Method for classifying and managing assets based on user characteristics

By classifying and clustering assets based on their characteristics and user usage, the method addresses the inefficiencies in conventional security systems, enabling quicker threat detection and more efficient asset management.

WO2025127300A1PCT designated stage expired Publication Date: 2025-06-19QUAD MINERS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/011034
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-12
Filing Date
2024-07-29
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Conventional security control systems require excessive time and effort to manually configure and update network asset information, limiting the ability to quickly detect and respond to external attack threats.

Method used

A method for classifying and clustering assets based on unique asset characteristics and user usage characteristics, allowing for quicker and more intuitive identification of asset types and their quantities by creating characteristic groups and cluster types.

Benefits of technology

This approach enhances search efficiency by reducing computation required for asset searches and facilitates more effective asset management within a company.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024011034_19062025_PF_FP_ABST
    Figure KR2024011034_19062025_PF_FP_ABST
Patent Text Reader

Abstract

A method for clustering and classifying assets, according to one embodiment of the present invention, may comprise: a step of classifying assets by characteristic so as to generate at least one characteristic group; a cluster sample generation step of classifying, into cluster types, at least one characteristic group to which the assets belong, and classifying the assets according to cluster type; and a step of storing the cluster sample in a database. In the method for classifying assets, according to the present invention, assets are classified according to cluster type, and thus the type of each asset and the number of assets for each type can be more quickly and intuitively identified and searched for.
Need to check novelty before this filing date? Find Prior Art

Description

User-Characteristic-Based Asset Classification and Management Method

[0001] The present invention relates to a method for classifying and clustering assets and a method for managing network groups. More specifically, the present invention relates to a method and device for classifying assets based on their unique characteristics and user usage characteristics, and classifying them according to cluster types.

[0002] Network assets, such as routers, switches, wireless access points (APs), web servers, access points (APs), and business devices (databases, PCs, tablets, smartphones, etc.), can be vulnerable to external attacks. Solutions exist to proactively detect and respond to these threats. However, detecting these threats requires first understanding the network structure, the deployment of network assets, and their intended use.

[0003]

[0004] The business network environment consists of a DMZ area where web servers and mail servers are deployed, a business network where PCs and mobile devices operate, and a server farm where AP servers and databases are deployed. The individual characteristics of network assets deployed in each area must be considered important when detecting external attack threats.

[0005]

[0006] For example, a PC on a corporate network typically connects to servers on the Internet or the internal network to perform tasks. If a previously inactive FTP server service starts up, this can be detected as an anomaly. Another example is a server that provides services to multiple clients. If a connection is attempted via the Internet or PC network bandwidth, this can be detected as an anomaly related to a command-and-control (C&C) server connection attempt or an internal network infiltration attempt (lateral movement).

[0007]

[0008] In conventional security control systems, network asset information was manually entered one by one, or a separate device like a network scanner was used to generate a traffic load to investigate asset information. However, these methods require excessive time and effort to compile network asset information, and the asset information update rate inevitably slows down, limiting the ability to quickly detect and respond to external attack threats.

[0009]

[0010] Recently, Republic of Korea Patent No. 10-2244036 (registration date: April 19, 2021) proposed an asset classification method that includes a classification learning model that extracts asset characteristics from flow data and classifies them. However, this method of extracting and classifying asset characteristics from flow data has the drawback of making it difficult to reflect user characteristics.

[0011] The present invention provides a method for classifying and clustering assets to facilitate asset management within a company by identifying the characteristics of assets and classifying and providing assets according to cluster types, thereby enabling quicker and more intuitive identification of asset types and the number of assets corresponding to each type.

[0012] The present invention is to achieve the above-described object, and an asset clustering classification method according to an embodiment of the present invention may include a step of classifying assets by characteristics to create at least one characteristic group, a step of classifying at least one characteristic group to which assets belong into cluster types, a step of creating a clustering sample for classifying assets according to the cluster types, and a step of storing the clustering sample in a database.

[0013] The method for classifying assets according to the present invention classifies assets according to cluster type, thereby enabling quicker and more intuitive identification and search of the type of each asset and the number of assets of each type.

[0014] In addition, the present invention can improve search efficiency by reducing the computation required for asset search by creating a cluster type to include at least one characteristic and storing assets by classifying them according to the cluster type.

[0015] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the description below.

[0016] FIG. 1 is a diagram illustrating a configuration of a computing device for classifying and clustering assets based on user characteristics according to an embodiment of the present invention.

[0017] FIG. 2 is a diagram illustrating assets clustered by type according to an embodiment of the present invention.

[0018] Figure 3 is a flowchart of a method for classifying and clustering assets according to an embodiment of the present invention.

