Network scanning method, scanning service device, scanned service device and storage medium
By establishing a VPN tunnel between the scanning service device and the scanned service device and establishing a virtual proxy interface mapping relationship, the problem of insufficient scanning flexibility in the existing technology is solved, and flexible detection of cross-subnet security scanning is achieved.
Patent Information
- Application Number
- CN202311389288.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-24
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2043-10-24
AI Technical Summary
Existing technologies lack flexibility when performing security scans on an enterprise's remote host subnet, especially when the gateway device cannot be modified, which affects the overall routing settings and increases Internet exposure.
Cross-subnet scanning is achieved by establishing a VPN tunnel between the scanning service device and the scanned service device, sending scanning instructions and establishing a mapping relationship between the virtual proxy interface and the host list to be detected.
No scanner or gateway configuration is required; cross-subnet detection can be completed directly through the virtual proxy interface, improving the flexibility of security scanning and detection.
Smart Images

Figure CN118827094B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network scanning method, a scanning service device, a scanned service device, and a storage medium. Background Art
[0002] Currently, there are two common methods for using remote scanners to scan and perform security checks on hosts within an enterprise's local host subnet. One method is host mapping: This involves setting up a gateway device on the host subnet, mapping the host to be tested to the public network, and then using the scanner for security checks. The other method is to establish a tunnel using a virtual private network (VPN) gateway. This scenario is common in multi-location enterprise environments, where a branch office gateway establishes a VPN tunnel with the headquarters gateway. Scanning traffic first enters the local gateway and then passes through the tunnel established by the two gateway devices to reach the target host.
[0003] However, host mapping technology requires mapping the host address to the public network, increasing the host subnet's internet exposure. Establishing a VPN tunnel through a gateway device affects the overall routing settings for all hosts in both the scanning subnet and the host subnet. This solution is unfeasible when the host network is already established and the gateway device cannot be modified. In summary, the current method of using remote scanners to scan hosts in remote host subnets has limitations, which in turn reduces the flexibility of security scanning detection. Summary of the Invention
[0004] The implementing legislation of this application provides a network scanning method, a scanning service device, a scanned service device and a storage medium, which can enhance the flexibility of security scanning detection.
[0005] The technical solution of the embodiment of the present application is implemented as follows:
[0006] In a first aspect, an embodiment of the present application provides a network scanning method, which is applied to a scanning service device, and includes:
[0007] Establish a VPN tunnel with the scanned service device;
[0008] Sending a scan instruction to a host service manager in the scanned service device based on the VPN tunnel, and receiving, through the scan service manager, a list of hosts to be detected sent by the scanned service device in response to the scan instruction;
[0009] Establishing a first mapping relationship between the first virtual proxy interface in the scanning service device and the host list to be detected according to the host list to be detected;
[0010] When the scanner scans the first virtual proxy interface, a scanning result of the host to be detected in the host to be detected list is determined based on the first mapping relationship.
[0011] In a second aspect, an embodiment of the present application provides a network scanning method, which is applied to a scanned service device, and includes:
[0012] Establish a VPN tunnel with the scanning service device;
[0013] Based on the VPN tunnel, receiving a scanning instruction sent by the scanning service device;
[0014] In response to the scanning instruction, the host list to be detected is sent to the scanning service manager in the scanning service device, so that the scanning service device obtains the scanning results of the hosts to be detected in the host list to be detected based on the host list to be detected.
[0015] In a third aspect, an embodiment of the present application provides a scanning service device, the scanning service device comprising: a first establishing unit, a first sending unit, a first receiving unit, and a determining unit;
[0016] The first establishing unit is used to establish a VPN tunnel with the scanned service device;
[0017] The first sending unit is configured to send a scan instruction to the host service manager in the scanned service device based on the VPN tunnel;
[0018] The first receiving unit is configured to receive, through a scanning service manager, a list of hosts to be detected sent by the scanned service device in response to the scanning instruction;
[0019] The first establishing unit is further configured to establish a first mapping relationship between the first virtual proxy interface in the scanning service device and the host list to be detected according to the host list to be detected;
[0020] The determining unit is configured to determine, when the scanner scans the first virtual proxy interface, a scanning result of the host to be detected in the host to be detected list based on the first mapping relationship.
[0021] In a fourth aspect, an embodiment of the present application provides a scanning service device, the scanning service device comprising: a first processor and a first memory; wherein,
[0022] The first memory is used to store a computer program that can be run on the processor;
[0023] The first processor is configured to execute the network scanning method described above when running the computer program.
[0024] In a fifth aspect, an embodiment of the present application provides a scanned service device, the scanned service device comprising: a second establishing unit, a second receiving unit, and a second sending unit;
[0025] The second establishing unit is configured to establish a VPN tunnel with the scanning service device;
[0026] The second receiving unit is configured to receive a scanning instruction sent by the scanning service device based on the VPN tunnel;
[0027] The second sending unit is configured to send the host list to be detected to the scanning service manager in the scanning service device in response to the scanning instruction, so that the scanning service device obtains scanning results of the hosts to be detected in the host list based on the host list to be detected.
[0028] In a sixth aspect, an embodiment of the present application provides a scanned service device, the scanned service device comprising: a second processor and a second memory; wherein,
[0029] The second memory is used to store a computer program that can be run on the processor;
[0030] The second processor is configured to execute the network scanning method described above when running the computer program.
[0031] In a seventh aspect, an embodiment of the present application provides a computer-readable storage medium, characterized in that computer program code is stored on the storage medium, and when the computer program code is executed by a computer, the network scanning method as described above is implemented.
[0032] An embodiment of the present application provides a network scanning method, a scanning service device, a scanned service device and a storage medium. The scanning service device can establish a VPN tunnel between itself and the scanned service device; then, based on the VPN tunnel, a scanning instruction is sent to the host service manager in the scanned service device, and a list of hosts to be detected sent by the scanned service device in response to the scanning instruction is received through the scanning service manager; a first mapping relationship is established between the first virtual proxy interface in the scanning service device and the list of hosts to be detected according to the list of hosts to be detected; when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the list of hosts to be detected is determined based on the first mapping relationship; the scanned service device can establish a VPN tunnel between itself and the scanning service device; based on the VPN tunnel, the scanning instruction is received from the scanning service device; in response to the scanning instruction, the list of hosts to be detected is sent to the scanning service manager in the scanning service device, so that the scanning service device obtains the scanning result of the host to be detected in the list of hosts to be detected based on the list of hosts to be detected. It can be seen that the network scanning method proposed in the embodiment of the present application adds a scanning service device and a scanned service device. The scanning service device can establish a VPN tunnel with the scanned service device and receive the list of hosts to be detected sent by the scanned service device through the VPN tunnel. Then, a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected can be established. Then, when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the list of hosts to be detected can be determined based on the first mapping relationship. In other words, when the scanner in the present application needs to scan the host to be detected in the list of hosts to be detected, it can directly scan the first virtual proxy interface to obtain the scanning result of the host to be detected in the list of hosts to be detected, thereby completing the cross-subnet detection task. The present application does not require any configuration of the scanner, nor does it require any configuration of the gateway, thereby improving the flexibility of security scanning detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 Schematic diagram for establishing a VPN gateway tunnel;
[0034] Figure 2 Schematic diagram of the network scanning method proposed in this embodiment Figure 1 ;
[0035] Figure 3 A schematic diagram of a scanner proposed in an embodiment of the present application;
[0036] Figure 4 Schematic diagram of the network scanning method proposed in this embodiment Figure 2 ;
[0037] Figure 5 Schematic diagram of the network scanning method proposed in this embodiment Figure 3 ;
[0038] Figure 6 Schematic diagram of the network scanning architecture proposed in this application embodiment Figure 1 ;
[0039] Figure 7 Schematic diagram of the network scanning architecture proposed in this application embodiment Figure 2 ;
[0040] Figure 8 Schematic diagram of the structure of the scanning service device proposed in this embodiment of the application Figure 1 ;
[0041] Figure 9 Schematic diagram of the structure of the scanning service device proposed in this embodiment of the application Figure 2 ;
[0042] Figure 10 Schematic diagram of the structure of the scanned service device proposed in the embodiment of this application Figure 1 ;
[0043] Figure 11 Schematic diagram of the structure of the scanned service device proposed in the embodiment of this application Figure 2 . DETAILED DESCRIPTION
[0044] The following will be combined with the accompanying drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. It should be understood that the specific embodiments described herein are only used to explain the related applications and are not intended to limit the applications. It should also be noted that for ease of description, only the portions relevant to the related applications are shown in the drawings.
