Network space anti-mapping method and device, electronic equipment and computer storage medium
By collecting and analyzing messages in cyberspace, judging and combating target detection messages, and using fingerprint obfuscation technology to effectively deal with illegal surveying and mapping, the problem of limited protection capabilities in the existing technology is solved.
Patent Information
- Application Number
- CN202510072926.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-16
- Publication Date
- 2025-05-06
AI Technical Summary
The existing network surveying and mapping solutions have limited protection capabilities and are difficult to effectively deal with complex and changeable illegal surveying and mapping behaviors.
By collecting messages from the target network space, it is determined whether they are target detection messages. If they are target detection messages, a fingerprint obfuscation message will be generated based on the fingerprint characteristics of the message, and a fingerprint obfuscation message will be sent to combat target detection.
It has achieved effective response to complex and changeable illegal surveying and mapping behaviors in the target cyberspace, and made it difficult for attackers to obtain real host fingerprint information through fingerprint obfuscation technology.
Smart Images

Figure CN119945765A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of cyberspace anti-mapping, and in particular to a cyberspace anti-mapping method, device, electronic equipment and computer storage medium. Background Art
[0002] With the continuous development of technology, new intelligent mapping methods make it easy for attackers to detect and obtain information such as network ports, devices, and applications, which brings serious security risks. The network anti-mapping solutions used in related technologies have limited protection capabilities, and a more effective cyberspace anti-mapping method is needed to deal with complex and changeable illegal mapping behaviors. Summary of the invention
[0003] The embodiments of the present application provide a cyberspace anti-mapping method, device, electronic device and computer storage medium, which can effectively deal with complex and changeable illegal mapping behaviors.
[0004] In a first aspect, an embodiment of the present application provides a cyberspace anti-mapping method, comprising:
[0005] Collect messages passing through the target network space;
[0006] Determine whether the message is a target detection message for a host in the target network space;
[0007] If the message is a target detection message, a fingerprint obfuscated message of the response message is generated based on the fingerprint characteristics of the message;
[0008] Send fingerprint obfuscated messages to counter the mapping of hosts in the target network space by target detection messages.
[0009] In a possible implementation, determining whether the message is a target detection message for a host in a target network space includes:
[0010] Determine whether the source address of the message belongs to the target list database;
[0011] If the source address of the message does not belong to the target list database, it is determined whether the message is a target detection message based on the preset protocol fingerprint feature library.
[0012] In a possible implementation, the target list database includes a blacklist database and a whitelist database;
[0013] After determining whether the source address of the message belongs to the target list database, the method further includes:
[0014] If the source address of the message belongs to the blacklist database, the message is determined to be a target detection message;
[0015] If the source address of the message belongs to the whitelist database, it is determined that the message is not a target detection message.
[0016] In a possible implementation, if the source address of the message does not belong to the target list database, then based on a preset protocol fingerprint feature library, determining whether the message is a target detection message includes:
[0017] If the source address of the message does not belong to the target list database, the message is subjected to deep packet inspection to extract the fingerprint features of the message;
[0018] Match the fingerprint features of the message with the fingerprint features pre-stored in the protocol fingerprint feature library to obtain a matching result;
[0019] Based on the matching result, determine whether the message is a target detection message.
[0020] In a possible implementation, after determining whether the message is a target detection message based on the matching result, the method further includes:
[0021] If the message is a target detection message, the source address of the message is added to the blacklist database.
[0022] In a possible implementation, after determining whether the message is a target detection message based on the matching result, the method further includes:
[0023] If the message is a target detection message, the subject information and attack behavior information of the message are determined based on the preset security intelligence database; the security intelligence database stores network security intelligence data from multiple sources;
[0024] Determine the risk level of the message based on the subject information and attack behavior information;
[0025] If the risk level of the message is higher than the preset risk level threshold, the source address of the message is added to the blacklist database.
[0026] In a possible implementation, the method further includes:
[0027] Get sample interaction data;
[0028] Perform reverse analysis on the sample interaction data to extract the fingerprint features of each sample message in the sample interaction data;
[0029] Based on the fingerprint features of each sample message, a protocol fingerprint feature library is constructed.
[0030] In a possible implementation, if the message is a target detection message, the fingerprint feature of the message is obfuscated to generate a fingerprint obfuscated message of the response message, including:
[0031] If the message is a target detection message, a fingerprint obfuscation template for the response message is determined based on the fingerprint features of the message and the protocol fingerprint feature library;
[0032] Generate a fingerprint obfuscated message for the response message based on the fingerprint obfuscation template.
[0033] In a second aspect, an embodiment of the present application provides a cyberspace anti-mapping device, including:
[0034] A collection module, used to collect messages passing through the target network space;
[0035] A judgment module, used to judge whether the message is a target detection message for a host in a target network space;
[0036] A generation module, used for generating a fingerprint obfuscated message of a response message based on the fingerprint feature of the message if the message is a target detection message;
[0037] The sending module is used to send fingerprint obfuscated messages to counter the mapping of hosts in the target network space by target detection messages.
[0038] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a processor and a memory; wherein the memory stores a computer program, and when the processor executes the computer program, the method steps provided in the first aspect of the embodiment of the present application are implemented.
[0039] In a fourth aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the method steps provided in the first aspect of the embodiment of the present application.