[0019] FIG. 4 is a drawing for explaining an example of a characteristic group generated according to an embodiment of the present invention.

[0020] Figure 5 is a flowchart illustrating a clustering sample generation step according to an embodiment of the present invention.

[0021] Figures 6 to 9 are diagrams illustrating a clustering sample generation step according to one embodiment of the present invention.

[0022] FIG. 10 is a diagram illustrating a footprint table according to one embodiment of the present invention.

[0023] Figure 11 is a diagram for explaining the effect of the asset clustering classification method according to the present invention.

[0024]

[0025] The advantages and features of the present invention, as well as the methods for achieving them, will become clearer with reference to the embodiments described in detail below, along with the accompanying drawings. However, the present invention is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided solely to ensure the completeness of the present invention and to fully inform those skilled in the art of the scope of the invention. The present invention is defined solely by the scope of the claims.

[0026] Unless otherwise defined, all terms (including technical and scientific terms) used herein may be used in their common sense to those of ordinary skill in the art to which the present invention pertains. Furthermore, terms defined in commonly used dictionaries are not to be interpreted ideally or excessively unless explicitly and specifically defined otherwise.

[0027] The terminology used herein is for the purpose of describing embodiments and is not intended to limit the present invention. In this specification, singular forms also include plural forms, unless specifically stated otherwise. As used herein, the terms "comprises" and / or "comprising" do not exclude the presence or addition of one or more other components in addition to the components mentioned.

[0028]

[0029] Network assets (hereinafter, “assets”) according to the present invention may be, for example, routers, switches, wireless APs, web servers, AP servers, databases, PCs, mobile devices such as tablet PCs or smartphones, network printers, etc., and any device that performs a certain function within a network may be included regardless of type and is not limited to the devices listed above.

[0030]

[0031] In the invention below, the user's usage characteristics refer to characteristics caused by the user while using the asset, such as how the user uses the asset, what actions the user performs with the asset, and where the asset is used, and include specific function usage information, access information, location information, and usage app information.

[0032] Asset-specific characteristics are characteristics related to the asset, such as the type of asset, the type of OS of the asset, the year of manufacture, the model name, and the IP address.

[0033] A cluster type refers to a classification type that includes at least one characteristic. That is, since assets can be included in more than one characteristic group, assets can be classified into cluster types that include at least one characteristic. In other words, a cluster type includes one or more characteristics. For example, a cluster type may include a cluster type that includes only a first characteristic, a cluster type that includes both a first and second characteristic, etc.

[0034]

[0035] Hereinafter, with reference to FIGS. 1 to 11, a method for classifying and clustering assets according to one embodiment of the present invention and / or a computing device (or server, hereinafter referred to as a computing device) for performing the same will be described. In the drawings, like reference numerals represent like components.

[0036]

[0037] FIG. 1 is a diagram illustrating a configuration of a computing device (1000) for classifying assets by clustering them by characteristics according to an embodiment of the present invention.

[0038] Referring to FIG. 1, a computing device (1000) according to the present invention may include a transceiver (1100), a memory (12000), and a processor (1300).

[0039] A computing device (1000) according to one embodiment of the present invention classifies each asset based on the usage characteristics of a user or the unique characteristics of an asset to create a characteristic group, creates a cluster type to include at least one characteristic, and classifies and clusters assets according to the cluster type, thereby quickly identifying the usage characteristics of each user and more easily and quickly identifying assets belonging to each type.

[0040] A computing device (1000) according to one embodiment of the present invention can classify assets by characteristics and create at least one characteristic group.

[0041] According to one embodiment of the present invention, a computing device (1000) can obtain various information related to assets, such as unique information of assets and user usage characteristic information, through a transceiver (1100). The transceiver (1100) of the computing device (1000) can communicate with any external device, external server, or internal server. For example, the computing device (1000) can obtain unique information of assets within a company and communication information of assets through the transceiver (1100). For example, the computing device (1000) can transmit clustering information of assets to any external device, any external server, or any internal server through the transceiver (1100).

[0042] The computing device (1000) can connect to a network and transmit and receive various data through the transceiver (1100). The transceiver (1100) can be broadly categorized into wired and wireless types. Since the wired and wireless types each have their own advantages and disadvantages, the computing device (1000) may be equipped with both wired and wireless types at the same time, depending on the case. Here, in the case of the wireless type, a communication method of the WLAN (Wireless Local Area Network) series, such as Wi-Fi, can be mainly used. Alternatively, in the case of the wireless type, a communication method of the cellular communication series, such as LTE or 5G, can be used. However, the wireless communication protocol is not limited to the examples described above, and any appropriate wireless communication method can be used. Representative examples of the wired type include LAN (Local Area Network) and USB (Universal Serial Bus) communication, and other methods are also possible.

