Network routing security test method and device for anonymous communication, and electronic equipment

By collecting and optimizing network routing information, the problem of anonymous nodes in the existing technology affecting the accuracy of network routing security testing is solved, and higher test accuracy is achieved.

CN119996032APending Publication Date: 2025-05-13709TH RESEARCH INSTITUTE CHINA STATE SHIPBUILDING CORP LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510248953.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing network routing security testing scheme has low accuracy when facing anonymous nodes, which affects the accuracy of network topology and the accuracy of network routing security testing.

Method used

By collecting the routing information of the target network, the original target network topology map is generated, and the topology map is optimized based on the preset optimization strategy under preset conditions, including identifying and collecting anonymous nodes, generating the optimized target network topology map, and finally conducting network routing security testing.

Benefits of technology

It improves the accuracy of network routing security testing, reduces the impact of abnormal nodes, and makes the optimized network topology diagram more accurate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996032A_ABST
    Figure CN119996032A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security, and particularly discloses a network routing security test method and device for anonymous communication and electronic equipment, and the method comprises the steps: collecting routing information of a target network; generating an original target network topological graph based on the routing information; optimizing the original target network topological graph based on a preset optimization strategy under a preset condition to obtain an optimized target network topological graph; and performing a network routing security test on the target network based on the optimized target network topological graph. According to the method, the accuracy of network routing security testing can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of network security technology, and more specifically, relates to a network routing security testing method, device and electronic device for anonymous communication. Background Art

[0002] With the development of computer network technology, the scale of the network continues to increase, and network security issues emerge in an endless stream. As the core of the inter-domain routing system, the Border Gateway Protocol (BGP) protocol undertakes the key task of transmitting network information and data. However, when the BGP protocol was originally designed, it did not fully consider the protection of the information it carries, which makes the BGP protocol particularly vulnerable when facing penetration testing. By blocking, rewriting, suppressing, disrupting, forging and hijacking routes, it can redirect the forwarding data of the network core routing nodes, thereby manipulating network traffic and carrying out malicious behaviors such as DDoS attacks. Therefore, penetration testing of the BGP protocol to discover its potential security risks has become an urgent problem to be solved in the field of network security.

[0003] Obtaining the router-level topology information of the target network is a prerequisite for conducting network routing security testing. At present, network routing security testers usually use the Traceroute tool to obtain the router addresses in the network and the neighbor relationships between routers, and form a router network topology map through address extraction and router address synthesis. However, during use, in order to ensure the privacy and security of the network under their jurisdiction, some network administrators set the routers not to respond to Traceroute detection messages. Therefore, these routers appear to time out in the Traceroute detection and can be called "anonymous nodes" in the network. Once multiple anonymous nodes appear in the Traceroute detection, it will seriously affect the accuracy and integrity of the network topology, and thus affect the accuracy of the network routing security test. Summary of the invention

[0004] In view of the defects of the prior art, the purpose of the present application is to provide a network routing security testing method, device and electronic device for anonymous communication, aiming to solve the problem of low accuracy of the existing network routing security testing scheme.

[0005] To achieve the above objectives, in a first aspect, the present application provides a network routing security testing method for anonymous communication, comprising: Collect routing information of the target network; Based on the routing information, generating an original target network topology map; Optimizing the original target network topology map based on a preset optimization strategy under preset conditions to obtain an optimized target network topology map; Based on the optimized target network topology diagram, a network routing security test is performed on the target network.

[0006] This application collects the routing information of the target network, constructs a network topology map of the target network by analyzing the relevant routing data of the target network, adopts preset optimization strategies under preset conditions to evaluate potential network vulnerabilities and aggregate and optimize the network topology map, and finally performs a network routing security test on the target network through the optimized network topology map to improve the accuracy of the network routing security test.

[0007] According to a network routing security testing method for anonymous communication provided by the present application, the preset conditions include: In a traceroute process, a node that times out three times in a row is identified as an anonymous node; The traceroute detection results have been processed comprehensively for multiple router addresses; The proportion of anonymous nodes in the target network is less than a preset threshold.

[0008] This application sets three conditions to optimize the original target network topology diagram to improve the accuracy of network routing security testing.

