Method, System, Device and Medium for Detecting and Recording the Survival of IPv4 Address Space

By using the IP_BITS data structure and compression algorithm that stores IP states with bit bits, the problem of low detection efficiency of IPv4 full address space survival state in the prior art is solved, high-density information recording and efficient information transmission are realized, and the ability to quickly master the situation of the entire network is improved.

CN115622977BActive Publication Date: 2025-06-10ZHONGNENG FUSION SMART TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211217857.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-30
Publication Date
2025-06-10
Estimated Expiration
2042-09-30

AI Technical Summary

Technical Problem

When detecting the survival status of IPv4 full address space, the prior art requires a large amount of storage space and computing resources, and the data transmission and storage efficiency are low, which affects the rapid grasp of the entire network situation.

Method used

Using a bit-based IP_BITS data structure, high-density information recording and efficient information transmission are realized by dividing IPv4 addresses into Class A address segments, and storing IP states based on bit groups, combining compression algorithms for storage and transmission.

Benefits of technology

It greatly reduces memory and storage usage, reduces network transmission and disk usage, and realizes rapid recording and retrieval of IPv4 address space survival attributes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115622977B_ABST
    Figure CN115622977B_ABST
Patent Text Reader

Abstract

The present application relates to a method, system, device and medium for detecting and recording the survival of the IPv4 address space. The method for detecting and recording the survival of the IPv4 address space includes that each detection node receives a detection instruction sent by a management center to detect the survival status of a specified single port; the detection node executes the detection instruction, and stores and compresses the detection result in the IP_BITS format; the detection node returns the stored detection result to the management center; by using IP_BITS to record, transmit and query the data result, the preservation of specific IP address information is avoided, so the memory occupancy and storage occupancy information are greatly reduced, and thus the effect of quickly grasping the situation of the entire network can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technologies, and particularly to a method, system, device and medium for detecting and recording the survival of IPv4 address space. Background Art

[0002] Currently, cyberspace surveying and mapping is a comprehensive technology that combines asset discovery, asset identification, vulnerability detection, geographic information, and big data analysis. It is very important for finding out the bottom line of assets, mastering the asset status, analyzing security threats, supporting situation awareness, and improving emergency response. Discovering surviving network assets based on address scanning and port scanning is the first step in cyberspace surveying and mapping. However, since the length of an IPv4 address is 4 bytes (32 bits) and the total number of addresses exceeds 4.2 billion, if a relational database or big data platform is used to record and quickly retrieve the port survival status of the entire IPv4 address space, a large amount of storage space and computing resources are required.

[0003] In the prior art, for the survival detection of the entire IPv4 address space, first, a distributed node deployment mode is usually adopted, and numerous detection engines concurrently carry out detections. A large amount of task and detection result information needs to be exchanged between the management control node and the detection engines. Second, the IP survival status information is a prerequisite for whether to carry out in-depth or comprehensive detections in the next step, and the survival attribute can be expressed by a Boolean value (True / False). Third, most network detection systems use a MongoDB cluster or an ElasticSearch cluster to store and retrieve the IPv4 address survival status.

[0004] However, in a distributed detection environment, the amount of detection result data transmitted between the management node and the detection nodes through the network is huge. Calculated based on 16 bytes of information for each IPv4 address, the minimum information transmission for only one A-class address segment requires 256M bytes, and recording all IPv4 addresses requires approximately 64G bytes. Secondly, the time spent on entering and storing the IP status information is relatively long. Calculated at an average of 10,000 records per second, 100 million data records will take more than two and a half hours, which is not conducive to quickly grasping the situation of the entire network. Summary of the Invention

[0005] Based on this, the present application provides a method, system, device and medium for detecting and recording the survival of IPv4 address space, which uses continuous storage space to map IP addresses and records Boolean attributes based on bit positions, combines basic information for encoding, and uses a compression algorithm to store files, so as to achieve the functions of high-density information recording, high-efficiency information transmission, and high-speed information retrieval of the survival attributes of the global IPv4 address space.

[0006] In a first aspect, the present application provides a method for detecting and recording the survival status of an IPv4 address space. The method includes: each detection node receives a detection instruction sent by a management center to detect the survival status of a specified single port; the detection node executes the detection instruction and stores and compresses the detection result in the IP_BITS format; the detection node returns the stored detection result to the management center.

