An IP anti-location method and system based on false web landmarks
By setting up false web landmarks near key network devices to mislead IP positioning, the problem of excessive deviation of street-level positioning results in existing technologies is solved, the effect of street-level IP anti-positioning is achieved, and the security and privacy protection of network devices are enhanced.
Patent Information
- Application Number
- CN202411725757.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2024-06-03
- Filing Date
- 2024-11-28
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-11-28
AI Technical Summary
Existing IP anti-positioning methods are difficult to apply to street-level positioning, and the positioning results are easily judged as incorrect by attackers due to excessive deviation, which makes it impossible to effectively protect the precise street-level geographic location of critical network equipment.
By setting up false web landmarks near the protected target, determining the offset distance and nominal location range, constructing a camouflaged entity, and generating false web landmarks to mislead IP positioning, the street-level positioning error is increased, and the rationality of the positioning results is ensured.
Street-level IP anti-positioning is achieved, and the positioning error is increased to an appropriate range, avoiding attackers' incorrect judgment results and improving the security and privacy protection of network equipment.
Smart Images

Figure CN119544334B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network space surveying and mapping, and in particular to an IP anti-localization method and system based on false Web landmarks. Background Art
[0002] IP location technology uses the IP address of an internet-connected device to determine its precise geographic location. This technology is crucial for numerous location-based services, such as personalized advertising, local news push, network performance optimization, and cybercrime tracing. Based on the different location methods used, IP location technology can be broadly categorized into two or three types: database-based, data mining-based, and network measurement-based. Network measurement-based IP location technology, which can determine the street-level geographic location of network devices independently of the user, has garnered significant attention in recent years.
[0003] Currently, academics are primarily concerned with improving the accuracy of measurement-based IP location. However, a key issue has been overlooked: high-precision, user-independent IP location technology can be abused by cyber attackers. As measurement-based IP location technology, particularly network-based measurement-based IP location technology, continues to improve in accuracy, its ability to perform non-cooperative, fine-grained location analysis has made it a potential tool for attackers to steal the precise geographic locations of network devices and users, target them with phishing campaigns, and ultimately spread viruses, significantly impacting network security and user privacy.
[0004] Technologies that counteract network-based IP location detection are known as IP anti-location techniques. These techniques can increase the error in network-based IP location detection, or even cause it to fail. Existing IP anti-location methods fall into two main categories: one is to hide the true IP address, such as through VPNs; the other is to mislead location detection technology by modifying the data response delay of the protected target. These methods can effectively counter city- or country-level IP location detection based on network measurements, significantly deviating from the country, province, or city-level location obtained by cyber attackers.
[0005] However, the above method is difficult to apply to some other scenarios. First, many businesses and even individuals need to use real IP addresses to communicate and provide services. Using VPNs can significantly impact normal work efficiency, such as in large industrial enterprises. Second, with the second method mentioned above, due to advances in IP location databases, users can often directly query the database to obtain coarse-grained geographic location information (such as national and provincial location information) for some important network devices (such as official government website servers and large enterprise network servers). The accuracy of this information exceeds 90% at the national level and 78% at the provincial level. Therefore, attackers can determine the approximate national and provincial location of the protected target with high confidence. Existing IP anti-location methods, however, take into account the protection of national-level locations and offset the attacker's location results by thousands or even tens of thousands of kilometers. Furthermore, the IP addresses of some important network facilities may be included in IP location databases, making their national or even provincial locations accessible through database queries. In this case, location results generated by existing anti-location methods that differ significantly from database query results can easily be interpreted as inaccurate by attackers, potentially attracting additional attention.
[0006] Furthermore, existing IP anti-location methods focus on protecting national-level locations, but not street-level IP location methods. However, street-level IP location, which is becoming increasingly accurate, is currently a key development direction for IP location. As database accuracy improves, many companies are prioritizing the precise street-level location of their critical network equipment, rather than protecting national or even city-level locations. Summary of the Invention
[0007] In order to at least partially solve the problem that the positioning results caused by anti-positioning methods are too offset and easily judged as incorrect by attackers, and the existing IP anti-positioning methods consider the protection of national-level locations but do not consider the existing street-level IP positioning methods, the present invention provides an IP anti-positioning method and system based on false Web landmarks, by determining the offset distance of the false Web landmark and the nominal position range of the false Web landmark, and determining a disguised entity within the nominal position range of the false Web landmark, and then generating a false Web landmark with landmark characteristics but a false nominal position, a low delay relative to the protection target, and a high credibility based on the disguised entity, thereby realizing street-level IP anti-positioning, ensuring the rationality of the positioning results, and avoiding excessive offset of the positioning results.