[0043]

[0044] The memory (1200) of the computing device (1000) can store various types of information. Various types of data can be temporarily or semi-permanently stored in the memory (1200). Examples of the memory (1200) may include a hard disk drive (HDD), a solid state drive (SSD), flash memory, read-only memory (ROM), random access memory (RAM), etc. The memory (1200) may be provided in a form that is built into the computing device (1000) or in a detachable form. The memory (1200) may store various types of data necessary for the operation of the computing device (1000), including an operating system (OS) for operating the computing device (1000) or a program for operating each component of the computing device (1000).

[0045]

[0046] The processor (1300) can control the overall operation of the computing device (1000). For example, the processor (1300) can control the overall operation of the computing device (1000), including an operation of classifying assets by characteristics to be described later and creating a characteristic group, an operation of creating a clustering sample to classify assets by cluster type, an operation of storing the clustering sample in a database, an operation of adding cluster type data to a vector space, an operation of creating a description table, an operation of creating a mapping table, an operation of creating a footprint table, an operation of creating a clustering type table, and the like. Specifically, the processor (1300) can load and execute a program for the overall operation of the computing device (1000) from the memory (1200). The processor (1300) can be implemented as an AP (Application Processor), a CPU (Central Processing Unit), an MCU (Microcontroller Unit), or a similar device according to hardware, software, or a combination thereof. At this time, in terms of hardware, it can be provided in the form of an electronic circuit that processes electrical signals and performs a control function, and in terms of software, it can be provided in the form of a program or code that drives a hardware circuit.

[0047]

[0048] As needed, the processor (1300) of the computing device (1000) may group assets by characteristics to create at least one characteristic group, create cluster types that include one or more characteristics, and classify assets by the cluster types to create clustered samples. Furthermore, the processor (1300) of the computing device (1000) may store the generated data and clustered samples in the memory (1200).

[0049] Additionally, the processor (1300) of the computing device (1000) can add cluster type data to a vector space. The vector space refers to a space for storing data, and refers to a space of flexible length for storing an arbitrary number of data. The processor (1300) can generate a description table including vector space information (including location information and length information) of data stored in the vector space and asset information. The vector space information includes offset information and length information of vectors input into the vector space, and the asset information includes information on the number of assets. Additionally, if necessary, the length of the vector may correspond to the number of characteristics included in the cluster type.

[0050] The processor (1300) may create a mapping table including mapping information corresponding to a primary index to classify assets according to cluster types, and may create a footprint table storing accumulated data of the mapping table. This is because the mapping table can be initialized when assets of a new characteristic group are added. The processor may sequentially add characteristic groups to a clustering type table, and match assets of the added characteristic groups with cluster types using the mapping information to create a clustering type table, thereby creating a clustered sample. In addition, the processor may add or update information about assets belonging to cluster types added to the clustering type table to a description table.

[0051]

[0052] Additionally, the processor (1300) of the computing device (1000) may classify assets included in the first characteristic group into a first cluster type, add data of the first cluster type to a vector space, and input a first vector. Furthermore, the processor may sort assets of the first characteristic group based on IP, create a clustering type table that matches cluster types to assets using mapping information, and update asset information of the first cluster type in the description table.

[0053] The processor (1300) can create a description table that assigns a primary index, create a mapping table that inputs a primary index corresponding to the primary index of the mapping table, sort assets of a first characteristic group based on IP, create a clustering type table that assigns the primary index to assets using the mapping table, and input asset information of the first cluster type into the description table.

[0054]

[0055] FIG. 2 is a diagram illustrating assets classified by cluster type according to one embodiment of the present invention. Referring to FIG. 2, a computing device (1000) according to one embodiment of the present invention divides cluster types into one or more characteristics using the unique characteristics and user usage characteristics of assets, classifies and clusters assets belonging to each cluster type, thereby enabling rapid identification of the number of assets by cluster type and information on the cluster type for each asset. Through this, the device enables rapid retrieval of which cluster type an asset belongs to, thereby enhancing asset management efficiency.

[0056]

[0057] Hereinafter, with reference to FIGS. 3 through 9, the operation of a computing device (1000) according to another embodiment of the present invention and the asset clustering classification method performed by the computing device (1000) will be described in more detail. Meanwhile, in describing the asset clustering classification method, some embodiments that overlap with the content previously described with reference to FIGS. 1 and 2 may be omitted. However, this is merely for convenience of explanation and should not be construed as limiting.