[0007] Optionally, the detection node executes the detection instruction and stores and compresses the detection result in the IP_BITS format, including: the detection node starts an IP scanning engine to execute the detection instruction;

[0008] The IP scanning engine inputs the scanned detection result into an IP marking writing component; when the scanning task ends, the IP marking writing component stores and compresses the detection result in the IP_BITS format.

[0009] Optionally, the IP_BITS format specifically includes: the IP_BITS is stored in binary form and mainly includes a header structure, a network segment count, and marking data for each network segment; among them, the header structure part first has 4 two-byte fields in sequence, namely type identifier (MagicID), version, header length, reserved field, and Json description; the network segment count part consists of 256 four-byte fields in sequence, where the first field is the count of all marked IPs, representing the number of surviving IPs; starting from the second field, it is the count of marked IPs in each Class A network segment; the marking data for each network segment is based on bit groups and sequentially records the marking data of network numbers A1 to A254.

[0010] Optionally, when the scanning task ends, the IP marking writing component stores and compresses the detection results in the IP_BITS format, which includes: dividing the addresses to be recorded into Class A addresses with network numbers from 1 to 255, arranging and storing the values to be recorded for each address segment in the order of IP address values based on the bit group (bit_group), and creating a bit group only when the IP in each address segment is hit or a non-zero record value needs to be written; each IPv4 address can be represented as a four-byte array b[4]. For example, for 1.2.3.4, the array values b[0], b[1], b[2], and b[3] are the numbers 1, 2, 3, and 4 respectively, where the value of b[0] is the network number, and b[1], b[2], and b[3] form the host number; when reading or recording the status of a certain IP, based on the network number b[0] of the IP, locate or create the corresponding bit group and the number of status bits (status_bits) to be recorded for each IP. If the number of status bits to be recorded for each IP is greater than or equal to 1 and less than or equal to 8, the length of the bit group is 2M * status_bits, and record the byte offset and bit offset within the byte of the IP status in the bit group; when the status to be read or recorded is of the unsigned char type, the lower status_bits binary values are specific boolean values; based on the recorded IP status type, the number of status bits, the bit group, and the offset recorded for the IP, read the recorded IP.

[0011] Optionally, when the scanning task ends, the IP marking writing component storing and compressing the detection results in the IP_BITS format further includes: updating and maintaining the bit status of each IP in the memory, and compressing the stored IPs in the IP_BITS format during persistent storage to reduce the volume.

[0012] Optionally, the detection node returning the stored detection results to the management center further includes: the detection node receiving a detection instruction to continue monitoring for new scan result files;

[0013] The detection node reads a new scan result file in the IP_BITS format and sends it to the management center.

[0014] Optionally, the detection node reading a new scan result file in the IP_BITS format and sending it to the management center further includes: the management center storing the scan results returned by each detection node; the IP marking management component reading and merging the scan results of the same scan type, and ending the IP address status query and network segment statistical value query through the interface; the IP marking management component storing the final scan results.

[0015] Second aspect, the present application provides a detection and recording system for the IPv4 address space survival, characterized in that the system includes: a detection and reception module: each detection node receives a detection instruction sent by the management center to detect the survival status of a specified single port; a detection execution module: the detection node executes the detection instruction, and stores and compresses the detection result based on the IP_BITS format; a management center module: the detection node returns the stored detection result to the management center.

[0016] Third aspect, the present application further provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that when the processor executes the computer program, the steps of the above-mentioned method are implemented.

[0017] Fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned method are implemented.

[0018] The present application has at least the following advantages:

[0019] According to the technical content provided by the embodiments of the present application, by designing a data structure for storing IP status based on bits, abbreviated as IP_BITS, it is realized that the addresses to be recorded are divided into Class A addresses with network numbers from 1 to 255. Each segment of the address is based on byte data, and the values to be recorded are arranged and stored in the order of IP address values. Each bit group has bit positions matching the number of IPs to store the IP status. The starting point of each bit group is the first address of the specified Class A address. The offset position of each bit relative to the first bit can calculate the corresponding specific IP address, thus avoiding saving specific IP address information. Therefore, the memory occupancy and storage occupancy information are greatly reduced, and a compression mode is adopted for persistent storage. The file size can generally be compressed to 2 - 10 M bytes, thus greatly reducing the network transmission volume and disk occupancy.