[0045] Currently, there are several methods for using a remote scanner (e.g., Shanghai) to scan and detect hosts in a company's local host subnet (e.g., Beijing): (1) Host mapping: Set up a gateway device in the host subnet, map the host to be detected to the public network, and then use the scanner to perform security detection. (2) VPN gateway tunnel: Figure 1 To establish a VPN gateway tunnel diagram, Figure 1 As shown in the figure, this scenario is common in multi-location enterprise environments. A branch office gateway establishes a VPN tunnel with the headquarters gateway. Scanning traffic sent by scanners (scanners 1, 2, ..., n) first enters the local gateway and then passes through the tunnel established between the two gateways to reach the target host, which can be host 1, host 2, ..., host n.
[0046] However, when performing scanning security detection using host mapping technology, the majority of the traffic emitted by the scanner is network attack traffic. This network attack traffic will be identified as malicious traffic by regulatory authorities, generating warnings. Furthermore, host mapping technology requires mapping the host address to be detected to the public network, increasing the host subnet's internet exposure. Furthermore, when performing scanning security detection using VPN gateway tunneling technology, the gateway device must support VPN functionality. Establishing a VPN tunnel through the gateway device affects the overall routing settings for all hosts in both the scanning subnet and the host subnet. This solution cannot be implemented when the host network is already established and the gateway device cannot be modified. In summary, the current method of using remote scanners to scan hosts in remote host subnets has limitations, which in turn reduces the flexibility of security scanning detection.
[0047] In order to solve the problem of reduced flexibility in current security scanning detection, an embodiment of the present application provides a network scanning method, a scanning service device, a scanned service device and a storage medium, wherein the scanning service device can establish a VPN tunnel between the scanning service device; then, based on the VPN tunnel, a scanning instruction is sent to the host service manager in the scanned service device, and the list of hosts to be detected sent by the scanned service device in response to the scanning instruction is received through the scanning service manager; a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected is established according to the list of hosts to be detected; when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the list of hosts to be detected is determined based on the first mapping relationship; the scanned service device can establish a VPN tunnel between the scanning service device; based on the VPN tunnel, the scanning instruction sent by the scanning service device is received; in response to the scanning instruction, the list of hosts to be detected is sent to the scanning service manager in the scanning service device, so that the scanning service device obtains the scanning result of the host to be detected in the list of hosts to be detected based on the list of hosts to be detected. It can be seen that the network scanning method proposed in the embodiment of the present application adds a scanning service device and a scanned service device. The scanning service device can establish a VPN tunnel with the scanned service device and receive the list of hosts to be detected sent by the scanned service device through the VPN tunnel. Then, a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected can be established. Then, when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the list of hosts to be detected can be determined based on the first mapping relationship. In other words, when the scanner in the present application needs to scan the host to be detected in the list of hosts to be detected, it can directly scan the first virtual proxy interface to obtain the scanning result of the host to be detected in the list of hosts to be detected, thereby completing the cross-subnet detection task. The present application does not require any configuration of the scanner, nor does it require any configuration of the gateway, thereby improving the flexibility of security scanning detection.
[0048] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application.
[0049] Example 1
[0050] The embodiment of the present application provides a network scanning method, which is applied to a scanning service device, wherein the scanning service device includes a scanning service manager connected to a scanner. Figure 2 Schematic diagram of the network scanning method proposed in this embodiment Figure 1 ,like Figure 2 As shown, the network scanning method may include the following steps:
[0051] Step 101: Establish a VPN tunnel with the scanned service device.
[0052] In an embodiment of the present application, the scanning service device may establish a VPN tunnel with the scanned service device.
[0053] It should be noted that, in the embodiments of this application, Figure 3 This is a schematic diagram of a scanner proposed in an embodiment of the present application, as shown in FIG. Figure 3 As shown, the number of scanners connected to the scanning service manager in the scanning service device can be n, where n is an integer greater than 0. This application does not specifically limit the number of scanners connected to the scanning service manager.
[0054] It should be noted that, in an embodiment of the present application, the scanning service device further includes a VPN terminal. When establishing a VPN tunnel with the scanned service device, the scanning service device can establish a VPN tunnel with the VPN client in the scanned service device through the VPN terminal.
[0055] Step 102: Based on the VPN tunnel, a scanning instruction is sent to the host service manager in the scanned service device, and a host list to be detected in response to the scanning instruction, which is sent by the scanned service device, is received through the scanning service manager.
[0056] In an embodiment of the present application, after establishing a VPN tunnel between the scanning service device and the scanned service device, the scanning service device can send a scanning instruction to the host service manager in the scanned service device based on the VPN tunnel, and receive the list of hosts to be detected sent by the scanned service device in response to the scanning instruction through the scanning service manager.
[0057] It should be noted that, in the embodiment of the present application, the host list to be detected may include n hosts to be detected, where n is an integer greater than 0. The present application does not specifically limit the number of hosts to be detected included in the host list to be detected.
[0058] It should be noted that in an embodiment of the present application, the list of hosts to be detected may include the Internet Protocol (IP) address, open port, host operating system type and host open service type corresponding to the host to be detected, for example, <host 1-IP, open port, host operating system type, host open service type>, <host 2-IP, open port, host operating system type, host open service type>....<host N-IP, open port, host operating system type, host open service type>. This application does not specifically limit the number and type of parameters included in the list of hosts to be detected.
[0059] Step 103: Establish a first mapping relationship between the first virtual proxy interface in the scanning service device and the host list to be detected according to the host list to be detected.
[0060] In an embodiment of the present application, the scanning service device sends a scanning instruction to the host service manager in the scanned service device based on the VPN tunnel, and after receiving the list of hosts to be detected sent by the scanned service device in response to the scanning instruction through the scanning service manager, a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected can be established according to the list of hosts to be detected.
[0061] It should be noted that in an embodiment of the present application, a scanning service device adds a first virtual proxy interface. The first virtual proxy interface can be a virtual host proxy interface. The legal IP address and subnet mask of the scanning subnet segment can be used as the IP address of the virtual interface. For example, the pseudo code can be ifconfig eth0:1x.xxx netmaskx.xxx.
[0062] It should be noted that in an embodiment of the present application, when the scanning service device establishes a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected based on the list of hosts to be detected, it can be based on the destination address translation (DNAT) function. According to the address information corresponding to the host to be detected in the list of hosts to be detected, the first initial destination address connected to the first virtual proxy interface is converted and processed to obtain the first mapping relationship between the first virtual proxy interface and the list of hosts to be detected.
[0063] It should be noted that, in the embodiment of the present application, the first initial destination address may be a public IP address.
