Network detection systems and methods, electronic devices, and storage media

By employing an address randomization generation module and asynchronous decoupled transceiver technology in IPv4 and IPv6 network spaces, the network detection system solves the problem of low efficiency in large-scale IPv6 network scanning in traditional methods, achieving efficient and accurate network detection and improving network security and reliability.

CN116743610BActive Publication Date: 2025-12-02TSINGHUA UNIVERSITY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310822311.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-05
Publication Date
2025-12-02
Estimated Expiration
2043-07-05

AI Technical Summary

Technical Problem

Traditional network probing methods struggle to efficiently perform large-scale scans in IPv6 network space, especially when probing is compatible with both IPv4 and IPv6 network space, resulting in low probing efficiency and an inability to effectively identify potential security threats.

Method used

The system employs an address randomization generation module to generate randomly arranged target probe addresses. Combined with the asynchronous decoupling transmission and reception technology of the data packet sending and receiving modules, the system disperses probe traffic through a full permutation modular multiplication algorithm, utilizes multiple transmission protocols for efficient scanning, and uses a probe result processing module to match check values ​​to determine valid response data packets.

Benefits of technology

It enables efficient, accurate, and large-scale scanning of IPv4 and IPv6 network spaces, reduces the impact on target networks, improves network security and reliability, and can identify potential security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116743610B_ABST
    Figure CN116743610B_ABST
Patent Text Reader

Abstract

A network detection system, method, electronic device, and storage medium are disclosed. The network detection system includes an address randomization generation module, a data packet sending module, a data packet receiving module, and a detection result processing module. The address randomization generation module is configured to generate multiple randomly arranged target detection addresses within the target address space to be detected. The data packet sending module is configured to send multiple request data packets corresponding to the multiple target detection addresses to a message buffer. The data packet receiving module is configured to receive multiple response data packets sent back from the multiple target detection addresses from the message buffer. The detection result processing module is configured to match the checksums of the multiple response data packets with the checksums of the multiple request data packets to determine the valid response data packets based on the matching results. This network detection system and method can efficiently and accurately perform large-scale scanning of network space, improving network security and reliability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of this disclosure relate to a network detection system and method, electronic device, and storage medium. Background Technology

[0002] Cyberspace probing is a method for studying and analyzing devices, services, network topology, and their security on the Internet. It is crucial for understanding resource distribution within a network, identifying potential security threats, and protecting critical infrastructure. Cyberspace probing helps businesses and governments monitor network security, optimize network resource allocation, and improve network service quality. By identifying open ports and scanning active hosts, cyberspace probing analyzes the configuration and performance of network services, discovers potential vulnerabilities, and evaluates the effectiveness of network security measures. Summary of the Invention

[0003] At least one embodiment of this disclosure provides a network detection system, comprising: an address randomization generation module configured to generate a plurality of randomly arranged target detection addresses within the target address space to be detected; a data packet sending module configured to send a plurality of request data packets corresponding to the plurality of target detection addresses to a message buffer; a data packet receiving module configured to receive a plurality of reply data packets sent back from the plurality of target detection addresses from the message buffer; and a detection result processing module configured to match the checksums of the plurality of reply data packets with the checksums of the plurality of request data packets to determine a valid reply data packet based on the matching result.

[0004] For example, in the network detection system provided in at least one embodiment of this disclosure, the protocol type of the target address space includes IPv4 protocol address or IPv6 protocol address.

[0005] For example, in the network detection system provided in at least one embodiment of this disclosure, the address randomization generation module is further configured to traverse multiple addresses in the target address space according to the full permutation modular multiplication algorithm to generate the multiple target detection addresses in a randomized permutation.

[0006] For example, in the network detection system provided in at least one embodiment of this disclosure, the address randomization generation module is further configured to: determine the address length according to the protocol type of the target address space; divide the target address space into multiple subspaces, and determine the range of scan numbers in each subspace according to the address length; and calculate the multiple target detection addresses arranged according to the scan numbers according to the full permutation modular multiplication algorithm.

[0007] For example, in a network detection system provided in at least one embodiment of this disclosure, the data packet sending module includes a data packet generation module, which is configured to generate a data segment and an identifier segment of the request data packet according to the protocol type of the target address space, and generate the checksum of the request data packet according to the identifier segment.

[0008] For example, in the network detection system provided in at least one embodiment of this disclosure, the identifier field includes an application layer identifier, a transport layer identifier, a network layer identifier, and a data link layer identifier.

[0009] For example, in the network detection system provided in at least one embodiment of this disclosure, the data packet generation module is further configured to: automatically obtain the MAC address of the target gateway through a MAC resolution query operation; and generate the data link layer identifier of the request data packet based on the MAC address.

[0010] For example, in the network detection system provided in at least one embodiment of this disclosure, the detection result processing module is further configured to: save or output detection result information according to the valid response data packet, wherein the detection result information includes the target detection address, the port of the target detection address, and the payload.

[0011] For example, at least one embodiment of the network detection system provided in this disclosure further includes: an initialization module configured to initialize and configure the detection parameters of the network detection system and receive address parameters input by the user; and a target space processing module configured to determine the target address space to be detected based on the address parameters.

[0012] For example, in the network detection system provided in at least one embodiment of this disclosure, the address parameter includes a prefix number of bits and a suffix number of bits, wherein the prefix number of bits is used to determine the starting traversal bit length of the target address space, and the suffix number of bits is used to determine the ending traversal bit length of the target address space.

[0013] For example, in the network detection system provided in at least one embodiment of this disclosure, the address parameter further includes a user-inputted starting address value.

[0014] The target space processing module is further configured to: use the starting address value as the value of the number of bits before the starting traversal bits of the target address space.

[0015] For example, in the network detection system provided in at least one embodiment of this disclosure, the address parameter further includes a user-inputted termination address value.

