A kind of active and passive combined network space anti-mapping system

By combining active and passive methods in a cyberspace anti-mapping system, the network status can be monitored and analyzed in real time, and active and passive strategies can be dynamically selected and executed. This solves the problem of inaccurate identification in complex environments by existing anti-mapping systems and improves the network's defense effectiveness and stability.

CN119402217BActive Publication Date: 2025-10-21FUDAN UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411275026.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-12
Publication Date
2025-10-21
Estimated Expiration
2044-09-12

AI Technical Summary

Technical Problem

Existing anti-mapping systems mainly rely on proactive strategies, which suffer from inaccurate traffic identification. This makes them unable to effectively respond to mapping attacks in complex and ever-changing network environments, and may even introduce additional security risks.

Method used

A combined active and passive anti-mapping strategy is adopted. The network status is collected and analyzed in real time through the network status awareness module. Combined with the detection traffic identification module, the active anti-mapping strategy module and the passive anti-mapping strategy module, the corresponding strategy is dynamically selected and executed to improve the identification and defense capabilities.

Benefits of technology

In complex and ever-changing network environments, the system's resistance to mapping and spoofing has been improved, enhancing network security and stability and ensuring the security of critical information and infrastructure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119402217B_ABST
    Figure CN119402217B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of computer network security, and particularly relates to a network space anti-mapping system combining active and passive modes. The system comprises a network state sensing module, a probe flow identification module, an active anti-mapping strategy module and a passive anti-mapping strategy module. The network state sensing module collects network topology and key node information to provide data support for strategy making. The probe flow identification module identifies mapping attacks by capturing and analyzing network flows. The active anti-mapping strategy module dynamically selects and executes strategies based on the identification results to actively defend against mapping attacks. The passive anti-mapping strategy module executes passive defense measures against mapping flows that are misidentified as normal flows. The application effectively improves network protection capability and reduces mapping risks by combining active and passive modes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of computer network security, and in particular relates to a cyberspace anti-mapping system. Background Art

[0002] Cyberspace mapping is a significant threat to cybersecurity. It utilizes various tools and techniques to probe and analyze target networks, obtaining information about their structure, services, devices, and potential security vulnerabilities. This mapping activity poses a serious threat to network security and privacy, making the development of cyberspace anti-mapping systems crucial. Effective anti-mapping systems can significantly enhance network protection capabilities, mitigate potential cybersecurity risks, and ensure the security of critical information and infrastructure.

[0003] Currently, most existing anti-mapping systems rely on active anti-mapping strategies. These systems typically include a detection traffic identification module that identifies potential mapping attack traffic through real-time monitoring and analysis of network traffic. The core of this approach lies in the accuracy of traffic identification, which requires the system to accurately analyze and identify mapping attack traffic so that corresponding active defense measures can be taken. However, the accuracy of traffic identification is affected by many factors, such as the complexity of the network environment, the diversity and dynamic nature of traffic characteristics, etc., which may lead to inaccurate traffic identification and thus affect the effectiveness of active anti-mapping strategies. When traffic identification errors occur, existing active anti-mapping systems may not be able to effectively respond to mapping attacks and may even introduce additional security risks due to misjudgments. Therefore, systems that rely solely on active anti-mapping strategies may appear to be powerless in complex and changing network environments. Summary of the Invention

[0004] The present invention aims to provide an efficient and dynamic active and passive combined cyberspace anti-mapping system to effectively resist network mapping attacks and protect the security and privacy of cyberspace.

[0005] The cyberspace anti-mapping system proposed in the present invention adopts an anti-mapping strategy that combines active and passive methods. It not only actively identifies and defends against mapping traffic through a detection traffic identification module, but also introduces a passive anti-mapping strategy module to maintain a certain degree of anti-mapping capability for mapping traffic that is mistakenly identified as normal traffic. This combination of active and passive methods can effectively resist network mapping attacks and protect the security and privacy of cyberspace. Specifically, the cyberspace anti-mapping system proposed in the present invention includes a network status perception module, a detection traffic identification module, an active anti-mapping strategy module, and a passive anti-mapping strategy module; wherein:

[0006] The network status perception module is used to collect and analyze network status information in real time, including network topology changes and key network node analysis, to provide a data basis for subsequent strategy formulation. It can identify potential signs of surveying and mapping attacks through in-depth analysis of network behavior.