[0009] According to a network routing security testing method for anonymous communication provided by the present application, the preset optimization strategy includes: Based on the survival time value of each anonymous node in the original target network topology graph, determining duplicate nodes in each anonymous node; Group duplicate nodes.

[0010] This application determines the duplicate nodes in each anonymous node based on the lifetime value of the anonymous node, and groups the duplicate nodes to reduce anomalies, making the optimized network topology more accurate, thereby improving the accuracy of network routing security testing.

[0011] According to a network routing security testing method for anonymous communication provided by the present application, the collecting of routing information of the target network includes: Collect the autonomous system (AS)-level topology information and router information of the target network.

[0012] According to a network routing security testing method for anonymous communication provided by the present application, generating an original target network topology map based on the routing information includes: Generate an AS topology map based on the AS-level topology information of the target network; The router information is subjected to multi-address merging processing to generate a target network topology map.

[0013] According to a network routing security testing method for anonymous communication provided by the present application, the network routing security testing of the target network is performed based on the optimized target network topology diagram, including: Based on the optimized target network topology diagram, analyzing the potential vulnerabilities of the target network and determining a network routing security testing strategy; Based on the network routing security test strategy, a corresponding message is generated, and the message is automatically loaded and injected into the target network to perform a network routing security test.

[0014] This application automatically loads and injects test cases and executes tests by selecting intelligent security testing strategies.

[0015] In a second aspect, the present application provides a network routing security testing device for anonymous communication, comprising: A collection module, used to collect routing information of the target network; A generating module, used for generating an original target network topology map based on the routing information; An optimization module, used to optimize the original target network topology map based on a preset optimization strategy under preset conditions to obtain an optimized target network topology map; The testing module is used to perform a network routing security test on the target network based on the optimized target network topology diagram.

[0016] In a third aspect, the present application provides an electronic device, comprising: at least one memory for storing programs; and at least one processor for executing the programs stored in the memory. When the programs stored in the memory are executed, the processor is used to execute the network routing security testing method for anonymous communication described in the first aspect or any possible implementation of the first aspect.

[0017] In a fourth aspect, the present application provides a computer-readable storage medium, which stores a computer program. When the computer program runs on a processor, the processor executes the network routing security testing method for anonymous communication described in the first aspect or any possible implementation of the first aspect.

[0018] In a fifth aspect, the present application provides a computer program product. When the computer program product runs on a processor, the processor executes the network routing security testing method for anonymous communication described in the first aspect or any possible implementation of the first aspect.

[0019] It can be understood that the beneficial effects of the second to sixth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here.

[0020] In general, the above technical solutions conceived by this application have the following beneficial effects compared with the prior art: By collecting the routing information of the target network, analyzing the relevant routing data of the target network, and constructing the network topology map of the target network, the preset optimization strategy under preset conditions is used to evaluate the potential network vulnerability and optimize the network topology map. Finally, the network routing security test of the target network is carried out through the optimized network topology map to improve the accuracy of the network routing security test. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the present application or the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0022] Figure 1 It is a flowchart of a network routing security testing method for anonymous communication provided by an embodiment of the present application; Figure 2 is the original network router topology diagram provided by the embodiment of the present application; Figure 3 It is a flow chart of the optimal anonymous aggregation node strategy provided by an embodiment of the present application; Figure 4 is an optimized network router topology diagram provided in an embodiment of the present application; Figure 5 It is a structural diagram of a network routing security testing device for anonymous communication provided by an embodiment of the present application; Figure 6 It is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0023] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0024] The term "and / or" in this article is a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The symbol " / " in this article indicates that the associated objects are in an or relationship, for example, A / B means A or B.

[0025] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0026] In the description of the embodiments of the present application, unless otherwise specified, "multiple" means two or more than two. For example, multiple processing units refer to two or more processing units, etc.; multiple elements refer to two or more elements, etc.

[0027] Next, combine Figure 1-Figure 4 The network routing security testing method for anonymous communication provided in an embodiment of the present application is introduced.

[0028] Figure 1 is a flow chart of a network routing security testing method for anonymous communication provided by an embodiment of the present application, such as Figure 1 As shown, the method comprises the following steps: Step 100, collecting routing information of the target network; The target network is the network that needs to be tested for routing security.

[0029] Optionally, the routing information may include router information, such as the number of nodes, a port address set, etc., and the routing information of the target network may be collected through a Traceroute tool or the like.

