Network asset scanning method, related device and scanning tool

By pre-constructing the detection message template in the memory cache area of ​​the scanning tool and sending it by the gateway, the problem of running pressure and high CPU consumption of existing network asset scanning tools is solved, and a more efficient scanning process is achieved.

CN120263497APending Publication Date: 2025-07-04BEIJING VENUS INFORMATION SECURITY TECH +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510475362.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

When building and sending probe packets, existing network asset scanning tools have problems such as high operation pressure, high CPU consumption, large thread concurrency, frequent context switching and performance bottlenecks.

Method used

The detection message templates corresponding to various scanning tasks are pre-built in the memory cache area of ​​the scanning tool, and the detection message is sent through the gateway, reducing the amount of thread concurrency and context switching during the detection message construction process, and simplifying the detection message construction process.

Benefits of technology

It effectively reduces the operating pressure of the scanning tool, reduces CPU consumption time, and improves scanning efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263497A_ABST
    Figure CN120263497A_ABST
Patent Text Reader

Abstract

The invention discloses a network asset scanning method, a related device and a scanning tool, and relates to the field of network asset scanning, the scanning tool is in communication connection with a gateway through a scanning port, the scanning port has a fixed and unique IP address, and the scanning tool is in communication connection with device ports of a plurality of devices to be scanned through the gateway. The method comprises the steps of obtaining a scanning task instruction, and reading a packaged detection message template corresponding to the type of a current scanning task from a first memory cache region of a scanning tool; and target equipment information carried in the detection message template is set as information of the current to-be-scanned port, so that a current detection message of the current to-be-scanned port is generated, a verification value is generated, and the current detection message and the verification value are sent to a gateway, so that the gateway sends the current detection message and the verification value to the current to-be-scanned port. According to the method and the device, the detection message can be obtained only by modifying partial data in the detection message template, and is sent by the gateway, so that the operation pressure of a scanning tool is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of network asset scanning, and in particular, to a network asset scanning method, related devices, and scanning tools. Background Art

[0002] Network asset scanning refers to a technology that scans all devices, applications, and services in a network or system to identify their existence, configuration, and vulnerabilities.

[0003] Network asset scanning can be achieved through specific scanning tools, such as Namp (Network Mapper). The scanning tool constructs a probing message and sends the probing message to the device to be scanned. It receives the response message returned by the device to be scanned, analyzes the relevant information of the device to be scanned and possible security vulnerabilities based on the response message, and outputs the scanning result.

[0004] Before each sending of a probing message, the scanning tool needs to first construct the probing message. In the process of constructing the probing message, the scanning tool first constructs the data structure of the probing message, then obtains the data of each layer required by the data structure of the probing message, then copies the data of each layer to the corresponding positions in the data structure, and finally performs packet encapsulation to obtain the probing message. After obtaining the probing message, the scanning tool also needs to perform tasks such as routing query and address resolution to determine the device to receive the probing message.

[0005] It can be seen that the above process is relatively cumbersome, bringing a large operating pressure to the scanning tool. Summary of the Invention

[0006] In view of the above problems, this application provides a network asset scanning method, related devices, and scanning tools to achieve the purpose of reducing the operating pressure of the scanning tool. The specific solutions are as follows:

[0007] In the first aspect of this application, a network asset scanning method is provided, which is applied to a scanning tool. The scanning tool is communicatively connected to a gateway through a scanning port. The scanning port has a fixed and unique IP address. The scanning tool is communicatively connected to the device ports of multiple devices to be scanned through the gateway. The network asset scanning method includes:

[0008] Obtain a scanning task instruction, where the scanning task instruction includes: multiple types of scanning tasks and the device ports of multiple devices to be scanned corresponding to each type of scanning task;

[0009] Determine one type of scanning task in the scanning task instruction as the current scanning task in a preset order, and perform the following processing on the current scanning task:

[0010] Read the encapsulated probe message template corresponding to the type of the current scan task from the first memory buffer of the scan tool. Multiple probe message templates are stored in the first memory buffer, and each probe message template corresponds to a type of scan task;

[0011] Determine a device port of the current scan task for which a probe message has not been sent as the current port to be scanned;

[0012] Set the destination device information carried in the probe message template to the information of the current port to be scanned, so as to generate the current probe message for the current port to be scanned, and generate the check value of the current probe message. Different current probe messages carry different destination device information;

[0013] Send the current probe message and the check value to the gateway through the scan port, so that the gateway sends the current probe message and the check value to the current port to be scanned, and return to execute the step of reading the encapsulated probe message template corresponding to the type of the current scan task from the first memory buffer of the scan tool.