[0064] For example, in an embodiment of the present application, when the scanning service device establishes a first mapping relationship between the first virtual proxy interface in the scanning service device and the host list to be detected based on the host list to be detected, it traverses the host list to be detected and takes out the IP of host 1 to be detected. DNAT can be configured on the scanning service device to convert the first initial destination address connected to the first virtual proxy interface according to the address information corresponding to host 1 to be detected in the host list to be detected, and obtain the mapping relationship between the first virtual proxy interface and host 1 to be detected. The scanning service device can also obtain the mapping relationship between the first virtual proxy interface and host 2 to be detected according to the same steps, until the host list to be detected is traversed and the mapping relationship between the first virtual proxy interface and host n to be detected is obtained.
[0065] That is to say, in an embodiment of the present application, when the scanner connected to the scanning service device under the scanning subnet needs to perform a security scan detection on the hosts in the list of hosts to be detected under the host subnet, due to the mapping relationship established between the first virtual proxy interface and the list of hosts to be detected, the scanner connected to the scanning service device only needs to scan the first virtual proxy interface to complete the security scan of the hosts in the list of hosts to be detected without any configuration of the gateway, thereby improving the flexibility of the security scan.
[0066] Step 104: When the scanner scans the first virtual proxy interface, a scanning result of the host to be detected in the host to be detected list is determined based on the first mapping relationship.
[0067] In an embodiment of the present application, after the scanning service device establishes a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected based on the list of hosts to be detected, when the scanner scans the first virtual proxy interface, it can determine the scanning result of the host to be detected in the list of hosts to be detected based on the first mapping relationship.
[0068] It should be noted that in an embodiment of the present application, when the scanner scans the first virtual proxy interface and determines the scanning result of the host to be detected in the list of hosts to be detected based on the first mapping relationship, the first scanning traffic can be mapped to the current host in the list of hosts to be detected based on the first mapping relationship; and then the second scanning traffic corresponding to the current host mapped by the scanned service device can be received; and the scanning result of the current host is determined based on the second scanning traffic.
[0069] Exemplarily, in an embodiment of the present application, when the scanner scans the first virtual proxy interface, the first scanning traffic is mapped to the current host in the host list to be detected based on the first mapping relationship, and the first scanning traffic can be mapped to a target host (the current host in the host list). The pseudo code used can be iptables-t nat-APREROUTING-d eth0:1-j DNAT--to-destination target_host.
[0070] Furthermore, it should be noted that, in an embodiment of the present application, routing can be configured on the scanning service device so that network traffic destined for target_host (the current host in the host list) can reach the scanned service device through the VPN tunnel. The pseudo code used can be route add-host target_host gw host_vpn_address.
[0071] It should be noted that, in an embodiment of the present application, after receiving the second scanning traffic corresponding to the current host mapped by the scanning service device, the scanning service device can send the second scanning traffic to the scanner based on the Source Network Address Translation (SNAT) function.
[0072] For example, in an embodiment of the present application, SNAT can be configured on the scanning service device so that the traffic actively initiated by target_host can establish a two-way network connection with the scanner through the VPN tunnel. The pseudo code used can be iptables -t nat-APOSTROUTING -o eth0:1 -j MASQUERADE.
[0073] It should be noted that in an embodiment of the present application, when the scanner determines the scanning result of the host to be detected in the host list to be detected based on the first mapping relationship, the first virtual host proxy interface can be scanned according to <open port, host operating system type, host open service type>.
[0074] To sum up, when the scanner under the scanning subnet needs to perform security scanning and detection on the hosts in the list of hosts to be detected under the host subnet, since a mapping relationship is established between the first virtual proxy interface of the scanning service device and the list of hosts to be detected, the scanner connected to the scanning service device only needs to scan the first virtual proxy interface to complete the security scan of the hosts in the list of hosts to be detected without any configuration of the gateway, thereby improving the flexibility of the security scan.
[0075] The embodiment of the present application provides a network scanning method, which is applied to a scanning service device, and the scanning service device can establish a VPN tunnel with the service device being scanned; then, based on the VPN tunnel, a scanning instruction is sent to the host service manager in the service device being scanned, and the list of hosts to be detected sent by the service device being scanned in response to the scanning instruction is received through the scanning service manager; a first mapping relationship between a first virtual proxy interface in the scanning service device and the list of hosts to be detected is established according to the list of hosts to be detected; when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the host list to be detected is determined based on the first mapping relationship. It can be seen that the network scanning method proposed in the embodiment of the present application adds a scanning service device and a service device being scanned, and the scanning service device can establish a VPN tunnel with the service device being scanned, and receive the list of hosts to be detected sent by the service device being scanned through the VPN tunnel, and then a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected can be established, and then when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the host list to be detected can be determined based on the first mapping relationship. That is to say, when the scanner in this application needs to scan the host to be detected in the host list to be detected, it can directly scan the first virtual proxy interface to obtain the scanning results of the host to be detected in the host list to be detected, thereby completing the cross-subnet detection task. This application does not require any configuration of the scanner or the gateway, thereby improving the flexibility of security scanning detection.
[0076] Example 2
[0077] Based on the above embodiment, another embodiment of the present application provides a network scanning method, which is applied to a scanned service device, wherein the scanned service device includes a host service manager, Figure 4 Schematic diagram of the network scanning method proposed in this embodiment Figure 2 ,like Figure 4 As shown, the network scanning method may include the following steps:
[0078] Step 201: Establish a VPN tunnel with a scanning service device.
[0079] In an embodiment of the present application, the scanned service device may establish a VPN tunnel with the scanning service device.
[0080] Step 202: Receive a scanning instruction sent by a scanning service device based on the VPN tunnel.
[0081] In an embodiment of the present application, after establishing a VPN tunnel with the scanning service device, the scanned service device can receive a scanning instruction sent by the scanning service device based on the VPN tunnel.
[0082] Furthermore, in an embodiment of the present application, after receiving the scanning instruction sent by the scanning service device, the scanned service device can determine the host information to be detected; and generate a host list to be detected based on the host information to be detected.
[0083] It should be noted that in an embodiment of the present application, the list of hosts to be detected may include the Internet Protocol (IP) address, open port, host operating system type and host open service type corresponding to the host to be detected, for example, <host 1-IP, open port, host operating system type, host open service type>, <host 2-IP, open port, host operating system type, host open service type>....<host N-IP, open port, host operating system type, host open service type>. This application does not specifically limit the number and type of parameters included in the list of hosts to be detected.
[0084] Step 203: In response to the scanning instruction, the host list to be detected is sent to the scanning service manager in the scanning service device, so that the scanning service device obtains the scanning results of the hosts to be detected in the host list to be detected based on the host list to be detected.
[0085] In an embodiment of the present application, after receiving a scanning instruction sent by the scanning service device based on a VPN tunnel, the scanned service device can respond to the scanning instruction and send a list of hosts to be detected to the scanning service manager in the scanning service device, so that the scanning service device can obtain the scanning results of the hosts to be detected in the list of hosts to be detected based on the list of hosts to be detected.
[0086] Furthermore, in an embodiment of the present application, the scanned service device may receive the first scanning traffic mapped by the scanning service device; and send the first scanning traffic to the current host in the host list to be detected based on the SNAT function.
[0087] Exemplarily, in an embodiment of the present application, SNAT can be configured on the scanned service device so that the first scanning traffic actively initiated by the scanner connected to the scanning service device can establish a two-way network connection with the current host (target_host) in the list of hosts to be detected through the VPN tunnel. The pseudo code used can be iptables -t nat-APOSTROUTING -o target_host -j MASQUERADE.
[0088] It should be noted that in an embodiment of the present application, the scanned service device can, based on the DNAT function, convert the second initial destination address connected to the second virtual proxy interface according to the address information corresponding to the scanner, and obtain a second mapping relationship between the second virtual proxy interface and the scanner; based on the second mapping relationship, the second scanning traffic corresponding to the current host is mapped to the scanning service device.