[0058]

[0059] Figure 3 is a flowchart of a clustering classification method for assets according to an embodiment of the present invention. Referring to Figure 3, the clustering classification method for assets may include a characteristic group creation step (S1000), a clustering sample creation step (S2000), and a database storage step (S3000).

[0060] FIG. 4 is a drawing for explaining an example of a characteristic group generated according to an embodiment of the present invention.

[0061] The characteristic group creation step (S1000) refers to the step of classifying assets into characteristic groups using acquired asset characteristic information. Assets may include one or more characteristics, and thus may be included in at least one characteristic group.

[0062] More specifically, the computing device (1000) can acquire various characteristic information regarding the user's assets. The characteristic information can include any information that can be acquired, including unique characteristics of the asset (such as IP address, OS information, etc.) as well as user usage characteristics generated by the user (such as user activity information, user information, location information, and user department information). Users can classify assets with these characteristics by specifying characteristics. The number and types of characteristics can be freely specified.

[0063] Referring to FIG. 4, in a specific embodiment of the present invention, the computing device (1000) may classify assets into characteristic groups having first to fourth characteristics. According to a specific embodiment, the first characteristic may be OS information of the device, the second characteristic may be whether the user accessed SNS using the asset, the third characteristic may be whether the user performed streaming using the asset, and the fourth characteristic may be information on the department to which the user belongs.

[0064] As needed, an asset can be included in one or more characteristic groups. Accordingly, the device can create cluster types to classify and cluster assets with multiple characteristics. A cluster type refers to a unit of type that includes at least one characteristic. More specifically, an asset can have multiple characteristics, and the device can categorize these characteristics into cluster types and cluster assets by classifying them according to the cluster types.

[0065]

[0066] If necessary, the computing device can classify assets included in the first characteristic group into a first cluster type. The computing device can classify assets included in both the first characteristic group and the second characteristic group into a second cluster type, and classify assets included in the second characteristic group but not the first characteristic group into a third cluster type. The computing device can further include a third characteristic group clustering step of classifying assets included in the third characteristic group, which are included in at least one of the first and second characteristic groups, according to their cluster types, and classifying assets included in the third characteristic group but not included in the first or second characteristic groups into a separate cluster type. More specifically, the device can classify assets into cluster types that are included in the third characteristic group and the first characteristic group but not in the second characteristic group, cluster types that are included in the third characteristic group and the second characteristic group but not in the first characteristic group, and cluster types that are included in both the first and third characteristic groups, and if there are assets included in the corresponding cluster type, it determines that this is a valid cluster type, and if there are no assets included in the corresponding cluster type, it determines that this is an invalid cluster type, and can classify future assets according to the generated cluster type. In addition, the computing device can classify assets that are included in the third characteristic group but not in the first or second characteristic groups into a separate cluster type.

[0067] That is, the computing device can divide the assets into n groups of characteristics, with a maximum of 2 n -Can create one cluster type.

[0068]

[0069] FIG. 5 is a flowchart illustrating a clustering sample generation step (S2000) according to an embodiment of the present invention, and FIGS. 6 to 9 are drawings illustrating the clustering sample generation step.

[0070] The clustering sample creation step (S2000) involves creating cluster types that include at least one characteristic and classifying assets according to the cluster types. This allows for a more rapid identification of asset types or the usage characteristics of users using the assets.

[0071] Optionally, the clustering sample generation step (S2000) may be characterized by sequentially adding characteristic groups to a clustering type table to generate a clustering sample that classifies assets within a characteristic group into cluster types. That is, the device can more effectively classify assets into cluster types by sequentially adding assets belonging to some characteristic groups among multiple characteristic groups to the clustering sample generation step.

[0072] Referring to FIGS. 5 to 9, the clustering sample generation step (S2000) may include a vector space generation step (S2100), a description table generation step (S2200), a mapping table generation step (S2300), a footprint table generation step (S2400), and a clustering type table generation step (S2500).

[0073] The step of generating a vector space (S2100) refers to a step of storing cluster type data in a vector space. Unlike an array, a vector space refers to a space in which data can be added without limiting the size of the space. If necessary, the step of generating a vector space may include a step of inputting a first vector into the generated vector space. The first vector input step refers to a step of classifying assets included in the first characteristic group into the first cluster type and adding cluster data of the first characteristic group to the vector space.

[0074]

[0075] Optionally, the clustering sample generation step (S2000) may include a vector input step for inputting cluster data regarding assets belonging to a specific cluster type into a vector space. More specifically, the clustering sample generation step (S2000) may further include a second vector input step for adding cluster data of a second cluster type into the vector space, and a third vector input step for adding cluster data of a third cluster type into the vector space.

