WO2023108832A1 - 网络空间地图生成方法、装置、设备及存储介质 - Google Patents

网络空间地图生成方法、装置、设备及存储介质 Download PDF

Info

Publication number
WO2023108832A1
WO2023108832A1 PCT/CN2021/143644 CN2021143644W WO2023108832A1 WO 2023108832 A1 WO2023108832 A1 WO 2023108832A1 CN 2021143644 W CN2021143644 W CN 2021143644W WO 2023108832 A1 WO2023108832 A1 WO 2023108832A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
data
surveying
mapping
preset
Prior art date
Application number
PCT/CN2021/143644
Other languages
English (en)
French (fr)
Inventor
周鸿祎
高瀚昭
韩昊晟
陈庆
范君
康浩荣
Original Assignee
三六零科技集团有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 三六零科技集团有限公司 filed Critical 三六零科技集团有限公司
Publication of WO2023108832A1 publication Critical patent/WO2023108832A1/zh

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/20Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
    • G06F16/29Geographical information databases
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/90Details of database functions independent of the retrieved data types
    • G06F16/95Retrieval from the web
    • G06F16/953Querying, e.g. by the use of web search engines
    • G06F16/9537Spatial or temporal dependent retrieval, e.g. spatiotemporal queries
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02DCLIMATE CHANGE MITIGATION TECHNOLOGIES IN INFORMATION AND COMMUNICATION TECHNOLOGIES [ICT], I.E. INFORMATION AND COMMUNICATION TECHNOLOGIES AIMING AT THE REDUCTION OF THEIR OWN ENERGY USE
    • Y02D10/00Energy efficient computing, e.g. low power processors, power management or thermal management