[0020] In the IP scanning system based on the present invention, IP_BITS is used to record, transfer, and query data results; a marker writing component for IP_BITS is designed to update and maintain the bit status of each IP in the memory, and a compression algorithm is used to compress IP_BITS during persistent storage to reduce the volume; at the same time, multiple IP_BITS data contents can be read and merged, and it is supported to query the number of marked IPs in each network segment and the marked status of specific IPs through an interface, so as to quickly query the number of marked IPs and the marked status of specific IPs to quickly grasp the situation of the entire network. Description of the Drawings

[0021] Figure 1It is an application environment diagram showing the method for detecting and recording the survival of the IPv4 address space in an embodiment;

[0022] Figure 2 It is a schematic flowchart showing the method for detecting and recording the survival of the IPv4 address space in an embodiment;

[0023] Figure 3 It is a flowchart showing the IP scanning based on the IP_BITS data format in an embodiment;

[0024] Figure 4 It is a schematic diagram showing the IP_BITS data format in an embodiment;

[0025] Figure 5 It is a schematic diagram showing the storage of IP status bit by bit in an embodiment;

[0026] Figure 6 It is a schematic flowchart showing the detection node executing the detection instruction in an embodiment;

[0027] Figure 7 It is a block diagram showing the system structure for detecting and recording the survival of the IPv4 address space in an embodiment;

[0028] Figure 8 It is a schematic structural diagram showing a computer device in an embodiment. Detailed implementation manners

[0029] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the embodiments of the present application will be described in detail below with reference to the accompanying drawings. However, those of ordinary skill in the art can understand that in the embodiments of the present application, many technical details are provided to help readers better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed in the present application can still be implemented. The following division of each embodiment is for convenience of description and should not constitute any limitation on the specific implementation manner of the present application. Each embodiment can be combined with each other and cross-referenced on the premise of no contradiction.

[0030] For ease of understanding, the system applicable to the present application will be described first. A method for detecting and recording the survival of the IPv4 address space provided by the present application can be applied to, for example Figure 1In the system architecture shown. The system includes: a user space file server 103 and a terminal device 101. The terminal device 101 communicates with the user space file server 103 via a network. Among them, the user space file server 103 can be a file server based on the NFSv3\v4 protocol, running in a Linux environment. And NFS (Network File System) is a network abstraction on top of the file system, allowing remote clients running on the terminal device 101 to access via the network in a similar way to the local file system. The terminal device 101 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, etc. The user space file server 103 can be implemented by an independent server or a server cluster composed of multiple servers.

[0031] Figure 2 It is a schematic flowchart of a method for detecting and recording the survival status of an IPv4 address space provided by an embodiment of the present application. This method can be executed by the user space file server in the system as shown in Figure 1 shown.

[0032] As shown in Figure 2 、 Figure 3 shown, this method may include the following steps:

[0033] Step 201: Each detection node receives a detection instruction sent by the management center to detect the survival status of a specified single port;

[0034] In this embodiment, it should be noted that this detection method adopts a distributed deployment structure, which is divided into a management center and each detection node. The management center task scheduler issues detection instructions to each detection node. One task only targets the survival or ping survival status of a specified single port. The detection node receives and executes the detection instruction.

[0035] Step 203: The detection node executes the detection instruction and stores and compresses the detection result based on the IP_BITS format.

[0036] In this embodiment, it should be noted that IP_BITS is a data structure for storing IP status based on bits (bit). As shown in Figure 4 shown, referring to the A-class address division of IPv4, the addresses to be recorded are divided into A-class addresses with network numbers from 1 to 255. Each segment of the address is arranged and stored in the order of the IP address value based on the bit group (bit_group). A bit group is only created when the IP in each address segment is hit or a non-zero record value needs to be written.

[0037] Please refer to Figure 5As shown, in each bit group, there are bit positions that match the number of IPs to store the IP status. The starting point of each bit group is the first address of the specified Class A address (e.g., 1.0.0.0). The offset position of each bit relative to the first bit can calculate the corresponding specific IP address, thus avoiding saving the specific IP address information; in the IP scanning system based on the present invention, IP_BITS is used to record, transfer, and query the data results.

[0038] Please refer to Figure 2 、 Figure 3 As shown, Step 205: The detection node returns the stored detection results to the management center;

[0039] In this embodiment, it should be noted that in the embodiment of the present application, the detection node receives the instruction from the management center and executes the detection instruction to scan and detect the port survival status of the entire IPv4 address space. After detection, the detection results are recorded and stored, and then returned to the management center for unified storage and management by the management center.