[0007] The detection traffic identification module is responsible for monitoring and analyzing network traffic, and using traffic identification technology to identify mapping attack traffic in real time from massive network traffic;

[0008] The active anti-mapping strategy module dynamically selects and executes an active anti-mapping strategy for the identified mapping traffic based on the data of the network status perception module and the results of the detection traffic identification module;

[0009] The passive anti-mapping strategy module dynamically selects and executes a passive anti-mapping strategy for mapping traffic that is mistakenly identified as normal traffic by the traffic identification module based on data from the network status perception module.

[0010] Further:

[0011] The network status perception module includes a network topology monitoring submodule and a key node analysis submodule.

[0012] The network topology monitoring submodule is mainly responsible for collecting and analyzing the topology information in the network and the size and direction of the traffic between topologies in real time;

[0013] The key node analysis submodule, based on network topology monitoring, further identifies and analyzes key nodes in the network. Key nodes include those with high traffic, high importance, or high risk characteristics, such as core routers, key servers, and data center access points. This in-depth analysis of key nodes provides more accurate target positioning for subsequent anti-mapping strategies.

[0014] The detection traffic identification module includes a traffic capture submodule, a traffic preprocessing submodule, a feature extraction submodule, a traffic identification submodule, and an identification result analysis submodule; wherein:

[0015] The traffic capture submodule is responsible for capturing network data packets flowing through the network. This is achieved by setting up traffic collection facilities at the network interface and ensuring that all or specified types of network traffic are captured through methods such as port mirroring and network splitters.

[0016] The traffic preprocessing submodule uses technologies such as protocol decoding, session reassembly, and IP fragment reassembly to perform preprocessing operations such as cleaning, deduplication, and decoding on the captured raw traffic data to facilitate subsequent analysis;

[0017] The feature extraction submodule extracts key features from the pre-processed traffic data for identifying and mapping traffic. Specifically, the model is trained using different features and the features with the highest recognition accuracy are selected as key features.

[0018] The traffic identification submodule is responsible for classifying and identifying traffic based on the extracted key features using machine learning, deep learning and other algorithms. It is responsible for dividing traffic into different categories such as normal traffic and potential mapping traffic, and further identifying specific mapping attack types.

[0019] The identification result analysis submodule outputs the traffic identification results to the system's active anti-mapping strategy module. Traffic identified as a mapping attack is processed by the active anti-mapping strategy module, while traffic identified as normal is processed by the passive anti-mapping strategy module. Simultaneously, the classification results are fed back to the feature extraction submodule and the traffic identification submodule to further optimize their functions.

[0020] The active anti-mapping strategy module includes a strategy generation submodule, a strategy selection submodule, and a strategy execution submodule.

[0021] in:

[0022] The strategy generation submodule dynamically generates a targeted active anti-mapping strategy group based on the network status provided by the network status perception module and the results of the detection traffic identification module;

[0023] The strategy selection submodule selects the optimal active anti-mapping strategy from the active anti-mapping strategy group according to the current node status;

[0024] The strategy execution submodule is responsible for executing the active anti-mapping strategy selected by the strategy selection module, which usually includes configuring network equipment, adjusting network traffic, simulating false targets or disguising network responses, etc., in order to confuse or interfere with the surveying party's detection activities.

[0025] The passive anti-mapping strategy module includes a node analysis submodule, a node configuration submodule, and a node management submodule.

[0026] in:

[0027] The node analysis submodule analyzes the applicable passive anti-mapping strategies based on the properties and functions of the protected target, such as dynamic ports, dynamic IP addresses, and mimicry defense.

[0028] The node configuration submodule is responsible for configuring the node according to the passive anti-mapping strategy provided by the node analysis submodule;

[0029] The node management submodule is responsible for managing the node adjustment process, such as the time interval for dynamic IP adjustment.