Definitions

  • the present invention relates to the technical field of data processing, in particular to a method, device, equipment and storage medium for generating a network space map.
  • the main purpose of the present invention is to provide a network space map generation method, device, equipment and storage medium, aiming to solve the technical problem of how to accurately obtain the network space map and manage the network space based on the network space map.
  • the present invention provides a method for generating a cyberspace map, the method for generating a cyberspace map includes the following steps:
  • the surveying and mapping data to be processed is collected according to the detection task;
  • a network space map is generated based on the network topology graph.
  • the step of collecting surveying and mapping data to be processed according to the detection task when receiving the detection task sent by the task scheduling includes:
  • the step of selecting surveying and mapping data to be processed from a plurality of initial surveying and mapping data according to a preset surveying and mapping strategy includes:
  • the surveying and mapping data to be processed are determined from the plurality of surveying and mapping data to be confirmed according to the data format information.
  • the step of determining the surveying and mapping data to be processed from a plurality of surveying and mapping data to be confirmed according to the data format information includes:
  • the surveying and mapping data to be processed is determined according to the plurality of surveying and mapping data to be confirmed.
  • the step of judging whether the data format information satisfies a preset format condition it further includes:
  • the surveying and mapping data to be processed is selected from the plurality of surveying and mapping data to be confirmed according to the preset format condition.
  • the step of mapping the multi-dimensional data across layers to corresponding preset network layers, so as to obtain network data corresponding to each preset network layer includes:
  • the multi-dimensional data is cross-layer mapped to corresponding preset network layers according to the identification information, so as to obtain network data corresponding to each preset network layer.
  • the step of mapping the multi-dimensional data across layers to corresponding preset network layers according to the identification information, so as to obtain network data corresponding to each preset network layer includes:
  • the step of classifying the multi-dimensional data according to the identification information to obtain multiple target network layer data includes:
  • the step of generating a cyberspace map based on the network topology map includes:
  • a cyberspace map is generated based on the cyberspace coordinate system.
  • step of generating a cyberspace map based on the cyberspace coordinate system it further includes:
  • the step of viewing corresponding cyberspace asset information through the cyberspace map according to the network data retrieval keywords includes:
  • the present invention also proposes a network space map generation device, the network space map generation device includes:
  • the collection module is configured to collect surveying and mapping data to be processed according to the detection task when receiving the detection task sent by the task scheduling;
  • An associating module configured to associate the target surveying and mapping data in the preset database with the surveying and mapping data to be processed, so as to obtain multi-dimensional data
  • a mapping module configured to map the multi-dimensional data to corresponding preset network layers across layers, so as to obtain network data corresponding to each preset network layer;
  • a construction module configured to construct a network topology diagram according to network data corresponding to each preset network layer
  • a generating module configured to generate a network space map based on the network topology graph.
  • the collection module is further configured to, when receiving a detection task sent by task scheduling, determine detection keywords according to the detection task;
  • the collection module is also used to collect a plurality of initial surveying and mapping data according to the detection keywords;
  • the acquisition module is further configured to select surveying and mapping data to be processed from a plurality of initial surveying and mapping data according to a preset surveying and mapping strategy.
  • mapping module is also used to obtain identification information corresponding to each multi-dimensional data
  • the mapping module is further configured to map the multi-dimensional data to corresponding preset network layers across layers according to the identification information, so as to obtain network data corresponding to each preset network layer.
  • mapping module is further configured to classify the multi-dimensional data according to the identification information, so as to obtain multiple target network layer data;
  • the mapping module is also used to map multiple target network layer data across layers to corresponding preset network layers, so as to obtain network data corresponding to each preset network layer.
  • the generating module is further configured to determine the Internet Protocol address and network geographic location information corresponding to the network topology diagram;
  • the generating module is further configured to construct a network space coordinate system according to the Internet protocol address and the network geographic location information;
  • the generating module is further configured to generate a cyberspace map based on the cyberspace coordinate system.
  • the cyberspace map generation device further includes a search module
  • the search module is configured to determine network data retrieval keywords according to the proactive surveying and mapping command when receiving the proactive surveying and mapping command;
  • the search module is further configured to view corresponding cyberspace asset information through the cyberspace map according to the network data retrieval keywords.
  • the search module is further configured to determine network location information according to the network data retrieval keywords
  • the search module is further configured to determine a network asset area from the network space map according to the network location information;
  • the search module is further configured to determine cyberspace asset information corresponding to the network asset area based on the cyberspace map.
  • the present invention also proposes a cyberspace map generation device, which includes: a memory, a processor, and a cyberspace map generation program stored in the memory and operable on the processor , the cyberspace map generation program is configured to implement the steps of the method for generating a cyberspace map as described above.
  • the present invention also proposes a storage medium on which a cyberspace map generation program is stored, and when the cyberspace map generation program is executed by a processor, the cyberspace map as described above is realized. The steps to generate the method.
  • the present invention When the present invention receives the detection task sent by task scheduling, it first collects the surveying and mapping data to be processed according to the detection task, and associates the target surveying and mapping data in the preset database with the surveying and mapping data to be processed to obtain multi-dimensional data, and then Dimension data is cross-layer mapped to the corresponding preset network layer to obtain the network data corresponding to each preset network layer, and then construct a network topology diagram based on the network data corresponding to each preset network layer, and finally generate a network based on the network topology diagram spatial map.
  • the multi-dimensional data corresponding to the detection task can be cross-layer mapped to the corresponding preset network layer, and then A network space map is generated according to network data corresponding to each preset network layer, thereby implementing network space management based on the network space map, thereby improving user experience.
  • Fig. 1 is a schematic structural diagram of a network space map generating device of a hardware operating environment involved in the solution of an embodiment of the present invention
  • Fig. 2 is a schematic flow chart of the first embodiment of the method for generating a cyberspace map of the present invention
  • FIG. 3 is a schematic diagram of the network topology structure of the first embodiment of the method for generating a network space map according to the present invention
  • FIG. 4 is a schematic flow diagram of the second embodiment of the method for generating a cyberspace map of the present invention.
  • Fig. 5 is a structural block diagram of the first embodiment of the network space map generation device of the present invention.
  • FIG. 1 is a schematic structural diagram of a network space map generation device of a hardware operating environment involved in an embodiment of the present invention.
  • the network space map generating device may include: a processor 1001, such as a central processing unit (Central Processing Unit, CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005.
  • the communication bus 1002 is used to realize connection and communication between these components.
  • the user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the optional user interface 1003 may also include a standard wired interface and a wireless interface.
  • the network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a wireless fidelity (WIreless-FIdelity, WI-FI) interface).
  • the memory 1005 may be a high-speed random access memory (Random Access Memory, RAM) memory, or a stable non-volatile memory (Non-Volatile Memory, NVM), such as a disk memory.
  • RAM Random Access Memory
  • NVM Non-Volatile Memory
  • the memory 1005 may also be a storage device independent of the aforementioned processor 1001 .
  • Figure 1 does not constitute a limitation to the network space map generation device, and may include more or less components than those shown in the illustration, or combine certain components, or arrange different components .
  • the memory 1005 as a storage medium may include an operating system, a data storage module, a network communication module, a user interface module, and a network space map generation program.
  • the network interface 1004 is mainly used for data communication with the network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 in the network space map generation device of the present invention .
  • the memory 1005 can be set in the cyberspace map generation device, and the cyberspace map generation device calls the cyberspace map generation program stored in the memory 1005 through the processor 1001, and executes the cyberspace map generation method provided by the embodiment of the present invention.
  • FIG. 2 is a schematic flowchart of a first embodiment of the method for generating a cyberspace map according to the present invention.
  • the method for generating a cyberspace map includes the following steps:
  • Step S10 When receiving the detection task sent by the task scheduling, collect the surveying and mapping data to be processed according to the detection task.
  • the execution subject of this embodiment may be a network space map generation device with functions such as image processing, data processing, network communication, and program operation, or other computer devices with similar functions. This embodiment does not be restricted.
  • a distributed cluster and scheduling system of surveying and mapping nodes can be built, and then detection tasks can be issued through task scheduling. It should be noted that the detection tasks can be to collect network asset information corresponding to a certain location or a certain unit.
  • the surveying and mapping data to be processed are multiple surveying and mapping data collected through the big data platform according to the detection tasks.
  • the big data platform is a data platform pre-built by the user, and the big data platform can collect and process the collected surveying and mapping data.
  • the step of collecting the surveying and mapping data to be processed according to the detection task may be to determine the detection keyword according to the detection task when the detection task sent by the task scheduling is received, and then according to the detection keyword Collect multiple initial surveying and mapping data, and select the surveying and mapping data to be processed from the multiple initial surveying and mapping data according to a preset surveying and mapping strategy.
  • the detection keyword can also be understood as the surveying and mapping data search term corresponding to the detection task.
  • the multiple initial surveying and mapping data are the initial surveying and mapping data related to the detection keywords collected through the big data platform, and the preset surveying and mapping strategy can be customized by the user, and all the collected initial surveying and mapping data can be used as the surveying and mapping data to be processed , it is also possible to select the surveying and mapping data to be processed from a plurality of initial surveying and mapping data according to user requirements.
  • the step of selecting the surveying and mapping data to be processed from the multiple initial surveying and mapping data according to the preset surveying and mapping strategy is to select a plurality of surveying and mapping data to be confirmed from the multiple initial surveying and mapping data according to the preset surveying and mapping strategy, and then obtain each surveying and mapping data to be confirmed The corresponding data format information, and then determine the surveying and mapping data to be processed from the plurality of surveying and mapping data to be confirmed according to the data format information.
  • the processing method of determining the surveying and mapping data to be processed from a plurality of surveying and mapping data to be confirmed can be to judge whether the data format information meets the preset format conditions, and when the data format information meets the preset When setting format conditions, determine the surveying and mapping data to be processed according to multiple surveying and mapping data to be confirmed; when the data format information does not meet the preset format conditions, select the surveying and mapping data to be processed from multiple surveying and mapping data to be processed according to the preset format conditions, wherein
  • the preset format condition is that there is no garbled format or user-defined format information, etc.
  • the plurality of surveying and mapping data to be confirmed are respectively the test data to be confirmed A, the test data to be confirmed B, and the test data to be confirmed C
  • the format information corresponding to A is 1
