Large-scale IPv6 network asset rapid detection method and system

By applying address space splitting algorithm and network flow data analysis in IPv6 networks, combined with active scanning technology, the IPv6 network assets are quickly determined, which solves the problem that traditional scanning methods are not feasible in IPv6 networks, and efficient network asset exploration and security assessment are achieved.

CN117914914BActive Publication Date: 2025-05-06TSINGHUA UNIVERSITY

Patent Information

Application Number
CN202311756105.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-19
Publication Date
2025-05-06
Estimated Expiration
2043-12-19

AI Technical Summary

Technical Problem

Due to the huge scale of IPv6 address space, the traditional traversal scanning method is not feasible in IPv6 networks, making it difficult to quickly detect IPv6 network assets, affecting network security assessment.

Method used

The prefix list of scannable IPv6 intranet active address prefixes is determined based on the preset address space segmentation algorithm, and combined with passive network flow data and active scanning algorithm, the active IPv6 network assets are quickly determined.

Benefits of technology

It realizes rapid exploration of large IPv6 network assets, significantly saving scanning time, reducing unnecessary network traffic, thereby improving the efficiency of network security assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117914914B_ABST
    Figure CN117914914B_ABST
Patent Text Reader

Abstract

The present invention provides a large-scale IPv6 network asset rapid exploration method and system, the method first determines a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm; then determines active IPv6 network assets based on the scannable IPv6 intranet active address prefix list, so as to use the active IPv6 network assets for vulnerability scanning and risk assessment. The present invention realizes rapid exploration of large-scale IPv6 network assets, saves scanning time, and reduces unnecessary scanning network traffic.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of next generation Internet IPv6 asset detection, and in particular to a large-scale IPv6 network asset rapid detection method and system. Background Art

[0002] With the advent of the information age, network and communication technologies are developing rapidly. The addresses of the IPv4 protocol can no longer meet the needs of network use. As the core of the next-generation Internet protocol, the IPv6 protocol has also begun to be promoted and deployed globally. The IPv6 protocol can effectively solve the problem of address shortage, but as a newly deployed network protocol, due to its limited historical application and research scope, it also brings certain security issues, such as protocol format issues, address privacy issues, message fragmentation and extension header issues. For potential security issues in cyberspace, asset exploration methods are generally used to explore network assets and services in order to conduct security risk assessments.

[0003] Since IPv4 addresses are only 32 bits long, it is very easy to scan IPv4 addresses. However, the address length of the IPv6 protocol is 128 bits, which is four times the length of the IPv4 address, making the size of the IPv6 address space increase exponentially. The traditional network space traversal enumeration scanning method would take hundreds of millions of years to scan the entire IPv6 address space. It can be seen that traversal scanning of IPv6 network addresses is currently not feasible at the technical level.

[0004] Therefore, studying the rapid asset detection method applicable to IPv6 networks is of great significance for the secure deployment of IPv6 networks. Summary of the invention

[0005] In order to solve the above technical problems, the present invention provides a method and system for rapid detection of large-scale IPv6 network assets, which realizes rapid detection of large-scale IPv6 network assets, saves scanning time, and reduces unnecessary scanning network traffic.

[0006] The present invention provides a method for quickly exploring large-scale IPv6 network assets, comprising: determining a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm; and determining active IPv6 network assets based on the scannable IPv6 intranet active address prefix list.

[0007] According to a large-scale IPv6 network asset rapid detection method provided by the present invention, the method of determining a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm includes: determining a scannable IPv6 intranet active address prefix list based on a pre-designed fee library.

[0008] According to a large-scale IPv6 network asset rapid detection method provided by the present invention, the scannable IPv6 intranet active address prefix list is determined based on a preset address space segmentation algorithm, comprising: obtaining passive network flow data; determining the IPv6 intranet active address prefix list based on the passive network flow data; and ranking the number of intranet active IPv6 addresses in the IPv6 intranet active address prefixes to obtain the scannable IPv6 intranet active address prefix list.

[0009] According to a large-scale IPv6 network asset rapid detection method provided by the present invention, the passive network flow data includes a source address and a destination address; determining the IPv6 intranet active address prefix list based on the passive network flow data includes: determining the IPv6 intranet active address list based on the source address and the destination address; determining the IPv6 intranet active address prefix list based on the IPv6 intranet active address list.

