A universal scanner countermeasure method and system

By establishing a slow-responsive TCP session between the network security equipment and the counter device, the problems of automatic IP switching and policy adjustment of the intelligent scanner are solved, and substantial disability of the scanner is achieved and the effectiveness of network defense is improved.

CN119420583BActive Publication Date: 2025-05-09SHANDONG XINGWEI JIUZHOU SECURITY TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510019142.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-05-09
Estimated Expiration
2045-01-07

AI Technical Summary

Technical Problem

Existing network defense technologies are difficult to effectively deal with the automatic IP switching and policy adjustment of intelligent scanners, making it difficult for hacker attacks to be completely blocked.

Method used

Through a slow DoS technology, the sendTCP function executes exceptionally slowly, causing the hacker scanner to not work properly. The specific method includes establishing a TCP session between the network security device and the counter device, and the counter device responds slowly to the data to ensure that the scanner is in a substantial disability state but does not report an error or timeout.

Benefits of technology

The substantial disability of the scanner is achieved, and the hacker cannot perceive abnormalities in the scanning state, resulting in an increase in time cost, providing sufficient response time for defenders, and is suitable for multiple programming languages ​​and TCP protocols at the same time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119420583B_ABST
    Figure CN119420583B_ABST
Patent Text Reader

Abstract

The present invention discloses a universal scanner countermeasure method and system, the countermeasure method includes forming communication traffic between a client and a TCP of a server through a network security device bridged in a link; setting an independent countermeasure device, the countermeasure device and the network security device are network-reachable, a port is opened on the countermeasure device and waits for connection; the network security device detects attack behaviors in the traffic, and records the client as a unique identifier; the network security device sends an RST or FIN message to the client to disconnect or reset the TCP session. The present invention can put the scanner in a substantially disabled state, but the scanner itself cannot perceive the abnormality of the scanning state. When a hacker checks the status of the scanner, the scanner will still show that the operating state is normal, which will cause a misjudgment to the hacker, and the hacker will continue to wait for the scan to be completed, thereby increasing his time cost and providing sufficient response time for the defender.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a universal scanner countermeasure method. Background Art

[0002] With the development of computer network technology, network security technology is also constantly developing. If there are major vulnerabilities in the network, hackers will use the vulnerabilities to steal important information from the server or client, causing serious consequences. Therefore, the importance of network security is becoming increasingly prominent.

[0003] In order to find vulnerabilities faster, hackers will use a variety of scanners to detect targets, such as information collection, vulnerability scanning, fingerprint detection, directory blasting, etc. These scanners greatly damage the network environment, allowing hackers to carry out attacks at the lowest cost in order to achieve the purpose of illegal profit.

[0004] The common method of blocking IP in existing defense technology is to block the scanning source IP on the firewall or other security devices after discovering the scanning behavior. After blocking, the server will actively cut off the session and reject all subsequent new sessions. At this time, the scanner will immediately remind "access anomaly". At this time, hackers often switch IPs and change scanning strategies to continue scanning. Some scanners with higher intelligence can even automatically detect whether they are blocked, and then automatically switch to new IPs to continue scanning. Or some hackers give up scanning and use other means to attack. Summary of the invention

[0005] At present, most programming languages ​​generally come with function libraries for processing network data, and these functions are encapsulated layer by layer. Therefore, when sending a network request, there is a fixed function call chain: the function that operates the seventh layer of the network calls the function that operates the fourth layer. For example, if a program wants to send an HTTP request, it calls the HTTP sending function (such as sendHTTP), and sendHTTP will call the function that operates TCP (such as sendTCP). When sendTCP sends data and receives it, it feeds back the received data to sendHTTP, and sendHTTP is executed.

[0006] In view of this, the present invention uses a slow DoS technology to make the sendTCP function execute abnormally slowly, and then call the sendHTTP upstream of the chain to wait for a long time, but will not report an error or timeout, thereby causing the hacker scanner to fail to work.