[0040] Please continue to refer to Figure 3 、 Figure 6 As shown, in some embodiments, in Step 203, the detection node executes the detection instruction and stores and compresses the detection results in the IP_BITS format, including:

[0041] S2031: The detection node starts the IP scanning engine to execute the detection instruction;

[0042] S2033: The IP scanning engine inputs the scanned detection results into the IP marking writing component;

[0043] S2035: When the scanning task ends, the IP marking writing component stores and compresses the detection results in the IP_BITS format.

[0044] In this embodiment, it should be noted that the task scheduling of the detection node starts the IP scanning engine to execute the detection instruction. The IP scanning engine performs scanning and detection, inputs the detected detection results into the IP marking writing component, and stores the detection results in the IP_BITS format through the IP marking writing component.

[0045] In addition, it should be noted that IP_BITS is stored in binary format, such as Figure 4As shown, it is mainly divided into a head structure, network segment counting, and marked data for each network segment. The head structure part first consists of 4 two-byte fields in sequence, namely the type identifier (MagicID), version, head length (head_len), reserved field, and Json description (Description). Among them, MagicID is identified by the program as a fixed value for distinguishing data types; version refers to the version of the data format, with the default being the number 1; head_len is the length of the head structure, from the first byte to the end byte of the Json description; Description is a Json-formatted description string for describing relevant information such as tasks and time. The network segment counting part consists of 256 four-byte fields in sequence. The first field is the count of all marked IPs, for example, it can represent the number of live IPs. Starting from the second field, it is the count of marked IPs for each Class A network segment. A1 represents network number 1 (i.e., 1.0.0.0 / 8), A2 represents network number 2 (i.e., 2.0.0.0 / 8), and so on. The marked data part for each network segment is to record the marked data for network numbers A1 to A254 based on bit groups in sequence. Only when there are marked ones within the network segment will bit groups be generated.

[0046] In this embodiment, it should also be noted that if the value of the number of status bits (status_bits) to be recorded for each IP is greater than or equal to 1 and less than or equal to 8, then the length of the bit group is 2M * status_bits. Assuming that each IP only records the status of whether it can be pinged, then status_bits is 1 and the length of the bit group is 2M bytes.

[0047] Please refer to Figure 4 、 Figure 5As shown, in some embodiments, in step 2035, when the scanning task ends, the IP marking writing component stores the detection results in the IP_BITS format, including: dividing the IPv4 addresses to be recorded into Class A addresses with network numbers from 1 to 255, arranging and storing the values to be recorded in numerical order of the IP address based on the bit groups for each address segment, and creating a bit group only when the IP in each address segment is hit or a non-zero record value needs to be written; each IPv4 address can be represented as a four-byte array b[4]. For example, for 1.2.3.4, the corresponding array values b[0], b[1], b[2], and b[3] are the numbers 1, 2, 3, and 4 respectively, where the value of b[0] is the network number, and b[1], b[2], and b[3] form the 24-bit host number, and the host number value is set to host_n; when reading or recording the status of a certain IP, based on the network number b[0] of the IP, locate or create the corresponding bit group or unsigned char array and the number of status bits (status_bits) to be recorded for each IP, set the byte offset of the recorded IP status in the bit group and the bit offset for recording the status within the byte; according to the type of the recorded IP status, based on the number of status bits, the bit group, and the offset recorded for the IP, read the recorded IP.

[0048] For ease of understanding, the access method of the bit group of IP_BITS is specifically described below:

[0049] Suppose when reading or recording the status of a certain IP, based on the network number b[0] of the IP, locate or create the corresponding bit group (unsigned char array), and set the byte offset of the recorded IP status. Then the byte offset value is equal to the host number host_n multiplied by the number of status bits and then divided by 8.

[0050] Set the bit offset of the recorded IP status within the byte. Then the bit offset value is equal to the remainder of the host number host_n multiplied by the number of status bits divided by 8 (i.e., modulo operation with 8).

[0051] Suppose the IP status to be read is the recorded status value (v_old) of the unsigned char type, and the status to be written is the new status value (v_new) of the unsigned char type. The low-order number of status bits of its binary values are specific boolean values, which are divided into the following situations:

[0052] When the sum of the bit offset and the number of status bits is less than or equal to 8, read the byte bit_group[byte_index] stored in the bit group through the byte offset, and calculate the status value through "bit shift" and "exclusive OR" operations to read the recorded status.