[0016] The target space processing module is further configured to generate the value of the number of bits after the termination traversal bit based on the termination address value or a predefined value in the fixed pattern or a randomization algorithm.

[0017] For example, in the network detection system provided in at least one embodiment of this disclosure, the detection parameters include the local network card, MAC address, detection speed, and detection blacklist / whitelist.

[0018] For example, at least one embodiment of the network detection system provided in this disclosure further includes: a network protocol scanning module configured to determine a target transmission protocol for scanning the plurality of target detection addresses;

[0019] The data packet sending module is further configured to send the plurality of request data packets corresponding to the plurality of target probe addresses to the message buffer based on the target transmission protocol, and the data packet receiving module is further configured to receive the plurality of reply data packets sent back from the plurality of target probe addresses from the message buffer based on the target transmission protocol.

[0020] For example, in the network detection system provided in at least one embodiment of this disclosure, the target transmission protocol includes at least one of Transmission Control Protocol, User Datagram Protocol, and Internet Control Message Protocol.

[0021] For example, in the network detection system provided in at least one embodiment of this disclosure, the network protocol scanning module is further configured to determine multiple target transmission protocols based on port parameters input by the user, and to perform multi-port parallel scanning of multiple target detection addresses based on multiple ports corresponding to the multiple target transmission protocols.

[0022] For example, in the network detection system provided in at least one embodiment of this disclosure, the network protocol scanning module includes: a DNS scanning module configured to resolve domain names and DNS server versions and configure query types; an address spoofing module configured to perform packet sending tests on the source address of the spoofed address; and a stateful scanning module configured to determine the content of the next probe based on the valid response data packet.

[0023] At least one embodiment of this disclosure also provides a network probing method, which includes: generating a plurality of randomly arranged target probe addresses within a target address space to be probed; sending a plurality of request data packets corresponding to the plurality of target probe addresses to a message buffer; receiving a plurality of reply data packets sent back from the plurality of target probe addresses from the message buffer; and matching the checksums of the plurality of reply data packets with the checksums of the plurality of request data packets to determine a valid reply data packet based on the matching result.

[0024] For example, at least one embodiment of the network detection method provided in this disclosure further includes: initializing and configuring the detection parameters of the network detection system and receiving address parameters input by the user; and determining the target address space to be detected by the target address space processing module based on the address parameters.

[0025] For example, the network probing method provided in at least one embodiment of this disclosure further includes: determining a target transport protocol for scanning the plurality of target probe addresses; sending the plurality of request data packets corresponding to the plurality of target probe addresses to the message buffer based on the target transport protocol; and receiving the plurality of reply data packets sent back from the plurality of target probe addresses from the message buffer based on the target transport protocol.

[0026] At least one embodiment of this disclosure also provides an electronic device, including: a memory that non-transitoryly stores computer-executable instructions; and a processor configured to run the computer-executable instructions, wherein the computer-executable instructions are executed by the processor to implement the network detection method described in any embodiment of this disclosure.

[0027] At least one embodiment of this disclosure also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, implement the network detection method described in any embodiment of this disclosure. Attached Figure Description

[0028] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the accompanying drawings of the embodiments will be briefly described below. Obviously, the drawings described below only relate to some embodiments of this disclosure and are not intended to limit this disclosure.

[0029] Figure 1 This is a schematic diagram of the structure of a network detection system provided in at least one embodiment of the present disclosure;

[0030] Figure 2 A block diagram of an exemplary network protocol scanning module provided for at least one embodiment of this disclosure;

[0031] Figure 3 A schematic diagram illustrating a network detection method provided in at least one embodiment of this disclosure;

[0032] Figure 4 A schematic block diagram of an electronic device provided for at least one embodiment of this disclosure; and

[0033] Figure 5 A schematic diagram of a non-transitory computer-readable storage medium provided for at least one embodiment of the present disclosure. Detailed Implementation

[0034] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments of this disclosure without creative effort are within the scope of protection of this disclosure.

[0035] Unless otherwise defined, the technical or scientific terms used in this disclosure shall have the ordinary meaning understood by one of ordinary skill in the art to which this disclosure pertains. The terms “first,” “second,” and similar terms used in this disclosure do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as “comprising” or “including” mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as “connected” or “linked” are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as “upper,” “lower,” “left,” and “right” are used only to indicate relative positional relationships, and these relative positional relationships may change accordingly when the absolute position of the described objects changes.

[0036] The present disclosure will now be described through several specific embodiments. To keep the following description of the embodiments of the present disclosure clear and concise, detailed descriptions of known functions and known components may be omitted. When any component of an embodiment of the present disclosure appears in more than one drawing, that component is represented by the same or similar reference numerals in each drawing.

[0037] The main purpose of network probing technology is to discover active devices, services, network resources, and potential security risks in the network's address space, thereby helping network administrators, security researchers, and enterprises understand network conditions, identify potential security risks, and optimize network resource allocation.

[0038] Full-network brute-force scanning is a commonly used network probing method. It involves traversing the entire network space, typically scanning in descending or ascending order of network addresses. This allows for the detection of devices and network assets, helping to identify potential security risks in a timely manner. However, full-network brute-force scanning has a narrow scope. Because it requires scanning all addresses in the entire network space, it is only suitable for networks with a relatively small number of addresses, such as the IPv4 address space, and is difficult to apply to networks with an extremely large number of addresses, such as the IPv6 address space.

[0039] The Internet Protocol (IP) is a datagram protocol that enables internetworking. The IP protocol assigns a digital address to each device connected to the network. An IP address is a unique combination of numbers that allows a user to communicate with others. IPv4 and IPv6 are two major versions of the Internet Protocol used for transmitting datagrams over a network. Although IPv4 and IPv6 are different types of IP addresses, they serve the same primary purpose: identifying different users and allowing them to communicate over the network. The main difference is that IPv4 is currently the most widely used version of the protocol, while IPv6 is the latest generation of IP addresses.