[0008] In order to achieve the above object, the technical solution of the present invention is:
[0009] The first aspect of the present invention provides an IP anti-localization method based on false Web landmarks, comprising the following steps:
[0010] Step 1: Obtain the network topology of the area where the protected target is located to facilitate the establishment of false web landmarks;
[0011] Step 2: Based on the network topology of the area where the protected target is located, set up at least one web server under the router directly connected to the protected target to set up a false web landmark;
[0012] Step 3: Determine an offset distance based on the size of the urban area where the protected target is located. The offset distance refers to the positional deviation between the nominal location of the fake web landmark to be constructed and the actual geographic location of the web server where it is located, which can easily mislead IP positioning and increase the error of IP positioning.
[0013] Step 4: Determine the nominal location range of the false Web landmark based on the offset distance, and determine at least one camouflaged entity required for the false Web landmark within the nominal location range of the false Web landmark, so as to obtain a suitable camouflaged entity;
[0014] Step 5: Construct a false Web landmark based on the preset website template and the information of the disguised entity, and deploy the false Web landmark on the Web server; wherein, the information of one disguised entity corresponds to one false Web landmark, and one false Web landmark corresponds to one Web server, which is convenient for resisting IP positioning.
[0015] Furthermore, the offset distance is half of the radius of the city where the protected target is located, so as to generate a sufficient positioning error.
[0016] Furthermore, determining the nominal location range of the false Web landmark based on the offset distance specifically includes:
[0017] Taking the protected target position as the center and the preset distance ± the error threshold as the radius, a circle is determined; wherein the preset distance is determined according to the offset distance;
[0018] The network landmarks located in the ring are constructed into landmark subsets, and the network landmarks in the landmark subset are clustered according to distance, and the coverage of all clusters is calculated;
[0019] The nominal location range of the false Web landmark is obtained according to the coverage of the ring and all clusters, which makes it easier to find the appropriate entity.
[0020] Furthermore, clustering the network landmarks in the landmark subset according to distance specifically includes:
[0021] If the distance between two network landmarks is within the set distance, they are determined to belong to the same cluster;
[0022] If the first network landmark is in the same cluster as the second network landmark, and the first network landmark is in the same cluster as the third network landmark, then the second network landmark is in the same cluster as the third network landmark;
[0023] A single network landmark does not constitute a cluster.
[0024] Furthermore, the nominal location range of the false Web landmark is obtained based on the coverage of the ring and all clusters, which is expressed by the following formula:
[0025]
[0026] Q x =∪S(L i ), L i ∈P x
[0027] Among them, A is the nominal location range of the false Web landmark, C is a circle with the protected target location as the center and the preset distance ± error threshold as the radius, ∪ is the union, Q x is the range covered by the xth cluster, S(L i ) is the range covered by the circle with the i-th network landmark as the center and the preset distance as the radius, ∩ is the intersection, L i is the i-th network landmark, P x is the xth cluster.
[0028] Furthermore, the step of determining at least one disguised entity required for the false Web landmark within the nominal location range of the false Web landmark specifically includes:
[0029] Determine the area with the most entities within the nominal location range of the fake Web landmark;
[0030] Count all entities in the region that do not have an official website and the types of all entities in the region, and sort them in descending order based on the number of types of all entities;
[0031] Among all entities that do not exist on the official website, a preset number of entities that match the top-ranked types are found and used as disguised entities of the false web landmark; one entity is found for each type; if there is no matching entity for a type, the next type is selected in the sorted order to determine the appropriate entity.