[0014] In a possible implementation, the network asset scanning method further includes:

[0015] Receive the response message of the current port to be scanned sent by the gateway;

[0016] If the response message is an invalid message, discard the response message;

[0017] If the response message is a valid message, extract at least part of the data in the response message according to the type of the current scan task, and save the extracted data in the second memory buffer of the scan tool.

[0018] In a possible implementation, the network asset scanning method further includes:

[0019] If the amount of data stored in the second memory buffer exceeds a preset threshold, aggregate the extracted data stored in the second memory buffer, and upload the aggregated extracted data to the data processing module.

[0020] In a possible implementation, the network asset scanning method further includes:

[0021] If no response message of the device port is received or no data upload is performed within a preset time, aggregate the extracted data stored in the second memory buffer, and upload the aggregated extracted data.

[0022] In a possible implementation, before reading the packetized probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool, the network asset scanning method further includes:

[0023] Reading whether there is a notification event in the shared memory, where the notification event is: prompting the scanning tool to send a response message of the scanning tool to the first scanning port, and the notification event carries: the type of the response message returned by the first scanning port and the information of the first scanning port;

[0024] If there is a notification event in the shared memory, determining the target type of the scanning task according to the type of the response message returned by the first scanning port, and reading the packetized first probe message template corresponding to the target type of the scanning task from the first memory buffer of the scanning tool;

[0025] Setting the destination device information carried in the first probe message template to the information of the first scanning port to generate the first probe message of the first scanning port, and generating the check value of the first probe message;

[0026] Taking the first probe message as the response message of the scanning tool, and sending the first probe message and the check value of the first probe message to the gateway through the scanning port, and the gateway sends the first probe message and the check value of the first probe message to the first scanning port.

[0027] In a possible implementation, the network asset scanning method further includes:

[0028] When the scanning tool needs to stop the current scanning task of the current port to be scanned, sending a probe end message to the gateway, so that the gateway sends a probe end message to the current port to be scanned.

[0029] A second aspect of the present application provides a scanning tool, which is communicatively connected to a gateway through a scanning port, the scanning port has a fixed and unique IP address, and the scanning tool is communicatively connected to the device ports of multiple devices to be scanned through the gateway. The scanning tool includes:

[0030] A response unit, configured to obtain a scanning task instruction, where the scanning task instruction includes: multiple types of scanning tasks and the device ports of multiple devices to be scanned corresponding to each type of scanning task;

[0031] A sending unit, configured to determine one type of scanning task in the scanning task instruction as the current scanning task in a preset order, and perform the following processing on the current scanning task:

[0032] Read the packetized probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool. Multiple probe message templates are stored in the first memory buffer, and each probe message template corresponds to a type of scanning task. Determine a device port of the current scanning task for which a probe message has not been sent as the current port to be scanned. Set the destination device information carried in the probe message template as the information of the current port to be scanned to generate the current probe message for the current port to be scanned, and generate the check value of the current probe message. Different current probe messages carry different destination device information. Send the current probe message and the check value to the gateway through the scanning port, so that the gateway sends the current probe message and the check value to the current port to be scanned, and then return to execute the step of reading the packetized probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool.

[0033] In a possible implementation, the scanning tool further includes a receiving unit, and the receiving unit is specifically configured as:

[0034] Receive the response message of the current port to be scanned sent by the gateway. If the response message is an invalid message, discard the response message. If the response message is a valid message, extract at least part of the data in the response message according to the type of the current scanning task, and save the extracted data in the second memory buffer of the scanning tool.

[0035] A third aspect of the present application provides an electronic device, including at least one processor and a memory connected to the processor, where:

[0036] The memory is used to store a computer program;

[0037] The processor is used to execute the computer program so that the electronic device can implement the network asset scanning method in the first aspect or any implementation manner of the first aspect.

[0038] A fourth aspect of the present application provides a computer program product, including computer-readable instructions, which when running on an electronic device, enable the electronic device to implement the network asset scanning method in the first aspect or any implementation manner of the first aspect.