[0030] Step 110, generating an original target network topology map based on the routing information; The network topology diagram is a graphical representation of the network structure, device connection relationships and communication paths. This application generates the original target network topology diagram based on the collected routing information.

[0031] Figure 2 is the original network router topology diagram provided in the embodiment of the present application, such as Figure 2 As shown, in one embodiment of the present application, based on the collected routing information, a Figure 2 The original target network topology diagram is shown.

[0032] Step 120, optimizing the original target network topology map based on a preset optimization strategy under preset conditions to obtain an optimized target network topology map; Since there may be a router in the original target network topology that is reflected on multiple anonymous routers, affecting the accuracy of the network routing security test, the present application optimizes the original target network topology based on a preset optimization strategy under preset conditions to collect repeated anonymous nodes and obtain an optimized target network topology.

[0033] Step 130: Perform a network routing security test on the target network based on the optimized target network topology diagram.

[0034] The optimized target network topology map is more accurate than the original target network topology map. Based on the optimized target network topology map, a network routing security test is performed on the target network, which can improve the accuracy of the network routing security test.

[0035] The present application provides a network routing security testing method for anonymous communication, which collects routing information of a target network, analyzes relevant routing data of the target network, constructs a network topology map of the target network, uses a preset optimization strategy under preset conditions to evaluate potential network vulnerabilities and performs group optimization processing on the network topology map, and finally performs a network routing security test on the target network through the optimized network topology map, thereby improving the accuracy of the network routing security test.

[0036] In some embodiments, the preset conditions in step 120 specifically include: In a traceroute process, a node that times out three times in a row is identified as an anonymous node; The traceroute detection results have been processed comprehensively for multiple router addresses; The proportion of anonymous nodes in the target network is less than the preset threshold.

[0037] The present application uses an optimal anonymous node aggregation strategy under restricted conditions to optimize the original target network topology. The basic idea is to aggregate multiple anonymous communication nodes into one anonymous node under restricted conditions to form a new aggregated network routing topology.

[0038] Among the restricted conditions, first of all, it is considered that in a Traceroute process, if a node times out three times in a row, it is considered to be an anonymous node, that is, unreachable. In the Traceroute results, it is recorded as a triple (IP1-anon-IP2) or quadruple (such as IP1- anon - anon -IP2) containing the anonymous node. These triples and quadruple are collectively called anonymous communication paths.

[0039] The second restriction is that the Traceroute detection results must have been processed comprehensively for multiple router addresses.

[0040] The third restriction is that the proportion of anonymous nodes in the target network is not large, that is, the proportion of anonymous nodes is less than the preset threshold.

[0041] In one embodiment of the present application, the preset threshold is set to 25%.

[0042] The above three conditions must be met simultaneously to implement the optimal anonymous node aggregation strategy.

[0043] In some embodiments, the preset optimization strategy in step 120 includes: Based on the survival time value of each anonymous node in the original target network topology, determine the duplicate nodes in each anonymous node; Group duplicate nodes.

[0044] Figure 3 is a flow chart of the optimal anonymous aggregation node strategy provided by the embodiment of the present application, such as Figure 3 As shown in the figure, the specific implementation steps of the optimal anonymous aggregation node strategy are as follows: Step 1: Analyze the router information of the original Traceroute data, construct an anonymous path set anonRoute, and store all anonymous path information; the anonymous path includes attributes such as anonymous communication path and path status, which are defined as follows: routeCase =<route, routeState> Among them, the anonymous communication path is represented by route, which is a triple or quadruple containing anonymous nodes; The path state routeState records the collection status of the anonymous communication path: the collected record is 1, and the uncollected record is 0.

[0045] right Figure 1 Analyze the original network router topology map and construct the anonymous path set anonRoute. anonRoute={<N1-V1-N2, 0> ,<N2-V2-V3-N3, 0> ,<N3-V4-N4, 0>} Assume that the difference between the TTL values ​​of anonymous nodes V1 and V2 in the figure is less than 2, and the difference between the TTL values ​​of anonymous nodes V3 and V4 is less than 2. In addition, the difference between the TTL values ​​of all other anonymous nodes is greater than 2.