[0032] The second aspect of the present invention provides an IP anti-location system based on false Web landmarks, comprising:
[0033] The collection module is used to obtain the network topology of the area where the protected target is located, so as to facilitate the setting of false web landmarks;
[0034] A server setting module is used to set at least one web server under a router directly connected to the protected target according to the network topology of the area where the protected target is located, so as to set a false web landmark;
[0035] An offset distance module is used to determine an offset distance based on the size of the urban area where the protected target is located. The offset distance refers to the positional deviation between the nominal location of the fake web landmark to be constructed and the actual geographical location of the web server where it is located, which can easily mislead IP positioning and increase the error of IP positioning;
[0036] A false web landmark nominal location range module is used to determine the false web landmark nominal location range based on the offset distance, and to determine at least one disguised entity required for the false web landmark within the false web landmark nominal location range, so as to obtain a suitable disguised entity;
[0037] The false web landmark webpage module is used to construct a false web landmark based on a preset website template and the information of the disguised entity, and deploy the false web landmark on the web server; wherein, the information of one disguised entity corresponds to one false web landmark, and one false web landmark corresponds to one web server, which is convenient for resisting IP positioning.
[0038] The third aspect of the present invention proposes an electronic device, comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements an IP anti-location method based on false Web landmarks as described in the first aspect above.
[0039] The fourth aspect of the present invention proposes a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute an IP anti-location method based on false Web landmarks as described in the first aspect above.
[0040] Beneficial effects of the present invention:
[0041] (1) The present invention obtains the nominal location range of a fake Web landmark by selecting an appropriate offset distance and constructing a fake Web landmark by selecting an appropriate entity within the nominal location range. This achieves street-level IP anti-localization. Furthermore, because the positioning error is street-level and within an appropriate range, it prevents attackers from judging the positioning result as incorrect, thereby avoiding attracting additional attention from the attacker.
[0042] (2) This invention deploys false web landmarks, causing errors in the key positioning data of illegal locators, achieving a good anti-positioning effect. In an experiment targeting 156 street-level IP positioning methods, when the false web landmarks were offset by 20 km, the maximum target positioning error was increased from 5.951 km to 31.4 km, and the median error was increased from 3.779 km to 31.8 km. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 A schematic diagram of an IP anti-localization method based on false Web landmarks provided in an embodiment of the present invention.
[0044] Figure 2 A flowchart of an IP anti-location method based on false Web landmarks provided by an embodiment of the present invention.
[0045] Figure 3 This is a flowchart of generating a false Web landmark according to an embodiment of the present invention.
[0046] Figure 4 A schematic diagram of normal positioning error provided by an embodiment of the present invention.
[0047] Figure 5 A schematic diagram of positioning errors after generating false Web landmarks according to an embodiment of the present invention.
[0048] Figure 6 A schematic diagram of the selection probability and positioning error after generating false Web landmarks provided by an embodiment of the present invention.
[0049] Figure 7 An architectural diagram of an IP anti-location system based on false Web landmarks provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0050] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly described below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0051] Example 1
[0052] This embodiment explains some professional terms in the present invention.
[0053] Network landmarks (abbreviated as "landmarks") are the foundation and key elements of IP positioning technology based on network measurement. The web page-based landmark acquisition method is one of the current mainstream landmark acquisition methods. The web page-based landmark acquisition method mainly uses Internet crawlers and other means to extract geographic location, postal code, domain name, IP and other information from web pages, associate IP addresses, web domain names with geographic locations, and thus build a mapping relationship from IP addresses to geographic locations to achieve landmark acquisition. In order to ensure the accuracy of the mapping relationship, this method usually adopts reliability assessment methods such as path measurement and reverse domain name query to eliminate inaccurate or erroneous mapping entries, and finally form an accurate mapping relationship between IP addresses and geographic locations.
[0054] False Web landmarks refer to Internet websites and their IP addresses that have been tampered with or forged and are easily accessible through mainstream landmark acquisition methods, with false geographic locations marked on their homepages. The anti-geolocation method for network equipment based on false Web landmarks aims to concentrate false Web landmarks (hereinafter referred to as "false Web landmarks") near important protected targets, so that when illegal positioning parties use landmarks to locate protected targets, they will obtain incorrect landmark information and generate large positioning errors. Its basic principles are as follows: Figure 1 shown.
[0055] Because high-precision landmark-based IP location methods often estimate the target device's location using the geographic location of landmark nodes with low latency to the target device, when fake web landmarks are deployed with low latency to the target, the location indicated by the fake web landmarks becomes key information that misleads unauthorized location operators. As the core of anti-location methods, fake web landmarks should be highly credible, easily accessible through conventional web landmark mining methods, have low latency relative to the protected target, and be highly controllable.