[0010] According to a large-scale IPv6 network asset rapid detection method provided by the present invention, the active IPv6 network assets are determined based on the scannable IPv6 intranet active address prefix list, including: determining the IPv6 intranet active address list corresponding to the scannable IPv6 intranet active address prefix list; determining the active port number list; scanning the IPv6 intranet active address list based on the active port number list and a preset scanning tool to determine the active IPv6 network assets.

[0011] According to a large-scale IPv6 network asset rapid detection method provided by the present invention, active IPv6 network assets are determined based on the scannable IPv6 intranet active address prefix list, including: scanning the scannable IPv6 intranet active address prefix list based on a preset active scanning algorithm to obtain a key device active address list; determining active IPv6 network assets based on the key device active address list.

[0012] According to a large-scale IPv6 network asset rapid detection method provided by the present invention, the scannable IPv6 intranet active address prefix list is scanned based on a preset active scanning algorithm to obtain a key device active address list, including: ranking the number of intranet active IPv6 addresses in the scannable IPv6 intranet active address prefix list to determine a preset ranked active address prefix list; scanning the preset ranked active address prefix list based on an XMAP scanning algorithm to obtain the key device active address list.

[0013] According to a large-scale IPv6 network asset rapid detection method provided by the present invention, the active IPv6 network assets are determined based on the active address list of key devices, including: determining an active port number list; scanning the active address list of key devices based on the active port number list and a preset scanning tool to determine the active IPv6 network assets.

[0014] A large-scale IPv6 network asset rapid detection method provided by the present invention also includes: calculating and determining the scanning time of the active IPv6 network assets based on the active address list of key devices and the active port number list.

[0015] The present invention also provides a large-scale IPv6 network asset rapid detection system, including: a segmentation module, used to determine a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm; an asset determination module, used to determine active IPv6 network assets based on the scannable IPv6 intranet active address prefix list.

[0016] The invention provides a large-scale IPv6 network asset rapid exploration method and system. The method first determines a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm; then determines active IPv6 network assets based on the scannable IPv6 intranet active address prefix list, so as to use the active IPv6 network assets for vulnerability scanning and risk assessment. The invention realizes rapid exploration of large-scale IPv6 network assets, saves scanning time, and reduces unnecessary scanning network traffic. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0018] Figure 1 It is a flow chart of a large-scale IPv6 network asset rapid detection method provided by the present invention;

[0019] Figure 2 It is a structural schematic diagram of a large-scale IPv6 network asset rapid detection system provided by the present invention;

[0020] Figure 3 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0021] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0022] The Internet has been invented for decades, and there are countless network devices connected to the network. With the advent of the Internet of Things era, the number of network devices has further exploded. The biggest problem facing the current IPv4 protocol is the lack of network address resources, which seriously restricts the application and development of the Internet. The application of the next generation Internet protocol IPv6 in the field of the Internet of Things is an inevitable trend. Compared with the 2 32 The IPv6 protocol has 2 128 The address space can effectively meet the node identification needs of the Internet of Things and completely solve the problem of insufficient address resource allocation.

[0023] At present, the IPv6 address protocol has been launched for many years, and countries are accelerating the deployment of IPv6. Network security issues are becoming increasingly prominent. An effective way to understand the status of IPv6 networks is to scan the addresses of IPv6 networks to understand their deployment status. Scanning the IPv6 address space faces difficulties such as large address space and insufficient scanning capabilities. If the IPv6 addresses in the entire address space are scanned, it will take hundreds of millions of years to complete. Therefore, reducing the scanning space of IPv6 addresses is crucial to understanding the status of IPv6 networks.

[0024] Traditional traversal address scanning technology cannot be applied in IPv6 networks. Therefore, studying address scanning technology suitable for IPv6 networks is of great significance for preventing new IPv6 scanning attacks and deploying security strategies.

[0025] Address scanning is the premise of network security scanning and vulnerability scanning. It sends a detection packet to the target host. If a reply is received, it means that the target host is turned on. It can be determined whether the host on the target network is reachable. This is the initial stage of information collection, which will directly affect subsequent work. Address scanning is of great significance to network security.

[0026] Generally, the key equipment asset scanning program scans the 32-64 bits of a / 32, which meets the backbone network engineering ethics requirements. Based on the speed of 100,000 packets per second, it takes 12 hours to complete a scan. Based on a large IPv6 network containing 4096 / 32 prefixes, it takes 2048 days to scan once, which is equivalent to 5.6 years. Even if 100 / 32 prefixes are scanned, it takes 50 days. Considering the engineering ethics of the access network egress, reducing the packet volume to less than 100,000 packets per second will take longer to scan.