[0040] The above-mentioned cyberspace anti-mapping method, device, electronic device and computer storage medium can collect messages passing through the target cyberspace and determine whether the messages are target detection messages for the host in the target cyberspace, so as to perform real-time detection of messages passing through the target cyberspace and promptly discover illegal mapping behaviors; if the message is a target detection message, a fingerprint obfuscated message is generated in response to the message based on the fingerprint feature of the message, and the fingerprint obfuscated message is sent to counter the mapping of the host in the target cyberspace by the target detection message, and the response strategy can be flexibly adjusted for different illegal mapping behaviors, making it difficult for attackers to obtain the real host fingerprint information in the target cyberspace, and the whole process can effectively deal with complex and changeable illegal mapping behaviors in the target cyberspace. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0042] Figure 1 A schematic diagram of an application environment of a cyberspace anti-mapping method provided by an exemplary embodiment of the present application;
[0043] Figure 2 The architectural intent of a cyberspace anti-mapping system provided for an exemplary embodiment of the present application;
[0044] Figure 3 A schematic flow chart of a cyberspace anti-mapping method provided as an exemplary embodiment of the present application;
[0045] Figure 4 A flowchart of a cyberspace anti-mapping method provided for another exemplary embodiment of the present application;
[0046] Figure 5 A schematic diagram of the structure of a cyberspace anti-mapping device provided as an exemplary embodiment of the present application;
[0047] Figure 6 A schematic structural diagram of an electronic device provided as an exemplary embodiment of the present application. DETAILED DESCRIPTION
[0048] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0049] In the description of the present application, it should be understood that the terms "first", "second", etc. are used for descriptive purposes only and should not be understood as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to the specific circumstances. In addition, in the description of the present application, unless otherwise specified, "multiple" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.
[0050] The cyberspace anti-mapping method provided in the embodiment of the present application can be applied to Figure 1In the application environment shown. Among them, the cyberspace anti-mapping system 10 communicates with at least one host (shown as host 21, host 22, host 23...) in the target cyberspace 20 through a communication network to identify and respond to detection behavior against any host in the target cyberspace 20, thereby protecting the hosts in the target cyberspace 20 from illegal mapping behavior. Specifically, the cyberspace anti-mapping system 10 collects messages passing through the target cyberspace 20, determines whether the message is a target detection message, and if the message is a target detection message, generates a fingerprint obfuscated message of the response message based on the network protocol characteristics of the message; the fingerprint obfuscated message is used to confuse the mapping of the target cyberspace 20.
[0051] like Figure 1 The cyberspace anti-mapping system 10 shown is composed of a 1U or 2U device in hardware form, which includes at least 2 Gigabit network ports, 1 video output interface and 2 USB interfaces. The network port is used to detect, analyze and filter the passing traffic, and take corresponding processing methods to respond to illegal mapping behaviors. At the same time, the device can also perform protocol reverse analysis on specific protocol interaction processes through manual import or online data collection, thereby continuously optimizing the generation of fingerprint obfuscated messages.
[0052] See also Figure 2 , is a schematic diagram of the architecture of a cyberspace anti-mapping system provided by an exemplary embodiment of the present application. The cyberspace anti-mapping system 10 may include, but is not limited to, a protocol fingerprint analysis subsystem 100, a host fingerprint obfuscation subsystem 200, and a behavior audit tracking subsystem 300. Among them, the protocol fingerprint analysis subsystem 100 is used to reversely analyze the sample interaction data manually imported or collected online, extract the protocol fingerprint features in the specific protocol interaction process, and thus assist the host fingerprint obfuscation subsystem 200 to efficiently generate fingerprint obfuscated messages. The host fingerprint obfuscation subsystem 200 is used to detect messages passing through the target network space in real time, and when the target detection message is identified, the protocol fingerprint features of the host are intelligently modified, and the remote host scanned and detected by the attacker is interacted and obfuscated, making it difficult for the attacker to obtain the real protocol fingerprint features of the host. The behavior audit tracking subsystem 300 is used to combine various types of network intelligence data to track and trace the main information of the target detection message and perform correlation analysis, and combine other network traffic data to determine whether there is an APT (Advanced Persistent Threat) attack behavior.
[0053] In some possible embodiments, the protocol fingerprint analysis subsystem 100 includes a fingerprint data acquisition module 110, a protocol reverse analysis module 120, and a protocol fingerprint feature library 130. Among them, the fingerprint data acquisition module 110 is used to collect the interaction data of the analyzed protocol, so as to store all the data related to the protocol, so as to facilitate the subsequent in-depth analysis of the protocol reverse analysis module 120. The protocol reverse analysis module 120 is used to reversely analyze the collected data, mine the protocol fingerprint features in the specific protocol interaction process, and import them into the protocol fingerprint feature library 130. The protocol fingerprint feature library 130 stores the port number, protocol format, fingerprint data and other contents of the protocol, which can effectively assist the host fingerprint obfuscation subsystem 200 to simulate the corresponding protocol behavior.
[0054] In some possible embodiments, the host fingerprint obfuscation subsystem 200 includes a target list database 210, a scanning behavior detection module 220, a fingerprint intelligent generation module 230 and a protocol simulation interaction module 240. Among them, the target list database 210 may include, but is not limited to, a white list database and a black list database. The white list database stores a list of addresses that are allowed to scan and detect hosts in the target network space, and the black list database stores a list of addresses that are prohibited from accessing and interacting with hosts in the target network space. By dynamically updating the target list database 210, the host fingerprint obfuscation subsystem 200 can adjust the security policy in real time to ensure that trusted users can access normally and prevent potential illegal mapping behaviors in time. The scanning behavior detection module 220 is used to perform deep packet inspection on messages whose source addresses do not belong to the target list database 210, and identify the messages in which the host fingerprint is scanned and detected. The fingerprint intelligent generation module 230 is used to generate fingerprint data for different scenarios according to the protocol fingerprint feature library 130, so as to achieve obfuscated mapping of the target network space. The protocol simulation interaction module 240 is used to follow the interaction process of the protocol, and generate corresponding fingerprint obfuscation messages to respond to the target detection messages according to the fingerprint data generated by the fingerprint intelligent generation module 230, thereby obfuscating the target detection messages from mapping the hosts in the target network space.