[0056] A web landmark is a website with a precise nominal location, often attributed to a specific entity. Therefore, the process of generating fake web landmarks involves selecting the type of entity to claim ownership of and generating basic website information. Furthermore, these fake web landmarks should be highly credible and pass standard landmark verification methods, ensuring that unauthorized locaters are likely to believe the fake web landmark is an online website belonging to a specific entity and use it as a landmark for location detection, thus achieving anti-location protection.
[0057] Landmarks acquired through web pages are often referred to as web landmarks, while fake web landmarks are referred to as false landmarks. Different from web landmarks, false web landmarks are web pages deployed by device owners to protect their devices from being arbitrarily located by illegal locators. The purpose of a false web landmark is to disguise itself as a normal web page, waiting for the illegally located person to obtain it as a network landmark through web page-based landmark acquisition methods to participate in positioning, and then use its own characteristics to interfere with positioning. To successfully interfere with illegal positioning, false web landmarks usually have the following characteristics:
[0058] False web landmarks that meet the characteristics of web landmarks should meet the basic characteristics of web landmarks, including having a public IP, an accessible web page, and the page containing entity location information (such as clearly marked in the form of "company address", etc.).
[0059] The nominal location information is wrong. In order to mislead illegal locators, the entity location information marked by the false Web landmark should have a certain gap with the actual geographical location of its server.
[0060] Easy to obtain. In order to ensure that fake Web landmarks can participate in the positioning process with a greater probability and interfere with illegal positioning behavior, they should be easier to obtain through conventional Web landmark mining methods (such as Structon algorithm, etc.), that is, to cater to conventional Web landmark mining methods and meet their requirements for target Web pages.
[0061] High credibility: after being obtained by illegal locators through landmark mining, fake Web landmarks should be able to pass conventional landmark verification methods, so that illegal locators can judge them as credible landmarks and participate in and interfere with IP positioning.
[0062] Good controllability: As a web page deployed on a specific server, the online time, quantity, response characteristics, etc. of the fake web landmark should be able to be dynamically adjusted according to actual needs and network environment.
[0063] In summary, as a web page that meets the characteristics of a web landmark, a fake web landmark is easy to obtain through web landmark mining methods and has high credibility. At the same time, it is well controllable and convenient to manage.
[0064] Example 2
[0065] Based on the above embodiment, the embodiment of the present invention provides an IP anti-location method based on false Web landmarks, such as Figure 2 As shown, the following steps are included:
[0066] S101: Obtain the network topology of the area where the protected target is located.
[0067] Specifically, network measurements are performed in the area where the protected target is located. Using detection sources deployed in the city where the protected target is located, measurements are taken of the protected target, surrounding landmarks, and routes to obtain the network topology of the area where the protected target is located.
[0068] S102: According to the network topology of the area where the protected target is located, at least one Web server is set under a router directly connected to the protected target.
[0069] Specifically, based on the network topology of the protected target's area, at least one server is deployed under the protected target's directly connected router to deploy the false web landmarks. The number of web servers depends on the number of false web landmarks to be deployed, with each false web landmark corresponding to one web server.
[0070] S103: used to determine the offset distance according to the size of the urban area where the protected target is located; the offset distance refers to the position deviation between the nominal position of the false Web landmark to be constructed and the real geographical location of the Web server where it is located.
[0071] Specifically, the nominal location of a fake web landmark is one of the decisive factors that causes network attackers to make large errors in IP positioning. In order to produce sufficient positioning error, the nominal location of the fake web landmark should have a certain positional deviation from the real geographical location of the web server. The distance between the two is called the offset distance. If the offset distance is too small, it is difficult to produce sufficient positioning error; if the offset distance is too large, the network attacker may notice that the positioning result is incorrect. To avoid the above two situations, the offset distance between the nominal location of the fake web landmark and the real geographical location of the protected target is generally set to approximately 1 / 2 city radius, depending on the city where the protected target is located.
[0072] S104: Determine a nominal position range of the false Web landmark according to the offset distance, and determine at least one disguised entity required for the false Web landmark within the nominal position range of the false Web landmark.
[0073] Specifically, after determining the offset distance R of the false Web landmark, a circle C is determined with the protected target location as the center O and a radius of R ± 2.5 km. The network landmarks located in the circle C are constructed as the landmark subset L sub , and L aub The network landmarks within are clustered by distance, and the specific rules are as follows:
[0074] 1. Two network landmarks are considered to belong to the same cluster if they are within 1 km of each other.