[0027] Please refer to Figure 1 , Figure 1 A schematic diagram of a process flow of a large-scale IPv6 network asset rapid detection method provided by the present invention.

[0028] In order to solve the technical problems existing in the prior art, the present invention provides a method for quickly exploring assets in a large-scale IPv6 network, comprising:

[0029] 101: Determine a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm.

[0030] As a preferred embodiment, determining a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm includes: determining a scannable IPv6 intranet active address prefix list based on a pre-designed fee library.

[0031] The large-scale IPv6 network asset rapid detection method of this embodiment is well adapted to the existing IPv6 address space key equipment asset detection system. Through the billing library, an IPv6 address space with a / 32 prefix is ​​divided into multiple address spaces with a / 48 prefix, thereby reducing the scanning time for key equipment assets.

[0032] The billing database contains a table of correspondence between the IPv6 address segments assigned to access units and the access units. The billing database generally selects a pre-split / 48 prefix from a / 32 prefix as the IPv6 intranet active address prefix, and assigns the IPv6 intranet active address prefix to an access unit. The billing database can be saved in the billing system.

[0033] As a preferred embodiment, a scannable IPv6 intranet active address prefix list is determined based on a preset address space segmentation algorithm, including: obtaining passive network flow data; determining the IPv6 intranet active address prefix list based on the passive network flow data; and ranking the number of intranet active IPv6 addresses in the IPv6 intranet active address prefixes to obtain a scannable IPv6 intranet active address prefix list.

[0034] As a preferred embodiment, the passive network flow data includes a source address and a destination address; determining the IPv6 intranet active address prefix list based on the passive network flow data includes: determining the IPv6 intranet active address list based on the source address and the destination address; determining the IPv6 intranet active address prefix list based on the IPv6 intranet active address list.

[0035] This embodiment uses a combination of active and passive methods to quickly detect large-scale IPv6 network assets. For example, passive network flow (netflow) data is collected from the backbone nodes of the CERNET2 backbone network at a ratio of 100:1 every day, and the collected passive network flow data is summarized to sort out a large-scale IPv6 intranet active address list, an IPv6 intranet active address prefix list and an active port number list. These three lists can be stored in the active address library, the active address prefix library and the active port number library respectively. Then, the number of intranet active IPv6 addresses in the IPv6 intranet active address prefix is ​​ranked, and a large-scale IPv6 network intranet / 48 and / 32 active address prefix list that can be scanned is sorted out.

[0036] The second generation of China Education and Research Computer Network CERNET2 is the largest core network and the only national academic network of China's Next Generation Internet Demonstration Project CNGI. It is the largest Next Generation Internet backbone network in the world known to use pure IPv6 technology. The CERNET2 backbone network includes the networks of various universities internally, and is interconnected with the three major operators and foreign networks externally. The CERNET2 education network backbone network is set up with multiple nodes in many cities across the country, and each node is deployed with a netflow data collector. The proportion of collectors can be considered by comprehensively balancing storage capacity and sample integrity, and the present invention is not particularly limited here.

[0037] Passive network flow data may include the following fields: source address, source port, destination address, destination port, protocol type, upstream traffic, downstream traffic, number of flows, and duration.

[0038] By deduplicating the source address and the destination address, a list of active IPv6 intranet addresses can be obtained. The addresses in the list of active IPv6 intranet addresses can be attributed to prefixes, such as / 32 and / 48 prefixes, to obtain a list of active IPv6 intranet address prefixes, such as 2001:db8:1001:: / 48 and 2001:db8:: / 32. The present invention does not make any special limitation here.

[0039] By deduplicating the source port and the destination port, an active port number list can be obtained, that is, a list of ports ranked high according to the number of ports recorded in the passive network flow data, such as the top 300 ports, which is not particularly limited in the present invention.

[0040] The large-scale IPv6 intranet active address list is a set of IPv6 addresses with traffic calculated from passive network flow data, such as 2001:db8:1001::1.

[0041] Passive network flow data is obtained by monitoring network traffic, extracting relevant fields according to certain rules, and retaining data locally. Passive network flow data is a network packet switching technology, and the mainstream version currently used is NetFlow V9.

[0042] 102: Determine active IPv6 network assets based on the scannable IPv6 intranet active address prefix list.