[0053] When the sum of the bit offset and the number of status bits is less than or equal to 8, read the byte bit_group[byte_index] storing the record in the bit group through the byte offset. After performing a "shift" operation on the new status value and then performing an "OR" operation with the byte value obtained above, a new character value is obtained. Then write the new character value back to the byte offset position of the bit group, thereby writing the new status value.

[0054] When the sum of the bit offset and the number of status bits is greater than 8, read two consecutive bytes bit_group[byte_index] and bit_group[byte_index + 1] storing the record in the bit group through the byte offset, and calculate the status value through "shift" and "exclusive OR" operations, thereby realizing the reading of the recorded status.

[0055] When the sum of the bit offset and the number of status bits is greater than 8, read two consecutive bytes bit_group[byte_index] and bit_group[byte_index + 1] storing the record in the bit group through the byte offset. After performing a "shift" operation on the new status value, perform an "OR" operation with the two byte values obtained above respectively to obtain a new character value. Then write the new character value back to the corresponding offset position of the bit group, thereby realizing the writing of the new status value.

[0056] According to the above, read the detection results stored in the IP_BITS format. If the value read before writing is 0 and the written value is non - zero, the corresponding network segment statistical value is incremented by 1.

[0057] Please refer to Figure 2 、 Figure 3 As shown, in some embodiments, in step 2035, when the scanning task ends, the IP marking writing component storing and compressing the detection results in the IP_BITS format further includes:

[0058] Update and maintain the bit status of each IP in the memory, and compress the stored IPs based on the IP_BITS format during persistent storage to reduce the volume.

[0059] In this embodiment, it should be noted that since the IP status is stored for each IP using bit positions and the specific IP addresses are not explicitly stored, the memory occupancy and storage occupancy information are significantly reduced. And when recording a single boolean - type attribute, the memory occupancy for recording one A - class network segment is about 2M bytes, and the memory occupancy for recording all IPv4 addresses is about 512M bytes. Since compressed mode is used for persistent storage, the file size can generally be compressed to 2 - 10M bytes, significantly reducing the network transmission volume and disk occupancy.

[0060] In some embodiments, in step 205, when the detection node returns the stored detection result to the management center, it further includes: the detection node receives a detection instruction to continue monitoring whether there is a new scan result file; the detection node reads the new scan result file in the IP_BITS format and sends it to the management center.

[0061] In this embodiment, it should be noted that, as Figure 3 shown, the detection node continuously monitors new scan result files and sends the result files to the management center, which is convenient for the management center to uniformly update and maintain, and discovers the surviving network assets based on address scanning and port scanning so as to provide a basis for network space mapping.

[0062] Please continue to refer to Figure 3 shown, when the detection node reads the new scan result file in the IP_BITS format and sends it to the management center, it further includes: the management center stores the scan results returned by each detection node; the IP marking management component reads and merges the scan results of the same scan type, and ends the IP address status query and network segment statistical value query through the interface; the IP marking management component stores the final scan result.

[0063] In this embodiment, it should be noted that in the IP scanning system based on the present invention, IP_BITS is used to record, transfer and query data results; a marking writing component for IP_BITS is designed to update and maintain the bit status of each IP in the memory, and a compression algorithm is used to compress IP_BITS during persistent storage to reduce the volume; at the same time, a marking processing component for IP_BITS is designed, which can read and merge multiple IP_BITS data contents, and supports querying the number of marked IPs in each network segment and the marking status of specific IPs through the interface, so as to facilitate quickly grasping the situation of the entire network.

[0064] The above steps mainly implement dividing the addresses to be recorded into Class A addresses with network numbers from 1 to 255 by designing a data structure for storing IP status based on bit bits, abbreviated as IP_BITS. Each address segment is based on byte data, that is, the bit groups are arranged and stored in the order of the IP address value. A bit group is created only when the IP in the address segment is hit or a non-zero record value needs to be written; there are bit positions matching the number of IPs in each bit group to store the IP status. The starting point of each bit group is the first address of the specified Class A address, and the offset position of each bit relative to the first bit can calculate the corresponding specific IP address, thus avoiding saving specific IP address information, and therefore significantly reducing the memory occupancy and storage occupancy information.