[0030] The cyberspace anti-mapping system provided by the present invention has the following working process:

[0031] The network status perception module collects and analyzes network status information in real time; the detection traffic identification module monitors and analyzes network traffic and identifies mapping attack traffic in real time; based on the data from the network status perception module and the results of the detection traffic identification module, the active anti-mapping strategy module dynamically selects and executes the active anti-mapping strategy; based on the data from the network status perception module, the passive anti-mapping strategy module dynamically selects and executes the passive anti-mapping strategy for the mapping traffic that is mistakenly identified as normal traffic.

[0032] The technical features and advantages of the present invention mainly lie in:

[0033] The innovative integration of active and passive anti-mapping strategies creates a more comprehensive and efficient cyberspace anti-mapping system. Active anti-mapping strategies rapidly identify and defend against potential mapping attacks through real-time monitoring and analysis of network traffic. Passive anti-mapping strategies, however, take effect when active identification fails. By dynamically configuring network nodes, such as by changing ports and IP addresses or employing mimicry defense techniques, they make mapping attacks more difficult for attackers. This combined active and passive strategy not only enhances the system's anti-mapping capabilities but also significantly strengthens network security, maintaining high defensive effectiveness and stability even in complex and changing network environments and when active anti-mapping strategies fail. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 It is a diagram of the overall structural framework of the cyberspace anti-mapping system of the present invention.

[0035] Figure 2 This is a diagram illustrating the composition of the network status perception module of the present invention.

[0036] Figure 3 This is a diagram illustrating the structure of the detection flow identification module of the present invention.

[0037] Figure 4 This is a diagram illustrating the active anti-mapping strategy module of the present invention.

[0038] Figure 5 This is a diagram illustrating the passive anti-mapping strategy module of the present invention. DETAILED DESCRIPTION

[0039] The present invention is further described below through embodiments in conjunction with the accompanying drawings.

[0040] The active and passive combined cyberspace anti-mapping system provided by the present invention has a structure as shown in Figure 1, including network status perception module, detection traffic identification module, active anti-mapping strategy module, and passive anti-mapping strategy module.

[0041] The network status perception module is the foundation of the system. It collects and analyzes network status information in real time, providing data support for the subsequent anti-mapping strategy formulation; the detection traffic identification module is responsible for monitoring and analyzing network traffic, and identifying mapping attack traffic in real time; the active anti-mapping strategy module dynamically selects and executes the active anti-mapping strategy based on the results of the network status perception module and the detection traffic identification module; the passive anti-mapping strategy is dynamically selected and executed based on the network status perception module and node information.

[0042] The network status perception module, its structure is as follows Figure 2 As shown, it includes a network topology monitoring submodule and a key node analysis submodule.

[0043] The network topology monitoring submodule uses sensors or probes deployed in the network to collect real-time network topology information, including node connectivity and link status. It then uses graph theory and network analysis algorithms to process the collected topology data, analyze topology trends, and identify possible abnormal behavior or potential signs of mapping attacks.

[0044] Based on network topology monitoring, the key node analysis submodule identifies key nodes in the network, such as core routers and key servers, through methods such as traffic analysis and importance assessment, and continuously monitors key nodes, analyzes the traffic characteristics and response time of the nodes, and further evaluates the security and potential risks of the nodes.

[0045] The structure of the detection flow identification module is shown in Figure 3 As shown, it includes a traffic capture submodule, a traffic preprocessing submodule, a feature extraction submodule, a traffic identification submodule and an identification result analysis submodule.

[0046] The traffic capture submodule is responsible for deploying traffic capture devices at key network nodes (such as border routers, firewalls, etc.) or at any designated location to capture network data packets. During this process, it is necessary to ensure that the captured data packets are complete and accurate, without missing any important traffic information;

[0047] The traffic preprocessing submodule performs preliminary processing on the traffic to facilitate subsequent analysis and processing operations. This module decodes the protocol of the captured raw data packets to restore the data content of the application layer; regroups the data packets belonging to the same session to facilitate subsequent analysis; removes duplicate data packets and irrelevant information, and cleans the data to improve analysis efficiency;

[0048] The feature extraction submodule extracts features that can characterize the attack from the preprocessed traffic data, such as specific protocol types, port numbers, traffic patterns, or deep features automatically extracted through deep learning methods. This module also continuously optimizes the feature selection process based on feedback from the recognition result analysis submodule to improve the effectiveness and discrimination of features.