[0076] Optionally, a second vector input step can be generated by copying the first vector input into the vector space and adding data from the second feature group. This is because the second cluster type belonging to the second vector represents assets that are included in both the first and second feature groups.

[0077] The third vector input stage can be generated by copying the data of the second feature group input into the vector space in the second vector input stage. This is because the third cluster type belonging to the third vector means assets that belong to the second feature group but not to the first feature group.

[0078] If necessary, the clustering sample generation step (S2000) may include a fourth vector input step of adding cluster data of valid cluster types classified in the third characteristic group cluster type classification step to the vector space.

[0079]

[0080] The description table creation step (S2200) refers to a step of creating a description table that includes information on the vector space of data stored in the vector space and information on assets.

[0081] More specifically, the computing device can input information of the first vector space into the description table and assign an index of the cluster type. That is, the device can arbitrarily assign an order to each cluster type and record information by cluster type index in the description table. That is, the description table can include information of the vector space of the classified cluster type, asset information, and index information of the cluster type. Referring to FIG. 6, the description table can assign an index of the cluster type to the input cluster type data and include an offset and length information indicating the position of the corresponding type in the vector space, and the asset information can include information on the number of assets corresponding to the cluster type. More specifically, looking at the description table, the first cluster type is input as a first vector in the vector space, and the information of the first vector can include 0, which is offset information of the first vector within the vector space, and 1, which is length information of the first vector.

[0082] The description table creation step (S2200) may further include a step of inputting information on the second vector and information on the vector space of the third vector into the description table, and assigning an index of a cluster type. Referring to FIG. 7, the second cluster type is assigned an index of 2 (id of the description table) for the cluster type, and inputs 1 as offset information of the second vector and 2 as length information into the description table. The third cluster type is assigned an index of 3 (id of the description table) for the cluster type, and inputs 3 as offset information of the third vector and 1 as length information into the description table.

[0083]

[0084] The cluster type index may be a number corresponding to the cluster type. That is, different cluster types have different cluster type indices. If necessary, the description table creation step (S2200) may further include a step of entering information about the vector space of the fourth vector into the description table and assigning an index to the cluster type.

[0085]

[0086] A mapping table is a table that records mapping information corresponding to a primary index to match cluster types to assets within a clustering type table. The mapping table creation step (S2300) refers to a step of entering mapping information corresponding to the primary index of the mapping table. If necessary, the mapping information may be cluster type index information.

[0087] The primary index of the mapping table may be an index already assigned to an asset in the clustering type table, or information corresponding to a cluster type already assigned to an asset in the clustering type table. Furthermore, the mapping table may be initialized when asset information for a new characteristic group is added to the clustering type table. This is because the cluster type information to which an existing asset belongs may change when a new characteristic group is added.

[0088]

[0089] Referring to Figures 6 and 7, the process of adding an asset to the cluster type table to which the existing asset belongs will be described.

[0090] Add assets of the first characteristic group to the clustering type table. Referring to the drawing, there are four assets with the first characteristic. Define the first characteristic group as the first cluster type. Store the first characteristic group as the first cluster type in the vector space, store information about the vector space of the first cluster type (position 0, length 1) and asset information (4 items) in the description table, and record the corresponding asset as group 1 in the mapping table. Since only information about the first cluster type (index number 1) is recorded in the description table and the mapping table, all assets of the first characteristic group can be classified as the first cluster type corresponding to the index number 1.

[0091] Hereafter, referring to FIG. 7, when a second characteristic asset is added to the clustering type table, asset types that have both the first characteristic and the second characteristic, and assets that only have the second characteristic but not the first characteristic are added as cluster types. Assets that have both the first characteristic and the second characteristic are defined as the second cluster type, and assets that only include the second characteristic but not the first characteristic are defined as the third cluster type. The vector space copies the first characteristic group, adds the second characteristic group, and stores the second cluster type in the vector space, and copies the vector of only the second characteristic group to store the third cluster type in the vector space.

[0092]

[0093] The description table contains information about vectors of the second (index number 2) cluster type and the third cluster type (index number 3).

[0094]

[0095] Assets within the clustering type table can belong to the first to third cluster types. That is, assets previously classified into the first cluster type can also be classified into a new cluster type when a new characteristic group is input. Accordingly, after initializing the mapping table, new index information can be assigned to assets within the clustering type table using the primary index of the mapping table and the index (mapping information) of the cluster type matching it. That is, since the second cluster type includes assets belonging to both the first characteristic group and the second characteristic group, assets 1.1.1.1 and 2.1.2.4 can be changed from the first cluster type to the second cluster type through the mapping table (cluster type index 1 -> cluster type index 2, second cluster type), and assets 1.1.1.2 and 1.1.2.1, which belong only to the second characteristic group, can be assigned the third cluster type (cluster type index 3, third cluster type). Assets in the third cluster type are assigned a cluster type index of 3, which matches the primary index 0 in the mapping table, and assets in the second cluster type are assigned a cluster type index of 2, which matches the primary index 1. Through this, each asset in the clustering type table is assigned a cluster type index corresponding to its cluster type.