[0065] In the IP scanning system based on the present invention, IP_BITS is used to record, transfer, and query data results; a tag writing component for IP_BITS is designed to update and maintain the bit status of each IP in memory, and a compression algorithm is used to compress IP_BITS during persistent storage to reduce its volume; at the same time, the data contents of multiple IP_BITS can be read and merged, and it is supported to query the number of marked IPs in each network segment and the marked status of specific IPs through an interface, so as to quickly query the number of marked IPs and the marked status of specific IPs to quickly grasp the overall network situation. Since the IP status is stored for each IP using bit positions and the specific IP addresses are not explicitly stored, the memory occupancy and storage occupancy information are greatly reduced, and persistent storage is performed in a compressed mode, and the file size can generally be compressed to 2 - 10 M bytes, thus greatly reducing the network transmission volume and disk occupancy, and enabling fast recording and retrieval with only a small amount of storage space and computing resources.

[0066] The embodiment of the present application also provides a detection and recording IPv4 address space survival system, please refer to Figure 7 , and this system may include: a detection receiving module, a detection execution module, and a management center module.

[0067] The main functions of each component module are as follows:

[0068] The detection receiving module 301 is used for each detection node to receive the detection instruction sent by the management center to detect the survival status of a specified single port.

[0069] The detection execution module 303 is used for the detection node to execute the detection instruction and store and compress the detection result in the format of IP_BITS;

[0070] The management center module 305 is used for the detection node to return the stored detection result to the management center.

[0071] According to the embodiment of the present application, the present application also provides a computer device and a computer-readable storage medium.

[0072] As Figure 8 shown, it is a block diagram of a computer device according to the embodiment of the present application. The computer device is intended to represent various forms of digital computers or mobile devices. Among them, the digital computer may include a desktop computer, a portable computer, a workbench, a personal digital assistant, a server, a mainframe computer, and other suitable computers. The mobile device may include a tablet computer, a smart phone, a wearable device, etc.

[0073] As Figure 8As shown, device 600 includes a computing unit 601, a ROM 602, a RAM 603, a bus 604, and an input / output (I / O) interface 605. The computing unit 601, the ROM 602, and the RAM 603 are connected to each other via the bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.

[0074] The computing unit 601 can perform various processes in the method embodiments of this application according to computer instructions stored in the read-only memory (ROM) 602 or computer instructions loaded into the random access memory (RAM) 603 from the storage unit 608. The computing unit 601 can be various general-purpose and / or dedicated processing components with processing and computing capabilities. The computing unit 601 can include, but is not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. In some embodiments, the method provided by the embodiments of this application can be implemented as a computer software program, which is tangibly included in a computer-readable storage medium, such as the storage unit 608.

[0075] The RAM 603 can also store various programs and data required for the operation of the device 600. Part or all of the computer programs can be loaded and / or installed onto the device 600 via the ROM 602 and / or the communication unit 609.

[0076] The input unit 606, the output unit 607, the storage unit 608, and the communication unit 609 in the device 600 can be connected to the I / O interface 605. Among them, the input unit 606 can be such as a keyboard, a mouse, a touch screen, a microphone, etc.; the output unit 607 can be such as a display, a speaker, an indicator light, etc. The device 600 can exchange information, data, etc. with other devices through the communication unit 609.

[0077] It should be noted that this device may also include other components necessary for normal operation. It may also only include the components necessary to implement the solution of this application, and does not necessarily include all the components shown in the figure.

[0078] Various embodiments of the systems and technologies described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof.

[0079] The computer instructions for implementing the method of the present application can be written in any combination of one or more programming languages. These computer instructions can be provided to the computing unit 601, so that when the computer instructions are executed by the computing unit 601 such as a processor, the various steps involved in the method embodiments of the present application are executed.

[0080] The computer-readable storage medium provided by the present application can be a tangible medium, which can contain or store computer instructions for executing the various steps involved in the method embodiments of the present application. The computer-readable storage medium can include, but is not limited to, storage media in the forms of electronic, magnetic, optical, electromagnetic, etc.

[0081] The above specific implementation manners do not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A method for detecting and recording the survival status of the IPv4 address space, characterized in that, the method includes: Each detection node receives a detection instruction sent by the management center to detect the survival status of a specified single port; The detection node executes the detection instruction and stores and compresses the detection result based on the IP_BITS format; The detection node returns the stored detection result to the management center; The detection node executes the detection instruction and stores and compresses the detection result based on the IP_BITS format, including: The detection node starts the IP scanning engine to execute the detection instruction; The IP scanning engine inputs the scanned detection result into the IP marking writing component; When the scanning task ends, the IP marking writing component stores and compresses the detection result in the IP_BITS format; The IP_BITS format specifically includes: The IP_BITS is stored in binary format and mainly includes a header structure, network segment count, and marking data for each network segment; Among them, the header structure part is first four 2-byte fields in sequence, namely type identifier (MagicID), version (version), header length (head_len), reserved field (reserved), and Json description (Description); The network segment count part consists of 256 4-byte fields in sequence. Among them, the first field is the count of all marked IPs, indicating the number of surviving IPs; starting from the second field, it is the count of marked IPs in each Class A network segment; The marking data for each network segment is to record the marking data of network numbers A1 to A254 based on the bit group in sequence.