[0040] IPv4 addresses are the most widely used address types, typically represented in dotted decimal notation, such as 172.16.254.1, which is represented in binary as 10101100.00010000.11111110.00000001, forming a 32-bit address scheme. Therefore, the number of possible IPv4 address combinations is finite, resulting in approximately 4 billion unique addresses. Due to the 32-bit address length, the number of allocable IPv4 addresses is limited, and with the rapid development of the Internet, IPv4 addresses are facing depletion.

[0041] As IPv4 address resources are gradually depleted, IPv6 deployment is receiving increasing attention. IPv6 addresses are the latest version of the Internet Protocol (IP) and are designed to replace IPv4 addresses. As the successor to IPv4, IPv6 has a 128-bit address length, providing a vast amount of address space to meet the needs of the future Internet. IPv6 addresses use colon-separated hexadecimal numbers, which can be divided into eight 16-bit blocks, for example, 0123:4567:89ab:cdef:0123:4567:89ab:cdef, forming a total of 128-bit address scheme.

[0042] IPv6 addresses not only provide a virtually unlimited supply of IP addresses to address the IPv4 address exhaustion problem, but also introduce numerous improvements and optimizations, such as a simpler packet format, more efficient routing, and automatic address configuration. For example, IPv6 simplifies the configuration and management of network devices, reducing network maintenance costs. Furthermore, IPv6 redesigns the packet header, simplifying router packet processing and improving network transmission efficiency. Simultaneously, IPv6 natively supports IPsec (the IP security protocol), providing stronger confidentiality, integrity, and authentication during data transmission over the internet. This helps improve network security and reduces the risk of hacking and data theft.

[0043] With the deployment of IPv6, IPv4 and IPv6 networks need to achieve interconnection, which will drive the development and optimization of various network protocols and services, improving the performance and stability of the entire Internet. While IPv6 offers more address resources, its integration and adaptation are more complex. For example, using IPv6 requires operating system compatibility, router support, and IP service provider support. Therefore, IPv4 and IPv6 cannot communicate directly with each other and require methods to translate addresses between the two protocols. New network probing techniques also need to be designed to address the characteristics of both protocols when probing IPv4 and IPv6 networks.

[0044] Due to the sheer size of the IPv6 address space, traditional network space probing methods are often inefficient at detecting targets within IPv6 networks. For example, because IPv4 has 2... 32 The IPv4 address space is 2^6, so a brute-force scan of the entire network can be used to scan the entire IPv4 space. However, the IPv6 address space is 2^6. 128 Traversing such a vast address space would take at least 40,000 years, rendering traversal and enumeration methods unsuitable. Therefore, how to perform large-scale scanning compatiblely across IPv4 and IPv6 network spaces has become a pressing issue.

[0045] This disclosure provides at least one embodiment of a network detection system. The network detection system includes an address randomization generation module, a data packet sending module, a data packet receiving module, and a detection result processing module. The address randomization generation module is configured to generate multiple randomly arranged target detection addresses within the target address space to be detected; the data packet sending module is configured to send multiple request data packets corresponding to the multiple target detection addresses to a message buffer; the data packet receiving module is configured to receive multiple reply data packets sent back from the multiple target detection addresses from the message buffer; and the detection result processing module is configured to match the checksums of the multiple reply data packets with the checksums of the multiple request data packets to determine valid reply data packets based on the matching results.

[0046] At least one embodiment of this disclosure also provides a network probing method. The network probing method includes generating a plurality of randomly arranged target probe addresses within the target address space to be probed; sending a plurality of request data packets corresponding to the plurality of target probe addresses to a message buffer; receiving a plurality of reply data packets sent back from the plurality of target probe addresses from the message buffer; and matching the checksums of the plurality of reply data packets with the checksums of the plurality of request data packets to determine a valid reply data packet based on the matching result.

[0047] At least one embodiment of this disclosure also provides an electronic device and a non-transitory computer-readable storage medium.

[0048] The network detection system and method provided in at least one embodiment of this disclosure can efficiently and accurately perform large-scale scanning of network space using an address randomization generation module and a send / receive separation asynchronous scanning mechanism. This helps to better understand and manage increasingly complex network environments and improve network security and reliability. In at least one embodiment, the network detection system and method can also solve the problem of efficiently detecting arbitrary target addresses, ports, and network protocols in IPv4 and IPv6 network space, reducing the impact on the target network and avoiding excessive burden on network devices.

[0049] The embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0050] Figure 1 This is a schematic diagram of the structure of a network detection system provided in at least one embodiment of this disclosure. For example... Figure 1 As shown, the network detection system 100 includes an address randomization generation module 30, a data packet sending module 50, a data packet receiving module 60, and a detection result processing module 70.

[0051] For example, the address randomization generation module 10 is configured to generate multiple target detection addresses in a randomized arrangement within the target address space to be detected.

[0052] In at least one embodiment of this disclosure, the protocol type of the target address space includes IPv4 protocol addresses or IPv6 protocol addresses. That is, the addresses in the target address space can be either IPv4 addresses or IPv6 addresses. The address randomization generation module 10 can select whether the protocol of the address space to be probed is IPv4 or IPv6 according to the user's needs, thereby generating multiple target probe addresses in a randomized arrangement of 32 bits or 128 bits in the target address space, thereby enabling compatible probes for both address protocols.

[0053] For example, in some embodiments of this disclosure, the target address space may be a portion of the IPv6 address space, or it may be all or part of the IPv4 address space. Here, a portion of the address space refers to a part of the entire IPv4 or IPv6 address space, and the total number of addresses in the portion of the address space is less than 2. 32 or 2 128 .