[0096]

[0097] When a third characteristic group is added, the variability increases. That is, there can be assets common to both the first and third characteristics, assets that include all three characteristics, and assets that include both the second and third characteristics.

[0098] In Figure 8, we assume that there are assets that include all three characteristics, and assets that include only the third characteristic. This is merely an example, and various cluster types may be created depending on the situation.

[0099] After a cluster type is assigned to an asset in the clustering type table, asset information is recorded in the description table. Furthermore, at this time, the number of assets recorded in the previous step may change. For example, if a second characteristic group is added and there are assets in the first characteristic group that are also included in the second characteristic group, the number of assets in the first cluster type will change. That is, in a specific embodiment of the present invention, assets 1.1.1.1 and 2.1.2.4 include both the first and second characteristics, and thus belong to the second cluster type. Therefore, 2 is subtracted from the number of assets in the first cluster type, and the number of assets in the second cluster type becomes 2.

[0100]

[0101] If necessary, the mapping table creation step (S2300) may include a step of initializing the mapping table and entering the cluster type index or mapping information corresponding to the primary index of the mapping table. The mapping table may be initialized periodically. If necessary, the mapping table may be initialized when a new asset is added to the cluster type table. This is to assign a new primary index to the newly entered asset.

[0102]

[0103] The device may include a footprint table generation step (S2400) that stores accumulated data of a mapping table. Referring to FIG. 10, the footprint table may include data regarding changes in cluster types. If necessary, the footprint table generation step (S2400) may include a step of generating corresponding cluster type data for each characteristic group using the accumulated data of the mapping table.

[0104]

[0105] The clustering type table creation step (S2500) refers to a step of sorting assets in the input characteristic group based on IP and matching the assets with cluster types using mapping information. In other words, the clustering type table creation step (S2500) is a step of assigning cluster type indices to assets using the mapping table. If necessary, the clustering type table creation step (S2500) may include a step of sorting assets in the first characteristic group based on IP and matching the assets with the cluster types using mapping information.

[0106] In addition, the step of adding assets of the second characteristic group to the clustering type table, sorting them based on IP, and assigning a cluster type index to the assets in the clustering type table using a mapping table may further be included. The step of generating the clustering type table (S2500) may further include the step of adding assets of the third characteristic group to the clustering type table, sorting them based on IP, and assigning a cluster type index to the assets in the clustering type table using a mapping table.

[0107]

[0108] If necessary, the step of creating a clustering type table (S2500) may include a step of classifying the asset into the second clustering type when the added asset already exists in the clustering type table when adding an asset of the second characteristic group, classifying the asset into the third clustering type when the asset does not exist in the clustering type table, and assigning a clustering type index to the asset using a mapping table.

[0109]

[0110] Thereafter, the device may input asset information of the first cluster type into the description table based on the asset types in the clustering type table. In addition, the device may periodically update the asset information recorded in the description table based on the asset types in the clustering type table. If necessary, the device may further include a step of updating asset information of the first to third cluster types in the description table. The asset clustering classification method may include a step of updating asset information in the description table. That is, when a new characteristic asset is added, existing assets may also be classified into a new cluster type, and thus, the asset information in the description table may be changed. Accordingly, information on the number of assets belonging to a cluster type in the description table may be periodically updated.

[0111]

[0112] The database storage step (S3000) refers to a step of storing data and clustering samples generated in the clustering sample generation step in a database.

[0113]

[0114] If necessary, the asset clustering classification method (S2000) according to the present invention may further include a step of classifying assets included in both the n-th characteristic group and the m-th characteristic group into the x-th cluster type, and classifying assets included in the m-th characteristic group but not included in the n-th characteristic group into the x+1-th cluster type (all m, n, and x are integers).

[0115] Additionally, the clustering sample generation step may further include an x-th vector input step of adding cluster data of the x-th cluster type to the vector space, and an x+1-th vector input step of adding cluster data of the x+1-th cluster type to the vector space.

[0116] The description table creation step may further include a step of inputting information of the x-th vector and information of the x+1-th vector into the description table and assigning an index of a cluster type.

[0117] The mapping table creation step may further include a step of initializing the mapping table and inputting an index of a cluster type corresponding to the primary index of the mapping table.