[0055] In some possible embodiments, the behavior audit tracking subsystem 300 includes a scanning subject association analysis module 310, an APT attack behavior identification module 320, and a security intelligence database 330. Among them, the scanning subject association analysis module 310 is used to collect and identify illegal surveying and mapping behaviors, and to audit and analyze the collected illegal surveying and mapping behaviors, to mine the host information and associated information of the illegal surveying and mapping behaviors, and to assist in tracing and tracing the subject of the illegal surveying and mapping behaviors. The APT attack behavior identification module 320 is used to combine other collected network traffic and attack behaviors to mine and analyze the entire scanning, penetration, and attack behavior chain, and determine whether there is an APT attack behavior against the target network space. The security intelligence database 330 is used to collect relevant network security intelligence data from different channels, and is combined with the scanning subject association analysis module 310 and the APT attack behavior identification module 320 to audit and track scanning behaviors.
[0056] In one embodiment, Figure 3 As shown, a network space anti-mapping method is provided, and the method is applied to the above-mentioned network space anti-mapping system 10 as an example for description, including the following steps:
[0057] S301: Collect messages passing through the target network space.
[0058] The target network space may be, but is not limited to, a specific network area where the network space anti-mapping system 10 is deployed. The message in the target network space is a data packet flowing through the target network space.
[0059] Optionally, the cyberspace anti-mapping system 10 collects messages passing through the target cyberspace in real time by deploying the cyberspace anti-mapping system 10 at key nodes (such as gateways, routers or switches) in the target cyberspace. After collecting messages passing through the target cyberspace, the cyberspace anti-mapping system 10 will further parse and identify the messages through the target list database 210 and the scanning behavior detection module 220 in the host fingerprint obfuscation subsystem 200, and determine whether the message is a target detection message. When the message is determined to be a target detection message, the protocol fingerprint feature library 130 is called through the fingerprint intelligent generation module 230 and the protocol simulation interaction module 240 to generate a corresponding fingerprint obfuscated message to confuse the attacker's mapping of the host in the target cyberspace, and the fingerprint obfuscated message is sent through the protocol simulation interaction module 240, thereby counteracting the mapping of the host in the target cyberspace by the target detection message.
[0060] S302: Determine whether the message is a target detection message for a host in a target network space.
[0061] It can be understood that the cyberspace anti-mapping system 10 determines whether the message is a target detection message for the host in the target cyberspace based on the target list database 210 and the scanning behavior detection module 220. The target list database 210 may include, but is not limited to, a whitelist database and a blacklist database. The whitelist database stores a list of addresses that are allowed to scan and detect the host in the target cyberspace, and the blacklist database stores a list of addresses that are prohibited from accessing and interacting with the host in the target cyberspace.
[0062] Optionally, the cyberspace anti-mapping system 10 first determines whether the source address of the message belongs to the blacklist database in the target list database 210. If the source address of the message belongs to the blacklist database, the message is determined to be a target detection message. If the source address of the message does not belong to the blacklist database, it is further determined whether the source address of the message belongs to the whitelist database. If the source address of the message belongs to the whitelist database, it is determined that the message is not a target detection message. If the source address of the message does not belong to the whitelist database, it is determined whether the message is a target detection message based on the preset protocol fingerprint feature library 130.
[0063] Specifically, if the source address of the message does not belong to the whitelist database or the blacklist database, the cyberspace anti-mapping system 10 performs deep packet inspection on the message through the scanning behavior detection module 220, extracts the fingerprint features of the message, and then matches the fingerprint features of the message with the fingerprint features pre-stored in the protocol fingerprint feature library 130 to obtain a matching result, and based on the matching result, determines whether the message is a target detection message. Among them, the protocol fingerprint feature library 130 is constructed based on sample interaction data manually imported or collected online.
[0064] It is worth noting that this embodiment only describes a preferred implementation of the present application. In actual applications, the cyberspace anti-mapping system 10 may also first determine whether the source address of the message belongs to the whitelist database in the target list database 210. If the source address of the message belongs to the whitelist database, it is determined that the message is not a target detection message. If the source address of the message does not belong to the whitelist database, it is further determined whether the source address of the message belongs to the blacklist database. If the source address of the message belongs to the blacklist database, it is determined that the message is a target detection message. If the source address of the message does not belong to the blacklist database, it is determined based on the preset protocol fingerprint feature library 130 whether the message is a target detection message. The specific method for determining whether the source address of the message belongs to the target list database is not limited in the embodiment of the present application.
[0065] S303: If the message is a target detection message, a fingerprint obfuscated message of a response message is generated based on the fingerprint feature of the message.
[0066] Among them, the fingerprint features of the message may include but are not limited to the protocol features of the message, the behavioral features of the message, etc. The protocol features of the message may include but are not limited to: the header format of the message, field type, protocol version, source IP address, destination IP address, source port, destination port, sequence number and confirmation number, flag bit, window size, checksum, TTL (Time to Live), option field (such as timestamp), etc. The behavioral features of the message may include but are not limited to: the way the protocol establishes a connection, the data transmission mode, the communication frequency and rate, the multi-target or multi-port scanning behavior, the serialized request mode, the repetitive request mode, the session duration, the response time, the traffic mode, the context association information, etc.
[0067] Optionally, if the message is a target detection message, the fingerprint intelligent generation module 230 and the protocol simulation interaction module 240 in the cyberspace anti-mapping system 10 call the protocol fingerprint feature library 130, and determine the fingerprint confusion template for responding to the message based on the fingerprint feature of the message and the protocol fingerprint feature library 130, and then generate a fingerprint confusion message for the response message based on the fingerprint confusion template. It can be understood that each fingerprint feature pre-stored in the protocol fingerprint feature library 130 has a corresponding fingerprint confusion template, and each fingerprint confusion template is used to guide the fingerprint intelligent generation module 230 to generate fingerprint data for different scenarios in a targeted manner. The protocol simulation interaction module 240 follows the interaction process of the protocol, and generates a corresponding fingerprint confusion message to respond to the target detection message based on the fingerprint data generated by the fingerprint intelligent generation module 230, thereby confusing the target detection message for mapping the host in the target cyberspace.