[0043] As a preferred embodiment, active IPv6 network assets are determined based on a scannable IPv6 intranet active address prefix list, including: determining an IPv6 intranet active address list corresponding to the scannable IPv6 intranet active address prefix list; determining an active port number list; and determining active IPv6 network assets by scanning the IPv6 intranet active address list based on the active port number list and a preset scanning tool.

[0044] In order to expand the number of active IPv6 network assets, in this embodiment, the IPv6 intranet active address list corresponding to the scannable IPv6 intranet active address prefix list is first determined; and the active port number list is determined; then the IPv6 intranet active address list is directly scanned based on the active port number list and the preset scanning tool, thereby expanding the number of active IPv6 network assets.

[0045] Among them, the active port number list of the billing library segmentation and the passive network flow data can be shared, and the present invention does not make any special limitation here.

[0046] As a preferred embodiment, active IPv6 network assets are determined based on a scannable IPv6 intranet active address prefix list, including: scanning the scannable IPv6 intranet active address prefix list based on a preset active scanning algorithm to obtain an active address list of key devices; determining active IPv6 network assets based on the active address list of key devices.

[0047] As a preferred embodiment, the scannable IPv6 intranet active address prefix list is scanned based on a preset active scanning algorithm to obtain a list of active addresses of key devices, including: ranking the number of active IPv6 addresses in the scannable IPv6 intranet active address prefix list to determine a preset ranked active address prefix list; scanning the preset ranked active address prefix list based on an XMAP scanning algorithm to obtain a list of active addresses of key devices.

[0048] Based on the characteristics of active scanning, different scanning strategies are set for different / 48 and / 32 prefixes. For example, multiple adjacent / 48 prefixes are aggregated into one prefix. A / 32 prefix is ​​further split into TopN / 48 prefixes for scanning based on the ranking of the number of active IPv6 addresses in the active address prefixes in the passive netflow traffic. The number of TopN is determined by the actual number of active intranet address prefixes if it is less than 50, and by the number of active intranet addresses of the / 32 prefix if it is greater than 50. Active intranet addresses exceeding 5 million generally respond to any address scan request, and ToP10 can be selected; active addresses between 50,000 and 5 million are generally caused by alias addresses, and ToP50 can be selected; ToP100 is selected between 10,000 and 50,000, ToP200 is selected between 5,000 and 10,000, ToP100 is selected between 1,000 and 5,000, and ToP50 is selected for less than 1,000 or according to the actual number of active intranet address prefixes. The effect of the selection only needs to ensure that the scan is completed within 5 days. After the XMAP scan is completed, the active address list of key devices is obtained.

[0049] XMAP is a fast scanner with both IPv6 and IPv4 network space detection functions, and it is also the first tool in academia + industry specifically for IPv6 asset fast scanning. It is developed based on the principles of ZMap, and the core code of ZMap is completely rewritten from the bottom up, transplanting ZMap's multiple scanning advantages in IPv4 network space to IPv6 space, and adding IPv6 device fast discovery technology and multi-port scanning functions. It is fully compatible with ZMap and has the ability to scan 32-bit network space in "5 minutes".

[0050] XMap is available for GNU / Linux, Mac OS and BSD operating systems, and already supports ICMP Echo, TCP SYN, UDP and DNS scanning.

[0051] Combined with the application layer scanning tool ZGrab2, XMap can bring out more scanning functions.

[0052] As a preferred embodiment, active IPv6 network assets are determined based on an active address list of key devices, including: determining an active port number list; and scanning the active address list of key devices based on the active port number list and a preset scanning tool to determine active IPv6 network assets.

[0053] As a preferred embodiment, the method further includes: calculating and determining the scanning time of active IPv6 network assets based on the active address list and active port number list of key devices.

[0054] Combine the active address list and active port number of key devices, use the port and fingerprint scanning tool to scan the active address list of key devices output by XMAP, and obtain active IPv6 services and application assets.

[0055] Service refers to a certain port service, such as the DNS (Domain Name System) service on port 53. However, the applications that provide DNS services include BIND (Berkeley Internet Name Domain), PowerDNS, UNbound, dnsmasq, Microsoft DNS and other different application software. Applications are generally identified through various application fingerprints, such as the masscan tool.