[0054] For example, the address randomization generation module 10 can use the address permutation randomization generation technology to traverse and scan all addresses in the target address space, thereby generating a random and non-repeating target address sequence in a large-scale address space. The address randomization generation module 10 can randomly arrange multiple target probe addresses in the address space according to the target address sequence, thereby performing balanced traversal and probe of the target address space, ensuring that the network probe of the target address space is comprehensive and complete.

[0055] For example, packet sending module 50 is configured to send multiple request packets corresponding to multiple target probe addresses to a message buffer. Packet receiving module 60 is configured to receive multiple reply packets sent back from the multiple target probe addresses from the message buffer.

[0056] For example, in some embodiments of this disclosure, the data packet sending module 50 includes a data packet generation module, which is configured to generate a data segment and an identifier segment of a request data packet according to the protocol type of the target address space, and generate a checksum of the request data packet according to the identifier segment.

[0057] When scanning a network, it is usually necessary to first construct a request packet (or probe packet), then send the probe packet to the target host and receive a reply packet (or response packet) from the target host, and finally analyze and process the response packet to generate probe result information (or scan result packet).

[0058] The format of data packets (or messages) is related to the relevant service layers of the network architecture. Current network architectures mainly include the application layer, transport layer, network layer, data link layer, and physical layer. For example, the application layer directly provides services to user application processes (such as email, file transfer, and terminal emulation); the transport layer is responsible for providing services for communication between processes on two hosts; the network layer is responsible for providing communication services to different hosts on a packet-switched network and selecting appropriate routes so that packets from the source host, transmitted through the transport layer, can find their destination host through routers in the network; the data link layer is responsible for assembling IP datagrams from the network layer into frames when transmitting data between two adjacent nodes; and the physical layer is responsible for transparently transmitting bit streams.

[0059] For example, in some embodiments of this disclosure, the identifier field of the data packet includes an application layer identifier, a transport layer identifier, a network layer identifier, and a data link layer identifier.

[0060] For example, in some embodiments of this disclosure, the packet generation module is further configured to automatically obtain the MAC address of the target gateway through a MAC resolution query operation; and generate a data link layer identifier for the request packet based on the MAC address. Utilizing a local MAC request resolution query can automatically obtain the MAC address of the local gateway, accelerating the packet sending process.

[0061] For example, embodiments of this disclosure utilize asynchronous decoupled data packet transmission and reception technology for sending and receiving data packets. In this technology, the sender and receiver communicate through middleware such as message queues or event buses (corresponding to the message buffer in this disclosure). That is, after the data packet sending module 50 sends a request data packet, the data packet receiving module 60 no longer needs to wait for a long time to receive the corresponding reply data packet.

[0062] For example, in at least one embodiment of this disclosure, the data packet sending module 50 can generate a specific request data packet for each target probe address. This request data packet is sent to a message buffer. The active host of the target probe address can retrieve the corresponding request data packet from the message buffer queue at an appropriate time and send a reply data packet to the message buffer. Correspondingly, the data packet receiving module 60 can also retrieve the reply data packet from the message buffer at an appropriate time. Therefore, the data packet sending module 50 does not need to wait for a response from the active host of the target probe address, nor does it need to worry about whether or when the data packet receiving module 60 receives the reply data packet. The data packet sending module 50 can immediately send the next data request packet after sending one data request packet, without being limited by the processing speed of the data packet receiving module 60. Simultaneously, the data packet receiving module 60 can acquire and process messages according to its own processing capabilities, avoiding performance degradation caused by blocking during the probe process.

[0063] For example, the detection result processing module 70 is configured to match the checksums of multiple response data packets with the checksums of multiple request data packets to determine the valid response data packets based on the matching results.

[0064] Since the data packet sending module 50 does not wait for the data packet receiving module 60 to finish receiving the reply data packet before sending the next request data packet, when the data packet receiving module 60 receives multiple reply data packets, it needs to match the multiple received reply data packets with the multiple sent request data packets to correctly match the reply data packets with the request data packets one by one.

[0065] The checksum is generated based on the entire data packet, and different data packets have different checksums. Each sent request data packet generates a separate checksum field based on the identifier field. After receiving a reply data packet, a checksum can be recalculated based on the reply data packet. If the checksum is equal to the checksum in the request data packet, it means that the reply data packet matches the sent data packet.

[0066] For example, in at least one embodiment of this disclosure, after the data packet receiving module 60 receives a reply data packet, the detection result processing module 70 can obtain the checksum in the reply data packet and compare and match the checksum in the reply data packet with the checksums of the multiple sent request data packets, thereby determining the successfully matched reply data packet as a valid reply data packet. Unmatched reply data packets can be discarded or identified as incorrect reply data packets for further processing.

[0067] For example, in some embodiments of this disclosure, the detection result processing module 70 is further configured to save or output detection result information based on valid response data packets, the detection result information including the target detection address, the port of the target detection address, and the payload.

[0068] For example, the detection result processing module 70 can output detection result information based on multifunctional detection results from files or databases. For example, by calling relevant databases and generating custom files (TXT, CSV, DB), it can selectively save or output all or specific fields in the valid response data packets, such as the target detection address, the port of the target detection address, and the payload.

[0069] Therefore, the network detection system provided in at least one embodiment of this disclosure utilizes full permutation randomization generation technology to enable the address randomization generation module 10 to perform harmless traversal detection of the target address space, thereby dispersing the detection traffic. It also utilizes asynchronous decoupling transmission and reception technology to separate the sending and receiving processes of the data packet sending module 50 and the data packet receiving module 60, allowing them to operate independently in time. This greatly improves the speed of network detection, increases the detection efficiency of large-scale scanning, and enables efficient and accurate large-scale scanning of the network space, thereby improving network security and reliability.