[0068] S304: Send a fingerprint obfuscation message to counter the mapping of the host in the target network space by the target detection message.
[0069] Optionally, the cyberspace anti-mapping system 10 sends a fingerprint obfuscated message through the protocol simulation interaction module 240 to counter the mapping of the target detection message against the host in the target cyberspace. It can be understood that the cyberspace anti-mapping system 10 can directly send the fingerprint obfuscated message to the source address of the target detection message through the protocol simulation interaction module 240, or send the fingerprint obfuscated message to a designated intermediate node or proxy server through the protocol simulation interaction module 240, and then forward it to the source address of the target detection message by these nodes to hide the real response path.
[0070] In this embodiment, the cyberspace anti-mapping system collects messages passing through the target cyberspace and determines whether the messages are target detection messages for the hosts in the target cyberspace. It can perform real-time detection on messages passing through the target cyberspace and promptly discover illegal mapping behaviors. If the message is a target detection message, a fingerprint obfuscated message is generated in response to the message based on the fingerprint feature of the message, and the fingerprint obfuscated message is sent to counter the mapping of the hosts in the target cyberspace by the target detection message. The response strategy can be flexibly adjusted for different illegal mapping behaviors, making it difficult for attackers to obtain the real host fingerprint information in the target cyberspace. The whole process can effectively deal with complex and changeable illegal mapping behaviors in the target cyberspace.
[0071] In one embodiment, Figure 4 As shown, another network space anti-mapping method is provided, which is described by taking the application of the method to the above-mentioned network space anti-mapping system 10 as an example, and includes the following steps:
[0072] S401: Obtain sample interaction data.
[0073] The sample interaction data includes a sample message set, and the sample message set includes at least one sample message.
[0074] Optionally, the cyberspace anti-mapping system 10 can obtain sample interaction data based on the method of manually importing files or online data collection, and perform protocol reverse analysis on specific protocol interaction processes in the sample interaction data, thereby enriching the fingerprint features of each sample message in the sample interaction data into the protocol fingerprint feature library 130. Specifically, the cyberspace anti-mapping system 10 parses the manually imported files through the fingerprint data collection module 110 to obtain sample interaction data; or collects sample interaction data online through the fingerprint data collection module 110.
[0075] S402: Perform reverse analysis on the sample interaction data to extract fingerprint features of each sample message in the sample interaction data.
[0076] The fingerprint features of each sample message may include, but are not limited to, protocol features of each sample message, behavior features of each sample message, and the like.
[0077] It can be understood that the cyberspace anti-mapping system 10 performs reverse analysis on the sample interaction data to identify and extract information in each sample message that can represent the characteristics of a specific network protocol, such as the data encapsulation method, connection establishment process, data transmission mode, etc. of the specific network protocol. Then the cyberspace anti-mapping system 10 stores the extracted information representing the characteristics of the specific network protocol into the protocol fingerprint feature library 130, so that the protocol fingerprint feature library 130 effectively assists the scanning behavior detection module 220 to identify the messages passing through the target cyberspace, and enables the protocol fingerprint feature library 130 to effectively assist the fingerprint intelligent generation module 230 and the protocol simulation interaction module 240 to generate fingerprint obfuscated messages by simulating the corresponding protocol behavior.
[0078] Optionally, the cyberspace anti-mapping system 10 performs reverse analysis on the acquired sample interaction data through the protocol reverse analysis module 120 to determine the protocol characteristics and behavioral characteristics of each sample message in the sample interaction data. Specifically, the protocol reverse analysis module 120 in the cyberspace anti-mapping system 10 first parses the elements including the IP address, port number, protocol type, message header information, and payload content in each sample message, and then analyzes the interaction mode between each sample message, thereby identifying and extracting the protocol characteristics and behavioral characteristics of each sample message.
[0079] S403: Building a protocol fingerprint feature library based on the fingerprint features of each sample message.
[0080] Optionally, the cyberspace anti-mapping system 10 classifies and annotates the protocol features and behavior features of each sample message, and constructs a protocol fingerprint feature library 130 through structured storage. It is worth noting that each fingerprint feature pre-stored in the protocol fingerprint feature library 130 has a corresponding fingerprint confusion template, and each fingerprint confusion template is used to guide the fingerprint intelligent generation module 230 to generate fingerprint data for different scenarios in a targeted manner.
[0081] In this embodiment, the cyberspace anti-mapping system obtains sample interaction data by manually importing files or collecting data online, which improves the flexibility and comprehensiveness of data acquisition and helps to include comprehensive and accurate fingerprint information in the subsequently constructed protocol fingerprint feature library; by reverse analyzing the sample interaction data, the fingerprint features of each sample message in the sample interaction data are extracted, and a protocol fingerprint feature library is constructed based on the fingerprint features of each sample message, thereby improving the detection and defense capabilities of the system and ensuring that the system can effectively respond to complex and changeable illegal mapping behaviors in the target cyberspace.
[0082] S404: Collect messages passing through the target network space.
[0083] The target network space may be, but is not limited to, a specific network area where the network space anti-mapping system 10 is deployed. The message in the target network space is a data packet flowing through the target network space.
[0084] Optionally, the cyberspace anti-mapping system 10 collects messages passing through the target cyberspace in real time by deploying the cyberspace anti-mapping system 10 at key nodes (such as gateways, routers or switches) in the target cyberspace. After collecting messages passing through the target cyberspace, the cyberspace anti-mapping system 10 will further parse and identify the messages through the target list database 210 and the scanning behavior detection module 220 in the host fingerprint obfuscation subsystem 200, and determine whether the message is a target detection message. When the message is determined to be a target detection message, the protocol fingerprint feature library 130 is called through the fingerprint intelligent generation module 230 and the protocol simulation interaction module 240 to generate a corresponding fingerprint obfuscated message to confuse the attacker's mapping of the host in the target cyberspace, and the fingerprint obfuscated message is sent through the protocol simulation interaction module 240, thereby counteracting the mapping of the host in the target cyberspace by the target detection message.