  • the surveying and mapping data corresponding to B is 1
  • the format information corresponding to C is 1, and the corresponding format information in the preset format condition is 1, then the test data A to be confirmed, the test data B to be confirmed, and the test data C to be confirmed are taken as the surveying and mapping data to be processed;
  • Step S20 Associating the target surveying and mapping data in the preset database with the surveying and mapping data to be processed to obtain multi-dimensional data.
  • the exascale big data is introduced into the preset database, that is, the target surveying and mapping data, and then the corresponding exascale big data in the preset database can be associated with the surveying and mapping data to be processed to obtain multi-dimensional data.
  • the multi-dimensional data may be real entity dimensional data, geographic location dimensional data, physical link dimensional data, network entity dimensional data, logical network dimensional data, and the like.
  • the associated data corresponding to the surveying and mapping data to be processed is searched from the preset database, and the obtained associated data is used as multi-dimensional data.
  • the associated data includes The actual entity data, geographic location data, physical link data, network entity data and logical network data corresponding to the surveying and mapping data D to be processed.
  • real entity data includes companies or units with similar business behaviors
  • geographic location data includes latitude and longitude, country, province, city, or region, etc.
  • physical link data includes operator optical cables or large topologies, etc.
  • logical network data Including Internet Protocol (Internet Protocol, IP) addresses or certificates, etc.
  • network entity data includes product or application information, operating system, computing power, network entity layer labels or firmware, etc.
  • Step S30 Map the multi-dimensional data to corresponding preset network layers across layers, so as to obtain network data corresponding to each preset network layer.
  • the preset network layer is a network layer customized by the user, and the network layer includes a real entity layer, a geographic location layer, a physical link layer, a logical network layer, and a network entity layer.
  • the step of mapping multi-dimensional data to corresponding preset network layers across layers to obtain network data corresponding to each preset network layer may be to obtain identification information corresponding to each multi-dimensional data, and then map the multi-dimensional data according to the identification information
  • the data is cross-layer mapped to corresponding preset network layers, so as to obtain network data corresponding to each preset network layer.
  • the identification information may be a geographical identification, and may also be a device identification or the like.
  • the multi-dimensional data is mapped across layers to the corresponding preset network layer according to the identification information, so as to obtain the network data corresponding to each preset network layer.
  • the processing method may be to classify the multi-dimensional data according to the identification information, A plurality of target network layer data is obtained, and then the plurality of target network layer data are cross-layer mapped to corresponding preset network layers, so as to obtain network data corresponding to each preset network layer.
  • the processing method of classifying multi-dimensional data according to identification information to obtain multiple target network layer data may be to classify multi-dimensional data according to identification information to obtain multiple initial network layer data, and then follow the preset
  • the network layer rule selects a plurality of target network layer data from a plurality of initial network layer data.
  • the preset network layer rule may be selecting target network layer data according to user interests, and the like.
  • Step S40 Construct a network topology structure diagram according to the network data corresponding to each preset network layer.
  • the preset network layer can set a preset number of network layers for users, which can be 5 different network layers, and can also be 6 different network layers, and there is an association between each network layer relationship etc.
  • the network topology diagram can understand the topology diagram constructed by different preset network layers and network data corresponding to the preset network layers.
  • Fig. 3 is the schematic diagram of the network topology structure of the first embodiment of the method for generating a cyberspace map of the present invention, including Y, U, I, O, P in Fig. 3, wherein Y is the real entity layer, and U is the geographic location layer , I is the physical link layer, O is the logical network layer, and P is the network entity layer. It should also be noted that the relationship between the actual entity layer and the geographic location layer is that the actual entity layer exists in the geographic location layer, and the geographic location layer It is interdependent with the physical link layer, and the logical network layer is attached to the physical link layer.
  • the logical network layer can check the geographic location layer through the Smart Living Group (SLG), mapping or geographic location, and the network entity The layer and the logical network layer are interdependent.
  • the network entity layer provides services to the real entity layer.
  • the real entity layer includes the name of the company or unit with similar business behavior.
  • the real entity layer also includes the information of the person in charge. Including latitude and longitude, continents, countries, provinces, districts and counties, streets, regions and distances, etc.
  • the physical link layer includes operators' optical cables (according to the actual geographical laying conditions), etc.
  • the logical network layer includes IP address routing to connect to topology and Certificates, etc.
  • the network entity layer includes product or application information (type, category, manufacturer, level, and model), operating system, computing power (terminal, process, memory, and central processing unit), network entity layer labels (content distribution network, Internet data centers and harmful) and firmware, etc.
  • Step S50 Generate a network space map based on the network topology map.
  • the network space map is a space map corresponding to searching specific location information or network asset information corresponding to a specific unit.
  • the step of generating the network space map based on the network topology structure diagram may be to determine the Internet Protocol address and network geographic location information corresponding to the network topology structure diagram, construct a network space coordinate system according to the Internet Protocol address and network geographic location information, and then based on the network
  • the spatial coordinate system generates a network spatial map.
  • the cyberspace map can help users realize active detection of cyberspace risks, early warning, support network security situational awareness, trace the source of advanced threats, and continuously update network security risks.
  • the cyberspace map is similar to the daily map, but in the cyberspace map, the corresponding network topology structure diagram and the like can be viewed in the cyberspace map according to the Internet Protocol address or network geographic location information.
  • the user can send an active surveying and mapping command in the cyberspace map.
  • the surveying and mapping instructions determine the network data retrieval keywords, and then view the corresponding cyberspace asset information through the network space map according to the network data retrieval keywords.
  • the network data retrieval keyword may be a word extracted from an active surveying and mapping instruction, such as a certain region.
  • the processing method of checking the corresponding cyberspace asset information through the network space map for detecting keywords based on network data can be to determine the network location information based on network data retrieval keywords, and then determine the network location information from the network space map according to the network location information. For the network asset area, determine the cyberspace asset information corresponding to the network asset area based on the network space map.
  • the network positioning information is unit F
  • the surveying and mapping data to be processed is first collected according to the detection task, and the target surveying and mapping data in the preset database is associated with the surveying and mapping data to be processed to obtain multi-dimensional data , and then map the multi-dimensional data to the corresponding preset network layer across layers to obtain the network data corresponding to each preset network layer, and then construct a network topology structure diagram based on the network data corresponding to each preset network layer, and finally based on the network topology Structural graphs generate cyberspace maps.
  • the multi-dimensional data corresponding to the detection task can be cross-layer mapped to the corresponding preset network layer, and then A network space map is generated according to network data corresponding to each preset network layer, thereby implementing network space management based on the network space map, thereby improving user experience.
  • FIG. 4 is a schematic flowchart of a second embodiment of a method for generating a cyberspace map according to the present invention.
  • the step S30 includes:
  • Step S301 Obtain identification information corresponding to each multi-dimensional data.
  • the multi-dimensional data can be analyzed separately to obtain the keywords corresponding to each multi-dimensional data, and then the corresponding identification information can be determined according to the keywords.
  • the identification information can be geographic identification information, or real entity identification information, etc. .
  • Step S302 Map the multi-dimensional data across layers to corresponding preset network layers according to the identification information, so as to obtain network data corresponding to each preset network layer.
  • the preset network layer is a network layer customized by the user, and the network layer includes a real entity layer, a geographic location layer, a physical link layer, a logical network layer, and a network entity layer.
  • the big data platform can also be used to perform cross-layer mapping on multi-dimensional data.
  • Cross-layer mapping means that the surveying and mapping data in virtual space is divided into real entity layer, geographic location layer, physical link layer, logical network layer, At different levels such as the network entity layer, data at different levels need to be related to each other, such as a server, what operating system it has, open application services, which unit it belongs to, what domain name it has, what its IP address is, and what routing it has relationship, where is the geographic location, etc., among which cross-layer mapping is the basic data analysis work of map drawing.
  • the processing method of classifying the multi-dimensional data according to the identification information to obtain multiple target network layer data may be to classify the multi-dimensional data according to the identification information to obtain multiple initial network layer data, and then according to the preset
  • the network layer rule selects a plurality of target network layer data from a plurality of initial network layer data.
  • the preset network layer rule may be selecting target network layer data according to user interests, and the like.
  • the multi-dimensional data are Q, W, E, R, T respectively, Q is a geographic identifier, W is a geographic identifier, E is a real entity identifier, R is a real entity identifier, and T is a physical link identifier, then the data Q and W is divided into one category, the data E and R are divided into one category, and the data T is one category. Then, the data Q and W are mapped to the geographic location layer across layers, and the data E and R are mapped to the real entity layer across layers. The data T is mapped to the physical link layer across layers, where the network data corresponding to the geographic location layer are Q and W, the network data corresponding to the real entity layer are E and R, and the network data corresponding to the physical link layer is T, etc.
  • the multi-dimensional data first obtain the identification information corresponding to each multi-dimensional data, and then map the multi-dimensional data to the corresponding preset network layer across layers according to the identification information, so as to obtain the network data corresponding to each preset network layer.
  • the obtained multi-dimensional data is directly stored in the database, which is inconvenient for the user to quickly search for the corresponding network data.
  • the multi-dimensional data is mapped to the corresponding preset network layer across layers. Thus, it is convenient for the user to quickly find the network data of interest.
  • FIG. 5 is a structural block diagram of a first embodiment of an apparatus for generating a network space map according to the present invention.
  • the network space map generation device proposed by the embodiment of the present invention includes:
  • the collection module 5001 is configured to collect surveying and mapping data to be processed according to the detection task when receiving the detection task sent by the task scheduling.
  • a distributed cluster and scheduling system of surveying and mapping nodes can be built, and then detection tasks can be issued through task scheduling. It should be noted that the detection tasks can be to collect network asset information corresponding to a certain location or a certain unit.
  • the surveying and mapping data to be processed are multiple surveying and mapping data collected through the big data platform according to the detection tasks.
  • the big data platform is a data platform pre-built by the user, and the big data platform can collect and process the collected surveying and mapping data.
  • the step of collecting the surveying and mapping data to be processed according to the detection task may be to determine the detection keyword according to the detection task when the detection task sent by the task scheduling is received, and then according to the detection keyword Collect multiple initial surveying and mapping data, and select the surveying and mapping data to be processed from the multiple initial surveying and mapping data according to a preset surveying and mapping strategy.
  • the detection keyword can also be understood as the surveying and mapping data search term corresponding to the detection task.