[0046] Step 2: Take an anonymous path with a path status of 0 from the anonymous path set anonRoute, R=<N1-V1-N2,0> ; Step 3, R is a triplet, the anonymous node V1 in R is grouped as C1, the anonymous communication path of R is modified to N1-C1-N2, and the path state of R1 is set to 1.

[0047] Step 4: Find an anonymous path P in the set anonRoute whose path state is 0 and contains address N1 or N2, except R. P =<N2-V2-V3-N3, 0> ; Step 5: The difference between the TTL value of the anonymous node V2 in P adjacent to the address N2 and the TTL value of the anonymous node V1 in R is less than 2. The anonymous nodes in P and the anonymous nodes in R can be grouped together, and the anonymous node in P is modified to C1. Step 6: Since P contains the unprocessed anonymous node V3, the path state of R2 cannot be set to 1, P =<N2-C1-V3-N3, 0> ; Step 7: Check the anonymous path set anonRoute. If there is an anonymous path with a path state routeState of 0, take the anonymous path R=<N2-C1-V3-N3, 0> , is a four-tuple, the anonymous node V3 in R is grouped as C2, the anonymous communication path of R is modified to N2-C1-C2-N3, and the path state of R is set to 1; Step 8: Find an anonymous path group P in the set anonRoute whose path status is 0 and contains address N2 or N3 except R, where P =<N3-V4-N4, 0> ; Step 9: If the difference between the TTL value of the anonymous node V4 in P adjacent to the address N3 and the TTL value of the anonymous node V3 in R is less than 2, the anonymous node V4 in P can be grouped with the anonymous nodes in R, and the anonymous node V4 in P is modified to C2; Step 10: P does not contain any unprocessed anonymous nodes, and the path state of P is set to 1; Step 11, checking the anonymous path set anonRoute, there is no anonymous path with a path state routeState of 0, so the anonymous router aggregation process is completed, and a new network router-level topology map is generated according to the processing result.

[0048] Figure 4 is an optimized network router topology diagram provided in an embodiment of the present application, such as Figure 4 As shown, in one embodiment of the present application, the optimized network router topology diagram is as follows Figure 4 shown.

[0049] In some embodiments, step 100 specifically includes: Collect the autonomous system AS-level topology information and router information of the target network.

[0050] Optionally, the IRR database, Traceroute tool, and BGP routing table can be used to accurately obtain the AS configuration details, AS-IP mapping relationship, and interconnection architecture between ASs of the target network.

[0051] Optionally, the Traceroute raw data of the target network may be obtained through the Traceroute tool, from which key information of the router nodes, such as the number of nodes, the port address set, and the neighbor relationship between nodes, etc., may be extracted.

[0052] In some embodiments, step 110 specifically includes: Step 1101, generating an AS topology map based on AS-level topology information of the target network; Step 1102, performing multi-address merging processing on the router information to generate a target network topology map.

[0053] By collecting the AS-level topology information and router-level topology information in the target network, the target network is analyzed for vulnerabilities. Specifically, the target network's AS-level topology information generates an accurate AS topology map of the target network. Based on the Traceroute data, the router information is merged with multiple addresses to form the original target network topology map.

[0054] In some embodiments, step 130 specifically includes: Step 1301, based on the optimized target network topology, analyzing the potential vulnerability of the target network and determining the network routing security test strategy; Step 1302: Generate a corresponding message based on the network routing security test strategy, and automatically load and inject the message into the target network to perform the network routing security test.

[0055] After obtaining the optimized target network topology, we can analyze the potential vulnerabilities of the target network based on the accurate AS-level and router-level topology of the target network, provide a network routing security test strategy, and then use the penetration test method according to the network routing security test strategy to encapsulate the selected test method into a message, automatically load and inject it into the target network, and perform the network routing security test.

[0056] Figure 5 is a schematic diagram of the structure of a network routing security testing device for anonymous communication provided by an embodiment of the present application, such as Figure 5 As shown, the device includes a collection module 510, a generation module 520, an optimization module 530 and a test module 540, wherein: A collection module 510, used to collect routing information of a target network; A generating module 520, configured to generate an original target network topology map based on the routing information; The optimization module 530 is used to optimize the original target network topology map based on a preset optimization strategy under preset conditions to obtain an optimized target network topology map; The testing module 540 is used to perform a network routing security test on the target network based on the optimized target network topology diagram.