[0085] S405: Determine whether the source address of the message belongs to the blacklist database. If yes, execute S413; if no, execute S406.
[0086] The source address of the message may be, but is not limited to, the source IP address of the message. The blacklist database is a sub-database of the target list database 210. The blacklist database stores a list of addresses that are prohibited from accessing and interacting with hosts in the target network space.
[0087] Optionally, the cyberspace anti-mapping system 10 compares the source IP address of the message passing through the target cyberspace with each IP address pre-stored in the blacklist database to determine whether the source IP address of the message belongs to the blacklist database. It can be understood that if the source IP address of the message is consistent with any IP address pre-stored in the blacklist database, the message is determined to be a target detection message, and it is necessary to generate a fingerprint obfuscated message of the response message based on the fingerprint feature of the message; if the source address of the message is inconsistent with all the IP addresses pre-stored in the blacklist database, it is necessary to further determine whether the source address of the message belongs to the whitelist database.
[0088] S406: Determine whether the source address of the message belongs to the whitelist database. If yes, then end; if no, then execute S407.
[0089] The whitelist database is a sub-database of the target list database 210. The whitelist database stores a list of addresses that are allowed to scan and detect hosts in the target network space.
[0090] Optionally, when the source address of the message does not belong to the blacklist database, the cyberspace anti-mapping system 10 further compares the source IP address of the message with the IP address pre-stored in the whitelist database to determine whether the source IP address of the message belongs to the whitelist database. It can be understood that if the source IP address of the message is consistent with any IP address pre-stored in the whitelist database, it is determined that the message is not a target detection message, and the cyberspace anti-mapping process ends; if the source IP address of the message is inconsistent with all IP addresses pre-stored in the whitelist database, it is necessary to further determine whether the message is a target detection message through deep packet inspection and fingerprint feature matching.
[0091] In this embodiment, the cyberspace anti-mapping system can quickly determine whether the message is a target detection message for mapping the host in the target cyberspace by comparing the source address of the message with the blacklist database and the whitelist database in the target list database 210, thereby effectively responding to the complex and changeable illegal mapping behaviors in the target cyberspace.
[0092] S407: Perform deep packet inspection on the message to extract fingerprint features of the message.
[0093] Optionally, the cyberspace anti-mapping system 10 performs deep packet inspection on the messages passing through the target cyberspace through the scanning behavior detection module 220, parses the header information of the message (such as IP address, port number), and deeply analyzes the payload content of the message, thereby extracting fingerprint features including protocol features and behavior features. Specifically, the cyberspace anti-mapping system 10 first parses the header field of the message, then further analyzes the payload part, identifies the specific content of the application layer protocol, and finally extracts the fingerprint features of the message, so that it is convenient to more accurately determine whether the message is a target detection message based on the extracted fingerprint features.
[0094] S408: Match the fingerprint features of the message with the fingerprint features pre-stored in the protocol fingerprint feature library to obtain a matching result.
[0095] Optionally, the cyberspace anti-mapping system 10 matches the fingerprint features of the message with the fingerprint features pre-stored in the protocol fingerprint feature library 130 respectively to obtain the matching degree between the fingerprint features of the message and the fingerprint features pre-stored in the protocol fingerprint feature library 130.
[0096] S409: Based on the matching result, determine whether the message is a target detection message. If yes, execute S410; if no, end.
[0097] Optionally, the cyberspace anti-mapping system 10 determines whether the message is a target detection message based on the matching degree between the fingerprint feature of the message and each fingerprint feature pre-stored in the protocol fingerprint feature library 130. Specifically, the cyberspace anti-mapping system 10 determines the highest matching degree among multiple matching degrees. If the highest matching degree is greater than or equal to a preset matching degree threshold, the message is determined to be a target detection message, and a fingerprint obfuscated message of the response message needs to be generated based on the fingerprint feature of the message; otherwise, the message is determined not to be a target detection message, and the cyberspace anti-mapping process ends.
[0098] In this embodiment, the cyberspace anti-mapping system performs deep packet inspection on the message through the scanning behavior detection module, extracts the fingerprint features of the message, matches the fingerprint features of the message with the fingerprint features pre-stored in the protocol fingerprint feature library, obtains the matching results, and judges whether the message is a target detection message based on the matching results. It can accurately judge whether the message is a target detection message based on the extracted fingerprint features, thereby effectively responding to the illegal mapping behavior of the target detection message against the host in the target cyberspace.
[0099] S410: Generate a fingerprint obfuscated message of the response message based on the fingerprint feature of the message.
[0100] Among them, the fingerprint features of the message may include but are not limited to the protocol features of the message, the behavior features of the message, etc. The protocol features of the message may include but are not limited to: the header format of the message, field type, protocol version, source IP address, destination IP address, source port, destination port, sequence number and confirmation number, flag bit, window size, checksum, TTL, option field, etc. The behavior features of the message may include but are not limited to: the way the protocol establishes a connection, the data transmission mode, the communication frequency and rate, the multi-target or multi-port scanning behavior, the serialized request mode, the repetitive request mode, the session duration, the response time, the traffic mode, the context association information, etc.
[0101] Optionally, if the message is a target detection message, the fingerprint intelligent generation module 230 and the protocol simulation interaction module 240 in the cyberspace anti-mapping system 10 call the protocol fingerprint feature library 130, and determine the fingerprint confusion template for responding to the message based on the fingerprint feature of the message and the protocol fingerprint feature library 130, and then generate a fingerprint confusion message for the response message based on the fingerprint confusion template. It can be understood that each fingerprint feature pre-stored in the protocol fingerprint feature library 130 has a corresponding fingerprint confusion template, and each fingerprint confusion template is used to guide the fingerprint intelligent generation module 230 to generate fingerprint data for different scenarios in a targeted manner. The protocol simulation interaction module 240 follows the interaction process of the protocol, and generates a corresponding fingerprint confusion message to respond to the target detection message based on the fingerprint data generated by the fingerprint intelligent generation module 230, thereby confusing the target detection message for mapping the host in the target cyberspace.