  • the multiple initial surveying and mapping data are the initial surveying and mapping data related to the detection keywords collected through the big data platform, and the preset surveying and mapping strategy can be customized by the user, and all the collected initial surveying and mapping data can be used as the surveying and mapping data to be processed , it is also possible to select the surveying and mapping data to be processed from a plurality of initial surveying and mapping data according to user requirements.
  • the step of selecting the surveying and mapping data to be processed from the multiple initial surveying and mapping data according to the preset surveying and mapping strategy is to select a plurality of surveying and mapping data to be confirmed from the multiple initial surveying and mapping data according to the preset surveying and mapping strategy, and then obtain each surveying and mapping data to be confirmed The corresponding data format information, and then determine the surveying and mapping data to be processed from the plurality of surveying and mapping data to be confirmed according to the data format information.
  • the processing method of determining the surveying and mapping data to be processed from a plurality of surveying and mapping data to be confirmed can be to judge whether the data format information meets the preset format conditions, and when the data format information meets the preset When setting format conditions, determine the surveying and mapping data to be processed according to multiple surveying and mapping data to be confirmed; when the data format information does not meet the preset format conditions, select the surveying and mapping data to be processed from multiple surveying and mapping data to be processed according to the preset format conditions, wherein
  • the preset format condition is that there is no garbled format or user-defined format information, etc.
  • the plurality of surveying and mapping data to be confirmed are respectively the test data to be confirmed A, the test data to be confirmed B, and the test data to be confirmed C
  • the format information corresponding to A is 1
  • the surveying and mapping data corresponding to B is 1
  • the format information corresponding to C is 1, and the corresponding format information in the preset format condition is 1, then the test data A to be confirmed, the test data B to be confirmed, and the test data C to be confirmed are taken as the surveying and mapping data to be processed;
  • the associating module 5002 is configured to associate the target surveying and mapping data in the preset database with the surveying and mapping data to be processed, so as to obtain multi-dimensional data.
  • the exascale big data is introduced into the preset database, that is, the target surveying and mapping data, and then the corresponding exascale big data in the preset database can be associated with the surveying and mapping data to be processed to obtain multi-dimensional data.
  • the multi-dimensional data may be real entity dimensional data, geographic location dimensional data, physical link dimensional data, network entity dimensional data, logical network dimensional data, and the like.
  • the associated data corresponding to the surveying and mapping data to be processed is searched from the preset database, and the obtained associated data is used as multi-dimensional data.
  • the associated data includes The actual entity data, geographic location data, physical link data, network entity data and logical network data corresponding to the surveying and mapping data D to be processed.
  • real entity data includes companies or units with similar business behaviors
  • geographic location data includes latitude and longitude, country, province, city, or region, etc.
  • physical link data includes operator optical cables or large topologies, etc.
  • logical network data Including IP addresses or certificates, etc.
  • network entity data includes product or application information, operating system, computing power, network entity layer labels or firmware, etc.
  • the mapping module 5003 is configured to map the multi-dimensional data to corresponding preset network layers across layers, so as to obtain network data corresponding to each preset network layer.
  • the preset network layer is a network layer customized by the user, and the network layer includes a real entity layer, a geographic location layer, a physical link layer, a logical network layer, and a network entity layer.
  • the step of mapping multi-dimensional data to corresponding preset network layers across layers to obtain network data corresponding to each preset network layer may be to obtain identification information corresponding to each multi-dimensional data, and then map the multi-dimensional data according to the identification information
  • the data is cross-layer mapped to corresponding preset network layers, so as to obtain network data corresponding to each preset network layer.
  • the identification information may be a geographical identification, and may also be a device identification or the like.
  • the multi-dimensional data is mapped across layers to the corresponding preset network layer according to the identification information, so as to obtain the network data corresponding to each preset network layer.
  • the processing method may be to classify the multi-dimensional data according to the identification information, A plurality of target network layer data is obtained, and then the plurality of target network layer data are cross-layer mapped to corresponding preset network layers, so as to obtain network data corresponding to each preset network layer.
  • the processing method of classifying multi-dimensional data according to identification information to obtain multiple target network layer data may be to classify multi-dimensional data according to identification information to obtain multiple initial network layer data, and then follow the preset
  • the network layer rule selects a plurality of target network layer data from a plurality of initial network layer data.
  • the preset network layer rule may be selecting target network layer data according to user interests, and the like.
  • a construction module 5004 configured to construct a network topology diagram according to network data corresponding to each preset network layer.
  • the preset network layer can set a preset number of network layers for users, which can be 5 different network layers, and can also be 6 different network layers, and there is an association between each network layer relationship etc.
  • the network topology diagram can understand the topology diagram constructed by different preset network layers and network data corresponding to the preset network layers.
  • Fig. 3 is the schematic diagram of the network topology structure of the first embodiment of the method for generating a cyberspace map of the present invention, including Y, U, I, O, P in Fig. 3, wherein Y is the real entity layer, and U is the geographic location layer , I is the physical link layer, O is the logical network layer, and P is the network entity layer. It should also be noted that the relationship between the actual entity layer and the geographic location layer is that the actual entity layer exists in the geographic location layer, and the geographic location layer Interdependence with the physical link layer.
  • the logical network layer is attached to the physical link layer.
  • the logical network layer can check the geographic location layer through SLG, mapping, or geographic location.
  • the network entity layer and the logical network layer are interdependent.
  • the network The entity layer provides services to the real entity layer.
  • the real entity layer includes the names of enterprises or units with similar business behaviors.
  • the real entity layer also includes the person in charge information.
  • the geographic location layer includes latitude and longitude, continent, country, province, city, district Counties, streets, regions and distances, etc.
  • the physical link layer includes operators' optical cables (according to the actual geographical laying conditions), etc.
  • the logical network layer includes IP address routing connections to topology and certificates, etc.
  • the network entity layer includes products or applications Information (type, category, manufacturer, tier, and model), operating system, computing power (terminal, process, memory, and CPU), network physical layer labels (content distribution network, Internet data center, and harmful), and firmware, etc.
  • a generation module 5005 configured to generate a network space map based on the network topology diagram.
  • the network space map is a space map corresponding to searching specific location information or network asset information corresponding to a specific unit.
  • the step of generating the network space map based on the network topology structure diagram may be to determine the Internet Protocol address and network geographic location information corresponding to the network topology structure diagram, construct a network space coordinate system according to the Internet Protocol address and network geographic location information, and then based on the network
  • the spatial coordinate system generates a network spatial map.
  • the cyberspace map can help users realize active detection of cyberspace risks, early warning, support network security situational awareness, trace the source of advanced threats, and continuously update network security risks.
  • the cyberspace map is similar to the daily map, but in the cyberspace map, the corresponding network topology structure diagram and the like can be viewed in the cyberspace map according to the Internet Protocol address or network geographic location information.
  • the user can send an active surveying and mapping command in the cyberspace map.
  • the surveying and mapping instructions determine the network data retrieval keywords, and then view the corresponding cyberspace asset information through the network space map according to the network data retrieval keywords.
  • the network data retrieval keyword may be a word extracted from an active surveying and mapping instruction, such as a certain region.
  • the processing method of checking the corresponding cyberspace asset information through the network space map for detecting keywords based on network data can be to determine the network location information based on network data retrieval keywords, and then determine the network location information from the network space map according to the network location information. For the network asset area, determine the cyberspace asset information corresponding to the network asset area based on the network space map.
  • the network positioning information is unit F
  • the surveying and mapping data to be processed is first collected according to the detection task, and the target surveying and mapping data in the preset database is associated with the surveying and mapping data to be processed to obtain multi-dimensional data , and then map the multi-dimensional data to the corresponding preset network layer across layers to obtain the network data corresponding to each preset network layer, and then construct a network topology structure diagram based on the network data corresponding to each preset network layer, and finally based on the network topology Structural graphs generate cyberspace maps.
  • the multi-dimensional data corresponding to the detection task can be cross-layer mapped to the corresponding preset network layer, and then A network space map is generated according to network data corresponding to each preset network layer, thereby implementing network space management based on the network space map, thereby improving user experience.
  • the acquisition module 5001 is further configured to determine the detection keyword according to the detection task when receiving the detection task sent by the task scheduling;
  • the collection module 5001 is further configured to collect a plurality of initial surveying and mapping data according to the detection keywords;
  • the collection module 5001 is further configured to select surveying and mapping data to be processed from a plurality of initial surveying and mapping data according to a preset surveying and mapping strategy.
  • mapping module 5003 is also used to obtain identification information corresponding to each multi-dimensional data
  • the mapping module 5003 is further configured to map the multi-dimensional data to corresponding preset network layers across layers according to the identification information, so as to obtain network data corresponding to each preset network layer.
  • mapping module 5003 is further configured to classify the multi-dimensional data according to the identification information, so as to obtain multiple target network layer data;
  • the mapping module 5003 is further configured to cross-layer map multiple target network layer data to corresponding preset network layers, so as to obtain network data corresponding to each preset network layer.
  • the generation module 5005 is also used to determine the Internet Protocol address and network geographic location information corresponding to the network topology diagram;
  • the generating module 5005 is further configured to construct a network space coordinate system according to the Internet protocol address and the network geographic location information;
  • the generating module 5005 is further configured to generate a cyberspace map based on the cyberspace coordinate system.
  • the network space map generation device also includes a search module
  • the search module is configured to determine network data retrieval keywords according to the proactive surveying and mapping command when receiving the proactive surveying and mapping command;
  • the search module is further configured to view corresponding cyberspace asset information through the cyberspace map according to the network data retrieval keywords.
  • search module is also used to determine network positioning information according to the network data retrieval keywords
  • the search module is further configured to determine a network asset area from the network space map according to the network location information;
  • the search module is further configured to determine cyberspace asset information corresponding to the network asset area based on the cyberspace map.
  • the methods of the above embodiments can be implemented by means of software plus a necessary general-purpose hardware platform, and of course also by hardware, but in many cases the former is better implementation.
  • the technical solution of the present invention can be embodied in the form of software products in essence or in other words, the part that contributes to the prior art, and the computer software products are stored in a storage medium (such as read-only memory/random access memory, magnetic disk, optical disk), including several instructions to make a terminal device (which can be a mobile phone, computer, server, air conditioner, or network equipment, etc.) execute the methods described in various embodiments of the present invention.