[0057] It should be understood that the above-mentioned device is used to execute the method in the above-mentioned embodiment. The implementation principle and technical effect of the corresponding program module in the device are similar to those described in the above-mentioned method. The working process of the device can refer to the corresponding process in the above-mentioned method, which will not be repeated here.

[0058] Based on the method in the above embodiment, Figure 6 An example of a physical structure diagram of an electronic device is shown in FIG. Figure 6 As shown, an embodiment of the present application provides an electronic device, which may include: a processor (processor) 610, a communication interface (Communications Interface) 620, a memory (memory) 630 and a communication bus 640, wherein the processor 610, the communication interface 620, and the memory 630 communicate with each other through the communication bus 640. The processor 610 can call the logic instructions in the memory 630 to execute the network routing security testing method for anonymous communication in the above embodiment.

[0059] In addition, the logic instructions in the above-mentioned memory 630 can be implemented in the form of software functional units and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the network routing security testing method for anonymous communication described in each embodiment of the present application.

[0060] Based on the method in the above embodiment, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program runs on a processor, the processor executes the network routing security testing method for anonymous communication in the above embodiment.

[0061] Based on the method in the above embodiment, an embodiment of the present application provides a computer program product. When the computer program product runs on a processor, the processor executes the network routing security testing method for anonymous communication in the above embodiment.

[0062] It is understandable that the processor in the embodiment of the present application may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0063] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, mobile hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.

[0064] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented by software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions may be transmitted from a website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state disk (SSD)), etc.

[0065] It should be understood that the various numerical numbers involved in the embodiments of the present application are only used for the convenience of description and are not used to limit the scope of the embodiments of the present application.

[0066] It will be easily understood by those skilled in the art that the above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A network routing security testing method for anonymous communication, characterized in that: include: Collect routing information of the target network; Based on the routing information, generating an original target network topology map; Optimizing the original target network topology map based on a preset optimization strategy under preset conditions to obtain an optimized target network topology map; Based on the optimized target network topology diagram, a network routing security test is performed on the target network.

2. The network routing security testing method for anonymous communication according to claim 1, characterized in that: The preset conditions include: In a traceroute process, a node that times out three times in a row is identified as an anonymous node; The traceroute detection results have been processed comprehensively for multiple router addresses; The proportion of anonymous nodes in the target network is less than a preset threshold.

3. The network routing security testing method for anonymous communication according to claim 1, characterized in that: The preset optimization strategy includes: Based on the survival time value of each anonymous node in the original target network topology graph, determining duplicate nodes in each anonymous node; Group duplicate nodes.

4. The network routing security testing method for anonymous communication according to claim 1, characterized in that: The collecting of routing information of the target network includes: Collect the target network's autonomous system AS-level topology information and router information.

5. The network routing security testing method for anonymous communication according to claim 4, characterized in that: The generating of the original target network topology map based on the routing information includes: Generate an AS topology map based on the AS-level topology information of the target network; The router information is subjected to multi-address merging processing to generate a target network topology map.

6. The network routing security testing method for anonymous communication according to claim 1, characterized in that: The performing a network routing security test on the target network based on the optimized target network topology diagram includes: Based on the optimized target network topology diagram, analyzing the potential vulnerabilities of the target network and determining a network routing security testing strategy; Based on the network routing security test strategy, a corresponding message is generated, and the message is automatically loaded and injected into the target network to perform a network routing security test.

7. A network routing security testing device for anonymous communication, characterized in that: include: A collection module, used to collect routing information of the target network; A generating module, used for generating an original target network topology map based on the routing information; An optimization module, used to optimize the original target network topology map based on a preset optimization strategy under preset conditions to obtain an optimized target network topology map; The testing module is used to perform a network routing security test on the target network based on the optimized target network topology diagram.

8. An electronic device, characterized in that: include: at least one memory for storing a computer program; At least one processor is used to execute the program stored in the memory. When the program stored in the memory is executed, the processor is used to execute the network routing security testing method for anonymous communication as described in any one of claims 1-6.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program runs on a processor, the processor is enabled to execute the network routing security testing method for anonymous communication according to any one of claims 1 to 6.

10. A computer program product, characterized in that When the computer program product runs on a processor, the processor is enabled to execute the network routing security testing method for anonymous communication according to any one of claims 1 to 6.