[0102] S411: Sending a fingerprint obfuscation message to counter the mapping of the host in the target network space by the target detection message.
[0103] Optionally, the cyberspace anti-mapping system 10 sends a fingerprint obfuscated message through the protocol simulation interaction module 240 to counter the mapping of the target detection message against the host in the target cyberspace. It can be understood that the cyberspace anti-mapping system 10 can directly send the fingerprint obfuscated message to the source address of the target detection message through the protocol simulation interaction module 240, or send the fingerprint obfuscated message to a designated intermediate node or proxy server through the protocol simulation interaction module 240, and then forward it to the source address of the target detection message by these nodes to hide the real response path.
[0104] S412: Add the source address of the message to the blacklist database.
[0105] Optionally, if the cyberspace anti-mapping system 10 determines that the message is a target detection message after performing deep packet inspection and fingerprint feature matching on the message, the source IP address of the message is added to the blacklist database to simplify the subsequent detection process for target detection messages in the target cyberspace.
[0106] In one embodiment, after determining whether the message is a target detection message based on the matching result, the method also includes: if the message is a target detection message, determining the subject information and attack behavior information of the message based on a preset security intelligence database; the security intelligence database stores network security intelligence data from multiple sources; determining the risk level of the message based on the subject information and attack behavior information; if the risk level of the message is higher than the preset risk level threshold, adding the source address of the message to the blacklist database.
[0107] Optionally, if the cyberspace anti-mapping system 10 determines that the message is a target detection message after performing deep packet inspection and fingerprint feature matching on the message, in order to simplify the subsequent detection process for the target detection message in the target cyberspace, another feasible method is to determine the subject information and attack behavior information of the message based on the scanning subject association analysis module 310, the APT attack behavior identification module 320 and the preset security intelligence database 330 in the behavior audit tracking subsystem 300, and determine the risk level of the message based on the subject information and the attack behavior information. If the risk level of the message is higher than the preset risk level threshold, the source address of the message is added to the blacklist database.
[0108] It can be understood that the scanning subject association analysis module 310 is used to collect and identify illegal surveying and mapping behaviors, and to audit and analyze the collected illegal surveying and mapping behaviors, to mine the host information and associated information of illegal surveying and mapping behaviors, and to assist in tracing and tracing the subject of illegal surveying and mapping behaviors. The APT attack behavior identification module 320 is used to combine other collected network traffic and attack behaviors to mine and analyze the entire scanning, penetration, and attack behavior chain to determine whether there are APT attack behaviors against the target network space. The security intelligence database 330 is used to collect relevant network security intelligence data from different channels, and is combined with the scanning subject association analysis module 310 and the APT attack behavior identification module 320 to audit and track scanning behaviors.
[0109] In this embodiment, the cyberspace anti-mapping system determines the subject information and attack behavior information of the message based on a preset security intelligence database, and determines the risk level of the message according to the subject information and attack behavior information. When the risk level of the message is higher than the preset risk level threshold, the source address of the message is added to the blacklist database, thereby enhancing the adaptability and scalability of the system and ensuring that it can efficiently and effectively respond to complex and changeable illegal mapping behaviors in the target cyberspace.
[0110] S413: Generate a fingerprint obfuscated message of the response message based on the fingerprint feature of the message.
[0111] Specifically, S413 is consistent with the above S410 and will not be repeated here.
[0112] S414: Sending a fingerprint obfuscation message to counter the mapping of the host in the target network space by the target detection message.
[0113] Specifically, S414 is consistent with the above-mentioned S411 and will not be repeated here.
[0114] The above-mentioned anti-mapping method for cyberspace can quickly determine whether the message is a target detection message for mapping the host in the target cyberspace by pre-building a protocol fingerprint feature library and comparing the source address of the message with the blacklist database and the whitelist database in the target list database, thereby effectively responding to the complex and changeable illegal mapping behaviors in the target cyberspace; the message is subjected to deep packet detection by a scanning behavior detection module to extract the fingerprint features of the message, and the fingerprint features of the message are matched with each fingerprint feature pre-stored in the protocol fingerprint feature library to obtain a matching result, and based on the matching result, it is determined whether the message is a target detection message, and it can accurately determine whether the message is a target detection message based on the extracted fingerprint features, thereby effectively responding to the illegal mapping behavior of the target detection message against the host in the target cyberspace; the subject information and attack behavior information of the message are determined based on a preset security intelligence database, and the risk level of the message is determined according to the subject information and the attack behavior information. When the risk level of the message is higher than the preset risk level threshold, the source address of the message is added to the blacklist database, thereby enhancing the adaptability and scalability of the system. The above method can efficiently and effectively deal with the complex and changeable illegal surveying and mapping behaviors in the target network space.
[0115] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0116] Based on the inventive concept of the above-mentioned network space anti-mapping method, Figure 5 As shown, the embodiment of the present application also provides a network space anti-mapping device 500 for implementing the network space anti-mapping method involved above. The network space anti-mapping device 500 includes:
[0117] A collection module 501 is used to collect messages passing through the target network space;
[0118] A determination module 502 is used to determine whether the message is a target detection message for a host in a target network space;
[0119] A generating module 503, configured to generate a fingerprint obfuscated message of a response message based on the fingerprint feature of the message if the message is a target detection message;
[0120] The sending module 504 is used to send fingerprint obfuscation messages to counter the mapping of hosts in the target network space by target detection messages.
[0121] In a possible implementation, the judgment module 502 is specifically used to judge whether the source address of the message belongs to the target list database; if the source address of the message does not belong to the target list database, it is judged whether the message is a target detection message based on a preset protocol fingerprint feature library.