[0089] Exemplarily, in an embodiment of the present application, the scanned service device can add a second virtual proxy interface, which can be a virtual scanner proxy interface. The legal IP address and subnet mask of the host subnet segment can be used as the IP address of the virtual interface. For example, the pseudo code can be ifconfig eth0:1x.xxx netmaskx.xxx.
[0090] It should be noted that in an embodiment of the present application, when the scanned service device obtains the second mapping relationship between the second virtual proxy interface and the scanner, it can convert the second initial destination address connected to the second virtual proxy interface according to the address information corresponding to the scanner based on the destination address translation (DNAT) function to obtain the second mapping relationship between the second virtual proxy interface and the scanner.
[0091] It should be noted that in an embodiment of the present application, the scanned service device can map the traffic (second scanning traffic) actively initiated by a target_host (current host) to a scanner based on the second mapping relationship between the second virtual proxy interface and the scanner. The pseudo-instruction used can be iptables-t nat-A PREROUTING-d eth0:1-j DNAT--to-destination scanner_ip.
[0092] To sum up, the scanned service device can send the list of hosts to be detected to the scanning service manager in the scanning service device through the VPN tunnel established between the device and the scanning service device, so that the scanning service device can obtain the scanning results of the hosts to be detected in the list of hosts to be detected based on the list of hosts to be detected. Without any configuration of the host or the gateway, the hosts to be detected in the list of hosts to be detected can be scanned to obtain the scanning results.
[0093] The embodiment of the present application provides a network scanning method, which is applied to a scanned service device. The scanned service device can establish a VPN tunnel with the scanning service device; based on the VPN tunnel, receive a scanning instruction sent by the scanning service device; in response to the scanning instruction, send a list of hosts to be detected to the scanning service manager in the scanning service device, so that the scanning service device obtains the scanning results of the hosts to be detected in the list of hosts to be detected based on the list of hosts to be detected. It can be seen that the scanned service device can send the list of hosts to be detected to the scanning service manager in the scanning service device through the VPN tunnel established between the scanned service device and the scanning service device, so that the scanning service device obtains the scanning results of the hosts to be detected in the list of hosts to be detected based on the list of hosts to be detected, and scans the hosts to be detected in the list of hosts to be detected without making any configuration on the host or the gateway.
[0094] Example 3
[0095] Based on the above embodiment, another embodiment of the present application provides a network scanning method, which is applied to a scanning service device and a scanned service device, wherein the scanning service device includes a scanning service manager connected to a scanner, and the scanned service device includes a host service manager. Figure 5 Schematic diagram of the network scanning method proposed in this embodiment Figure 3 ,like Figure 5 As shown, the network scanning method may include the following steps:
[0096] Step 301: The scanning service device establishes a VPN tunnel with the scanned service device.
[0097] It should be noted that, in an embodiment of the present application, the scanning service device further includes a VPN terminal. When establishing a VPN tunnel with the scanned service device, the scanning service device can establish a VPN tunnel with the VPN client in the scanned service device through the VPN terminal.
[0098] Step 302: The scanning service device sends a scanning instruction to the host service manager in the scanned service device based on the VPN tunnel.
[0099] Step 303: The scanned service device responds to the scanning instruction and sends the host list to be detected to the scanning service manager in the scanning service device.
[0100] Furthermore, in an embodiment of the present application, the scanned service device may receive the first scanning traffic mapped by the scanning service device; and send the first scanning traffic to the current host in the host list to be detected based on the SNAT function.
[0101] Exemplarily, in an embodiment of the present application, SNAT can be configured on the scanned service device so that the first scanning traffic actively initiated by the scanner connected to the scanning service device can establish a two-way network connection with the current host (target_host) in the list of hosts to be detected through the VPN tunnel. The pseudo code used can be iptables -t nat-APOSTROUTING -o target_host -j MASQUERADE.
[0102] It should be noted that in an embodiment of the present application, the scanned service device can, based on the DNAT function, convert the second initial destination address connected to the second virtual proxy interface according to the address information corresponding to the scanner, and obtain a second mapping relationship between the second virtual proxy interface and the scanner; based on the second mapping relationship, the second scanning traffic corresponding to the current host is mapped to the scanning service device.
[0103] Exemplarily, in an embodiment of the present application, the scanned service device can add a second virtual proxy interface, which can be a virtual scanner proxy interface. The legal IP address and subnet mask of the host subnet segment can be used as the IP address of the virtual interface. For example, the pseudo code can be ifconfig eth0:1x.xxx netmaskx.xxx.
[0104] It should be noted that in an embodiment of the present application, when the scanned service device obtains the second mapping relationship between the second virtual proxy interface and the scanner, it can convert the second initial destination address connected to the second virtual proxy interface according to the address information corresponding to the scanner based on the destination address translation (DNAT) function to obtain the second mapping relationship between the second virtual proxy interface and the scanner.
[0105] It should be noted that in an embodiment of the present application, the scanned service device can map the traffic (second scanning traffic) actively initiated by a target_host (current host) to a scanner based on the second mapping relationship between the second virtual proxy interface and the scanner. The pseudo-instruction used can be iptables-t nat-A PREROUTING-d eth0:1-j DNAT--to-destination scanner_ip.
[0106] Step 304: The scanning service device establishes a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected according to the list of hosts to be detected.
[0107] It should be noted that in an embodiment of the present application, a scanning service device adds a first virtual proxy interface. The first virtual proxy interface can be a virtual host proxy interface. The legal IP address and subnet mask of the scanning subnet segment can be used as the IP address of the virtual interface. For example, the pseudo code can be ifconfig eth0:1x.xxx netmaskx.xxx.
[0108] It should be noted that in an embodiment of the present application, when the scanning service device establishes a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected based on the list of hosts to be detected, it can be based on the destination address translation (DNAT) function. According to the address information corresponding to the host to be detected in the list of hosts to be detected, the first initial destination address connected to the first virtual proxy interface is converted and processed to obtain the first mapping relationship between the first virtual proxy interface and the list of hosts to be detected.
[0109] It should be noted that, in the embodiment of the present application, the first initial destination address may be a public IP address.
[0110] For example, in an embodiment of the present application, when the scanning service device establishes a first mapping relationship between the first virtual proxy interface in the scanning service device and the host list to be detected based on the host list to be detected, it traverses the host list to be detected and takes out the IP of host 1 to be detected. DNAT can be configured on the scanning service device to convert the first initial destination address connected to the first virtual proxy interface according to the address information corresponding to host 1 to be detected in the host list to be detected, and obtain the mapping relationship between the first virtual proxy interface and host 1 to be detected. The scanning service device can also obtain the mapping relationship between the first virtual proxy interface and host 2 to be detected according to the same steps, until the host list to be detected is traversed and the mapping relationship between the first virtual proxy interface and host n to be detected is obtained.
[0111] That is to say, in an embodiment of the present application, when the scanner connected to the scanning service device under the scanning subnet needs to perform a security scan detection on the hosts in the list of hosts to be detected under the host subnet, due to the mapping relationship established between the first virtual proxy interface and the list of hosts to be detected, the scanner connected to the scanning service device only needs to scan the first virtual proxy interface to complete the security scan of the hosts in the list of hosts to be detected without any configuration of the gateway, thereby improving the flexibility of the security scan.
[0112] Step 305: When the scanner scans the first virtual proxy interface, a scanning result of the host to be detected in the host to be detected list is determined based on the first mapping relationship.