[0075] 2. If the network landmark L k With network landmark L j Same cluster, and network landmark Lk With network landmark L i In the same cluster, the network landmark L j With network landmark L i Same cluster.
[0076] 3. A single network landmark does not constitute a cluster.
[0077] After obtaining all the network landmark clusters in the ring C, calculate the coverage of all clusters. x , its coverage is expressed by the following formula:
[0078] Q x =∪S(L i ), L i ∈P x .
[0079] Among them, L i is the i-th network landmark, ∪ is the union, Q x is the range covered by the xth cluster, S(L i ) is the coverage of a circle with a radius of 1 km and the i-th network landmark as the center, P x is the xth cluster.
[0080] Then, the nominal location range of the false Web landmark can be obtained, which is expressed as follows:
[0081]
[0082] Among them, A is the nominal location range of the false Web landmark, C is a circle with the protected target location as the center and the offset distance ±2.5km as the radius, and ∩ is the intersection.
[0083] In the nominal location range A of the fake Web landmarks, the network landmarks are relatively sparse, which makes it difficult to effectively compare the detection data of the fake Web landmarks, thus increasing the credibility of the fake Web landmarks. Outside A, the network landmarks exist in clusters and are relatively densely distributed, that is, they have similar corresponding features and similar detection data. If the location of the fake Web landmark is nominally located at the location Q of a cluster, x Since the measurement data characteristics of the fake Web landmarks are too different from those of the network landmarks in the cluster, it is very easy for network attackers to identify the data as wrong or abnormal, and then eliminate the detection data of the fake Web landmarks, making the anti-localization fail.
[0084] Identify the area with the most entities within the nominal location of the fake web landmark. Count all entities within the area that do not have an official website, as well as the types of all entities within the area, and sort all entities in descending order based on the number of types. Among all entities that do not have an official website, find a preset number of entities that match the top-ranked types and use them as disguised entities for the fake web landmark. One entity is found for each type. If no entity matches a type, move on to the next type in the sorted order.
[0085] S105: constructing a false Web landmark based on a preset website template and the information of the disguised entity, and deploying the false Web landmark on the Web server; wherein, one piece of information of a disguised entity corresponds to one false Web landmark, and one false Web landmark corresponds to one Web server.
[0086] Specifically, a website template of the same type as the disguised entity is crawled, and a false web landmark is created based on the disguised entity and the website template, and is deployed on a set web server.
[0087] The present invention first sets up at least one web server under a router directly connected to the protected target based on the network topology of the area where the protected target is located, and determines the offset distance based on the size of the urban area where the protected target is located. Then, the nominal location range of the false web landmark is determined based on the offset distance, and at least one camouflage entity required for the false web landmark is determined within the nominal location range of the false web landmark. Finally, a false web landmark is constructed based on the camouflage entity and a preset website template, and the false web landmark is deployed on the web server. The present invention successfully increases the error of the street-level IP positioning method. At the same time, because the error is at the street level, it can prevent attackers from making incorrect judgments through database queries.
[0088] Example 3
[0089] Based on the above embodiments, the present invention proposes a specific process for determining at least one disguised entity required for a false Web landmark based on its nominal location range and constructing a false Web landmark based on a preset website template and information about the disguised entity:
[0090] Specifically, to make the fake Web landmark have higher credibility, the fake Web landmark is disguised as a Web page of an entity within the nominal location range A of the fake Web landmark. By crawling local enterprise statistical information and querying online maps and local government department public registration enterprise lists, etc., the distribution of entities within the nominal location range A of the fake Web landmark is counted, and the area with the most entity distribution in the nominal location range A of the fake Web landmark is determined (such as a certain business street, a certain industrial zone, etc.). Then, the crawled entity information is screened, and the entity information without an official Web page in the area is collected, and the entity without an official Web page is selected as a candidate disguising entity of the fake Web landmark.
[0091] For example, the crawled entity information shows that the entity quantity of a street s within the nominal location range A of the fake Web landmark is the most, and the information shows that n entities do not have an official website, so the detailed information (such as name, address, zip code, telephone, etc.) of the above n entities is collected, and the above n entities are selected as candidate disguising entities of the fake Web landmark.