[0118] Optionally, the step of generating the clustering type table may further include the step of adding assets of the m characteristic group to the clustering type table, sorting them by IP, and assigning a clustering type index to the assets within the clustering type table using a mapping table.

[0119] Optionally, the description table may further include a step of updating asset information of the first to x+1th cluster types.

[0120] Figure 10 is a schematic diagram illustrating a footprint table according to one embodiment of the present invention. The footprint table cumulatively stores information from the mapping table. It facilitates a more intuitive understanding of relationships between cluster types and is configured to facilitate more efficient future asset searches. Specifically, the footprint table records the history of assets belonging to cluster type 1, changing to cluster type 2, and then to cluster type 9, for example.

[0121] Figure 11 is a diagram illustrating the effectiveness of a clustering classification method for assets according to the present invention. The numbers recorded in the first row represent characteristic groups, and the numbers within the circles represent cluster types. Figure 11 represents the overall cluster type generation process. If there are four characteristics, up to 15 cluster types can be generated. Furthermore, a line connecting a relationship indicates inclusion of the corresponding characteristic. In a specific example, cluster type 5 is connected by a line to characteristic groups 1 and 2, indicating that cluster type 5 includes characteristics 1, 2, and 3. Cluster type 7 includes only characteristic 3. In a conventional case, if there are 15 cluster types, finding assets belonging to a specific cluster type required comparing all types 1 through 15. However, when classifying cluster types according to the present invention, assets belonging to a specific cluster type can be found with just 3 to 4 searches, as shown in Figure 11, thereby improving search efficiency.

[0122] In another embodiment of the present invention, there may be a computer-readable recording medium having recorded thereon a program for executing an asset clustering classification method.

[0123]

[0124] Hereinafter, embodiments of the present disclosure have been described. In the above description, the components constituting the computing device illustrated in FIG. 1 may be implemented as modules. A module refers to software or hardware components such as a Field Programmable Gate Array (FPGA) or an Application Specific Integrated Circuit (ASIC), and the module performs certain roles. However, the module is not limited to software or hardware. The module may be configured to reside on an addressable storage medium or may be configured to execute one or more processors.

[0125] Thus, as an example, a module may include components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuitry, data, databases, data structures, tables, arrays, and variables. The functionality provided by components and modules may be combined into a smaller number of components and modules or further separated into additional components and modules.

[0126] Meanwhile, the disclosed embodiments may be implemented in the form of a recording medium storing computer-executable instructions. The instructions may be stored in the form of program code, and when executed by a processor, may generate program modules to perform the operations of the disclosed embodiments. The recording medium may be implemented as a computer-readable recording medium.

[0127] Computer-readable recording media include all types of recording media that store instructions that can be deciphered by a computer. Examples include read-only memory (ROM), random access memory (RAM), magnetic tape, magnetic disk, flash memory (200), and optical data storage devices.

[0128] Additionally, a computer-readable recording medium may be provided in the form of a non-transitory storage medium. Here, the term "non-transitory storage medium" simply means a tangible device that does not contain signals (e.g., electromagnetic waves). This term does not distinguish between cases where data is permanently stored in the storage medium and cases where data is temporarily stored. For example, a "non-transitory storage medium" may include a buffer in which data is temporarily stored.

[0129] According to one embodiment, the method according to the various embodiments disclosed in the present document may be provided as included in a computer program product. The computer program product may be traded as a product between a seller and a buyer. The computer program product may be distributed in the form of a machine-readable recording medium (e.g., compact disc read only memory (CD-ROM)), or distributed directly between two user devices (e.g., smartphones) via an application store (e.g., Play Store™), or distributed online (e.g., downloaded or uploaded). In the case of online distribution, at least a portion of the computer program product (e.g., downloadable app) may be temporarily stored or temporarily generated on a machine-readable recording medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.

[0130] The embodiments of the present disclosure have been described with reference to the above and the attached drawings. Those skilled in the art will appreciate that the present disclosure can be implemented in other specific forms without altering the technical spirit or essential features thereof. Therefore, the embodiments described above should be understood to be illustrative in all respects and not restrictive.

Claims

1. In a clustering classification method of characteristic-based assets, A step of classifying assets by characteristics to create at least one characteristic group; A clustering sample generation step for generating cluster types including at least one characteristic and classifying the assets according to the cluster types; A step of storing the above clustered sample in a database; The above clustering sample generation step is; A step of adding data of the above cluster type to a vector space; A step of generating a description table including information of the above vector space and information of the above asset; A mapping table generation step including mapping information corresponding to the primary index to classify the above assets according to the cluster type; A step of creating a footprint table that stores accumulated data of the above mapping table; A step of creating a clustering type table that adds assets of a characteristic group by sorting them based on IP and matches the cluster type to the assets using the mapping information; including; A method for classifying asset clusters.