[0113] It should be noted that in an embodiment of the present application, when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the list of hosts to be detected is determined based on the first mapping relationship; when the scanner scans the first virtual proxy interface, the first scanning traffic is mapped to the current host in the list of hosts to be detected based on the first mapping relationship; the second scanning traffic corresponding to the current host mapped by the scanned service device is received; and the scanning result of the current host is determined based on the second scanning traffic.
[0114] Exemplarily, in an embodiment of the present application, when the scanner scans the first virtual proxy interface, the first scanning traffic is mapped to the current host in the host list to be detected based on the first mapping relationship, and the first scanning traffic can be mapped to a target host (the current host in the host list). The pseudo code used can be iptables-t nat-APREROUTING-d eth0:1-j DNAT--to-destination target_host.
[0115] Furthermore, it should be noted that, in an embodiment of the present application, routing can be configured on the scanning service device so that network traffic destined for target_host (the current host in the host list) can reach the scanned service device through the VPN tunnel. The pseudo code used can be route add-host target_host gw host_vpn_address.
[0116] It should be noted that, in an embodiment of the present application, after receiving the second scanning traffic corresponding to the current host mapped by the scanning service device, the scanning service device can send the second scanning traffic to the scanner based on the Source Network Address Translation (SNAT) function.
[0117] For example, in an embodiment of the present application, SNAT can be configured on the scanning service device so that the traffic actively initiated by target_host can establish a two-way network connection with the scanner through the VPN tunnel. The pseudo code used can be iptables -t nat-APOSTROUTING -o eth0:1 -j MASQUERADE.
[0118] It should be noted that in an embodiment of the present application, when the scanner determines the scanning result of the host to be detected in the host list to be detected based on the first mapping relationship, the first virtual host proxy interface can be scanned according to <open port, host operating system type, host open service type>.
[0119] To sum up, when the scanner connected to the scanning service device under the scanning subnet needs to perform security scanning and detection on the hosts in the list of hosts to be detected under the host subnet, since a mapping relationship is established between the first virtual proxy interface and the list of hosts to be detected, the scanner connected to the scanning service device only needs to scan the first virtual proxy interface to complete the security scan of the hosts in the list of hosts to be detected without any configuration of the gateway, thereby improving the flexibility of the security scan.
[0120] An embodiment of the present application provides a network scanning method, which is applied to a scanning service device and a scanned service device, the scanning service device can establish a VPN tunnel between the scanning service device; then, based on the VPN tunnel, a scanning instruction is sent to the host service manager in the scanned service device, and a list of hosts to be detected sent by the scanned service device in response to the scanning instruction is received through the scanning service manager; a first mapping relationship between a first virtual proxy interface in the scanning service device and the list of hosts to be detected is established according to the list of hosts to be detected; when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the list of hosts to be detected is determined based on the first mapping relationship; the scanned service device can establish a VPN tunnel between the scanning service device; based on the VPN tunnel, the scanning instruction sent by the scanning service device is received; in response to the scanning instruction, the list of hosts to be detected is sent to the scanning service manager in the scanning service device, so that the scanning service device obtains the scanning result of the host to be detected in the list of hosts to be detected based on the list of hosts to be detected. It can be seen that the network scanning method proposed in the embodiment of the present application adds a scanning service device and a scanned service device. The scanning service device can establish a VPN tunnel with the scanned service device and receive the list of hosts to be detected sent by the scanned service device through the VPN tunnel. Then, a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected can be established. Then, when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the list of hosts to be detected can be determined based on the first mapping relationship. In other words, when the scanner in the present application needs to scan the host to be detected in the list of hosts to be detected, it can directly scan the first virtual proxy interface to obtain the scanning result of the host to be detected in the list of hosts to be detected, thereby completing the cross-subnet detection task. The present application does not require any configuration of the scanner, nor does it require any configuration of the gateway, thereby improving the flexibility of security scanning detection.
[0121] Example 4
[0122] Based on the above embodiment, another embodiment of the present application provides a network scanning method, Figure 6 Schematic diagram of the network scanning architecture proposed in this application embodiment Figure 1 ,like Figure 6As shown, a scanning service host (scanning service device) is added to the scanning subnet, and a scanned service host (scanned service device) is added to the host subnet. A VPN tunnel is established between the scanning service host (scanning service device) and the scanned service host (scanned service device). The scanning service host creates a virtual host proxy interface eth0:1 (first virtual proxy interface), and uses DNAT technology to pull the scanner traffic (first scanning traffic) to the VPN tunnel. The scanned service host uses SNAT technology to send the scanning traffic from the VPN tunnel to each detected host. The scanned service host creates a virtual scanner proxy interface eth0:1 (second virtual proxy interface), and uses DNAT technology to pull the host asynchronous return traffic (second scanning traffic) to the VPN tunnel. The scanning service host uses SNAT technology to send the asynchronous scanning return traffic (second scanning traffic) from the VPN tunnel to the current scanner, as shown. Figure 6 As shown, the scanning service host (scanning service device) installs VPN terminal software and is connected to the gateway in the scanning subnet, and the scanning service manager is connected to each scanner in the scanning subnet; the scanned service host (scanned service device) installs VPN client software and is connected to the gateway in the host subnet, and the host service manager is connected to each host in the host subnet.
[0123] It should be noted that, in an embodiment of the present application, when the scanner performs a scanning task, the host service manager collects a list of all hosts to be detected in the host subnet and sends it to the scanning service manager. The scanning service manager maps the IP address of each host to be detected in the host subnet to the virtual host proxy interface (first virtual proxy interface) of the scanning service host in sequence. The scanner scans the virtual host proxy interface (first virtual proxy interface) of the scanning service host to complete the cross-subnet detection task.
[0124] Furthermore, in the embodiments of this application, the network scanning method is further described below using WireGuard VPN as an example; WireGuard VPN is a new type of VPN protocol. Other VPN technologies such as IPSEC VPN and PPTP VPN may also be applicable. This application does not specifically limit the type of VPN technology.
[0125] It should be noted that, in the embodiments of this application, Figure 7 Schematic diagram of the network scanning architecture proposed in this application embodiment Figure 2 ,like Figure 7As shown, the present application can add a VPN relay to the Internet to establish a VPN connection between the scanned service host (the scanned service device) and the scanning service host (the scanning service device). The VPN relay installs the VPN service software, configures the public IP address, and provides a UDP port as the VPN relay service port. Alternatively, a VPN connection can be directly established between the scanned service host (the scanned service device) and the scanning service host (the scanning service device). A scanning service host (the scanning service device) and a scanned service host (the scanned service device) are added to the scanning subnet and the host subnet, respectively. The scanning service host installs the VPN client software and is connected to the gateway in the scanning subnet and to each scanner in the scanning subnet. The scanning subnet boundary firewall is configured so that the scanning service host eth0 can access the public network VPN relay service UDP port. The scanned service host (the scanned service device) installs the VPN client software and is connected to the gateway in the host subnet and to each host in the host subnet. The host subnet boundary firewall is configured so that the scanned service host eth0 can access the public network VPN relay service UDP port.
[0126] It should be noted that, in an embodiment of the present application, the host service manager can collect a host list and send it to the scanning service manager. According to the instructions of the scanning server manager, local SNAT or DNAT is configured; the scanning server manager receives the host list (host list to be detected), forms a sequential strategy based on the scanner list in the scanning subnet and the host list in the host subnet (host list to be detected), configures local DNAT and SNAT, and notifies the host service manager to configure SNAT or DNAT.