Landscapes

  • Engineering & Computer Science (AREA)
  • Databases & Information Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Data Mining & Analysis (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Remote Sensing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明涉及数据处理技术领域,公开了一种网络空间地图生成方法、装置、设备及存储介质,所述方法包括:在接收到任务调度发送的探测任务时,根据探测任务采集待处理测绘数据;将预设数据库中的目标测绘数据与待处理测绘数据进行关联,以获得多维度数据;将多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据;根据各预设网络层对应的网络数据构建网络拓扑结构图;基于网络拓扑结构图生成网络空间地图。相较于现有技术中仅获取各个单位的设备信息,而本发明中可以将探测任务对应的多维数据跨层映射至对应的预设网络层,之后根据各预设网络层对应的网络数据生成网络空间地图,从而基于网络空间地图实现网络空间管理。

Description

网络空间地图生成方法、装置、设备及存储介质 技术领域
本发明涉及数据处理技术领域,尤其涉及一种网络空间地图生成方法、装置、设备及存储介质。
背景技术
目前网络空间的治理、管理和安全防护,离不开对网络空间要素的探测认识。但现有技术中仅仅根据网络地址获取对应的操作系统或设备信息,并不能根据获得的操作信息或设备信息进行探测和分析,因此,如何精准获取网络空间地图,并基于网络空间地图对网络空间进行管理是亟待解决的问题。
上述内容仅用于辅助理解本发明的技术方案,并不代表承认上述内容是现有技术。
发明内容
本发明的主要目的在于提供了一种网络空间地图生成方法、装置、设备及存储介质,旨在解决如何精准获取网络空间地图,并基于网络空间地图对网络空间进行管理的技术问题。
为实现上述目的,本发明提供了一种网络空间地图生成方法,所述网络空间地图生成方法包括以下步骤:
在接收到任务调度发送的探测任务时,根据所述探测任务采集待处理测绘数据;
将预设数据库中的目标测绘数据与所述待处理测绘数据进行关联,以获得多维度数据;
将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据;
根据所述各预设网络层对应的网络数据构建网络拓扑结构图;
基于所述网络拓扑结构图生成网络空间地图。
可选地,所述在接收到任务调度发送的探测任务时,根据所述探测任务采集待处理测绘数据的步骤,包括:
在接收到任务调度发送的探测任务时,根据所述探测任务确定探测关键词;
根据所述探测关键词采集多个初始测绘数据;
按照预设测绘策略从多个所述初始测绘数据中选取待处理测绘数据。
可选地,所述按照预设测绘策略从多个所述初始测绘数据中选取待处理测绘数据的步骤,包括:
按照预设测绘策略从多个所述初始测绘数据中选取多个待确认测绘数据;
获取各待确认测绘数据对应的数据格式信息;
根据所述数据格式信息从多个待确认测绘数据中确定待处理测绘数据。
可选地,所述根据所述数据格式信息从多个待确认测绘数据中确定待处理测绘数据的步骤,包括:
判断所述数据格式信息是否满足预设格式条件;
在所述数据格式信息满足所述预设格式条件时,根据多个所述待确认测绘数据确定待处理测绘数据。
可选地,所述判断所述数据格式信息是否满足预设格式条件的步骤之后,还包括:
在所述数据格式信息不满足所述预设格式条件时,根据所述预设格式条件从多个所述待确认测绘数据中选取待处理测绘数据。
可选地,所述将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据的步骤,包括:
获取各多维度数据对应的标识信息;
根据所述标识信息将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
可选地,所述根据所述标识信息将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据的步骤,包括:
根据所述标识信息对所述多维度数据进行分类,以获得多个目标网络层数据;
将多个目标网络层数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
可选地,所述根据所述标识信息对所述多维度数据进行分类,以获得多个目标网络层数据的步骤,包括:
根据所述标识信息对所述多维度数据进行分类,以获得多个初始网络层数据;
按照预设网络层规则从多个初始网络层数据中选取多个目标网络层数据。
可选地,所述基于所述网络拓扑结构图生成网络空间地图的步骤,包括:
确定所述网络拓扑结构图对应的互联网协议地址及网络地理位置信息;
根据所述互联网协议地址及所述网络地理位置信息构建网络空间坐标系;
基于所述网络空间坐标系生成网络空间地图。
可选地,所述基于所述网络空间坐标系生成网络空间地图的步骤之后,还包括:
在接收到主动式测绘指令时,根据所述主动式测绘指令确定网络数据检索关键词;
根据所述网络数据检索关键词通过所述网络空间地图查看对应的网络空间资产信息。
可选地,所述根据所述网络数据检索关键词通过所述网络空间地图查看对应的网络空间资产信息的步骤,包括:
根据所述网络数据检索关键词确定网络定位信息;
根据所述网络定位信息从所述网络空间地图中确定网络资产区域;
基于所述网络空间地图确定所述网络资产区域对应的网络空间资产信息。
此外,为实现上述目的,本发明还提出一种网络空间地图生成装置,所述网络空间地图生成装置包括:
采集模块,用于在接收到任务调度发送的探测任务时,根据所述探测任务采集待处理测绘数据;
关联模块,用于将预设数据库中的目标测绘数据与所述待处理测绘数据进行关联,以获得多维度数据;
映射模块,用于将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据;
构建模块,用于根据所述各预设网络层对应的网络数据构建网络拓扑结构图;
生成模块,用于基于所述网络拓扑结构图生成网络空间地图。
可选地,所述采集模块,还用于在接收到任务调度发送的探测任务时,根据所述探测任务确定探测关键词;
所述采集模块,还用于根据所述探测关键词采集多个初始测绘数据;
所述采集模块,还用于按照预设测绘策略从多个所述初始测绘数据中选取待处理测绘数据。
可选地,所述映射模块,还用于获取各多维度数据对应的标识信息;
所述映射模块,还用于根据所述标识信息将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
可选地,所述映射模块,还用于根据所述标识信息对所述多维度数据进行分类,以获得多个目标网络层数据;
所述映射模块,还用于将多个目标网络层数据跨层映射至对应的预设网络层,以获得 各预设网络层对应的网络数据。
可选地,所述生成模块,还用于确定所述网络拓扑结构图对应的互联网协议地址及网络地理位置信息;
所述生成模块,还用于根据所述互联网协议地址及所述网络地理位置信息构建网络空间坐标系;
所述生成模块,还用于基于所述网络空间坐标系生成网络空间地图。
可选地,所述网络空间地图生成装置还包括查找模块;
所述查找模块,用于在接收到主动式测绘指令时,根据所述主动式测绘指令确定网络数据检索关键词;
所述查找模块,还用于根据所述网络数据检索关键词通过所述网络空间地图查看对应的网络空间资产信息。
可选地,所述查找模块,还用于根据所述网络数据检索关键词确定网络定位信息;
所述查找模块,还用于根据所述网络定位信息从所述网络空间地图中确定网络资产区域;
所述查找模块,还用于基于所述网络空间地图确定所述网络资产区域对应的网络空间资产信息。
此外,为实现上述目的,本发明还提出一种网络空间地图生成设备,所述设备包括:存储器、处理器及存储在所述存储器上并可在所述处理器上运行的网络空间地图生成程序,所述网络空间地图生成程序配置为实现如上文所述的网络空间地图生成方法的步骤。
此外,为实现上述目的,本发明还提出一种存储介质,所述存储介质上存储有网络空间地图生成程序,所述网络空间地图生成程序被处理器执行时实现如上文所述的网络空间地图生成方法的步骤。
本发明在接收到任务调度发送的探测任务时,首先根据探测任务采集待处理测绘数据,并将预设数据库中的目标测绘数据与待处理测绘数据进行关联,以获得多维度数据,然后将多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据,之后根据各预设网络层对应的网络数据构建网络拓扑结构图,最后基于网络拓扑结构图生成网络空间地图。相较于现有技术中仅获取各个单位的设备信息,并不能对获取的设备信息进行资产分析,而本发明中可以将探测任务对应的多维数据跨层映射至对应的预设网络层,之后根据各预设网络层对应的网络数据生成网络空间地图,从而基于网络空间地图实 现网络空间管理,进而提高了用户体验。
附图说明
图1是本发明实施例方案涉及的硬件运行环境的网络空间地图生成设备的结构示意图;
图2为本发明网络空间地图生成方法第一实施例的流程示意图;
图3为本发明网络空间地图生成方法第一实施例的网络拓扑结构示意图;
图4为本发明网络空间地图生成方法第二实施例的流程示意图;
图5为本发明网络空间地图生成装置第一实施例的结构框图。
本发明目的的实现、功能特点及优点将结合实施例,参照附图做进一步说明。
具体实施方式
应当理解,此处所描述的具体实施例仅用以解释本发明,并不用于限定本发明。
参照图1,图1为本发明实施例方案涉及的硬件运行环境的网络空间地图生成设备结构示意图。
如图1所示,该网络空间地图生成设备可以包括:处理器1001,例如中央处理器(Central Processing Unit,CPU),通信总线1002、用户接口1003,网络接口1004,存储器1005。其中,通信总线1002用于实现这些组件之间的连接通信。用户接口1003可以包括显示屏(Display)、输入单元比如键盘(Keyboard),可选用户接口1003还可以包括标准的有线接口、无线接口。网络接口1004可选的可以包括标准的有线接口、无线接口(如无线保真(WIreless-FIdelity,WI-FI)接口)。存储器1005可以是高速的随机存取存储器(Random Access Memory,RAM)存储器,也可以是稳定的非易失性存储器(Non-Volatile Memory,NVM),例如磁盘存储器。存储器1005可选的还可以是独立于前述处理器1001的存储装置。
本领域技术人员可以理解,图1中示出的结构并不构成对网络空间地图生成设备的限定,可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置。
如图1所示,作为一种存储介质的存储器1005中可以包括操作系统、数据存储模块、网络通信模块、用户接口模块以及网络空间地图生成程序。
在图1所示的网络空间地图生成设备中,网络接口1004主要用于与网络服务器进行数据通信;用户接口1003主要用于与用户进行数据交互;本发明网络空间地图生成设备中的处理器1001、存储器1005可以设置在网络空间地图生成设备中,所述网络空间地图 生成设备通过处理器1001调用存储器1005中存储的网络空间地图生成程序,并执行本发明实施例提供的网络空间地图生成方法。
本发明实施例提供了一种网络空间地图生成方法,参照图2,图2为本发明网络空间地图生成方法第一实施例的流程示意图。
本实施例中,所述网络空间地图生成方法包括以下步骤:
步骤S10:在接收到任务调度发送的探测任务时,根据所述探测任务采集待处理测绘数据。