[0056] The working principle of the fingerprint scanning tool is as follows: First, for some common operating system fingerprints, an operating system fingerprint library is built; on this basis, deep packet matching is used to identify common operating system versions. Secondly, in addition to static text rules, based on some statistical rules such as data packet length and data packet timing, some features of the operating system are further matched to improve the recognition accuracy of the operating system and related versions.

[0057] Based on the operating system identification and classification, behavioral models and fingerprint libraries are built for various types of application software. The main methods are: based on the static fingerprint characteristics of the software, such as browser UA, service banner characteristics, etc.

[0058] On the basis of obtaining the fingerprint of the operating system and the fingerprint of the application software, further analysis and mining of the key component information used by the operating system or application software is carried out. This mainly includes: discovering the component dependencies of related software in the interaction process between the software or operating system and the code library or software library when upgrading or installing the software, and building the communication traffic fingerprint library corresponding to the key components.

[0059] The scanning time is calculated based on the number of key device addresses and the number of active port numbers. For example, for a large IPv6 network with 60,000 key device addresses, the top 300 active port numbers are taken, and the packet sending rate is 65,535 packets per second, then the scanning time is about 50 minutes. At the same rate, for a large IPv6 network with 360,000 key device addresses, the top 300 active port numbers are taken, and the scanning time is 45 minutes. At the same time, these 300 port numbers can be updated every day. For example, the number of assets with open port 7547 in a large IPv6 network ranks high. These assets can be used for vulnerability scanning and security risk assessment. The above realizes the rapid exploration of large IPv6 network assets, saves scanning time, and reduces unnecessary scanning network traffic.

[0060] The scanning time of large IPv6 network address space is greatly shortened: a / 32 prefix in the billing database generally allocates 900 to 1800 / 48 prefixes to access users. A / 48 prefix 48-64 bits is calculated at a speed of 65535 packets per second (about 45Mb / s), and it only takes 1 second to scan it. A / 32 prefix can be scanned in less than half an hour. For 4096 / 32 prefixes in a large IPv6 network, such as the Future Internet Technology Infrastructure (FITI), each prefix is ​​averaged according to passive netflow data to calculate the most active 100 / 48 prefixes. Without considering the switching time of different prefixes, a scan can be completed in 4.74 days.

[0061] Engineering practicality of IPv6 address space scanning: A large network with 400 / 32 prefixes, each prefix averaged out to the most active 1000 / 48 prefixes, can complete a scan in less than 5 days. Increase the number of scanning nodes to 5 distributed deployments, set to scan simultaneously, and without considering the imbalance of the distribution of the scanned IPv6 assets in each network segment, and without triggering the automatic blocking mechanism of the firewall, the scan can be completed within 1 day. Considering that key equipment assets are relatively stable, 1-5 days is enough to reflect their changing trends, so this method meets the engineering needs of asset exploration such as key equipment.

[0062] In summary, the IPv6 network asset rapid detection method IXMAP (Integration XMAP) of the present invention can improve the efficiency of asset detection in large IPv6 network address spaces by combining passive network flow data with active scanning, and solves the problem of huge scanning difficulties of IPv6 addresses through address segmentation by using a billing library and different subnet prefixes, thereby shortening the scanning time of key equipment asset detection.

[0063] The large-scale IPv6 network asset rapid detection system provided by the present invention is described below. The large-scale IPv6 network asset rapid detection system described below and the large-scale IPv6 network asset rapid detection method described above can be referenced to each other.

[0064] Please refer to Figure 2 , Figure 2 A structural schematic diagram of a large-scale IPv6 network asset rapid detection system provided by the present invention.

[0065] The present invention also provides a large-scale IPv6 network asset rapid detection system, including: a segmentation module 1, used to determine a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm; an asset determination module 2, used to determine active IPv6 network assets based on the scannable IPv6 intranet active address prefix list.

[0066] Figure 3 An example of a structural diagram of an electronic device is shown in FIG. Figure 3 As shown, the electronic device may include: a processor 301, a communication interface 302, a memory 303 and a communication bus 304, wherein the processor 301, the communication interface 302 and the memory 303 communicate with each other through the communication bus 304. The processor 301 may call the logic instructions in the memory 303 to execute a large-scale IPv6 network asset rapid exploration method, the method comprising: determining a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm; determining active IPv6 network assets according to the scannable IPv6 intranet active address prefix list.

[0067] In addition, the logic instructions in the above-mentioned memory 303 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.

[0068] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the large-scale IPv6 network asset rapid detection method provided by the above-mentioned methods, and the method includes: determining a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm; determining active IPv6 network assets based on the scannable IPv6 intranet active address prefix list.