[0122] In one possible implementation, the target list database includes a blacklist database and a whitelist database; the judgment module 502 is also used to determine that the message is a target detection message if the source address of the message belongs to the blacklist database; if the source address of the message belongs to the whitelist database, determine that the message is not a target detection message.
[0123] In a possible implementation, the judgment module 502 is also used to perform deep packet inspection on the message and extract the fingerprint features of the message if the source address of the message does not belong to the target list database; match the fingerprint features of the message with the fingerprint features pre-stored in the protocol fingerprint feature library to obtain a matching result; and based on the matching result, determine whether the message is a target detection message.
[0124] In a possible implementation, the cyberspace anti-mapping device 500 further includes an update module for adding the source address of the message to a blacklist database if the message is a target detection message.
[0125] In one possible implementation, the above-mentioned update module is also used to determine the subject information and attack behavior information of the message based on a preset security intelligence database if the message is a target detection message; the security intelligence database stores network security intelligence data from multiple sources; the risk level of the message is determined based on the subject information and attack behavior information; if the risk level of the message is higher than the preset risk level threshold, the source address of the message is added to the blacklist database.
[0126] In a possible implementation, the cyberspace anti-mapping device 500 also includes a construction module for acquiring sample interaction data; performing reverse analysis on the sample interaction data to extract fingerprint features of each sample message in the sample interaction data; and constructing a protocol fingerprint feature library based on the fingerprint features of each sample message.
[0127] In a possible implementation, the generation module 503 is specifically used to determine a fingerprint obfuscation template for a response message based on the fingerprint feature of the message and the protocol fingerprint feature library if the message is a target detection message; and generate a fingerprint obfuscation message of the response message based on the fingerprint obfuscation template.
[0128] Each module in the above-mentioned cyberspace anti-mapping device 500 can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each of the above modules.
[0129] The embodiment of the present application also provides an electronic device, which may be a server, and its internal structure diagram may be as follows: Figure 6 As shown. The electronic device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The application database of the electronic device is used to store fingerprint feature data. The input / output interface of the electronic device is used to exchange information between the processor and an external device. The communication interface of the electronic device is used to communicate with an external terminal through a network connection. The processor of the electronic device executes a computer program to implement a cyberspace anti-mapping method.
[0130] Those skilled in the art will understand that Figure 6 The structure shown in the figure is merely a block diagram of a partial structure related to the scheme of the present application, and does not constitute a limitation on the electronic device to which the scheme of the present application is applied. The specific electronic device may include more or fewer components than shown in the figure, or combine certain components, or have a different arrangement of components.
[0131] In a possible implementation, an electronic device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:
[0132] Collect messages passing through the target network space;
[0133] Determine whether the message is a target detection message for a host in the target network space;
[0134] If the message is a target detection message, a fingerprint obfuscated message of the response message is generated based on the fingerprint characteristics of the message;
[0135] Send fingerprint obfuscated messages to counter the mapping of hosts in the target network space by target detection messages.
[0136] In a possible implementation, the processor also implements the following steps when executing the computer program: determining whether the source address of the message belongs to the target list database; if the source address of the message does not belong to the target list database, determining whether the message is a target detection message based on a preset protocol fingerprint feature library.
[0137] In one possible implementation, the target list database includes a blacklist database and a whitelist database; when the processor executes the computer program, it also implements the following steps: if the source address of the message belongs to the blacklist database, the message is determined to be a target detection message; if the source address of the message belongs to the whitelist database, the message is determined not to be a target detection message.
[0138] In a possible implementation, the processor also implements the following steps when executing the computer program: if the source address of the message does not belong to the target list database, deep packet inspection is performed on the message to extract the fingerprint features of the message; the fingerprint features of the message are matched with the fingerprint features pre-stored in the protocol fingerprint feature library to obtain a matching result; based on the matching result, it is determined whether the message is a target detection message.
[0139] In a possible implementation, when the processor executes the computer program, the following steps are further implemented: if the message is a target detection message, the source address of the message is added to a blacklist database.
[0140] In one possible implementation, the processor also implements the following steps when executing the computer program: if the message is a target detection message, the subject information and attack behavior information of the message are determined based on a preset security intelligence database; the security intelligence database stores network security intelligence data from multiple sources; the risk level of the message is determined based on the subject information and attack behavior information; if the risk level of the message is higher than a preset risk level threshold, the source address of the message is added to a blacklist database.
[0141] In a possible implementation, when the processor executes the computer program, it also implements the following steps: obtaining sample interaction data; performing reverse analysis on the sample interaction data to extract fingerprint features of each sample message in the sample interaction data; and constructing a protocol fingerprint feature library based on the fingerprint features of each sample message.
[0142] In a possible implementation, the processor further implements the following steps when executing the computer program: if the message is a target detection message, a fingerprint obfuscation template for a response message is determined based on the fingerprint features of the message and a protocol fingerprint feature library; and a fingerprint obfuscation message for the response message is generated based on the fingerprint obfuscation template.
[0143] The present application also provides a computer storage medium, which stores instructions, and when the instructions are executed on a computer or a processor, the computer or the processor executes one or more steps in the above embodiment. If the components of the above electronic device are implemented in the form of software functional units and sold or used as independent products, they can be stored in the above computer storage medium.
[0144] In a possible implementation, a computer storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0145] Collect messages passing through the target network space;
[0146] Determine whether the message is a target detection message for a host in the target network space;
[0147] If the message is a target detection message, a fingerprint obfuscated message of the response message is generated based on the fingerprint characteristics of the message;
[0148] Send fingerprint obfuscated messages to counter the mapping of hosts in the target network space by target detection messages.
[0149] In one possible implementation, when the computer program is executed by the processor, the following steps are implemented: determining whether the source address of the message belongs to the target list database; if the source address of the message does not belong to the target list database, determining whether the message is a target detection message based on a preset protocol fingerprint feature library.
