to the nodes.

[0056] For connection records with empty external asset IDs, the corresponding external IP is marked as "unmanaged asset" and identified separately in the topology diagram.

[0057] Step S5: Disposal of abnormal connections and unmanaged assets.

[0058] like Figure 2 As shown, it interfaces with the work order system to achieve automated processing.

[0059] For abnormal connections: A handling work order is automatically generated and dispatched to the local asset manager. The manager determines whether the connection is a normal service; if so, the connection is marked as normal and updated to the network connection baseline; if it is abnormal behavior, the manager instructs operations personnel to configure policies on the host firewall or network firewall to block it.

[0060] For unmanaged assets: A claim work order is generated and dispatched to the local asset manager. Based on their understanding of the interactions between business systems, the local asset manager makes a preliminary judgment on the suspected ownership of the external IP (e.g., belonging to a specific business system, department, or external partner), and forwards the work order to the suspected manager. Upon receiving the work order, the suspected manager completes the asset management process by installing an agent or entering asset information.

[0061] It should be noted that although the operation of the method of the present invention has been described in a specific order in the above embodiments and figures, this does not require or imply that the operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0062] Based on the same inventive concept, this invention also proposes a topology generation and asset management device based on a connection baseline. The implementation of this device can refer to the implementation of the method described above, and repeated details will not be repeated. The term "module" used below can refer to a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0063] Figure 3This is a schematic diagram of the topology generation and asset management device based on the connection baseline of the present invention. Figure 3 As shown, the device includes:

[0064] The acquisition module 101 is used to acquire network connection information of hosts in the target network. The network connection information includes at least the local IP, external IP, protocol and port.

[0065] The record generation module 102 is used to generate network connection records between the local asset and external assets based on the network connection information.

[0066] The baseline determination module 103 is used to determine whether a connection in the network connection record is an abnormal connection based on a pre-established network connection baseline; wherein the network connection baseline includes allowed normal connection conditions;

[0067] The topology drawing module 104 is used to draw a network connection topology diagram based on the network connection record, and to highlight the connections that are judged to be abnormal connections in the network connection topology diagram.

[0068] The unmanaged asset identification module 105 is used to identify external IPs in the network connection records that are not associated with a known asset ID as unmanaged assets.

[0069] The disposal module 106 is used to generate disposal tasks for the abnormal connection and the unmanaged assets respectively, and dispatch them to the corresponding responsible persons.

[0070] It should be noted that although several modules of the topology generation and asset management device based on the connection baseline have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the present invention, the features and functions of two or more modules described above can be embodied in one module. Conversely, the features and functions of one module described above can be further divided and embodied by multiple modules.

[0071] Based on the aforementioned inventive concept, such as Figure 4 As shown, the present invention also proposes a computer device 200, including a memory 210, a processor 220, and a computer program 230 stored in the memory 210 and executable on the processor 220. When the processor 220 executes the computer program 230, it implements the aforementioned topology generation and asset management method based on connection baseline.

[0072] Based on the aforementioned inventive concept, the present invention also proposes a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the topology generation and asset management method based on the connection baseline.

[0073] Through the above solution, the present invention effectively solves the problems of traditional SOC platforms in assessing the impact of threats and in being unable to quickly discover and claim unmanaged assets, thereby improving the efficiency of security operations and the level of proactive defense.

[0074] While the spirit and principles of the invention have been described with reference to several specific embodiments, it should be understood that the invention is not limited to the disclosed specific embodiments, and the division of aspects does not imply that features in these aspects cannot be combined for benefit; such division is merely for ease of description. The invention is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.

[0075] Regarding the limitation of the scope of protection of this invention, those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solution of this invention are still within the scope of protection of this invention.

Claims

1. A method for topology generation and asset management based on connectivity baselines, characterized in that, The method includes: Collect network connection information of hosts within the target network. The network connection information includes at least the local IP, external IP, protocol, and port. Generate network connection records between the local asset and external assets based on the network connection information; Based on a pre-established network connection baseline, it is determined whether the connections in the network connection records are abnormal connections; wherein, the network connection baseline includes allowed normal connection conditions; Draw a network connection topology diagram based on the network connection records, and highlight the connections that are identified as abnormal connections in the network connection topology diagram. External IPs in the network connection records that are not associated with a known asset ID are identified as unmanaged assets; Disposal tasks are generated for the abnormal connections and the unmanaged assets, and then assigned to the corresponding responsible persons.

2. The method for topology generation and asset management based on connection baselines according to claim 1, characterized in that, The steps for establishing the network connectivity baseline include: The generated network connection records will be displayed; The system receives the marking operation of the network connection records displayed by the operators, and adds the records marked as having a normal connection, along with their local IP, external IP, protocol, and port, to the network connection baseline.

3. The method for topology generation and asset management based on connection baselines according to claim 1, characterized in that, The step of drawing a network connection topology diagram based on the network connection records includes: Using the local IP address as the central node and the external IP addresses as edge nodes, a star topology is constructed based on the network connection records. Connections that are not within the network connectivity baseline are highlighted with red lines to emphasize abnormal connections. The node in the network connection topology diagram displays the asset ownership information of the corresponding IP address.

4. The topology generation and asset management method based on connection baselines according to claim 1, characterized in that, After identifying external IPs not associated with known asset IDs as unmanaged assets, the method further includes: marking the nodes corresponding to the unmanaged assets separately in the network connection topology diagram.

5. The topology generation and asset management method based on connection baselines according to claim 1, characterized in that, The task for handling the abnormal connection includes: The abnormal connection information is dispatched to the local asset manager to confirm whether the abnormal connection is a normal service. If it is confirmed to be normal, the abnormal connection is added to the network connection baseline. If it is confirmed to be abnormal, an interception action is triggered.

6. The method for topology generation and asset management based on connection baselines according to claim 1, characterized in that, The disposal tasks generated for the aforementioned unmanaged assets include: The unmanaged asset information is assigned to the asset manager on this end, so that the manager can designate a suspected responsible party based on business relationships; and the work order is then forwarded to the suspected responsible party, who will complete the asset management.

7. A topology generation and asset management device based on a connection baseline, characterized in that, The device includes: The acquisition module is used to collect network connection information of hosts within the target network. The network connection information includes at least the local IP, external IP, protocol, and port. The record generation module is used to generate network connection records between the local asset and external assets based on the network connection information. The baseline determination module is used to determine whether a connection in the network connection record is an abnormal connection based on a pre-established network connection baseline; wherein, the network connection baseline includes allowed normal connection conditions; The topology drawing module is used to draw a network connection topology diagram based on the network connection records, and to highlight connections that are judged to be abnormal connections in the network connection topology diagram. The unmanaged asset identification module is used to identify external IPs in the network connection records that are not associated with a known asset ID as unmanaged assets. The disposal module is used to generate disposal tasks for the abnormal connection and the unmanaged assets respectively, and to dispatch them to the corresponding responsible persons.

8. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1-6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1-6.