2. The method for detecting and recording the survival status of the IPv4 address space according to claim 1, characterized in that, When the scanning task ends, the IP marking writing component stores and compresses the detection result in the IP_BITS format, including: The addresses to be recorded are divided into Class A addresses with network numbers 1-255. Each address segment arranges and stores the values to be recorded in the order of IP address values based on the bit group (bit_group). A bit group is created only when the IP in each address segment is hit or a non-zero record value needs to be written; Each IPv4 address can be represented as a four-byte array b[4]. Among them, for 1.2.3.4, the corresponding array values b[0], b[1], b[2], b[3] are the numbers 1, 2, 3, 4 respectively. Among them, the value of b[0] is the network number, and b[1]b[2]b[3] form the host number; If it is necessary to read or record the status of a certain IP, based on the network number b[0] of the IP, the corresponding bit group and the number of status bits (status_bits) to be recorded for each IP are located or created. The value of the number of status bits to be recorded for each IP is greater than or equal to 1 and less than or equal to 8. Then the length of the bit group is 2M * status_bits, and the byte offset and bit offset within the byte of the IP status are recorded; When the status to be read or recorded is of the unsigned char type, the lower status_bits binary values are specific boolean values; According to the recorded IP status type, based on the status bits, bit groups, and offset of the IP record, the reading of the recorded IP is implemented.

3. The method for detecting and recording the survival of the IPv4 address space according to claim 1, characterized in that when the scanning task ends, the IP marking writing component storing and compressing the detection results in the IP_BITS format further includes: updating and maintaining the bit status of each IP in the memory, and compressing the stored IP based on the IP_BITS format during persistent storage to reduce the volume.

4. The method for detecting and recording the survival of the IPv4 address space according to claim 1, characterized in that the detection node returning the stored detection results to the management center further includes: the detection node receiving a detection instruction to continue monitoring whether there is a new scan result file; the detection node reading the new scan result file in the IP_BITS format and sending it to the management center.

5. The method for detecting and recording the survival of the IPv4 address space according to claim 4, characterized in that the detection node reading the new scan result file in the IP_BITS format and sending it to the management center further includes: the management center storing the scan results returned by each detection node; the IP marking management component reading and merging the scan results of the same scan type, and ending the IP address status query and network segment statistical value query through an interface; the IP marking management component storing the final scan results.

6. A system for detecting and recording the survival of the IPv4 address space, characterized in that the system includes: Detection receiving module: Each detection node receives a detection instruction sent by the management center to detect the survival status of a specified single port; Detection execution module: The detection node executes the detection instruction and stores and compresses the detection results in the IP_BITS format; Management center module: The detection node returns the stored detection results to the management center; The detection node executing the detection instruction and storing and compressing the detection results in the IP_BITS format includes: the detection node starting the IP scanning engine to execute the detection instruction; the IP scanning engine inputting the scanned detection results into the IP marking writing component; when the scanning task ends, the IP marking writing component storing and compressing the detection results in the IP_BITS format; the IP_BITS format specifically includes: The IP_BITS is stored in binary mode and mainly includes a header structure, network segment count, and marking data for each network segment; wherein, the header structure part is first four 2-byte fields in sequence, namely type identifier (MagicID), version, header length, reserved field, and Json description; The network segment counting part consists of 256 4-byte fields in sequence. The first field is the count of all marked IPs, represented as the number of live IPs; starting from the second field, it is the count of marked IPs in each Class A network segment. The marking data for each network segment is the marking data of network numbers A1 to A254 recorded based on bit groups in sequence.

7. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, when the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 are implemented.

8. A computer-readable storage medium, on which a computer program is stored, wherein, when the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Industrial control network topological graph generation method based on active and passive detection

    CN112671553A

  • Asset detection method, device and equipment and storage medium

    CN114244755A