易于理解的是,本实施例的执行主体可以是具有图像处理、数据处理、网络通讯和程序运行等功能的网络空间地图生成设备,也可以为其他具有相似功能的计算机设备,本实施例并不加以限制。
在本实施例中可以建设测绘节点分布式集群和调度系统,之后通过任务调度下发探测任务,需要说明的是探测任务可以为采集某地点或某单位对应的网络资产信息等。
需要说明的是,待处理测绘数据为根据探测任务通过大数据平台收集的多个测绘数,其中大数据平台为用户预先构建的数据平台,该大数据平台可以收集和处理采集的测绘数据等。
进一步地,在接收到任务调度发送的探测任务时,根据探测任务采集待处理测绘数据的步骤可以为在接收到任务调度发送的探测任务时,根据探测任务确定探测关键词,之后根据探测关键词采集多个初始测绘数据,并按照预设测绘策略从多个初始测绘数据中选取待处理测绘数据。探测关键词还可以理解为探测任务对应的测绘数据检索词等。
应理解的是,多个初始测绘数据为通过大数据平台采集探测关键词相关的初始测绘数据等,预设测绘策略可以为用户自定义设置,可以将全部采集的初始测绘数据作为待处理测绘数据,还可以为根据用户需求从多个初始测绘数据中选取待处理测绘数据等。
进一步地,按照预设测绘策略从多个初始测绘数据中选取待处理测绘数据的步骤为按照预设测绘策略从多个初始测绘数据中选取多个待确认测绘数据,之后获取各待确认测绘数据对应的数据格式信息,之后根据数据格式信息从多个待确认测绘数据中确定待处理测绘数据。
在具体实现中为了避免乱码出现的问题,根据数据格式信息从多个待确认测绘数据中确定待处理测绘数据的处理方式可以为判断数据格式信息是否满足预设格式条件,在数据格式信息满足预设格式条件时,根据多个待确认测绘数据确定待处理测绘数据;在数据格式信息不满足预设格式条件时,根据预设格式条件从多个待处理测绘数据中选取待处理测 绘数据,其中预设格式条件为不存在乱码格式或用户自定义设置的格式信息等。
在本实施例中,假设多个待确认测绘数据分别为待确认测试数据A、待确认测试数据B、待确认测试数据C,则A对应的格式信息为1、B对应的测绘数据为1、C对应的格式信息为1,且预设格式条件中对应的格式信息为1,则将待确认测试数据A、待确认测试数据B、待确认测试数据C作为待处理测绘数据;假设A对应的格式信息为2、B对应的测绘数据为1、C对应的格式信息为2,且预设格式条件中对应的格式信息为2,则将待确认测试数据A、待确认测试数据C作为待处理测绘数据等。
步骤S20:将预设数据库中的目标测绘数据与所述待处理测绘数据进行关联,以获得多维度数据。
需要说明的是,预设数据库中引入百万亿级大数据即目标测绘数据,之后可以将预设数据库中对应的百万亿级大数据与待处理测绘数据进行关联,以获得多维度数据,该多维度数据可以为现实实体维度数据、地理位置维度数据、物理链路维度数据、网络实体维度数据及逻辑网络维度数据等。
在具体实现中,若待处理测绘数据为D,则从预设数据库中查找与待处理测绘数据D对应的关联数据,并将获取的关联数据作为多维度数据,需要说明的是关联数据中包括待处理测绘数据D对应的现实实体数据、地理位置数据、物理链路数据、网络实体数据及逻辑网络数据等。
还应理解的是,现实实体数据中包括业务行为相似的企业或单位,地理位置数据包括经纬度、国家、省市或区域等,物理链路数据中包括运营商光缆或大拓扑等,逻辑网络数据包括网际互连协议(Internet Protocol,IP)地址或证书等,网络实体数据包括产品或应用信息、操作系统、计算力、网络实体层标签或固件等。
步骤S30:将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
还需要说明的是,预设网络层为用户自定义设置的网络层,该网络层包括现实实体层、地理位置层、物理链路层、逻辑网络层、网络实体层等。
进一步地,将多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据的步骤可以为获取各多维度数据对应的标识信息,之后根据标识信息将多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。标识信息可以为地理标识,还可以为设备标识等。
在本实施例中,根据标识信息将多维度数据跨层映射至对应的预设网络层,以获得各 预设网络层对应的网络数据的处理方式可以为根据标识信息对多维度数据进行分类,以获得多个目标网络层数据,之后将多个目标网络层数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
在具体实现中,根据标识信息对多维度数据进行分类,以获得多个目标网络层数据的处理方式可以为根据标识信息对多维度数进行分类,以获得多个初始网络层数据,之后按照预设网络层规则从多个初始网络层数据中选取多个目标网络层数据。预设网络层规则可以为根据用户兴趣选取目标网络层数据等。
步骤S40:根据所述各预设网络层对应的网络数据构建网络拓扑结构图。
需要说明的是,预设网络层可以为用户自定义设置预设数量的网络层,可以为5个不同的网络层,还可以为6个不同的网络层,其中各个网络层之间均存在关联关系等。网络拓扑结构图可以理解不同预设网络层及预设网络层对应的网络数据所构建的拓扑结构图等。
参考图3,图3为本发明网络空间地图生成方法第一实施例的网络拓扑结构示意图,图3中包括Y、U、I、O、P,其中Y为现实实体层,U为地理位置层,I为物理链路层,O为逻辑网络层,P为网络实体层,还需要说明的是,现实实体层与地理位置层之间的关系为现实实体层存在于地理位置层,地理位置层与物理链路层之间相互依赖,逻辑网络层依附于物理链路层,逻辑网络层可以通过智能生活事业群组(Smart Living Group,SLG)、映射或地理位置反查地理位置层,网络实体层与逻辑网络层之间相互依存,网络实体层提供服务至现实实体层,现实实体层中包括业务行为相似的企业名称或单位名称,现实实体层中还包括负责人信息等,地理位置层中包括经纬度、大洲、国家、省市、区县、街道、区域及距离等,物理链路层中包括运营商光缆(根据实际地理铺设情况)等,逻辑网络层中包括IP地址路由连接至拓扑及证书等,网络实体层中包括产品或应用信息(类型、类别、厂商、层级及型号)、操作系统、计算力(终端、进程、内存及中央处理器)、网络实体层标签(内容分发网络、互联网数据中心及有害)及固件等。
步骤S50:基于所述网络拓扑结构图生成网络空间地图。
需要说明的是,网络空间地图为查找特定位置信息或特定单位对应的网络资产信息对应的空间地图等。
进一步地,基于网络拓扑结构图生成网络空间地图的步骤可以为确定网络拓扑结构图对应的互联网协议地址及网络地理位置信息,根据互联网协议地址及网络地理位置信息构建网络空间坐标系,之后基于网络空间坐标系生成网络空间地图。网络空间地图能够帮助 用户实现对网络空间风险主动探测、提前预警、支撑网络安全态势感知、对高级威胁追踪溯源、以及持续更新网络安全风险。
在本实施例中网络空间地图与日常地图相似,但网络空间地图中可以根据互联网协议地址或网络地理位置信息在网络空间地图中查看对应的网络拓扑结构图等。
在具体实现中,网络空间地图构建成功后,用户可以在网络空间地图中发送主动式测绘指令,该主动式测绘指令可以为用户发送的需要查看某地区的网络资产信息的指令,然后根据主动式测绘指令确定网络数据检索关键词,之后根据网络数据检索关键词通过网络空间地图查看对应的网络空间资产信息等。
应理解的是,网络数据检索关键词可以从主动式测绘指令中提取的词,例如某地区等。
还需要说明的是,根据网络数据检测关键词通过网络空间地图查看对应的网络空间资产信息的处理方式可以为根据网络数据检索关键词确定网络定位信息,然后根据网络定位信息从网络空间地图中确定网络资产区域,基于网络空间地图确定网络资产区域对应的网络空间资产信息等。
假设网络定位信息为F单位,则确定F单位在网络空间地图中预设范围内的区域即网络资产区域,之后获取网络资产区域对应的网络空间资产信息,其中网络空间资产信息可以根据网络拓扑结构图的形式进行展示,以使用户快速理解该网络资产区域对应的网络空间资产信息等。
在具体实现中,还可以通过主动式测绘获得一个城市所有开放的网站服务,然后通过对网站服务和其中间件版本的确认,可以帮助用户迅速找到自己的暴露资产,之后对测绘资产和单位组织数据的跨层映射,可以帮助用户了解到某行业或者某单位的关联资产情况,最后整体绘制城市网络空间地图,并且结合安全大数据和威胁情报,对城市安全态势实时感知和监控等。
在本实施例中,在接收到任务调度发送的探测任务时,首先根据探测任务采集待处理测绘数据,并将预设数据库中的目标测绘数据与待处理测绘数据进行关联,以获得多维度数据,然后将多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据,之后根据各预设网络层对应的网络数据构建网络拓扑结构图,最后基于网络拓扑结构图生成网络空间地图。相较于现有技术中仅获取各个单位的设备信息,并不能对获取的设备信息进行资产分析,而本发明中可以将探测任务对应的多维数据跨层映射至对应的预设网络层,之后根据各预设网络层对应的网络数据生成网络空间地图,从而基于网络空间地图实现网络空间管理,进而提高了用户体验。
参考图4,图4为本发明网络空间地图生成方法第二实施例的流程示意图。
基于上述第一实施例,在本实施例中,所述步骤S30步骤,包括:
步骤S301:获取各多维度数据对应的标识信息。
在具体实现中可以分别对多维度数据进行分析,以获得各多维度数据对应的关键词,之后根据关键词确定对应的标识信息,标识信息可以为地理标识信息,还可以为现实实体标识信息等。
步骤S302:根据所述标识信息将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
还需要说明的是,预设网络层为用户自定义设置的网络层,该网络层包括现实实体层、地理位置层、物理链路层、逻辑网络层、网络实体层等。
在本实施例中还可以利用大数据平台,对多维度数据进行跨层映射,跨层映射是指虚拟空间的测绘数据分为现实实体层、地理位置层、物理链路层、逻辑网络层、网络实体层等不同层次,还需要把不同层次的数据对应关联打通,例如一个服务器,有什么操作系统,开放应用服务,他归属那个单位,有什么域名,他的IP地址是什么,有什么路由关系,地理定位在哪等,其中跨层映射是地图绘制的基础数据分析工作。
应理解的是,根据标识信息对多维度数据进行分类,以获得多个目标网络层数据的处理方式可以为根据标识信息对多维度数进行分类,以获得多个初始网络层数据,之后按照预设网络层规则从多个初始网络层数据中选取多个目标网络层数据。预设网络层规则可以为根据用户兴趣选取目标网络层数据等。
假设多维度数据分别为Q、W、E、R、T,Q为地理标识、W为地理标识、E为现实实体标识、R为现实实体标识、T为物理链路标识,则将数据Q和W划分为一类,将数据E和R划分为一类,数据T为一类,之后将数据Q和W跨层映射至地理位置层,将数据E和R跨层映射层至现实实体层,将数据T跨层映射至物理链路层,其中地理位置层对应的网络数据为Q和W,现实实体层对应的网络数据为E和R,物理链路层对应的网络数据为T等。
在本实施例中首先获取各多维度数据对应的标识信息,之后根据标识信息将多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据,相较于现有技术中直接将获得的多维度数据存储至数据库中,这种方式不便于用户后续快速查找对应的网络数据,而本实施例中将多维度数据跨层映射至对应的预设网络层,从而便于用户快速查找感兴趣的网络数据。
参照图5,图5为本发明网络空间地图生成装置第一实施例的结构框图。
如图5所示,本发明实施例提出的网络空间地图生成装置包括:
采集模块5001,用于在接收到任务调度发送的探测任务时,根据所述探测任务采集待处理测绘数据。
在本实施例中可以建设测绘节点分布式集群和调度系统,之后通过任务调度下发探测任务,需要说明的是探测任务可以为采集某地点或某单位对应的网络资产信息等。