[0049] The traffic identification submodule uses machine learning, deep learning, and other algorithms to classify and identify traffic. This module trains a recognition model using known normal traffic and mapped attack traffic data. It then feeds real-time captured traffic data into the trained model for real-time identification and classification. Assume there is a normal vector, norm, and a mapped vector, map.

[0050] The identification result analysis submodule performs statistical analysis on the results of traffic identification. This module can obtain the mapping description vector α=[a1,a2,a3, … ,a n ] and the mapping change vector β = [b1, b2, b3, … ,b n ]. On the one hand, the recognition result analysis submodule feeds back the mapping description vector and mapping change vector to the feature extraction submodule and the traffic identification submodule to further optimize the performance of the feature extraction and recognition algorithms. On the other hand, this submodule sends the mapping description vector and mapping change vector to the active anti-mapping strategy module;

[0051] The structure of the active anti-mapping strategy module is shown in Figure 4 As shown, it includes a strategy generation submodule, a strategy selection submodule and a strategy execution submodule.

[0052] The strategy generation submodule is responsible for building the active anti-mapping strategy matrix. The active anti-mapping strategy matrix is ​​a library of strategies that includes various active anti-mapping strategies, such as configuring network devices, adjusting network traffic, simulating false targets, or camouflaging network responses. Assuming the active anti-mapping strategy matrix includes d strategies, each strategy is evaluated for its performance against different mapping attacks. This yields the adaptability vector of strategy i against different mapping attacks:

[0053]

[0054] And the cost description vector:

[0055]

[0056] The adaptability matrix of the entire active anti-mapping strategy matrix can be obtained:

[0057] R=[γ1,γ2,γ3, … ,γ d ],

[0058] And the cost description matrix:

[0059] C=[cost1,cost2,cost3,…,cost d ];

[0060] The strategy selection module is based on the adaptability vector γ i , cost description vector cost i And the currently identified mapping traffic map, select the most appropriate strategy. The strategy selection logic formula is as follows:

[0061]

[0062] Among them, i * represents the final active anti-mapping strategy selected; ∈ represents the adaptability weight factor, which is used to adjust the importance of adaptability in strategy selection; γ i [map] represents the adaptability of strategy i to the mapping traffic map; ε represents a small positive number used to avoid division by zero; λ represents the cost weight factor used to adjust the importance of cost in strategy selection; represents the total cost of strategy i;

[0063] The passive anti-mapping strategy module, see Figure 5 As shown in the figure, it includes node analysis submodule, node configuration submodule and node management submodule. The main function of this module is to reduce the probability of successful node mapping through passive anti-mapping strategy when traffic identification fails.

[0064] The node analysis submodule is responsible for analyzing each node in the protected network and building an appropriate passive anti-mapping matrix based on its properties and functions. Common passive anti-mapping strategies include dynamic port configuration, dynamic IP configuration, and mimicry defense. Similarly, we can assume that the passive anti-mapping strategy matrix includes d strategies. For each strategy, its performance against different mapping attacks is evaluated, and the adaptability vector of strategy i against different mapping attacks can be obtained:

[0065]

[0066] And the cost description vector:

[0067]

[0068] The adaptability matrix of the entire active anti-mapping strategy matrix can be obtained:

[0069] R=[γ1,γ2,γ3,…,γ a ],

[0070] And the cost description matrix:

[0071] C=[cost1,cost2,cost3,…,cost a ];

[0072] The node configuration submodule configures the corresponding nodes according to the strategy provided by the node analysis submodule to achieve the passive anti-mapping effect. Unlike the active anti-mapping strategy, the passive anti-mapping strategy does not know the specific mapping traffic type, so it needs to be based on the mapping description vector α=[a1,a2,a3,…,a n ]、Surveying change vector β=[b1,b2,b3,…,b n ] and the adaptability vector R and the cost description matrix C to obtain the final selected strategy. The strategy selection steps are as follows:

[0073] (1) For each strategy i, calculate its comprehensive adaptability score to the current mapping attack environment. The formula is as follows:

[0074]

[0075] Among them, w j is the element b in the mapping change vector j The weight of is used to adjust the contribution of attack increase or decrease to the adaptability score.