[0127] Furthermore, in an embodiment of the present application, a VPN tunnel is created between the scanning service host (scanning service device) and the scanned service host (scanned service device) through a VPN relay. Or a VPN tunnel is directly established between the scanning service host and the scanned service host; and then the scanning task of the host to be detected can be completed by the following steps: (1) the host service manager can collect the host information to be detected and generate a host list to be detected. The list example is as follows: <host 1-IP, open port, host operating system type, host open service type>, <host 2-IP, open port, host operating system type, host open service type>.... <host N-IP, open port, host operating system type, host open service type>; (2) the host service manager sends the host list to be detected to the scanning service manager; (3) the scanning service manager selects scanner 1; (4) the scanning service manager notifies the host service manager of the Internet Protocol (IP) address of scanner 1; (5) the scanning service host (scanning service device) traverses the host list to be detected and takes out the IP of the host to be detected; (6) according to the following "network IP mapping" steps, establish a mapping of the virtual host proxy interface (first virtual proxy interface) to the IP of the host to be detected, and a virtual scanning proxy interface (second virtual proxy interface) to the current scanner 1 Mapping of IP addresses; (7) Scanning service host (scanning service device) notifies scanner 1 to scan virtual host proxy interface (first virtual proxy interface) according to <open port, host operating system type, host open service type>; (8) Scanning service host (scanning service device) monitors the connection status of virtual host proxy interface (first virtual proxy interface), and when the connection is disconnected (after scanning is completed), obtains the scanning result of scanner 1, and converts the IP address in the scanning result document to the host-IP to be detected mapped by the current virtual host proxy interface; (9) Scanning service host (scanning service device) notifies scanner 1 to scan virtual host proxy interface (first virtual proxy interface) according to <open port, host operating system type, host open service type>; (10) Scanning service host (scanning service device) notifies scanner 1 to scan virtual host proxy interface (first virtual proxy interface) according to <open port, host operating system type, host open service type>; (11) Scanning service host (scanning service device) notifies scanner 1 to scan virtual host proxy interface (first virtual proxy interface) according to <open port, host operating system type, host open service type>; (12) Scanning service host (scanning service device) notifies scanner 1 to scan virtual host proxy interface (first virtual proxy interface) according to <open port, host operating system type, host open service type>; (13) Scanning service host (scanning service device) notifies scanner 1 to scan virtual host proxy interface (first virtual proxy interface) according to <open port, host operating system type, host open service type>; (14) Scanning service host (scanning service device) notifies scanner 1 to scan virtual host proxy interface (first virtual proxy interface) according to <open port The service device) takes out the next record in the list of hosts to be detected, and establishes the mapping of the virtual host proxy interface (first virtual proxy interface) to the host-IP to be detected again according to steps 6-8, and notifies scanner 1 to scan until scanner 1 has traversed and scanned all hosts in the list of hosts to be detected; (10) the scanning service host selects scanner 2, and according to steps (4) to (9), scanner 2 scans all hosts to be scanned (hosts to be detected) in the host subnet; (11) the scanning service host (scanning service device) selects all scanners and completes the scanning of the hosts to be detected in the host subnet.
[0128] That is to say, in an embodiment of the present application, when the scanner connected to the scanning service device under the scanning subnet needs to perform a security scan detection on the hosts in the list of hosts to be detected under the host subnet, due to the mapping relationship established between the first virtual proxy interface and the list of hosts to be detected, the scanner connected to the scanning service device only needs to scan the first virtual proxy interface to complete the security scan of the hosts in the list of hosts to be detected without any configuration of the gateway, thereby improving the flexibility of the security scan.
[0129] It should be noted that, in the embodiment of the present application, the network IP mapping can be mapped by the following method: first, the scanning service host can be configured to forward the scanning traffic into the VPN tunnel; (1) a virtual interface eth0:1 (first virtual proxy interface) is created on the scanning service host (scanning service device), and the legal IP address and subnet mask of the scanning subnet segment are used as the IP address of the virtual interface. The pseudo code is as follows: ifconfig eth0:1x.xxx netmask xxxx; (2) DNAT is configured on the scanning service host (scanning service device) to map the scanning traffic (first scanning traffic) of a scanner to a target host. The pseudo instruction used is as follows: iptables -t nat -A PREROUTING -d eth0:1 -jDNAT --to-destination target_host; (3) routing is configured on the scanning service host (scanning service device) so that the network traffic to target_host reaches the scanned service host through the VPN tunnel. The pseudo instruction used is as follows: routeadd -host target_host gw host_vpn_address; (4) Configure SNAT on the scanning service host so that the traffic (second scanning traffic) initiated by target_host (current host) can establish a two-way network connection with the scanner through the VPN tunnel. The pseudo-instruction used is as follows: iptables -t nat-APOSTROUTING -o eth0:1 -jMASQUERADE.
[0130] It should be noted that, in the embodiments of the present application, the scanned service host (the scanned service device) can also be configured to forward the scanning traffic from the VPN tunnel to the target host; (1) a virtual interface eth0:1 (the second virtual proxy interface) is created on the scanned service host, and the legal IP address and subnet mask of the host subnet segment are used as the IP address of the virtual interface. The pseudo code is as follows: ifconfig eth0:1x.xxx netmask xxxx; (2) Configure SNAT on the scanned service host (the scanned service device) so that the traffic initiated by the scanner can establish a two-way network connection with the target_host through the VPN tunnel. The pseudo code is as follows: iptables -t nat -A POSTROUTING -o target_host -j MASQUERADE; (3) Configure DNAT on the scanned service host (the scanning service device) to map the traffic initiated by a target_host to a scanner. The pseudo command used is as follows: iptables -t nat -A PREROUTING -d eth0:1 -j DNAT --to-destination scanner_ip; (4) Configure routing on the scanned service host so that the network traffic to the scanner can reach the scanned service host through the VPN tunnel. The pseudo code used is as follows: route add-host target_scanner gwscanner_vpn_address.
[0131] To sum up, when the scanner connected to the scanning service device under the scanning subnet needs to perform security scanning and detection on the hosts in the list of hosts to be detected under the host subnet, since a mapping relationship is established between the first virtual proxy interface and the list of hosts to be detected, the scanner connected to the scanning service device only needs to scan the first virtual proxy interface to complete the security scan of the hosts in the list of hosts to be detected without any configuration of the gateway, thereby improving the flexibility of the security scan.
[0132] An embodiment of the present application provides a network scanning method, which is applied to a scanning service device and a scanned service device, the scanning service device can establish a VPN tunnel between the scanning service device; then, based on the VPN tunnel, a scanning instruction is sent to the host service manager in the scanned service device, and a list of hosts to be detected sent by the scanned service device in response to the scanning instruction is received through the scanning service manager; a first mapping relationship between a first virtual proxy interface in the scanning service device and the list of hosts to be detected is established according to the list of hosts to be detected; when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the list of hosts to be detected is determined based on the first mapping relationship; the scanned service device can establish a VPN tunnel between the scanning service device; based on the VPN tunnel, the scanning instruction sent by the scanning service device is received; in response to the scanning instruction, the list of hosts to be detected is sent to the scanning service manager in the scanning service device, so that the scanning service device obtains the scanning result of the host to be detected in the list of hosts to be detected based on the list of hosts to be detected. It can be seen that the network scanning method proposed in the embodiment of the present application adds a scanning service device and a scanned service device. The scanning service device can establish a VPN tunnel with the scanned service device and receive the list of hosts to be detected sent by the scanned service device through the VPN tunnel. Then, a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected can be established. Then, when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the list of hosts to be detected can be determined based on the first mapping relationship. In other words, when the scanner in the present application needs to scan the host to be detected in the list of hosts to be detected, it can directly scan the first virtual proxy interface to obtain the scanning result of the host to be detected in the list of hosts to be detected, thereby completing the cross-subnet detection task. The present application does not require any configuration of the scanner, nor does it require any configuration of the gateway, thereby improving the flexibility of security scanning detection.