[0039] With the above technical solution, the present application provides a network asset scanning method, related devices, and a scanning tool. This method takes the type of scanning task as a dimension and pre-constructs probe message templates corresponding to various types of scanning tasks in the first memory buffer. The data of each layer required by it has been pre-encapsulated, and there is no need to copy data each time. The corresponding probe message template can be determined according to the type of scanning task executed each time. Moreover, since the IP address of the scanning port where the scanning tool is connected to the gateway is fixed and unique, the sender information of the probe message in the memory buffer is fixed, and only the destination device information in the probe message needs to be modified and the corresponding check value needs to be generated. Therefore, when constructing the probe message, there is no need to reconstruct the data structure of the probe message each time and copy the data of each required layer accordingly. Only the probe message template corresponding to the scanning task type needs to be obtained from the first memory buffer, and the destination device information and the check value are modified therein. And in this method, the gateway sends the probe message to the port to be scanned, and the gateway replaces the work of routing query and address resolution, etc. In summary, this method can effectively reduce the operating pressure of the scanning tool. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic and the original elements and elements are not necessarily drawn to scale.

[0041] Figure 1 It is a deployment schematic diagram of a scanning device provided by an embodiment of the present application;

[0042] Figure 2 It is a flowchart of a network asset scanning method provided by an embodiment of the present application;

[0043] Figure 3 It is a structural schematic diagram of a scanning tool provided by an embodiment of the present application;

[0044] Figure 4 It is a hardware structure block diagram of an electronic device provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0045] The following describes the embodiments of the present application in combination with the accompanying drawings in the embodiments of the present application. The terms used in the embodiment part of the present application are only used to explain the specific embodiments of the present application, and are not intended to limit the present application.

[0046] The following describes the embodiments of the present application in combination with the accompanying drawings. Those skilled in the art know that with the development of technology and the emergence of new scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0047] In the description of this application and the above-mentioned drawings, terms such as "first" and "second" are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same attributes when describing embodiments of this application. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device including a series of units does not have to be limited to those units, but may include other units not clearly listed or inherent to these processes, methods, products or devices.

[0048] With the rapid development of the Internet of Things, the number of devices connected to the Internet of Things is also increasing continuously. Since most of the devices connected to the Internet of Things are unattended or dumb terminals, and most of them are deployed remotely or outdoors in a distributed manner, it not only increases the difficulty of operation and maintenance and management, but also brings many security risks. Network asset scanning can help operation and maintenance personnel quickly check and sort out the assets (devices, applications, and services in the network) in the network.

[0049] Network asset scanning can be achieved through a scanning tool in the scanning device for automatic scanning, such as Namp (Network Mapper). The technical logic of network asset scanning is: the scanning device constructs a detection message with special content and sends it to the target asset, and based on whether the target asset returns the expected response, it is used to discover, identify, or detect relevant information and possible security vulnerabilities of the target asset, etc.

[0050] Before each sending of a detection message, the scanning device first switches the operating environment of the scanning tool, creates a socket (a network communication endpoint), then creates an skb_buff (socket buffer), copies the required data in the skb_buff multiple times, and obtains the detection message through packet encapsulation at each protocol layer. After obtaining the detection message, it then performs processes such as route query and address resolution to achieve the sending of the detection message. The above process is not only cumbersome, but also in the face of a large network space, since a large network space has a large number of network assets, the number of detection messages sent also becomes huge. Therefore, the above message construction and sending mechanism can bring huge additional overheads, and the specific reasons are as follows:

[0051] When a scanning device processes a scanning task, system calls are involved, and system calls involve switching between the user mode and the kernel mode. The user mode is the mode in which ordinary programs run. In this mode, only the resources allocated by the operating system to itself can be accessed, and some instructions involving low-level operations cannot be directly executed, with relatively low privileges. The kernel mode is the mode in which the operating system kernel runs, which can access all resources and execute privileged instructions, having the highest privileges. Therefore, during the operation of a user-mode program, if some high-privilege operations are required, such as reading and writing files, network communication, etc., it is necessary to switch to the kernel mode to complete. After the kernel mode completes the high-privilege operation, it switches back to the user mode to continue execution.

[0052] Specifically, the running environment of the scanning tool switches from the user mode to the kernel mode (the first switch). The scanning tool implements the above-mentioned processes of constructing and sending probe messages. After sending the probe message, the running environment of the scanning tool switches from the kernel mode to the user mode (the second switch). And the switching process may involve the message and restoration of context information. Specifically, when switching from the user mode to the kernel mode, the operating system of the scanning device will save the context information of the user mode (such as register values, program counters, etc.), then load the context information of the kernel mode, and execute the kernel code to complete related operations. After completing the related operations, the context information of the user mode is restored and the user mode continues to run. In the face of a large number of network assets in a large network space, the scanning tool needs to send a large number of probe messages in a short time. Each construction and sending of a probe message involves two switches of the running environment, and each switch requires the operating system of the scanning device to save the state of the current mode and load the state of the mode to be switched to (context switching). Therefore, when the scanning tool is executing the construction and sending of probe messages, it needs to repeat the cumbersome processes of constructing and sending probe messages many times, and involves multiple context switches, consuming a large amount of CPU time.