需要说明的是,待处理测绘数据为根据探测任务通过大数据平台收集的多个测绘数,其中大数据平台为用户预先构建的数据平台,该大数据平台可以收集和处理采集的测绘数据等。
进一步地,在接收到任务调度发送的探测任务时,根据探测任务采集待处理测绘数据的步骤可以为在接收到任务调度发送的探测任务时,根据探测任务确定探测关键词,之后根据探测关键词采集多个初始测绘数据,并按照预设测绘策略从多个初始测绘数据中选取待处理测绘数据。探测关键词还可以理解为探测任务对应的测绘数据检索词等。
应理解的是,多个初始测绘数据为通过大数据平台采集探测关键词相关的初始测绘数据等,预设测绘策略可以为用户自定义设置,可以将全部采集的初始测绘数据作为待处理测绘数据,还可以为根据用户需求从多个初始测绘数据中选取待处理测绘数据等。
进一步地,按照预设测绘策略从多个初始测绘数据中选取待处理测绘数据的步骤为按照预设测绘策略从多个初始测绘数据中选取多个待确认测绘数据,之后获取各待确认测绘数据对应的数据格式信息,之后根据数据格式信息从多个待确认测绘数据中确定待处理测绘数据。
在具体实现中为了避免乱码出现的问题,根据数据格式信息从多个待确认测绘数据中确定待处理测绘数据的处理方式可以为判断数据格式信息是否满足预设格式条件,在数据格式信息满足预设格式条件时,根据多个待确认测绘数据确定待处理测绘数据;在数据格式信息不满足预设格式条件时,根据预设格式条件从多个待处理测绘数据中选取待处理测绘数据,其中预设格式条件为不存在乱码格式或用户自定义设置的格式信息等。
在本实施例中,假设多个待确认测绘数据分别为待确认测试数据A、待确认测试数据B、待确认测试数据C,则A对应的格式信息为1、B对应的测绘数据为1、C对应的格式信息为1,且预设格式条件中对应的格式信息为1,则将待确认测试数据A、待确认测试数据B、待确认测试数据C作为待处理测绘数据;假设A对应的格式信息为2、B对应的测绘数据为1、C对应的格式信息为2,且预设格式条件中对应的格式信息为2,则将待确认测试数据A、待确认测试数据C作为待处理测绘数据等。
关联模块5002,用于将预设数据库中的目标测绘数据与所述待处理测绘数据进行关联,以获得多维度数据。
需要说明的是,预设数据库中引入百万亿级大数据即目标测绘数据,之后可以将预设数据库中对应的百万亿级大数据与待处理测绘数据进行关联,以获得多维度数据,该多维度数据可以为现实实体维度数据、地理位置维度数据、物理链路维度数据、网络实体维度数据及逻辑网络维度数据等。
在具体实现中,若待处理测绘数据为D,则从预设数据库中查找与待处理测绘数据D对应的关联数据,并将获取的关联数据作为多维度数据,需要说明的是关联数据中包括待处理测绘数据D对应的现实实体数据、地理位置数据、物理链路数据、网络实体数据及逻辑网络数据等。
还应理解的是,现实实体数据中包括业务行为相似的企业或单位,地理位置数据包括经纬度、国家、省市或区域等,物理链路数据中包括运营商光缆或大拓扑等,逻辑网络数据包括IP地址或证书等,网络实体数据包括产品或应用信息、操作系统、计算力、网络实体层标签或固件等。
映射模块5003,用于将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
还需要说明的是,预设网络层为用户自定义设置的网络层,该网络层包括现实实体层、地理位置层、物理链路层、逻辑网络层、网络实体层等。
进一步地,将多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据的步骤可以为获取各多维度数据对应的标识信息,之后根据标识信息将多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。标识信息可以为地理标识,还可以为设备标识等。
在本实施例中,根据标识信息将多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据的处理方式可以为根据标识信息对多维度数据进行分类,以获得多个目标网络层数据,之后将多个目标网络层数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
在具体实现中,根据标识信息对多维度数据进行分类,以获得多个目标网络层数据的处理方式可以为根据标识信息对多维度数进行分类,以获得多个初始网络层数据,之后按照预设网络层规则从多个初始网络层数据中选取多个目标网络层数据。预设网络层规则可以为根据用户兴趣选取目标网络层数据等。
构建模块5004,用于根据所述各预设网络层对应的网络数据构建网络拓扑结构图。
需要说明的是,预设网络层可以为用户自定义设置预设数量的网络层,可以为5个不同的网络层,还可以为6个不同的网络层,其中各个网络层之间均存在关联关系等。网络拓扑结构图可以理解不同预设网络层及预设网络层对应的网络数据所构建的拓扑结构图等。
参考图3,图3为本发明网络空间地图生成方法第一实施例的网络拓扑结构示意图,图3中包括Y、U、I、O、P,其中Y为现实实体层,U为地理位置层,I为物理链路层,O为逻辑网络层,P为网络实体层,还需要说明的是,现实实体层与地理位置层之间的关系为现实实体层存在于地理位置层,地理位置层与物理链路层之间相互依赖,逻辑网络层依附于物理链路层,逻辑网络层可以通过SLG、映射或地理位置反查地理位置层,网络实体层与逻辑网络层之间相互依存,网络实体层提供服务至现实实体层,现实实体层中包括业务行为相似的企业名称或单位名称,现实实体层中还包括负责人信息等,地理位置层中包括经纬度、大洲、国家、省市、区县、街道、区域及距离等,物理链路层中包括运营商光缆(根据实际地理铺设情况)等,逻辑网络层中包括IP地址路由连接至拓扑及证书等,网络实体层中包括产品或应用信息(类型、类别、厂商、层级及型号)、操作系统、计算力(终端、进程、内存及中央处理器)、网络实体层标签(内容分发网络、互联网数据中心及有害)及固件等。
生成模块5005,用于基于所述网络拓扑结构图生成网络空间地图。
需要说明的是,网络空间地图为查找特定位置信息或特定单位对应的网络资产信息对应的空间地图等。
进一步地,基于网络拓扑结构图生成网络空间地图的步骤可以为确定网络拓扑结构图对应的互联网协议地址及网络地理位置信息,根据互联网协议地址及网络地理位置信息构建网络空间坐标系,之后基于网络空间坐标系生成网络空间地图。网络空间地图能够帮助用户实现对网络空间风险主动探测、提前预警、支撑网络安全态势感知、对高级威胁追踪溯源、以及持续更新网络安全风险。
在本实施例中网络空间地图与日常地图相似,但网络空间地图中可以根据互联网协议地址或网络地理位置信息在网络空间地图中查看对应的网络拓扑结构图等。
在具体实现中,网络空间地图构建成功后,用户可以在网络空间地图中发送主动式测绘指令,该主动式测绘指令可以为用户发送的需要查看某地区的网络资产信息的指令,然后根据主动式测绘指令确定网络数据检索关键词,之后根据网络数据检索关键词通过网络 空间地图查看对应的网络空间资产信息等。
应理解的是,网络数据检索关键词可以从主动式测绘指令中提取的词,例如某地区等。
还需要说明的是,根据网络数据检测关键词通过网络空间地图查看对应的网络空间资产信息的处理方式可以为根据网络数据检索关键词确定网络定位信息,然后根据网络定位信息从网络空间地图中确定网络资产区域,基于网络空间地图确定网络资产区域对应的网络空间资产信息等。
假设网络定位信息为F单位,则确定F单位在网络空间地图中预设范围内的区域即网络资产区域,之后获取网络资产区域对应的网络空间资产信息,其中网络空间资产信息可以根据网络拓扑结构图的形式进行展示,以使用户快速理解该网络资产区域对应的网络空间资产信息等。
在具体实现中,还可以通过主动式测绘获得一个城市所有开放的网站服务,然后通过对网站服务和其中间件版本的确认,可以帮助用户迅速找到自己的暴露资产,之后对测绘资产和单位组织数据的跨层映射,可以帮助用户了解到某行业或者某单位的关联资产情况,最后整体绘制城市网络空间地图,并且结合安全大数据和威胁情报,对城市安全态势实时感知和监控等。
在本实施例中,在接收到任务调度发送的探测任务时,首先根据探测任务采集待处理测绘数据,并将预设数据库中的目标测绘数据与待处理测绘数据进行关联,以获得多维度数据,然后将多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据,之后根据各预设网络层对应的网络数据构建网络拓扑结构图,最后基于网络拓扑结构图生成网络空间地图。相较于现有技术中仅获取各个单位的设备信息,并不能对获取的设备信息进行资产分析,而本发明中可以将探测任务对应的多维数据跨层映射至对应的预设网络层,之后根据各预设网络层对应的网络数据生成网络空间地图,从而基于网络空间地图实现网络空间管理,进而提高了用户体验。
进一步地,所述采集模块5001,还用于在接收到任务调度发送的探测任务时,根据所述探测任务确定探测关键词;
所述采集模块5001,还用于根据所述探测关键词采集多个初始测绘数据;
所述采集模块5001,还用于按照预设测绘策略从多个所述初始测绘数据中选取待处理测绘数据。
进一步地,所述映射模块5003,还用于获取各多维度数据对应的标识信息;
所述映射模块5003,还用于根据所述标识信息将所述多维度数据跨层映射至对应的预 设网络层,以获得各预设网络层对应的网络数据。
进一步地,所述映射模块5003,还用于根据所述标识信息对所述多维度数据进行分类,以获得多个目标网络层数据;
所述映射模块5003,还用于将多个目标网络层数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
进一步地,所述生成模块5005,还用于确定所述网络拓扑结构图对应的互联网协议地址及网络地理位置信息;
所述生成模块5005,还用于根据所述互联网协议地址及所述网络地理位置信息构建网络空间坐标系;
所述生成模块5005,还用于基于所述网络空间坐标系生成网络空间地图。
进一步地,所述网络空间地图生成装置还包括查找模块;
所述查找模块,用于在接收到主动式测绘指令时,根据所述主动式测绘指令确定网络数据检索关键词;
所述查找模块,还用于根据所述网络数据检索关键词通过所述网络空间地图查看对应的网络空间资产信息。
进一步地,所述查找模块,还用于根据所述网络数据检索关键词确定网络定位信息;
所述查找模块,还用于根据所述网络定位信息从所述网络空间地图中确定网络资产区域;
所述查找模块,还用于基于所述网络空间地图确定所述网络资产区域对应的网络空间资产信息。
本发明网络空间地图生成装置的其他实施例或具体实现方式可参照上述各方法实施例,此处不再赘述。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者系统不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者系统所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者系统中还存在另外的相同要素。
上述本发明实施例序号仅仅为了描述,不代表实施例的优劣。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法 可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本发明的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如只读存储器/随机存取存储器、磁碟、光盘)中,包括若干指令用以使得一台终端设备(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本发明各个实施例所述的方法。
以上仅为本发明的优选实施例,并非因此限制本发明的专利范围,凡是利用本发明说明书及附图内容所作的等效结构或等效流程变换,或直接或间接运用在其他相关的技术领域,均同理包括在本发明的专利保护范围内。