2. In paragraph 1, The above clustering sample generation step is; A first vector input step of classifying assets included in the first characteristic group into a first cluster type and adding data of the first cluster type to the vector space; A step of creating a clustering type table that sorts assets of the above first characteristic group based on IP and matches the cluster type to the assets using the mapping information; comprising a step of updating asset information of the first cluster type in the description table; A method for classifying asset clusters.

3. In paragraph 2, A step of classifying assets included in both the first characteristic group and the second characteristic group into a second cluster type, and classifying assets included in the second characteristic group but not included in the first characteristic group into a third cluster type; further comprising; The above clustering sample generation step is; Further comprising a second vector and a third vector input step for adding data of the second cluster type and the third cluster type to the vector space; The above description table creation step is: A step of inputting information on the vector space of the second vector and the third vector into the description table; The above mapping table creation step is: A step of initializing the above mapping table and inputting mapping information corresponding to the first index of the above mapping table; The steps for generating the above clustering type table are: A step of adding assets of the second characteristic group to the clustering type table, sorting them based on IP, and matching the cluster type to assets in the clustering type table using the mapping table; Further comprising a step of updating asset information of the first cluster type to the third cluster type in the description table; A method for classifying asset clusters.

4. In paragraph 3, A third characteristic group cluster type classification step, which further includes a third characteristic group cluster type classification step, wherein assets included in at least one of the first and second characteristic groups among the assets included in the third characteristic group are each classified into a separate cluster type, and assets included in the third characteristic group but not included in the first and second characteristic groups are classified into a separate cluster type; The above clustering sample generation step is; A fourth vector input step of adding data of the cluster type classified in the cluster type classification step of the third characteristic group to the above vector space; The above description table creation step is: Further comprising a step of inputting vector space information of the fourth vector into the description table; The steps for generating the above clustering type table are: A step of adding assets of the third characteristic group to the clustering type table and sorting them based on IP, and matching the cluster type to assets in the clustering type table using the mapping table; further comprising; comprising a step of updating asset information in the above description table; A method for classifying asset clusters.

5. In paragraph 2, The information of the above vector space is, Contains offset information and length information of the above vector, The above asset information is, Contains information on the number of assets, A method for classifying asset clusters.

6. In paragraph 1, The above footprint table creation step is: A step of generating cluster type data corresponding to each characteristic group by using accumulated data of the above mapping table; further comprising; A method for classifying asset clusters.

7. In paragraph 3, The second and third vector input steps are as follows: A step of copying the first vector and inputting a second vector by adding data of the second characteristic group; A step of inputting a third vector by copying data of the second characteristic group; A method for classifying asset clusters.

8. In paragraph 1, The information of the above vector space is, Contains the length information of the above vector, The length of the above vector is, characterized in that it corresponds to the number of characteristics included in the above cluster type, A method for classifying asset clusters.

9. In paragraph 1, The above clustering sample generation step is; Characterized in that a clustering sample is generated by sequentially adding the above characteristic groups. A method for classifying asset clusters.

10. A computer-readable recording medium having recorded thereon a program for executing a method according to any one of claims 1 to 8 on a computer.

11. A computing device for classifying assets into cluster types based on the characteristics of the assets, A transceiver unit for obtaining asset information and characteristic information of said asset; and A processor configured to generate a clustering sample by classifying the assets according to cluster types using the above information; A memory for storing the above clustered sample; The above processor, Classifying the above assets by characteristics to create at least one characteristic group, creating a cluster type to include at least one characteristic, and classifying the above assets by the cluster type to create a clustered sample. The above processor A method for classifying an asset by a cluster type, comprising: adding data of the above cluster type to a vector space, generating a description table including information of the vector space of the data, generating a mapping table including mapping information corresponding to a primary index to classify the asset by the cluster type, generating a footprint table storing accumulated data of the mapping table, sequentially adding the characteristic group to a clustering type table, matching the asset of the added characteristic group with the cluster type using the mapping information and adding it to the clustering type table, and adding information of the asset belonging to the cluster type to the description table. Computing device.

Citation Information

Patent Citations

  • User Interface Providing Method in Home Network System

    KR1020030062735A

  • Real-time identification of an asset model and categorization of an asset to assist in computer network security

    KR1020090061627A

  • Method of providing virtual arrangement services for event facilities and server

    KR102073891B1

  • Artificial Intelligence-Based Security Event Analysis System and Its Method Using Semi-Supervised Machine Learning

    KR102089688B1

  • Method for Classifying Network Asset Using Network Flow data and Method for Detecting Threat to the Network Asset Classified by the Same Method

    KR102244036B1