[0053] Furthermore, the current scanning tool introduces a multi-threaded model in the process of sending probe messages. The multi-threaded model allows a program to run multiple threads simultaneously. Each thread is an independent execution path in the program and shares program resources. To ensure data consistency and thread safety, in the multi-threaded model, a lock mechanism is used to synchronize and manage multiple threads, ensuring that only one thread can access shared resources at the same time. In a high-concurrency scenario, a large number of threads need to access the same shared resource, and multiple threads simultaneously try to acquire the same lock, resulting in lock contention among multiple threads. When a thread successfully acquires the lock and accesses the shared resource, other threads that try to acquire the lock will be forced to wait until the thread completes its access and then switches to the next thread for access. During the sequential switching access of multiple threads, the operating system needs to allocate a certain amount of memory to save the context information of the threads. When a thread switches to running, it needs to switch to the context information saved by the thread to restore the running state of the thread. Therefore, the greater the concurrency of threads, the more intense the lock contention, the more frequent the context switching of threads, and when the concurrency of threads is higher than a certain threshold, a performance bottleneck may also be encountered.

[0054] In the process of implementing the parallel sending of probe messages through the multi-threaded model, processes such as the data acquisition process and the data copying process during the construction of each probe message can each be considered a thread, and the sending process of the probe message can also be considered a thread. Therefore, when the scanning tool sends a large number of probe messages in parallel in a short period of time, it can cause a huge thread concurrency, resulting in frequent thread context switching, thereby consuming a large amount of CPU time and possibly encountering a performance bottleneck.

[0055] To solve the above problems, the embodiment of the present application provides a network asset scanning method. In this method, probe message templates corresponding to various scanning tasks are pre-configured in the first memory buffer. The corresponding probe message template can be directly selected and read according to the type of the scanning task. Only the destination device information in the probe message template needs to be modified and the check value needs to be regenerated, which simplifies the construction process of the probe message. And the probe message is sent by the gateway, thereby reducing the concurrency of threads in the construction process and the sending process of the probe message, effectively reducing the CPU consumption time. And this method switches between the user mode and the kernel mode in terms of scanning tasks, rather than switching between the user mode and the kernel mode in terms of probe messages. Therefore, when this method executes a scanning task, it switches from the user mode to the kernel mode, the scanning task is executed by the kernel mode, and then switches back from the kernel mode to the user mode, only requiring two switches, reducing the number of context information switches of the operating system and further reducing the CPU consumption time. The network asset scanning method of the embodiment of the present application will be introduced in detail below with reference to the accompanying drawings.

[0056] Refer to Figure 1 , Figure 1It is a deployment schematic diagram of a scanning device. The scanning device is loaded with a scanning tool. The scanning device bypasses and directly connects to a switch using a fixed scanning port, and only one IP address is configured on this scanning port. The access switch can be a high-performance core switch or an aggregation switch. The scanning device can communicate with devices in the local network or other networks through the access switch. In this embodiment, the access switch is a gateway. Therefore, the device deployment in this embodiment can be specifically: the scanning tool in the scanning device communicates with the gateway through a scanning port, and a scanning port has a fixed and unique IP address. The scanning tool communicates with the device ports of multiple devices to be scanned through the gateway. Among them, the scanning tool can be a scanning engine or a scanning application in the scanning device. The scanning tool may include a sending module, a first memory buffer interacting with the sending module, a receiving module, a second memory buffer interacting with the receiving module, and a shared memory between the sending module and the receiving module. The sending module can read the probe message module from the first buffer to facilitate constructing a probe message and send the constructed probe message to the gateway. The receiving module can receive the response message sent by the device to be scanned and cache the valid data in the response message to the second memory buffer. The shared memory between the sending module and the receiving module can be used for the receiving module to send a notification event to the sending module to facilitate the sending module to send the response message of the scanning tool.

[0057] Referring to Figure 2 , Figure 2 is a flowchart schematic diagram of a network asset scanning method provided by an embodiment of the present application. As Figure 2 shown, a network asset scanning method provided by an embodiment of the present application is applied to the scanning tool in the above device deployment. The network asset scanning method may include steps S10 to S15, and the following will describe these steps in detail.

[0058] S10. Obtain a scanning task instruction, where the scanning task instruction includes: multiple types of scanning tasks and the device ports of multiple devices to be scanned corresponding to each type of scanning task.