[0076] (2) For each strategy i, calculate its comprehensive cost. The comprehensive cost is calculated by summing the elements of the cost description vector:

[0077]

[0078] (3) In order to balance adaptability and cost, a utility function U is defined, which takes adaptability and cost into consideration;

[0079]

[0080] Where ∈ is a small positive number that prevents the denominator from being zero. Then, we choose U i The largest strategy i * As the optimal strategy:

[0081] i * =arg max i U i , (5).

[0082] The node management submodule is responsible for managing and maintaining the node's passive anti-mapping configuration to ensure the effectiveness and sustainability of the policy. A regular monitoring mechanism is set up to check the effectiveness of the current policy and adjust the policy configuration as needed. A fault alarm mechanism is set up to automatically notify the administrator when a configuration anomaly is detected, and provide recovery instructions or automatic repair functions.

Claims

1. A combined active and passive cyberspace anti-mapping system, characterized in that: An anti-mapping strategy combining active and passive methods is adopted. Active mapping traffic identification and defense are performed through the detection traffic identification module. A passive anti-mapping strategy module is introduced to maintain a certain anti-mapping capability for mapping traffic that is mistakenly identified as normal traffic. The combination of the two can effectively resist network mapping attacks and protect the security and privacy of cyberspace. Specifically, the cyberspace anti-mapping system includes a network status perception module, a detection traffic identification module, an active anti-mapping strategy module, and a passive anti-mapping strategy module. Among them: The network status perception module is used to collect and analyze network status information in real time, including network topology changes and key network node analysis, to provide a data basis for subsequent strategy formulation; and to identify potential signs of mapping attacks through in-depth analysis of network behavior; The detection traffic identification module is responsible for monitoring and analyzing network traffic, and using traffic identification technology to identify mapping attack traffic in real time from massive network traffic; The active anti-mapping strategy module dynamically selects and executes an active anti-mapping strategy for the identified mapping traffic based on the data of the network status perception module and the results of the detection traffic identification module; The passive anti-mapping strategy module dynamically selects and executes a passive anti-mapping strategy for mapping traffic that is mistakenly identified as normal traffic by the traffic identification module based on data from the network status perception module; The active anti-mapping strategy module includes a strategy generation submodule, a strategy selection submodule, and a strategy execution submodule; wherein: The strategy generation submodule dynamically generates a targeted active anti-mapping strategy group based on the network status provided by the network status perception module and the results of the detection traffic identification module; The strategy selection submodule selects the optimal active anti-mapping strategy from the active anti-mapping strategy group according to the current node status; The strategy execution submodule is responsible for executing the active anti-mapping strategy selected by the strategy selection module, including configuring network devices, adjusting network traffic, simulating false targets or disguising network response operations to confuse or interfere with the surveying party's detection activities; The passive anti-mapping strategy module includes a node analysis submodule, a node configuration submodule, and a node management submodule; wherein: The node analysis submodule analyzes the applicable passive anti-mapping strategies based on the properties and functions of the protected target, including dynamic ports, dynamic IP addresses, and mimicry defense. The node configuration submodule is responsible for configuring the node according to the passive anti-mapping strategy provided by the node analysis submodule; The node management submodule is responsible for managing the node adjustment process, including the time interval for dynamic IP adjustment.

2. The cyberspace anti-mapping system according to claim 1, characterized in that: The network status perception module includes a network topology monitoring submodule and a key node analysis submodule; wherein: The network topology monitoring submodule is responsible for collecting and analyzing the topology information in the network and the size and direction of the traffic between topologies in real time; The key node analysis submodule further identifies and analyzes key nodes in the network based on network topology monitoring; key nodes include nodes with high traffic, high importance or high risk characteristics; through in-depth analysis of key nodes, more accurate target positioning is provided for subsequent anti-mapping strategies.