[0070] Probe traffic refers to data packets sent by a probe to a target network in order to probe the target space. If data packets are concentrated in the same small area of ​​the target network for a period of time, it will have a significant impact on the target network. Therefore, probe traffic should be distributed.

[0071] For example, in some embodiments of this disclosure, the address randomization generation module 30 is further configured to traverse multiple addresses in the target address space according to the full permutation modular multiplication algorithm to generate multiple target probe addresses with randomized permutations.

[0072] For example, the full permutation modular multiplication algorithm can be used to randomly generate all integer numbers within a certain range. Rigorous mathematical verification ensures the completeness of the address randomization generation. The address randomization generation module 30 can traverse multiple addresses in a target address space with an arbitrary custom address space range according to the full permutation modular multiplication algorithm, thereby generating multiple randomly permuted target probe addresses.

[0073] For example, the address randomization generation module 30 first determines the address length based on the protocol type of the target address space. If the target address space is an IPv4 protocol address, the address length is determined to be 32 bits; if the target address space is an IPv6 protocol address, the address length is determined to be 128 bits. Then, the address randomization generation module 30 divides the target address space into multiple subspaces and determines the range of scan sequence numbers in each subspace based on the address length. For example, it converts IPv4 or IPv6 addresses, which are at most 32 bits or 128 bits, into custom large integer scan sequence numbers. For IPv6, the scan sequence number range can be 2... n The range of n is 0 to 128. Finally, based on the full permutation modular multiplication algorithm, for the integer value range of the determined scan sequence number, multiple iterations are performed using pre-calculated prime factors and modulo. In each iteration, different inputs are specified, i.e., from 1 to the largest address sequence number, and the corresponding address part value is output. Based on this, mathematical operations can be performed to obtain multiple randomly distributed target detection addresses arranged according to the scan sequence number.

[0074] Therefore, the network detection system 100 can detect the target address space according to the address sequence of full permutation randomization, and can randomly distribute the detection traffic to different target networks, which greatly reduces the impact on the target network and avoids the security risks and detection of network defense facilities caused by continuous address scanning.

[0075] like Figure 1 As shown, in some embodiments of this disclosure, the network detection system 100 further includes an initialization module 10 and a target space processing module 20.

[0076] For example, the initialization module 10 is configured to initialize the detection parameters of the network detection system 100 and receive address parameters input by the user.

[0077] For example, detection parameters include the local network card, MAC address, detection speed, detection blacklist / whitelist, and other detection parameters required by subsequent modules.

[0078] In at least one embodiment of this disclosure, the initialization module 10 is responsible for starting and initializing the files of the entire network detection system 100. For example, the initialization module 10 can automatically identify the local network card, MAC address list, configure detection speed, detection blacklist / whitelist list, or other relevant parameters of the module, and can also receive some data parameters input by the user, such as address parameters.

[0079] For example, the target space processing module 20 is configured to determine the target address space to be probed based on address parameters.

[0080] In at least one embodiment of this disclosure, the target space processing module 20 can determine the size of the target address space based on the address parameters input by the user. For example, the target space processing module 20 can determine any custom address range for scanning based on the specified address space input by the user, providing great flexibility.

[0081] For example, in some embodiments of this disclosure, the address parameters include a prefix number of bits and a suffix number of bits, wherein the prefix number of bits is used to determine the starting traversal bit length of the target address space and the suffix number of bits is used to determine the ending traversal bit length of the target address space.

[0082] Current detection systems typically only allow specifying the prefix of the probe address, unable to control the suffix, and even less able to traverse only the middle portion of the address space. The embodiments of this disclosure, by setting the prefix and suffix bit lengths, can support scanning any part of the IPv4 or IPv6 address space, such as bits 16 to 24 of the IPv4 address space or bits 32 to 48 of the IPv6 address space. Upon receiving the prefix and suffix bit lengths, the target space processing module 20 considers the address space within this range as the target for address permutation generation, randomly generates it using the permutation modular multiplication algorithm, and finally combines the generated address portion with the address prefix identifier and address suffix identifier to form the complete target address space.

[0083] For example, in some embodiments of this disclosure, the address parameter also includes a user-input starting address value, which can be used as an address prefix identifier, i.e., can be configured by the target space processing module 20 as the value of the number of bits before the starting traversal bits of the target address space.

[0084] For example, in some embodiments of this disclosure, the address parameter also includes a user-inputted termination address value, which can be used as an address suffix identifier, that is, it can be configured by the target space processing module 20 as the value of the number of bits after the termination traversal bit of the target address space.

[0085] For example, in one instance, for a user-specified IPv4 address space, the prefix length of the user-input IPv4 address space is 16, the suffix length is 24, the starting address value is 10101100.00010000, and the ending address value is 00000000. Then, the target space processing module 20 can determine that the target address space to be probed is from 10101100.00010000.00000000.00000000 to 10101100.00010000.11111111.00000000.

[0086] For example, in some embodiments of this disclosure, the target space processing module is further configured to generate the value of the bits after the terminating traversal bits based on predefined values ​​in a fixed pattern. That is, the address suffix identifier can also be some fixed predefined values, such as all 0s, all 1s, or FFFE. For example, in one example, the prefix bits of the IPv4 address space input by the user are 16, the suffix bits are 24, the starting address value is 10101100.00010000, and the ending address value is composed of predefined values ​​in a fixed pattern, such as the ending address value is 11111111. Then the target space processing module 20 can determine that the target address space to be probed is from 10101100.00010000.00000000.11111111 to 10101100.00010000.11111111.11111111.

[0087] For example, in some embodiments of this disclosure, the target space processing module is further configured to generate the value of the number of bits after the terminating traversal bit according to a randomization algorithm. That is, the address suffix identifier can also be a randomly generated number, and this disclosure does not limit the specific value of the randomization algorithm and the randomly generated address suffix identifier.