[0133] Example 5
[0134] Based on the above embodiments, the present application provides a scanning service device. Figure 8 Schematic diagram of the structure of the scanning service equipment Figure 1 ,like Figure 8 As shown, the scanning service device 10 includes: a first establishing unit 11, a first sending unit 12, a first receiving unit 13, and a determining unit 14;
[0135] The first establishing unit 11 is used to establish a VPN tunnel with the scanned service device;
[0136] The first sending unit 12 is configured to send a scan instruction to the host service manager in the scanned service device based on the VPN tunnel;
[0137] The first receiving unit 13 is configured to receive, through the scanning service manager, a list of hosts to be detected sent by the scanned service device in response to the scanning instruction;
[0138] The first establishing unit 11 is further configured to establish a first mapping relationship between the first virtual proxy interface in the scanning service device and the host list to be detected according to the host list to be detected;
[0139] The determining unit 14 is configured to determine a scanning result of the host to be detected in the host to be detected list based on the first mapping relationship when the scanner scans the first virtual proxy interface.
[0140] In the embodiments of the present application, further, Figure 9 Schematic diagram of the structure of the scanning service equipment Figure 2 ,like Figure 9 As shown, the scanning service device 10 proposed in the embodiment of the present application may also include a first processor 15, a first memory 16 storing executable instructions of the first processor 15, and further, the scanning service device 10 may also include a first communication interface 17, and a first bus 18 for connecting the first processor 15, the first memory 16 and the first communication interface 17.
[0141] In an embodiment of the present application, the first processor 15 may be at least one of an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a central processing unit (CPU), a controller, a microcontroller, and a microprocessor. It is understandable that for different devices, the electronic device used to implement the above-mentioned processor function may also be other, and the embodiment of the present application does not specifically limit this. The scanning service device 10 may also include a first memory 16, which may be connected to the first processor 15, wherein the first memory 16 is used to store executable program code, which includes computer operating instructions. The first memory 16 may include a high-speed RAM memory, and may also include a non-volatile memory, for example, at least two disk memories.
[0142] In the embodiment of the present application, the first bus 18 is used to connect the first communication interface 17, the first processor 15, and the first memory 16, and to facilitate mutual communication between these devices.
[0143] In the embodiment of the present application, the first memory 16 is used to store instructions and data.
[0144] Furthermore, in an embodiment of the present application, the above-mentioned first processor 15 is used to establish a VPN tunnel with the scanned service device; based on the VPN tunnel, send a scanning instruction to the host service manager in the scanned service device, and receive the list of hosts to be detected sent by the scanned service device in response to the scanning instruction through the scanning service manager; establish a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected according to the list of hosts to be detected; when the scanner scans the first virtual proxy interface, determine the scanning result of the host to be detected in the list of hosts to be detected based on the first mapping relationship.
[0145] In practical applications, the first memory 16 may be a volatile memory, such as a random-access memory (RAM); or a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the first processor 15.
[0146] An embodiment of the present application provides a scanning service device, which establishes a VPN tunnel between the scanning service device and the scanned service device; then, based on the VPN tunnel, sends a scanning instruction to the host service manager in the scanned service device, and receives a list of hosts to be detected sent by the scanned service device in response to the scanning instruction through the scanning service manager; a first mapping relationship between a first virtual proxy interface in the scanning service device and the list of hosts to be detected is established according to the list of hosts to be detected; when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the list of hosts to be detected is determined based on the first mapping relationship; the scanned service device can establish a VPN tunnel between the scanning service device; based on the VPN tunnel, receive the scanning instruction sent by the scanning service device; in response to the scanning instruction, send the list of hosts to be detected to the scanning service manager in the scanning service device, so that the scanning service device obtains the scanning result of the host to be detected in the list of hosts to be detected based on the list of hosts to be detected. It can be seen that the network scanning method proposed in the embodiment of the present application adds a scanning service device and a scanned service device. The scanning service device can establish a VPN tunnel with the scanned service device and receive the list of hosts to be detected sent by the scanned service device through the VPN tunnel. Then, a first mapping relationship between the first virtual proxy interface in the scanning service device and the list of hosts to be detected can be established. Then, when the scanner scans the first virtual proxy interface, the scanning result of the host to be detected in the list of hosts to be detected can be determined based on the first mapping relationship. In other words, when the scanner in the present application needs to scan the host to be detected in the list of hosts to be detected, it can directly scan the first virtual proxy interface to obtain the scanning result of the host to be detected in the list of hosts to be detected, thereby completing the cross-subnet detection task. The present application does not require any configuration of the scanner, nor does it require any configuration of the gateway, thereby improving the flexibility of security scanning detection.
[0147] An embodiment of the present application provides a computer-readable storage medium having a program stored thereon, which implements the network scanning method described above when executed by a processor.
[0148] Specifically, the program instructions corresponding to a network scanning method in this embodiment can be stored on a storage medium such as a CD, a hard disk, or a USB flash drive. When the program instructions corresponding to a network scanning method in the storage medium are read or executed by an electronic device, the following steps are included:
[0149] Establish a VPN tunnel with the scanned service device;
[0150] Sending a scan instruction to a host service manager in the scanned service device based on the VPN tunnel, and receiving, through the scan service manager, a list of hosts to be detected sent by the scanned service device in response to the scan instruction;
[0151] Establishing a first mapping relationship between the first virtual proxy interface in the scanning service device and the host list to be detected according to the host list to be detected;
[0152] When the scanner scans the first virtual proxy interface, a scanning result of the host to be detected in the host to be detected list is determined based on the first mapping relationship.
[0153] In the embodiments of the present application, further, Figure 10 Schematic diagram of the structure of the scanned service equipment Figure 1 ,like Figure 10 As shown, the scanned service device 20 includes: a second establishing unit 21, a second receiving unit 22, and a second sending unit 23;
[0154] The second establishing unit 21 is configured to establish a VPN tunnel with the scanning service device;
[0155] The second receiving unit 22 is configured to receive a scanning instruction sent by the scanning service device based on the VPN tunnel;
[0156] The second sending unit 23 is configured to send the host list to be detected to the scanning service manager in the scanning service device in response to the scanning instruction, so that the scanning service device obtains scanning results of the hosts to be detected in the host list based on the host list to be detected.
[0157] In the embodiments of the present application, further, Figure 11 Schematic diagram of the structure of the scanned service equipment Figure 2 ,like Figure 11 As shown, the scanned service device 20 proposed in the embodiment of the present application may also include a second processor 24, a second memory 25 storing executable instructions of the second processor 24, and further, the scanned service device 20 may also include a second communication interface 26, and a second bus 27 for connecting the second processor 24, the second memory 25 and the second communication interface 26.
[0158] In an embodiment of the present application, the second processor 24 may be at least one of an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a central processing unit (CPU), a controller, a microcontroller, and a microprocessor. It is understandable that for different devices, the electronic device used to implement the above-mentioned processor function may also be other, and the embodiment of the present application does not specifically limit this. The scanned service device 20 may also include a second memory 25, which may be connected to the second processor 24, wherein the second memory 25 is used to store executable program code, which includes computer operating instructions. The second memory 25 may include a high-speed RAM memory, and may also include a non-volatile memory, for example, at least two disk memories.
[0159] In the embodiment of the present application, the second bus 27 is used to connect the second communication interface 26, the second processor 24 and the second memory 25, and to facilitate mutual communication between these devices.
[0160] In the embodiment of the present application, the second memory 25 is used to store instructions and data.
[0161] Furthermore, in an embodiment of the present application, the above-mentioned second processor 24 is used to establish a VPN tunnel with the scanning service device; based on the VPN tunnel, receive a scanning instruction sent by the scanning service device; in response to the scanning instruction, send the list of hosts to be detected to the scanning service manager in the scanning service device, so that the scanning service device obtains the scanning results of the hosts to be detected in the list of hosts to be detected based on the list of hosts to be detected.