Claims (20)

  1. 一种网络空间地图生成方法,其特征在于,所述网络空间地图神生成方法包括以下步骤:
    在接收到任务调度发送的探测任务时,根据所述探测任务采集待处理测绘数据;
    将预设数据库中的目标测绘数据与所述待处理测绘数据进行关联,以获得多维度数据;
    将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据;
    根据所述各预设网络层对应的网络数据构建网络拓扑结构图;
    基于所述网络拓扑结构图生成网络空间地图。
  2. 如权利要求1所述的方法,其特征在于,所述在接收到任务调度发送的探测任务时,根据所述探测任务采集待处理测绘数据的步骤,包括:
    在接收到任务调度发送的探测任务时,根据所述探测任务确定探测关键词;
    根据所述探测关键词采集多个初始测绘数据;
    按照预设测绘策略从多个所述初始测绘数据中选取待处理测绘数据。
  3. 如权利要求2所述的方法,其特征在于,所述按照预设测绘策略从多个所述初始测绘数据中选取待处理测绘数据的步骤,包括:
    按照预设测绘策略从多个所述初始测绘数据中选取多个待确认测绘数据;
    获取各待确认测绘数据对应的数据格式信息;
    根据所述数据格式信息从多个待确认测绘数据中确定待处理测绘数据。
  4. 如权利要求3所述的方法,其特征在于,所述根据所述数据格式信息从多个待确认测绘数据中确定待处理测绘数据的步骤,包括:
    判断所述数据格式信息是否满足预设格式条件;
    在所述数据格式信息满足所述预设格式条件时,根据多个所述待确认测绘数据确定待处理测绘数据。
  5. 如权利要求4所述的方法,其特征在于,所述判断所述数据格式信息是否满足预设格式条件的步骤之后,还包括:
    在所述数据格式信息不满足所述预设格式条件时,根据所述预设格式条件从多个所述 待确认测绘数据中选取待处理测绘数据。
  6. 如权利要求1-5任一项所述的方法,其特征在于,所述将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据的步骤,包括:
    获取各多维度数据对应的标识信息;
    根据所述标识信息将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
  7. 如权利要求6所述的方法,其特征在于,所述根据所述标识信息将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据的步骤,包括:
    根据所述标识信息对所述多维度数据进行分类,以获得多个目标网络层数据;
    将多个目标网络层数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
  8. 如权利要求7所述的方法,其特征在于,所述根据所述标识信息对所述多维度数据进行分类,以获得多个目标网络层数据的步骤,包括:
    根据所述标识信息对所述多维度数据进行分类,以获得多个初始网络层数据;
    按照预设网络层规则从多个初始网络层数据中选取多个目标网络层数据。
  9. 如权利要求1-5任一项所述的方法,其特征在于,所述基于所述网络拓扑结构图生成网络空间地图的步骤,包括:
    确定所述网络拓扑结构图对应的互联网协议地址及网络地理位置信息;
    根据所述互联网协议地址及所述网络地理位置信息构建网络空间坐标系;
    基于所述网络空间坐标系生成网络空间地图。
  10. 如权利要求9所述的方法,其特征在于,所述基于所述网络空间坐标系生成网络空间地图的步骤之后,还包括:
    在接收到主动式测绘指令时,根据所述主动式测绘指令确定网络数据检索关键词;
    根据所述网络数据检索关键词通过所述网络空间地图查看对应的网络空间资产信息。
  11. 如权利要求10所述的方法,其特征在于,所述根据所述网络数据检索关键词通过所述网络空间地图查看对应的网络空间资产信息的步骤,包括:
    根据所述网络数据检索关键词确定网络定位信息;
    根据所述网络定位信息从所述网络空间地图中确定网络资产区域;
    基于所述网络空间地图确定所述网络资产区域对应的网络空间资产信息。
  12. 一种网络空间地图生成装置,其特征在于,所述网络空间地图生成装置包括:
    采集模块,用于在接收到任务调度发送的探测任务时,根据所述探测任务采集待处理测绘数据;
    关联模块,用于将预设数据库中的目标测绘数据与所述待处理测绘数据进行关联,以获得多维度数据;
    映射模块,用于将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据;
    构建模块,用于根据所述各预设网络层对应的网络数据构建网络拓扑结构图;
    生成模块,用于基于所述网络拓扑结构图生成网络空间地图。
  13. 如权利要求12所述的装置,其特征在于,所述采集模块,还用于在接收到任务调度发送的探测任务时,根据所述探测任务确定探测关键词;
    所述采集模块,还用于根据所述探测关键词采集多个初始测绘数据;
    所述采集模块,还用于按照预设测绘策略从多个所述初始测绘数据中选取待处理测绘数据。
  14. 如权利要求12或13所述的装置,其特征在于,所述映射模块,还用于获取各多维度数据对应的标识信息;
    所述映射模块,还用于根据所述标识信息将所述多维度数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
  15. 如权利要求14所述的装置,其特征在于,所述映射模块,还用于根据所述标识信息对所述多维度数据进行分类,以获得多个目标网络层数据;
    所述映射模块,还用于将多个目标网络层数据跨层映射至对应的预设网络层,以获得各预设网络层对应的网络数据。
  16. 如权利要求12或13所述的装置,其特征在于,所述生成模块,还用于确定所述网络拓扑结构图对应的互联网协议地址及网络地理位置信息;
    所述生成模块,还用于根据所述互联网协议地址及所述网络地理位置信息构建网络空间坐标系;
    所述生成模块,还用于基于所述网络空间坐标系生成网络空间地图。
  17. 如权利要求16所述的装置,其特征在于,所述网络空间地图生成装置还包括查找模块;
    所述查找模块,用于在接收到主动式测绘指令时,根据所述主动式测绘指令确定网络数据检索关键词;
    所述查找模块,还用于根据所述网络数据检索关键词通过所述网络空间地图查看对应的网络空间资产信息。
  18. 如权利要求17所述的装置,其特征在于,所述查找模块,还用于根据所述网络数据检索关键词确定网络定位信息;
    所述查找模块,还用于根据所述网络定位信息从所述网络空间地图中确定网络资产区域;
    所述查找模块,还用于基于所述网络空间地图确定所述网络资产区域对应的网络空间资产信息。
  19. 一种网络空间地图生成设备,其特征在于,所述网络空间地图生成设备包括:存储器、处理器及存储在所述存储器上并可在所述处理器上运行的网络空间地图生成程序,所述网络空间地图生成程序配置有实现如权利要求1至11中任一项所述的网络空间地图生成方法的步骤。
  20. 一种存储介质,其特征在于,所述存储介质上存储有网络空间地图生成程序,所述网络空间地图生成程序被处理器执行时实现如权利要求1至11中任一项所述的网络空间地图生成方法的步骤。
PCT/CN2021/143644 2021-12-16 2021-12-31 网络空间地图生成方法、装置、设备及存储介质 WO2023108832A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202111557944.5A CN116340442A (zh) 2021-12-16 2021-12-16 网络空间地图生成方法、装置、设备及存储介质
CN202111557944.5 2021-12-16

Publications (1)

Publication Number Publication Date
WO2023108832A1 true WO2023108832A1 (zh) 2023-06-22

Family

ID=86775090

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/143644 WO2023108832A1 (zh) 2021-12-16 2021-12-31 网络空间地图生成方法、装置、设备及存储介质

Country Status (2)

Country Link
CN (1) CN116340442A (zh)
WO (1) WO2023108832A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN117041070A (zh) * 2023-10-09 2023-11-10 中国人民解放军国防科技大学 一种网络空间测绘节点发现与归属判别方法和装置

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106980668A (zh) * 2017-03-22 2017-07-25 中国电子科技网络信息安全有限公司 一种网络空间测绘要素的形式化建模方法
WO2020113981A1 (zh) * 2018-12-03 2020-06-11 清华大学 网络空间地图模型创建方法及装置
CN112667765A (zh) * 2021-03-22 2021-04-16 远江盛邦(北京)网络安全科技股份有限公司 网络空间地图构建方法、装置及设备

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106980668A (zh) * 2017-03-22 2017-07-25 中国电子科技网络信息安全有限公司 一种网络空间测绘要素的形式化建模方法
WO2020113981A1 (zh) * 2018-12-03 2020-06-11 清华大学 网络空间地图模型创建方法及装置
CN112667765A (zh) * 2021-03-22 2021-04-16 远江盛邦(北京)网络安全科技股份有限公司 网络空间地图构建方法、装置及设备

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
GUO, LI ET AL.: "Cyberspace Resources Surveying and Mapping: The Concepts and Technologies", JOURNAL OF CYBER SECURITY, vol. 3, no. 4, 31 July 2018 (2018-07-31), XP009547054 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN117041070A (zh) * 2023-10-09 2023-11-10 中国人民解放军国防科技大学 一种网络空间测绘节点发现与归属判别方法和装置
CN117041070B (zh) * 2023-10-09 2023-12-08 中国人民解放军国防科技大学 一种网络空间测绘节点发现与归属判别方法和装置

Also Published As

Publication number Publication date
CN116340442A (zh) 2023-06-27

Similar Documents

Publication Publication Date Title
Adam et al. Spatial computing and social media in the context of disaster management
US7561169B2 (en) Systems and methods for generating user specified information from a map
CN109977690A (zh) 一种数据处理方法、装置和介质
JP6713238B2 (ja) 電子装置、小売店舗評価モデルを構築する方法、システム及び記憶媒体
CN108881346B (zh) 面向位置服务的网络空间实体资源可视化方法及系统
KR20130135977A (ko) 소셜 네트워크 내의 피드의 추적
JP5065470B2 (ja) サーバ、情報管理方法、情報管理プログラム、及びそのプログラムを記録するコンピュータ読み取り可能な記録媒体
JP2015536504A (ja) 地理位置情報のための装置および方法
US8462991B1 (en) Using images to identify incorrect or invalid business listings
CN111966866A (zh) 一种数据资产管理的方法和装置
CN106649770A (zh) 一种大数据查询方法及系统
CN111427983A (zh) 基于地理信息检索的服务方法、系统、设备及存储介质
US11263267B1 (en) Apparatuses, methods, and computer program products for generating interaction vectors within a multi-component system
US9959268B2 (en) Semantic modeling of geographic information in business intelligence
WO2023108832A1 (zh) 网络空间地图生成方法、装置、设备及存储介质
JP6562877B2 (ja) 情報提供装置、方法およびシステム
CN111488594A (zh) 一种基于云服务器的权限检查方法、装置、存储介质及终端
CN111949845A (zh) 处理测绘信息的方法、装置、计算机设备和存储介质
CN112838956B (zh) 面向用户的网络空间资源分析方法及设备
CN109582406A (zh) 使用卡片系统框架的基于剧本的安全调查
CN115438719A (zh) 数据处理方法、装置、服务器及存储介质
US10185747B2 (en) Presenting publisher data sets in context
WO2018004083A1 (ko) 지도 검색 기록을 이용한 유동인구 추정 장치 및 방법
CN113076308A (zh) 一种时空大数据服务系统
CN111125272B (zh) 一种区域特征获取方法、装置、计算机设备及介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21967961

Country of ref document: EP

Kind code of ref document: A1