3. The cyberspace anti-mapping system according to claim 2, characterized in that: The detection traffic identification module includes a traffic capture submodule, a traffic preprocessing submodule, a feature extraction submodule, a traffic identification submodule, and an identification result analysis submodule; wherein: The traffic capture submodule is responsible for capturing network data packets flowing through the network, which is achieved by setting up traffic collection facilities at the network interface to ensure that all or specified types of network traffic are captured; The traffic pre-processing submodule uses protocol decoding, session reassembly, and IP fragment reassembly technology to clean, de-duplicate, and decode the captured raw traffic data for subsequent analysis. The feature extraction submodule extracts key features for identifying and mapping traffic from the preprocessed traffic data; specifically, the model is trained using different features, and the feature with the highest recognition accuracy is selected as the key feature; The traffic identification submodule is responsible for classifying and identifying traffic based on the extracted key features using machine learning and deep learning algorithms. It is responsible for dividing traffic into different categories such as normal traffic and potential mapping traffic, and further identifying specific mapping attack types. The identification result analysis submodule outputs the traffic identification result to the system's active anti-mapping strategy module; the traffic whose identification result is a mapping attack is handed over to the active anti-mapping strategy module for processing, and the traffic whose identification result is normal is handed over to the passive anti-mapping strategy module for processing; at the same time, the classification result is fed back to the feature extraction submodule and the traffic identification submodule to further optimize the functions of both.

4. The cyberspace anti-mapping system according to claim 1, characterized in that: In the active anti-mapping strategy module, the strategy generation submodule is responsible for building an active anti-mapping strategy matrix; the active anti-mapping strategy matrix is ​​a strategy library containing multiple active anti-mapping strategies, including configuring network devices, adjusting network traffic, simulating false targets or disguising network responses; Assume that the active anti-mapping strategy matrix includes d strategies. For each strategy, its performance in preventing different mapping attacks is evaluated, and the adaptability vector of strategy i against different mapping attacks is obtained: And the cost description vector: Get the adaptability matrix of the entire active anti-mapping strategy matrix: R=[γ1,γ2,γ3,…,γ d ], And the cost description matrix: C=[cost1,cost2,cost3,…,cost d ]; The strategy selection module is based on the adaptability vector γ i , cost description vector cost i And the currently identified surveying and mapping traffic map, select the most appropriate strategy; the strategy selection logic formula is as follows: Among them, i * represents the final active anti-mapping strategy selected; ω represents the adaptability weight factor, which is used to adjust the importance of adaptability in strategy selection; γ i [map] indicates the adaptability of strategy i to the mapping traffic map; ε represents a small positive number used to avoid division by zero; λ represents the cost weight factor, which is used to adjust the importance of cost in strategy selection; represents the total cost of strategy i.

5. The cyberspace anti-mapping system according to claim 4, characterized in that: In the passive anti-mapping strategy module, the node analysis submodule is responsible for analyzing each node in the protected network and building an appropriate passive anti-mapping matrix based on its properties and functions. Assuming that the passive anti-mapping strategy matrix includes d strategies, for each strategy, its performance in preventing different mapping attacks is evaluated to obtain the adaptability vector of strategy i against different mapping attacks: And the cost description vector: Get the adaptability matrix of the entire active anti-mapping strategy matrix: R=[γ1,γ2,γ3,…,γ d ], And the cost description matrix: C=[cost1,cost2,cost3,…,cost d ]; The node configuration submodule configures the corresponding nodes according to the strategy provided by the node analysis submodule to achieve passive anti-mapping. Specifically, for the mapping description vector α=[a1,a2,a3,…,a n ]、Surveying change vector β=[b1,b2,b3,…,b n ] and the adaptability vector R and the cost description matrix C to obtain the final selected strategy. The strategy selection steps are as follows: (1) For each strategy i, calculate its comprehensive adaptability score to the current mapping attack environment. The formula is as follows: Among them, w j is the element b in the mapping change vector j The weight of is used to adjust the contribution of attack increase or decrease to the fitness score; (2) For each strategy i, calculate its comprehensive cost. The comprehensive cost is calculated by summing the elements of the cost description vector: (3) In order to balance adaptability and cost, a utility function U is defined, which takes adaptability and cost into consideration; Among them, ∈ is a small positive number used to prevent the denominator from being zero; then, choose U i The largest strategy i * As the optimal strategy: i * =arg max i U i , (5)。

Citation Information

Patent Citations

  • Network space map construction method, device and equipment

    CN112667765A

  • Automatic detection method for intranet attack surface

    CN114389848A