[0092] The number of different types of entities in the street s is counted, and the number of entities is sorted in descending order according to the type. Among the n candidate disguising entities, three entities that meet the top three (such as no extension) and their corresponding information are found, and the three entities are selected as disguising entities. Then, the same type of website is crawled as a fake Web landmark website building template, so that the fake Web landmark website is more consistent with the actual related industry website.
[0093] For example, the entity type quantity ranking in the street s is school, construction company, hardware company, etc., and one entity of each of the above three types of entities and its corresponding information is found among the n candidate disguising entities. If there is no entity of a certain type, find an entity of the next ranked type and its corresponding information. Then, the same type of website is crawled as a fake Web landmark website building template.
[0094] According to the crawled Web page template and the information of the corresponding disguising entity, a fake Web landmark Web page is made. The information of the disguising entity is slightly changed, such as changing the entity name from A City X Primary School to A City Y Middle School. Then, the corresponding content in the template Web page is replaced with the information of the disguising entity after the slight change, and a fake Web landmark Web page is obtained. After obtaining the generated fake Web landmark, it is deployed on the deployed Web server.
[0095] So far, three false Web landmarks with close nominal positions (all located in the street s), similar measurement data (directly connected to the same router), and real physical objects and professional website pages are obtained. To further improve the anti-positioning effect, more false Web landmarks can be deployed, corresponding to more Web servers. The above false Web landmark generation process is shown in Figure 3 .
[0096] Embodiment 4
[0097] On the basis of the above embodiments, the application proposes a verification analysis method of an IP anti-positioning method based on false Web landmarks.
[0098] In order to verify the anti-positioning effect of the application in a real network environment, part of the landmarks in city G are selected as protection targets, multiple network measurements are performed on the target and its surrounding landmarks by using multiple probe sources, probe data is obtained, and the classic high-precision positioning algorithm SLG is used to position the protection target. The positioning error changes before and after anti-positioning are compared.
[0099] First, 156 landmarks in city G are positioned as targets, and the positioning results are shown in Figure 4 , the average error is 5.951 km, and the median is 3.779 km. Through the smaller median, it can be seen that a considerable number of network devices can be accurately positioned, although they do not publish their geographic location and do not use remote positioning technology (such as GPS, Beidou system, etc.), they can still be exposed to street-level location by illegal locators, exposing geographic location privacy.
[0100] Then, false Web landmarks are generated by the application, and the false Web landmarks are deployed to the router directly connected to the target, and the offset distance is set to 20 km. By positioning the 156 targets one by one and calculating the average error, median and maximum error of each positioning round, the results are obtained by repeating 6 times, as shown in Figure 5 .
[0101] In the 6 experiments, the false Web landmarks are deployed on different servers, twice on the server close to the target directly connected router (corresponding to the first and second experiments), twice on the server far away from the target directly connected router (corresponding to the third and fourth experiments), and on the same server as the target (corresponding to the fifth and sixth experiments).
[0102] Experimental results show that when false web landmarks are placed on servers that are far away from the target's direct route, the mean and median of the positioning error only increase slightly, and the maximum error even decreases. However, when false web landmarks are placed on servers that are close to the target's direct route, the anti-positioning effect is more significant, with a significant improvement in the mean, median, and maximum. When the false web landmark and the target are placed on the same server, the anti-positioning effect is intermediate. Analysis shows that the IP positioning algorithm based on high-precision landmarks mainly uses landmarks with a lower relative delay to the target for positioning. Therefore, when choosing to place false web landmarks on different servers, it actually changes the relative delay between the false web landmark and the target. When the relative delay between the false web landmark and the target is too large, the positioning algorithm will use other landmarks instead of false web landmarks to infer the target's location, causing anti-positioning to fail.