[0150] In one possible implementation, the target list database includes a blacklist database and a whitelist database; when the computer program is executed by the processor, the following steps are implemented: if the source address of the message belongs to the blacklist database, the message is determined to be a target detection message; if the source address of the message belongs to the whitelist database, the message is determined not to be a target detection message.
[0151] In one possible implementation, the computer program implements the following steps when executed by a processor: if the source address of the message does not belong to the target list database, perform deep packet inspection on the message to extract the fingerprint features of the message; match the fingerprint features of the message with the fingerprint features pre-stored in the protocol fingerprint feature library to obtain a matching result; based on the matching result, determine whether the message is a target detection message.
[0152] In a possible implementation manner, when the computer program is executed by a processor, the following steps are implemented: if the message is a target detection message, the source address of the message is added to a blacklist database.
[0153] In one possible implementation, the computer program implements the following steps when executed by a processor: if the message is a target detection message, the subject information and attack behavior information of the message are determined based on a preset security intelligence database; the security intelligence database stores network security intelligence data from multiple sources; the risk level of the message is determined based on the subject information and attack behavior information; if the risk level of the message is higher than a preset risk level threshold, the source address of the message is added to a blacklist database.
[0154] In one possible implementation, when the computer program is executed by a processor, the following steps are implemented: obtaining sample interaction data; performing reverse analysis on the sample interaction data to extract fingerprint features of each sample message in the sample interaction data; and constructing a protocol fingerprint feature library based on the fingerprint features of each sample message.
[0155] In one possible implementation, when the computer program is executed by a processor, the following steps are implemented: if the message is a target detection message, a fingerprint obfuscation template for a response message is determined based on the fingerprint features of the message and a protocol fingerprint feature library; and a fingerprint obfuscation message for the response message is generated based on the fingerprint obfuscation template.
[0156] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted by the computer-readable storage medium. The computer instructions can be transmitted from a website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (Digital Subscriber Line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server, data center, etc. that contains one or more available media integrated. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital versatile disc (DVD)), or a semiconductor medium (eg, a solid state disk (SSD)).
[0157] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The aforementioned storage medium includes: ROM, RAM, magnetic disk or optical disk and other media that can store program codes. In the absence of conflict, the technical features in this embodiment and the implementation scheme can be combined arbitrarily.
[0158] The embodiments described above are merely preferred embodiments of the present application and are not intended to limit the scope of the present application. Without departing from the design spirit of the present application, various modifications and improvements made to the technical solutions of the present application by ordinary technicians in this field should fall within the protection scope determined by the claims.
[0159] The above describes a specific embodiment of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
Claims
1. A cyberspace anti-mapping method, characterized in that: The method comprises: Collect messages passing through the target network space; Determining whether the message is a target detection message for a host in the target network space; If the message is the target detection message, generating a fingerprint obfuscated message in response to the message based on the fingerprint feature of the message; The fingerprint obfuscation message is sent to counter the mapping of the host in the target network space by the target detection message.
2. The method according to claim 1, characterized in that The determining whether the message is a target detection message for a host in the target network space includes: Determining whether the source address of the message belongs to the target list database; If the source address of the message does not belong to the target list database, it is determined whether the message is the target detection message based on a preset protocol fingerprint feature library.
3. The method according to claim 2, characterized in that The target list database includes a blacklist database and a whitelist database; After determining whether the source address of the message belongs to the target list database, the method further includes: If the source address of the message belongs to the blacklist database, determining that the message is the target detection message; If the source address of the message belongs to the whitelist database, it is determined that the message is not the target detection message.
4. The method according to claim 2, characterized in that If the source address of the message does not belong to the target list database, judging whether the message is a target detection message based on a preset protocol fingerprint feature library includes: If the source address of the message does not belong to the target list database, deep packet inspection is performed on the message to extract fingerprint features of the message; Matching the fingerprint features of the message with the fingerprint features pre-stored in the protocol fingerprint feature library to obtain a matching result; Based on the matching result, it is determined whether the message is a target detection message.
5. The method according to claim 4, characterized in that After determining whether the message is a target detection message based on the matching result, the method further includes: If the message is a target detection message, the subject information and attack behavior information of the message are determined based on a preset security intelligence database; the security intelligence database stores network security intelligence data from multiple sources; Determining a risk level of the message according to the subject information and the attack behavior information; If the risk level of the message is higher than a preset risk level threshold, the source address of the message is added to the blacklist database.
6. The method according to claim 2, characterized in that The method further comprises: Get sample interaction data; Performing reverse analysis on the sample interaction data to extract fingerprint features of each sample message in the sample interaction data; Based on the fingerprint features of the sample messages, the protocol fingerprint feature library is constructed.
7. The method according to claim 1, characterized in that If the message is a target detection message, the fingerprint feature of the message is obfuscated to generate a fingerprint obfuscated message in response to the message, including: If the message is a target detection message, determining a fingerprint obfuscation template for responding to the message based on the fingerprint feature of the message and the protocol fingerprint feature library; Based on the fingerprint obfuscation template, a fingerprint obfuscated message is generated in response to the message.
8. A cyberspace anti-mapping device, characterized in that: The device comprises: A collection module, used to collect messages passing through the target network space; A judging module, used to judge whether the message is a target detection message for a host in the target network space; A generating module, configured to generate a fingerprint obfuscated message in response to the message based on the fingerprint feature of the message if the message is the target detection message; The sending module is used to send the fingerprint obfuscation message to counter the mapping of the host in the target network space by the target detection message.
9. An electronic device, characterized in that: include: A processor and a memory; the memory stores a computer program, and the processor implements the method steps of any one of claims 1 to 7 when executing the computer program.
10. A computer storage medium, characterized in that: The computer storage medium stores a plurality of instructions, which are suitable for being loaded by a processor and executing the method steps according to any one of claims 1 to 7.