[0069] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it is implemented to execute the large-scale IPv6 network asset rapid detection method provided by the above-mentioned methods. The method includes: determining a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm; determining active IPv6 network assets based on the scannable IPv6 intranet active address prefix list.

[0070] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0071] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0072] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for rapid detection of large-scale IPv6 network assets, characterized in that: include: Determine the scannable IPv6 intranet active address prefix list based on the preset address space segmentation algorithm; Determining active IPv6 network assets according to the scannable IPv6 intranet active address prefix list; The step of determining active IPv6 network assets according to the scannable IPv6 intranet active address prefix list includes: Scan the scannable IPv6 intranet active address prefix list based on a preset active scanning algorithm to obtain an active address list of key devices; Determine active IPv6 network assets based on the active address list of key devices; The scanning of the scannable IPv6 intranet active address prefix list based on a preset active scanning algorithm to obtain a key device active address list includes: Ranking the number of intranet active IPv6 addresses in the scannable intranet active IPv6 address prefix list to determine a preset ranked active address prefix list; Scan the preset ranked active address prefix list based on the XMAP scanning algorithm to obtain the key device active address list; Determining active IPv6 network assets according to the active address list of key devices includes: Determine the list of active port numbers; Scanning the active address list of key devices based on the active port number list and a preset scanning tool to determine the active IPv6 network assets; Also includes: The scanning time of the active IPv6 network assets is calculated and determined according to the active address list of key devices and the active port number list.

2. The large-scale IPv6 network asset rapid detection method according to claim 1 is characterized in that: The method of determining a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm includes: Determine the scannable IPv6 intranet active address prefix list based on the pre-designed fee library.

3. The large-scale IPv6 network asset rapid detection method according to claim 1 is characterized in that: The method of determining a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm includes: Get passive network flow data; Determine an IPv6 intranet active address prefix list based on the passive network flow data; The number of intranet active IPv6 addresses in the IPv6 intranet active address prefixes is ranked to obtain the scannable IPv6 intranet active address prefix list.

4. The large-scale IPv6 network asset rapid detection method according to claim 3 is characterized in that: The passive network flow data includes a source address and a destination address; The determining of the IPv6 intranet active address prefix list according to the passive network flow data includes: Determine an IPv6 intranet active address list according to the source address and the destination address; Determine the IPv6 intranet active address prefix list according to the IPv6 intranet active address list.

5. The large-scale IPv6 network asset rapid detection method according to any one of claims 1 to 4, characterized in that: The step of determining active IPv6 network assets according to the scannable IPv6 intranet active address prefix list includes: Determine an IPv6 intranet active address list corresponding to the scannable IPv6 intranet active address prefix list; Determine the list of active port numbers; The active IPv6 network assets are determined by scanning the IPv6 intranet active address list based on the active port number list and a preset scanning tool.

6. A large-scale IPv6 network asset rapid detection system, characterized in that: include: A segmentation module, used to determine a scannable IPv6 intranet active address prefix list based on a preset address space segmentation algorithm; An asset determination module, configured to determine active IPv6 network assets based on the scannable IPv6 intranet active address prefix list; The step of determining active IPv6 network assets according to the scannable IPv6 intranet active address prefix list includes: Scan the scannable IPv6 intranet active address prefix list based on a preset active scanning algorithm to obtain an active address list of key devices; Determine active IPv6 network assets based on the active address list of key devices; The scanning of the scannable IPv6 intranet active address prefix list based on a preset active scanning algorithm to obtain a key device active address list includes: Ranking the number of intranet active IPv6 addresses in the scannable intranet active IPv6 address prefix list to determine a preset ranked active address prefix list; Scan the preset ranked active address prefix list based on the XMAP scanning algorithm to obtain the key device active address list; Determining active IPv6 network assets according to the active address list of key devices includes: Determine the list of active port numbers; Scanning the active address list of key devices based on the active port number list and a preset scanning tool to determine the active IPv6 network assets; Also includes: The scanning time of the active IPv6 network assets is calculated and determined according to the active address list of key devices and the active port number list.

Citation Information

Patent Citations

  • IPv6 address information determination method, apparatus and device, and medium

    CN115225613A

  • IPv6 address detection method and device and electronic equipment

    CN116800720A

Cited By

  • IPv6 space industrial internet security asset management method

    CN120512314A