[0088] like Figure 1 As shown, in some embodiments of this disclosure, the network detection system 100 further includes a network protocol scanning module 40. For example, the network protocol scanning module 40 is configured to determine a target transport protocol for scanning multiple target detection addresses. For example, in this embodiment, the data packet sending module 50 is further configured to send multiple request data packets corresponding to the multiple target detection addresses to a message buffer based on the target transport protocol, and the data packet receiving module 60 is further configured to receive multiple reply data packets sent back from the multiple target detection addresses from the message buffer based on the target transport protocol.

[0089] For example, in some embodiments of this disclosure, the target transport protocol includes at least one of Transmission Control Protocol (TCP), User Datagram Protocol (UDP), and Internet Control Message Protocol (ICMP).

[0090] For example, at least one embodiment of this disclosure utilizes the Transmission Control Protocol (TCP) message segment as specified in RFC 793. A TCP message segment is the basic unit for data transmission in a network. A TCP message segment includes a series of fields used to implement reliable, connection-oriented data transmission services. A TCP segment consists of a header and a data portion. The header mainly includes fields such as source port, destination port, sequence number, acknowledgment number, and data offset, used to implement functions such as ordered data transmission, retransmission control, and reliable data transmission. Control bits, such as SYN, ACK, and FIN, are used to control the establishment, maintenance, and termination of TCP connections. TCP message segments play a crucial role in achieving reliable data transmission.

[0091] For example, at least one embodiment of this disclosure utilizes User Datagram Protocol (UDP) message messages as specified in RFC 768. A UDP message is the basic unit for data transmission in a network, providing a connectionless, best-effort data transmission service. A UDP message consists of a header and a data portion. The header is relatively simple, including only fields such as source port, destination port, length, and checksum. Compared to TCP, UDP lacks complex flow control, congestion control, and reliability guarantee mechanisms, thus offering faster transmission speeds and making it suitable for applications with high real-time requirements, such as voice communication and video streaming. UDP messages may be lost or corrupted during transmission, requiring application layer handling of these issues. UDP can deliver data from transport layer segments (identifier segments in this disclosure) to the correct sockets through demultiplexing. UDP can also collect data blocks from different sockets on the source host through multiplexing and add header information to generate segments.

[0092] For example, at least one embodiment of this disclosure utilizes Internet Control Protocol (ICMP) message messages as specified in RFC 4443. ICMP message messages are the basic units used in a network to transmit control and network diagnostic information. ICMP messages consist of fields such as type, code, and checksum, and are typically embedded in IP data segments for transmission. The main functions of ICMP messages are to transmit error information, diagnose network problems, and probe network connectivity. For example, ICMP ping and pong messages are used to detect connectivity between two nodes in a network. Additionally, ICMP messages can also transmit error messages such as "destination unreachable" and "timeout." ICMP control message messages play a crucial role in network maintenance and diagnostics.

[0093] For example, in some embodiments of this disclosure, the network protocol scanning module 40 is further configured to determine multiple target transmission protocols based on port parameters input by the user, and to perform multi-port parallel scanning of multiple target probe addresses based on multiple ports corresponding to the multiple target transmission protocols.

[0094] Figure 2 This is a block diagram of an exemplary network protocol scanning module provided for at least one embodiment of the present disclosure. For example, the network protocol scanning module 40 may include IPv4-oriented scanning or IPv6 scanning. For example, performing multi-port parallel scanning based on multiple target transport protocols includes selecting TCP_SYN scan, TCP_SCAN scan, UDP scan, ICMP_ECHO scan, ICMP_GW scan, or ICMP_TMXD scan, etc.

[0095] For example, in some embodiments of this disclosure, the network protocol scanning module 40 includes: a DNS scanning module configured to resolve domain names and DNS server versions and configure query types; an address spoofing module configured to perform packet sending tests on the source address of the spoofed address; a stateful scanning module configured to determine the content of the next probe based on valid response data packets; and a network vulnerability scanning module configured to scan for routing vulnerabilities.

[0096] In summary, the network protocol scanning module 40 supports the integration of various user-defined network protocol scanning functions. Based on IPv4, IPv6, TCP, UDP, and ICMP protocols, it implements scanning functions for almost all mainstream network protocols. It can perform parallel scanning of multiple ports to discover critical network devices (such as border devices), and also supports deep customized detection of some protocols, such as address spoofing, stateful scanning, and DNS software version detection. It also incorporates some network vulnerability scanning, such as routing loop vulnerabilities. The customizable development of the network protocol scanning module greatly facilitates the integration of subsequent scanning modules.

[0097] At least one embodiment of this disclosure also utilizes modular system development technology to implement a network detection system. Modular system development technology divides a complex system into multiple independent, reusable, and interchangeable modules. In the embodiments of this disclosure, each module, such as the initialization module 10, target space processing module 20, address randomization generation module 30, network protocol scanning module 40, data packet sending module 50, data packet receiving module 60, and detection result processing module, has a clearly defined function and interacts with other modules through well-defined interfaces. This design principle allows each module to be developed, tested, and maintained independently, reducing coupling between modules and minimizing risks during development. Furthermore, modular design facilitates code reuse and sharing, contributing to improved software development efficiency.

[0098] Figure 3 This is a schematic diagram illustrating a network detection method provided in at least one embodiment of this disclosure. Figure 3 As shown, the network detection method includes steps S100 to S400.

[0099] Step S100: Generate multiple target detection addresses in a randomized arrangement within the target address space to be detected using the address randomization generation module.

[0100] Step S200: Send multiple request data packets corresponding to multiple target probe addresses to the message buffer through the data packet sending module.

[0101] Step S300: Receive multiple reply data packets sent back from multiple target probe addresses from the message buffer via the data packet receiving module.

[0102] Step S400: The detection result processing module matches the checksums of multiple response data packets with the checksums of multiple request data packets to determine the valid response data packets based on the matching results.