[0103] In order to verify the conclusion, the selection probability p of the false Web landmark corresponding to the six experiments is calculated, which is referred to as the selection probability, as follows: Figure 6 The selection probability p is defined as the percentage of targets whose locations are estimated using the nominal locations of false web landmarks as primary positioning data. For the SLG algorithm, the selection probability p can also be equivalently defined as the percentage of targets whose locations are estimated using the nominal locations of false web landmarks. The selection probability p is calculated as shown in Table 1:
[0104] Table 1. The selection probability and average positioning error of false Web landmarks corresponding to the 6 experiments
[0105]
[0106] By comparing the selection probability p with the positioning results of the corresponding round, it can be found that when the false web landmarks have the same offset distance, the anti-localization effect is significantly more significant in the experimental rounds with a larger selection probability p, and the size of the selection probability p is significantly positively correlated with the anti-localization effect. Because in the first two rounds of experiments, the false web landmarks were placed on servers far away from the direct route to the target, the relative delay between the false web landmarks and the target increased, thereby reducing the selection probability p, resulting in poor anti-localization effect. In the third and fourth experiments, the opposite was true. Due to the higher selection probability p, the anti-localization effect was significantly improved. In the final two experiments, because the false web landmarks and the target were on the same server, the relative delay between them was in the middle position compared to the first two cases.
[0107] In summary, the present invention lays out false Web landmarks to cause errors in the key positioning data of illegal locaters, thereby achieving good anti-positioning effect.
[0108] Preferably, in order to achieve better anti-positioning effect, the false Web landmark can be placed on a server that is closer to the protected target through a direct route, so that the relative delay between the false Web landmark and the protected target is smaller, thereby achieving a good anti-positioning effect.
[0109] Example 5
[0110] Based on the above embodiment, the present invention proposes an IP anti-location system based on false Web landmarks corresponding to the above method. Figure 7 Shown, including:
[0111] A collection module, used to obtain the network topology of the area where the protected target is located;
[0112] A server setting module is used to set at least one web server under a router directly connected to the protected target according to the network topology of the area where the protected target is located;
[0113] An offset distance module is used to determine an offset distance based on the size of the urban area where the protected target is located; the offset distance refers to the positional deviation between the nominal location of the fake web landmark to be constructed and the actual geographical location of the web server where it is located;
[0114] A nominal location range module for a false Web landmark, configured to determine a nominal location range of the false Web landmark based on the offset distance, and to determine at least one disguised entity required for the false Web landmark within the nominal location range of the false Web landmark;
[0115] The false Web landmark webpage module is used to construct a false Web landmark based on a preset website template and information of a disguised entity, and deploy the false Web landmark on the Web server; wherein, information of one disguised entity corresponds to one false Web landmark, and one false Web landmark corresponds to one Web server.
[0116] It should be noted that the IP anti-positioning system based on false Web landmarks provided in an embodiment of the present invention is intended to implement the above-mentioned IP anti-positioning method based on false Web landmarks. Its specific functions can be referred to the above-mentioned method embodiments and will not be repeated here.
[0117] Example 6
[0118] Based on the above embodiments, the present invention proposes an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements an IP anti-location method based on false Web landmarks as in the above embodiments.
[0119] The application provides a computer readable storage medium, the storage medium comprising a stored computer program, wherein the computer program controls a device where the storage medium is located to execute an IP anti-positioning method based on a false Web landmark when the computer program is running.
[0120] In conclusion, the application obtains the nominal position range of the false Web landmark by selecting a proper offset distance, and constructs the false Web landmark by selecting a proper entity in the nominal position range of the false Web landmark. The street-level IP anti-positioning is realized, and since the positioning error is street-level and the positioning error is in a proper range, the attacker can be prevented from judging that the positioning result is wrong, and further prevented from causing additional attention of the attacker. The application can make the key positioning data of the illegal positioner wrong by deploying the false Web landmark, and achieve good anti-positioning effect. The street-level IP positioning method is resisted, and in an experiment with 156 landmarks as targets, the maximum positioning error mean of the target is increased from 5.951 km to 31.4 km and the error median is increased from 3.779 km to 31.8 km when the position of the false Web landmark is offset by 20 km.
[0121] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the application, but not to limit it; although the application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the application.