[0007] In one aspect, the present invention provides a general scanner countermeasure method, comprising the following steps:

[0008] S1: The client forms a communication flow with the TCP of the server through the network security device bridged in the link; an independent countermeasure device is set, the countermeasure device and the network security device are network-reachable, and a port is opened on the countermeasure device and waits for connection;

[0009] S2: The network security device detects attack behaviors in the traffic and records the client as a unique identifier;

[0010] S3: The network security device sends an RST or FIN message to the client to disconnect or reset the TCP session;

[0011] S4: The network security device detects the newly established TCP session. If the unique identifier recorded in S2 is detected in the newly established session, the TCP uplink communication is forwarded to the countermeasure device, and the destination port is the port opened in S1; the downlink data is forwarded to the client in real time; the server will not receive any uplink data from the client, and the network security device acts as a reverse proxy to proxy the traffic of the hacker client to the countermeasure device;

[0012] S5: The countermeasure device establishes a TCP session with the network security device, accepts all uplink data forwarded by S4, and does not process the data content;

[0013] S6: The countermeasure device responds to any downlink data of 1 bit in length, and responds to another 1-bit data after an interval of S seconds, where S is 1-3;

[0014] S7: Keep the S6 looping without setting a loop end condition;

[0015] S8: The client sends RST or FIN to actively request to end the session, or does not respond to any confirmation message for a long time, and the countermeasure device ends the countermeasure process and releases memory resources and thread pool resources.

[0016] Furthermore, the network security device is an IPS or a WAF or a load balancer or a reverse proxy.

[0017] Furthermore, S5-S8 are executed in one thread.

[0018] Furthermore, the countermeasure device is a dynamic multi-threaded device; each time the client creates a new TCP session, the countermeasure device creates a new thread to execute the process of S5-S8 to maintain the session.

[0019] Furthermore, the countermeasure device responds to data slowly within a session.

[0020] Furthermore, the slow response data specifically includes sending only one byte each time, sending another byte after an interval of S seconds, and repeating wirelessly; S≥1.

[0021] Furthermore, the S seconds is 10 seconds.

[0022] In a second aspect, the present invention further provides a universal scanner countermeasure system, the system comprising:

[0023] Client, network security equipment, server, countermeasures;

[0024] The network security device is used to detect attack behaviors in traffic;

[0025] The countermeasure device is used to establish a TCP communication tunnel with the hacker client;

[0026] If the network security device detects attack behavior in the traffic, the traffic of the client is proxied to the countermeasure device;

[0027] If the network security device does not detect any attack behavior in the traffic, the traffic is released.

[0028] In a third aspect, the present invention further provides an electronic device, comprising a memory and a processor, wherein the memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement a general scanner countermeasure method as described above.

[0029] On the other hand, the present invention further provides a readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the steps of the general scanner countermeasure method as described above are implemented.

[0030] Beneficial effects of the present invention:

[0031] 1. The present invention can make the scanner in a state of substantial incapacity, but the scanner itself cannot sense the abnormality of the scanning state. When the hacker checks the scanner status, the scanner will still display "normal operation status". This will cause a misjudgment to the hacker, who will continue to wait for the scan to be completed, thereby increasing his time cost and providing defenders with sufficient response time.

[0032] 2. The present invention adopts a universal solution, which is effective for scanning tools developed in multiple programming languages ​​​​(Golang, Python, C++, etc.), and is also effective for multiple mainstream protocols based on TCP (such as HTTP, etc.). BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 The structural diagram of the present invention under normal circumstances;

[0034] Figure 2 The present invention discovers the framework diagram of attack behavior;

[0035] Figure 3 Schematic diagram of the communication tunnel between the countermeasure device and the hacker client in an embodiment of the present invention;

[0036] Figure 4 Schematic diagram of the response data of the countermeasure device in a session in an embodiment of the present invention;

[0037] Figure 5 A diagram showing the countermeasure effect of the present invention. DETAILED DESCRIPTION

[0038] In order to make the objects, advantages and features of the present invention more obvious, the present invention is further described in detail in the following specific embodiments.

[0039] The overall architecture is as follows Figure 1 As shown in the figure, in the first step, under normal circumstances, the TCP communication traffic between the client and the server passes through the network security device bridged in the link, which can be IPS, WAF, load balancing, reverse proxy, etc. The countermeasure device is an independent device that is network-accessible to the network security device. A port will be opened on the countermeasure device and wait for a connection. The network security device unpacks and detects the bidirectional traffic. If no problem is detected, the traffic is released.