[0103] For example, at least one embodiment of the network detection method provided in this disclosure further includes: initializing and configuring the detection parameters of the network detection system and receiving address parameters input by the user through an initialization module; and determining the target address space to be detected based on the address parameters through a target space processing module.

[0104] For example, at least one embodiment of the network probing method provided in this disclosure further includes: determining a target transmission protocol for scanning multiple target probe addresses using a network protocol scanning module; sending multiple request data packets corresponding to the multiple target probe addresses to a message buffer based on the target transmission protocol using a data packet sending module; and receiving multiple reply data packets sent back from the multiple target probe addresses from the message buffer based on the target transmission protocol using a data packet receiving module.

[0105] For example, the process of using the network probing system 100 to quickly probe the address space of IPv4 or IPv6 includes: starting the network probing system 100; initializing the system through the initialization module 10 and receiving user-inputted parameter information, such as address parameters and port parameters; processing the user-inputted address parameters through the target space processing module 20 to determine the space range that needs to be traversed when generating target probe addresses, i.e., the target address space; generating randomized target probe addresses through the address randomization generation module 30 according to the user-specified method and the full permutation algorithm until traversal is complete; determining the user-specified scanning module through the network protocol scanning module 40; generating request packets for multiple target probe addresses using the packet generation module; sending request packets through the packet sending module 50; receiving reply packets through the packet receiving module 60; saving or outputting the probe results information through the probe result processing module 70 according to the user-specified output module; determining whether the network space probe is complete, exiting if the result is yes, otherwise continuing to generate randomized target probe addresses through the address randomization generation module 30 until the probe of the target network is completed.

[0106] The network probing method provided in at least one embodiment of this disclosure utilizes full permutation randomization generation technology to enable the address randomization generation module 10 to perform harmless traversal probing of the target address space, thereby dispersing the probing traffic. It also utilizes asynchronous decoupling transmission and reception technology to separate the sending and receiving processes of the data packet sending module 50 and the data packet receiving module 60, allowing them to operate independently in time. This greatly improves the speed of network probing, increases the detection efficiency of large-scale scanning, and enables efficient and accurate large-scale scanning of the network space, thereby improving network security and reliability.

[0107] At least one embodiment of this disclosure also provides an electronic device. Figure 4 This is a schematic block diagram of an electronic device provided for at least one embodiment of the present disclosure.

[0108] For example, such as Figure 4 As shown, the electronic device includes a processor 1001, a communication interface 1002, a memory 1003, and a communication bus 1004. The processor 1001, communication interface 1002, and memory 1003 communicate with each other through the communication bus 1004, and the components such as the processor 1001, communication interface 1002, and memory 1003 can also communicate with each other through network connection.

[0109] For example, memory 1003 is used to store computer-executable instructions non-transitory. When processor 1001 runs the computer-executable instructions, the computer-executable instructions are executed by processor 1001 to implement the network probing method according to any of the above embodiments. For details on the specific implementation and related explanations of each step of this network probing method, please refer to the above text, and will not be repeated here.

[0110] For example, processor 1001 can control other components in an electronic device to perform desired functions. Processor 1001 can be a central processing unit (CPU), a network processor (NP), or a digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The central processing unit (CPU) can be an x86 or ARM architecture, etc. For example, the implementation of the network detection method by processor 1001 executing the program stored in memory 1003 is the same as in the embodiments described above, and will not be repeated here.

[0111] For example, the communication bus 1004 can be a Peripheral Component Interconnect Standard (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but this does not indicate that there is only one bus or one type of bus. For example, the communication interface 1002 is used to realize communication between electronic devices and other devices.

[0112] For example, memory 1003 may include any combination of one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, erasable programmable read-only memory (EPROM), portable compact disc read-only memory (CD-ROM), USB memory, flash memory, etc. One or more computer-executable instructions may be stored on the computer-readable storage medium, and processor 1001 may execute the computer-executable instructions to implement various functions of the electronic device. Various application programs and various data may also be stored in the storage medium. For a detailed description of the process by which the electronic device performs the network probing method, please refer to the relevant descriptions in the embodiments of the network probing method above; repeated details will not be repeated here.

[0113] Figure 5 This is a schematic diagram of a non-transitory computer-readable storage medium provided for at least one embodiment of the present disclosure. For example, such as Figure 5As shown, one or more computer-executable instructions 1101 may be stored non-temporarily on storage medium 1100. For example, when the computer-executable instructions 1101 are executed by a processor, one or more steps in the network probing method described above may be performed.

[0114] For example, the storage medium 1100 can be used in the aforementioned electronic device 800. For example, the storage medium 1100 may include the memory 1003 in the electronic device. A description of the storage medium 1100 can be found in the description of the memory 1003 in the embodiments of the electronic device; details will not be repeated here.

[0115] Although the present disclosure has been described in detail above with general descriptions and specific embodiments, modifications or improvements can be made to the embodiments of the present disclosure, which will be obvious to those skilled in the art. Therefore, all such modifications or improvements made without departing from the spirit of the present disclosure are within the scope of protection claimed by the present disclosure.

[0116] The following points should be noted regarding this disclosure:

[0117] (1) The accompanying drawings of the embodiments of this disclosure only involve the structures involved in the embodiments of this disclosure. Other structures can be referred to the general design.

[0118] (2) For clarity, the thickness of layers or regions in the drawings used to describe embodiments of the present disclosure is enlarged or reduced, i.e., these drawings are not drawn to actual scale.

[0119] (3) Where there is no conflict, the embodiments of this disclosure and the features in the embodiments can be combined with each other to obtain new embodiments.

[0120] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. The scope of protection of this disclosure should be determined by the scope of protection of the claims.