[0162] In actual applications, the above-mentioned second memory 25 can be a volatile memory (volatile memory), such as random-access memory (RAM); or a non-volatile memory (non-volatile memory), such as read-only memory (ROM), flash memory, hard disk drive (HDD) or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the second processor 24.
[0163] The embodiment of the present application provides a scanned service device, which can establish a VPN tunnel with the scanning service device; based on the VPN tunnel, receive a scanning instruction sent by the scanning service device; in response to the scanning instruction, send a list of hosts to be detected to the scanning service manager in the scanning service device, so that the scanning service device obtains the scanning results of the hosts to be detected in the list of hosts to be detected based on the list of hosts to be detected. It can be seen that the scanned service device can send the list of hosts to be detected to the scanning service manager in the scanning service device through the VPN tunnel established between the scanned service device and the scanning service device, so that the scanning service device obtains the scanning results of the hosts to be detected in the list of hosts to be detected based on the list of hosts to be detected, and scans the hosts to be detected in the list of hosts to be detected without making any configuration on the host or the gateway.
[0164] An embodiment of the present application provides a computer-readable storage medium having a program stored thereon, which implements the network scanning method described above when executed by a processor.
[0165] Specifically, the program instructions corresponding to a network scanning method in this embodiment can be stored on a storage medium such as a CD, a hard disk, or a USB flash drive. When the program instructions corresponding to a network scanning method in the storage medium are read or executed by an electronic device, the following steps are included:
[0166] Establish a VPN tunnel with the scanning service device;
[0167] Based on the VPN tunnel, receiving a scanning instruction sent by the scanning service device;
[0168] In response to the scanning instruction, the host list to be detected is sent to the scanning service manager in the scanning service device, so that the scanning service device obtains the scanning results of the hosts to be detected in the host list to be detected based on the host list to be detected.
[0169] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of hardware embodiments, software embodiments, or embodiments combining software and hardware. Furthermore, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage and optical storage, etc.) containing computer-usable program code.
[0170] The present application is described with reference to the implementation flow charts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flow charts and / or block diagrams, as well as the combination of processes and / or boxes in the flow charts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the implementation flow charts. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0171] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which is implemented in the implementation flow diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0172] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process described in the flowchart. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0173] The above description is merely a preferred embodiment of the present application and is not intended to limit the scope of protection of the present application.
Claims
1. A network scanning method, characterized in that: The method is applied to a scanning service device, the scanning service device including a scanning service manager, the scanning service manager being connected to a scanner, and the method comprising: Establish a virtual private network VPN tunnel with the scanned service device; Sending a scan instruction to a host service manager in the scanned service device based on the VPN tunnel, and receiving, through the scan service manager, a list of hosts to be detected sent by the scanned service device in response to the scan instruction; Establishing a first mapping relationship between the first virtual proxy interface in the scanning service device and the host list to be detected according to the host list to be detected; When the scanner scans the first virtual proxy interface, a scanning result of the host to be detected in the host to be detected list is determined based on the first mapping relationship.
2. The method according to claim 1, characterized in that The scanning service device further includes a VPN terminal, and the step of establishing a VPN tunnel with the scanned service device includes: A VPN tunnel is established between the VPN terminal and the VPN client in the scanned service device.
3. The method according to claim 2, characterized in that The establishing a first mapping relationship between the first virtual proxy interface in the scanning service device and the host list to be detected according to the host list to be detected includes: Based on the destination address translation DNAT function, the first initial destination address connected to the first virtual proxy interface is converted according to the address information corresponding to the host to be detected in the host list to obtain a first mapping relationship between the first virtual proxy interface and the host list to be detected.
4. The method according to claim 3, characterized in that When the scanner scans the first virtual proxy interface, determining a scan result of the host to be detected in the host to be detected list based on the first mapping relationship includes: When the scanner scans the first virtual proxy interface, mapping the first scan traffic to the current host in the list of hosts to be detected based on the first mapping relationship; receiving second scanning traffic corresponding to the current host mapped by the scanned service device; A scan result of the current host is determined based on the second scan traffic.
5. The method according to claim 4, characterized in that After receiving the second scanning traffic corresponding to the current host mapped by the scanned service device, the method further includes: The second scanning traffic is sent to the scanner based on a source address translation (SNAT) function.
6. A network scanning method, characterized in that: The method is applied to a scanned service device, wherein the scanned service device includes a host service manager, and the method includes: Establish a VPN tunnel with the scanning service device; Based on the VPN tunnel, receiving a scanning instruction sent by the scanning service device; In response to the scanning instruction, the host list to be detected is sent to the scanning service manager in the scanning service device, so that the scanning service device obtains the scanning results of the hosts to be detected in the host list to be detected based on the host list to be detected.
7. The method according to claim 6, characterized in that After receiving the scanning instruction sent by the scanning service device, the method further includes: Determine the host information to be detected; The host list to be detected is generated based on the host information to be detected.
8. The method according to claim 7, characterized in that The method further comprises: receiving first scanning traffic mapped by the scanning service device; The first scanning traffic is sent to the current host in the list of hosts to be detected based on the SNAT function.
9. The method according to claim 8, characterized in that The method further comprises: Based on the DNAT function, converting the second initial destination address connected to the second virtual proxy interface according to the address information corresponding to the scanner to obtain a second mapping relationship between the second virtual proxy interface and the scanner; The second scanning traffic corresponding to the current host is mapped to the scanning service device based on the second mapping relationship.
10. A scanning service device, characterized in that: The scanning service device includes: a first establishing unit, a first sending unit, a first receiving unit, a determining unit, The first establishing unit is used to establish a VPN tunnel with the scanned service device; The first sending unit is configured to send a scan instruction to the host service manager in the scanned service device based on the VPN tunnel; The first receiving unit is configured to receive, through a scanning service manager, a list of hosts to be detected sent by the scanned service device in response to the scanning instruction; The first establishing unit is further configured to establish a first mapping relationship between the first virtual proxy interface in the scanning service device and the host list to be detected according to the host list to be detected; The determining unit is configured to determine, when the scanner scans the first virtual proxy interface, a scanning result of the host to be detected in the host to be detected list based on the first mapping relationship.
11. A scanning service device, characterized in that: The scanning service device includes: a first processor and a first memory; wherein, The first memory is used to store a computer program that can be run on the processor; The first processor is configured to execute the method according to any one of claims 1 to 5 when running the computer program.
12. A scanned service device, characterized in that: The scanned service device includes: a second establishing unit, a second receiving unit, a second sending unit, The second establishing unit is configured to establish a VPN tunnel with the scanning service device; The second receiving unit is configured to receive a scanning instruction sent by the scanning service device based on the VPN tunnel; The second sending unit is configured to send the host list to be detected to the scanning service manager in the scanning service device in response to the scanning instruction, so that the scanning service device obtains scanning results of the hosts to be detected in the host list based on the host list to be detected.
13. A scanned service device, characterized in that: The scanned service device includes: a second processor and a second memory; wherein, The second memory is used to store a computer program that can be run on the processor; The second processor is configured to execute the method according to any one of claims 6 to 9 when running the computer program.
14. A computer-readable storage medium, characterized in that The storage medium stores computer program code, which, when executed by a computer, executes the method according to any one of claims 1 to 5 or 6 to 9.
Citation Information
Patent Citations
Vulnerability scanning cooperation method based on new communication protocol
CN105491009A
Reverse source-tracing method and equipment for scanner based on multipath VPN (Virtual Private Network) load balance
CN106549936A