[0040] like Figure 2 As shown, in the second step, the network security device detects the attack behavior in the traffic. The detection method is defined by the security device. When the attack behavior is found, the unique identifier of the client is recorded. The unique identifier can be the source IP, Cookie, UserID, etc., which can be selected according to different detection protocols and scenarios.

[0041] In the third step, the network security device sends a RST or FIN message to the client to disconnect or reset the TCP session, and proxies the client's traffic to the countermeasure device.

[0042] In the fourth step, the network security device will detect the newly established TCP session. If the unique identifier recorded in the second step is detected in the newly established session, the TCP uplink communication will be forwarded to the countermeasure device. The destination port is the port opened in the first step, and the downlink data will be forwarded to the client in real time. The server will no longer receive any uplink data from the client, thereby ensuring the security of the server. At this time, the network security device will act as a reverse proxy to proxy the traffic of the hacker client to the countermeasure device.

[0043] In the fifth step, the countermeasure device establishes a TCP session with the network security device. Because the security device only acts as a proxy at this time, it actually establishes a session with the hacker client and then accepts all the uplink data forwarded in the fourth step, but does not process the data content.

[0044] Step 6: The countermeasure device responds to any 1-bit downlink data, and responds to another 1-bit data after an interval of S seconds. S is generally 1-3. The smaller the S value, the shorter the scanner downtime, but the better the compatibility with the scanner.

[0045] Step 7: Repeat step 6 without setting a loop end condition. This maintains a long connection. The countermeasure device will not actively terminate the connection.

[0046] Step 8: After a period of time, the client will send RST or FIN to actively request to end the session, or will not respond to any confirmation message for a long time. It is considered that the client has stopped the scanning task or the client process has ended. Then the countermeasure device needs to end this countermeasure process and release memory resources and thread pool resources.

[0047] Inside the countermeasure system, the above steps 5 to 8 are executed in one thread. The countermeasure should be designed as dynamic multithreading. Every time a client creates a new TCP session, the countermeasure creates a new thread to execute the steps 5 to 8 to maintain the session.

[0048] At this point, from the client's side, the scanner displays a normal status, but is actually disabled.

[0049] The countermeasure described in the present invention should be connected after the detection module. After the scan is found, the countermeasure takes over the service port. After waiting for the scanner to establish a session again, it slowly sends any characters to the scanner. The countermeasure is designed to be multi-threaded, and the number of threads should always be equal to the concurrent connections of the scanner, so that the scanner thread pool can be exhausted and it can completely stop working.

[0050] Example 1

[0051] like Figure 1 As shown in the figure, under normal circumstances, the communication traffic between the client and the server passes through the intermediate network security device. The security device unpacks and detects the bidirectional traffic, and releases the traffic if no problem is detected.

[0052] like Figure 2 As shown, when the network security device finds that a client has attack behavior, it will proxy the client's traffic to the countermeasure device.

[0053] like Figure 3As shown, the countermeasure device establishes a TCP communication tunnel with the hacker client and receives all requests from the client, and the client is now waiting for a response.

[0054] like Figure 4 As shown in the figure, the countermeasure device responds to data slowly within a session by sending only one byte (such as character A) at a time, and then sending A again after an interval of S seconds, and repeating it indefinitely... At this point, the countermeasure effect on the hacker client is achieved. The client is constantly receiving data and cannot release thread resources, causing the client to become disabled.

[0055] Figure 5 It is a demonstration of the counter-effect. Figure 5 There are two lines of code written in Python, which simulates the scanner initiating an HTTP request. The timeout is set to 10 seconds in the code, but the request has lasted for 47 minutes and the scanner still has not completed the request, nor has it reported an error or timed out.

[0056] Example 2

[0057] An electronic device includes a memory and a processor, wherein the memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement the above-mentioned method of interfering with a network scanner.

[0058] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the electronic device described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0059] Example 3

[0060] A computer-readable storage medium stores computer instructions, which implement the steps of the method in Example 1 when executed by a processor.