Claims

1. A network detection system, comprising: The initialization module is configured to initialize the detection parameters of the network detection system and receive address parameters input by the user. The target space processing module is configured to determine the target address space to be probed based on the address parameters, wherein the address parameters include a prefix length, a suffix length, a user-inputted start address value, and a user-inputted end address value. The prefix length is used to determine the starting traversal length of the target address space, and the suffix length is used to determine the ending traversal length of the target address space. The target space processing module is further configured as follows: The starting address value is used as the value of the bits before the starting traversal bits in the target address space; the value of the bits after the ending traversal bits is generated based on the ending address value; The address randomization generation module is configured to generate multiple target detection addresses in a randomized arrangement within the target address space to be detected; The data packet sending module is configured to send multiple request data packets corresponding to the multiple target detection addresses to a message buffer; The data packet receiving module is configured to receive multiple reply data packets sent back from the multiple target probe addresses from the message buffer; The detection result processing module is configured to match the checksums of the multiple response data packets with the checksums of the multiple request data packets, so as to determine the valid response data packets based on the matching results. The message buffer is used for communication between the sender and receiver in asynchronous decoupled send / receive technology.

2. The network detection system according to claim 1, wherein, The target address space includes IPv4 protocol addresses or IPv6 protocol addresses.

3. The network detection system according to claim 2, wherein, The address randomization generation module is further configured to traverse multiple addresses in the target address space according to the full permutation modular multiplication algorithm to generate the multiple target probe addresses in a randomized permutation.

4. The network detection system according to claim 3, wherein, The address randomization generation module is also configured to: The address length is determined based on the address type of the target address space; The target address space is divided into multiple subspaces, and the range of scan sequence numbers in each subspace is determined according to the address length. The multiple target detection addresses, arranged according to the scan sequence number, are calculated based on the full permutation modular multiplication algorithm.

5. The network detection system according to claim 2, wherein, The data packet sending module includes a data packet generation module. The data packet generation module is configured to generate a data segment and an identifier segment of the request data packet according to the address type of the target address space, and to generate the checksum of the request data packet according to the identifier segment.

6. The network detection system according to claim 5, wherein, The identifier field includes application layer identifiers, transport layer identifiers, network layer identifiers, and data link layer identifiers.

7. The network detection system according to claim 6, wherein, The data packet generation module is also configured to: The MAC address of the target gateway is automatically obtained through MAC parsing query operations; The data link layer identifier of the request data packet is generated based on the MAC address.

8. The network detection system according to claim 1, wherein, The detection result processing module is also configured to: Based on the valid response data packet, the detection result information is saved or output, and the detection result information includes the target detection address, the port of the target detection address, and the payload.

9. The network detection system according to claim 1, wherein, The detection parameters include the local network card, MAC address, detection speed, and detection blacklist / whitelist.

10. The network detection system according to any one of claims 1-8, further comprising: The network protocol scanning module is configured to determine the target transmission protocol used to scan the plurality of target probe addresses; The data packet sending module is further configured to send the plurality of request data packets corresponding to the plurality of target probe addresses to the message buffer based on the target transmission protocol. The data packet receiving module is further configured to receive, based on the target transmission protocol, the plurality of reply data packets sent back from the plurality of target probe addresses from the message buffer.

11. The network detection system according to claim 10, wherein, The target transmission protocol includes at least one of Transmission Control Protocol, User Datagram Protocol, and Internet Control Message Protocol.

12. The network detection system according to claim 10, wherein, The network protocol scanning module is further configured to determine multiple target transmission protocols based on the port parameters input by the user, and to perform multi-port parallel scanning of multiple target probe addresses based on the multiple ports corresponding to the multiple target transmission protocols.

13. The network detection system according to claim 10, wherein, The network protocol scanning module includes: The DNS scanning module is configured to resolve domain names and DNS server versions and configure query types; The address spoofing scanning module is configured to perform packet sending tests on the source address of the spoofed address; A stateful scanning module is configured to determine the content of the next probe based on the valid response data packet. The network vulnerability scanning module is configured to scan for routing vulnerabilities.

14. A network detection method, comprising: Initialize and configure the network detection system's detection parameters and receive address parameters input by the user; The target address space to be probed is determined based on the address parameters, wherein the address parameters include a prefix length, a suffix length, a user-inputted starting address value, and a user-inputted ending address value. The prefix length is used to determine the starting traversal length of the target address space, and the suffix length is used to determine the ending traversal length of the target address space. The method further includes: The starting address value is used as the value of the bits before the starting traversal bits in the target address space; the value of the bits after the ending traversal bits is generated based on the ending address value; Generate multiple randomly arranged target probe addresses within the target address space that needs to be probed; Send multiple request packets corresponding to the multiple target detection addresses to the message buffer; Receive multiple response data packets sent back from the multiple target probe addresses from the message buffer; The checksums of the multiple response data packets are matched with the checksums of the multiple request data packets to determine the valid response data packets based on the matching results. The message buffer is used for communication between the sender and receiver in asynchronous decoupled send / receive technology.

15. The network detection method according to claim 14, further comprising: Determine the target transmission protocol used to scan the plurality of target detection addresses; Based on the target transmission protocol, the multiple request data packets corresponding to the multiple target probe addresses are sent to the message buffer; Based on the target transmission protocol, the message buffer receives the plurality of reply data packets sent back from the plurality of target probe addresses.

16. An electronic device comprising: Memory stores computer-executable instructions non-transiently; The processor is configured to run computer-executable instructions. The computer-executable instructions are executed by the processor to implement the network detection method according to claim 14 or 15.

17. A non-transitory computer-readable storage medium, wherein, The non-transitory computer-readable storage medium stores computer-executable instructions that, when executed by a processor, implement the network detection method according to claim 14 or 15.

Citation Information

Patent Citations

  • IPv6 address scanning method and device, computer equipment and storage medium

    CN114157637A