Claims
1. A method for IP anti-location based on false Web landmarks, characterized in that: The following steps are involved: Step 1: Obtain the network topology of the area where the protected target is located; Step 2: Based on the network topology of the protected target's area, set up at least one web server under the router directly connected to the protected target; Step 3: Determine an offset distance based on the size of the urban area where the protected target is located; the offset distance refers to the positional deviation between the nominal location of the fake web landmark to be constructed and the actual geographical location of the web server where it is located; Step 4: Determine the nominal location range of the false Web landmark based on the offset distance, and determine at least one disguised entity required for the false Web landmark within the nominal location range of the false Web landmark; Step 5: constructing a false web landmark based on the preset website template and the information of the disguised entity, and deploying the false web landmark on the web server; wherein one piece of information of the disguised entity corresponds to one false web landmark, and one false web landmark corresponds to one web server; Determining the nominal location range of the false Web landmark based on the offset distance specifically includes: Taking the protected target position as the center and the preset distance ± the error threshold as the radius, a circle is determined; wherein the preset distance is determined according to the offset distance; The network landmarks located in the ring are constructed into landmark subsets, and the network landmarks in the landmark subset are clustered according to distance, and the coverage of all clusters is calculated; The nominal location range of the false Web landmarks is obtained based on the coverage of the ring and all clusters.
2. The method for anti-locating IP addresses based on false Web landmarks according to claim 1, wherein: The offset distance is half the radius of the city where the protected target is located.
3. The method for anti-locating IP addresses based on false Web landmarks according to claim 1, wherein: Clustering the network landmarks in the landmark subset according to distance specifically includes: If the distance between two network landmarks is within the set distance, they are determined to belong to the same cluster; If the first network landmark is in the same cluster as the second network landmark, and the first network landmark is in the same cluster as the third network landmark, then the second network landmark is in the same cluster as the third network landmark; A single network landmark does not constitute a cluster.
4. The method for anti-locating IP addresses based on false Web landmarks according to claim 1, wherein: The nominal location range of the false Web landmark is obtained based on the coverage of the ring and all clusters, which is expressed by the following formula: Q x =∪S(L i ),L i ∈P x Among them, A is the nominal location range of the false Web landmark, C is a circle with the protected target location as the center and the preset distance ± error threshold as the radius, ∪ is the union, Q x is the range covered by the xth cluster, S(L i ) is the range covered by the circle with the i-th network landmark as the center and the preset distance as the radius, ∩ is the intersection, L i is the i-th network landmark, P x is the xth cluster.
5. The method for anti-locating IP addresses based on false Web landmarks according to claim 1, wherein: The step of determining at least one disguised entity required for the false Web landmark within the nominal location range of the false Web landmark specifically includes: Determine the area with the most entities within the nominal location range of the fake Web landmark; Count all entities in the region that do not have an official website and the types of all entities in the region, and sort them in descending order based on the number of types of all entities; Among all entities that do not exist on the official website, a preset number of entities that match the top-ranked types are found and used as disguised entities of the false web landmarks; one entity is found for each type; if there is no matching entity for a type, the next type is selected in the sorted order.
6. An IP anti-location system based on false Web landmarks, characterized in that: include: A collection module, used to obtain the network topology of the area where the protected target is located; A server setting module is used to set at least one web server under a router directly connected to the protected target according to the network topology of the area where the protected target is located; An offset distance module is used to determine an offset distance based on the size of the urban area where the protected target is located; the offset distance refers to the positional deviation between the nominal location of the fake web landmark to be constructed and the actual geographical location of the web server where it is located; A nominal location range module for a false Web landmark, configured to determine a nominal location range of the false Web landmark based on the offset distance, and to determine at least one disguised entity required for the false Web landmark within the nominal location range of the false Web landmark; A fake web landmark webpage module is used to construct a fake web landmark based on a preset website template and information about a disguised entity, and deploy the fake web landmark on the web server; wherein one fake entity's information corresponds to one fake web landmark, and one fake web landmark corresponds to one web server; Determining the nominal location range of the false Web landmark based on the offset distance specifically includes: Taking the protected target position as the center and the preset distance ± the error threshold as the radius, a circle is determined; wherein the preset distance is determined according to the offset distance; The network landmarks located in the ring are constructed into landmark subsets, and the network landmarks in the landmark subset are clustered according to distance, and the coverage of all clusters is calculated; The nominal location range of the false Web landmarks is obtained based on the coverage of the ring and all clusters.
7. An electronic device, characterized in that: The invention comprises a processor, a memory and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, an IP anti-location method based on false Web landmarks as described in any one of claims 1 to 5 is implemented.
8. A computer-readable storage medium, characterized in that The storage medium includes a stored computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute an IP anti-location method based on false Web landmarks as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Network entity landmark evaluation method and device with error upper limit
CN110119437A
Street-level landmark acquisition method based on service identification and domain name association
CN111026829A