[0061] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, devices, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0062] The present invention is described with reference to the flowcharts and / or block diagrams of the method, terminal device (system), and computer program product according to the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0063] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0064] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0065] The above embodiments describe the technical solutions of the present invention in detail. Obviously, the present invention is not limited to the described embodiments. Based on the embodiments of the present invention, people familiar with the technical field can also make various changes accordingly, but any changes that are equivalent or similar to the present invention belong to the scope of protection of the present invention.

[0066] The contents not described in detail in this specification belong to the prior art known to professional and technical personnel in this field.

Claims

1. A general scanner countermeasure method, characterized in that: The steps include: S1: The client forms a communication flow with the TCP of the server through the network security device bridged in the link; an independent counter device is set up, the counter device and the network security device are network-reachable, and a port is opened on the counter device and waits for a connection; S2: The network security device detects attack behaviors in the traffic and records the client as a unique identifier; S3: The network security device sends an RST or FIN message to the client to disconnect or reset the TCP session; S4: The network security device detects a newly established TCP session, and if the unique identifier is detected in the newly established session, forwards the TCP uplink communication to the countermeasure device, with the destination port being the open port; The downlink data is forwarded to the client in real time; The server will not receive any uplink data from the client, and the network security device acts as a reverse proxy to proxy the client's traffic to the countermeasure device; S5: The countermeasure device establishes a TCP session with the network security device, accepts all uplink data forwarded by the network security device, and does not process the data content; S6: The countermeasure device responds to any downlink data with a length of 1 bit, and then responds with another 1-bit data after an interval of n seconds, where n is 1-3; S7: Keep the S6 looping without setting a loop end condition; S8: The client sends RST or FIN to actively request to end the session, or does not respond to any confirmation message for a long time, and the countermeasure device ends the current countermeasure process and releases memory resources and thread pool resources; The countermeasure device responds to data slowly within a session; the slow response data includes sending only one byte each time, sending another byte after an interval of S seconds, and repeating wirelessly, S≥1.

2. A universal scanner countermeasure method as claimed in claim 1, characterized in that: The network security device is IPS or WAF or load balancing or reverse proxy.

3. A universal scanner countermeasure method as claimed in claim 2, characterized in that: S5-S8 are executed in one thread.

4. A universal scanner countermeasure method as claimed in claim 3, characterized in that: The countermeasure device is a dynamic multi-threaded device; each time the client creates a new TCP session, the countermeasure device creates a new thread to execute the process of S5-S8 to maintain the session.

5. A universal scanner countermeasure method as claimed in claim 4, characterized in that: The S seconds is 10 seconds.

6. A universal scanner countermeasure system, characterized in that: The system comprises: Client, network security equipment, server, countermeasures; The client forms a communication flow with the TCP of the server through the network security device bridged in the link; an independent counter device is set up, the counter device and the network security device are network-reachable, and a port is opened on the counter device and waits for connection; The network security device detects attack behaviors in traffic and records the client as a unique identifier; The network security device sends a RST or FIN message to the client to disconnect or reset the TCP session; The network security device detects a newly established TCP session. If the unique identifier is detected in the newly established session, the TCP uplink communication is forwarded to the countermeasure device, and the destination port is the open port; the downlink data is forwarded to the client in real time; the server will not receive any uplink data from the client, and the network security device acts as a reverse proxy to proxy the client's traffic to the countermeasure device; The countermeasure device establishes a TCP session with the network security device, accepts all uplink data forwarded by the network security device, and does not process the data content; The countermeasure device responds to any downlink data with a length of 1 bit, and responds to another 1-bit data after an interval of n seconds, where n is 1-3; and keeps looping without setting a loop end condition; The client sends RST or FIN to actively request to end the session, or does not respond to any confirmation message for a long time, and the countermeasure device ends the countermeasure process and releases memory resources and thread pool resources; The countermeasure device responds to data slowly within a session; the slow response data includes sending only one byte each time, sending another byte after an interval of S seconds, and repeating wirelessly, S≥1.

7. An electronic device, characterized in that: It comprises a memory and a processor, wherein the memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement a universal scanner countermeasure method as claimed in any one of claims 1 to 5.

8. A readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of a universal scanner countermeasure method as claimed in any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Network attack tracing method and device for honeypot trapping based on reverse proxy

    CN116781331A