[0059] Among them, the scanning task instruction is an instruction sent by the operating system of the scanning device to the scanning tool when triggering a scanning task. The scanning task instruction may include the scanning task type of this scanning task, multiple devices to be scanned (the IP address range of the devices to be scanned). Of course, it may also include the IP address of the local gateway, the IP address and MAC address of the scanning port, and the MAC address of the next hop of the local gateway. The content included in the scanning task instruction can be pre-configured manually. After configuration, it is sent to the scanning device to trigger the scanning task.

[0060] Scanning tasks can be divided into multiple types of scanning tasks by type, such as port scanning, banner scanning (a network detection technology that sends requests to specific ports of a target system and parses the returned response information to identify the name, version, and other relevant information of the services running on the target system), etc. Each type of scanning task can include multiple devices to be scanned, and each device to be scanned can include multiple device ports to be scanned. Therefore, in each type of scanning task, there can be a large number of device ports to be scanned, and there can be an overlapping part of the device ports to be scanned between each type of scanning task. For example, in type A scanning tasks, the device ports to be scanned can include: port 1 and port 2 of device a, port 1, port 2, and port 3 of device b. In type B scanning tasks, the device ports to be scanned can include: port 1 of device a, port 1 and port 2 of device b.

[0061] S11. Determine a type of scanning task in the scanning task instruction as the current scanning task in accordance with a preset order, and perform the following processing on the current scanning task:

[0062] S12. Read the encapsulated probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool. Multiple probe message templates are stored in the first memory buffer, and each probe message template corresponds to a type of scanning task;

[0063] S13. Determine a device port of the current scanning task for which a probe message has not been sent as the current port to be scanned;

[0064] S14. Set the destination device information carried in the probe message template to the information of the current port to be scanned to generate the current probe message for the current port to be scanned, and generate the check value of the current probe message. Among them, the destination device information carried in different current probe messages is different;

[0065] Among them, the preset order can be: the sequence of execution between various types of scanning tasks when configuring scanning tasks. The execution mode of performing scanning tasks in this embodiment can be: serial execution. When the current scanning task is completed, the next type of scanning task is executed. Then the current scanning task can be: the scanning task being executed. The sending mode of probe messages in this embodiment can also be: serial sending. When a probe message is sent, the preparation for sending the next probe message starts. Then the current probe message can be: the probe message that needs to be sent to the device port of a certain device to be scanned currently. The first memory buffer can be: a memory area storing various types of probe message templates, and each type of probe message template corresponds to the type of scanning task. The probe message template can be a probe message after encapsulating data of each layer. The destination device information can refer to: information such as the IP address, MAC address of the device to be scanned, and the device port to be scanned.

[0066] When deploying the scanning device in this embodiment, it is connected to the gateway only through the scanning port of a fixed IP address. Therefore, the sender information of the probing message can be fixed. And in the probing messages under the same type of scanning task, except for the different destination device information, the data in other layers are basically the same. Therefore, for the same type of scanning task, the same probing message template can be reused. Only individual different data needs to be replaced, and there is no need to repeat the cumbersome construction process of the probing message every time, thus reducing the concurrency of threads. Therefore, when constructing the probing message in this embodiment, the sending module of the scanning tool can directly obtain the pre-constructed probing message template from the first memory buffer, and this probing message template corresponds to the type of the current scanning task.

[0067] Since this embodiment selects to change some data of the probing message template to obtain the probing message when constructing the probing message, rather than directly constructing the probing message according to the processes such as creating a socket and creating an skb_buff, this embodiment chooses to abandon the support of the socket and the protocol stack. However, the purpose of this embodiment is to scan the network assets in the network space, which requires message interaction work with the devices to be scanned. Therefore, when constructing the probing message in this embodiment, it is necessary to solve the routing and forwarding problem of the probing message and the handshake and timing problem of TCP type scanning.

[0068] This embodiment preferentially counts the scanning types supported by the upper-layer scanning application program, which may include: ICMP request, TCP SYN request, TCP ACK response, TCP RST response, and TCP application-layer request. Among them, the TCP application-layer request is relatively special, and different TCP PSH / ACK messages can correspond to different application-layer protocols.

[0069] Among them, ICMP (Internet Control Message Protocol) is a sub - protocol of the TCP / IP protocol suite. TCP SYN request is a handshake signal used when establishing a connection in the TCP / IP protocol. TCP (Transmission Control Protocol) is a connection - oriented transport - layer communication protocol. SYN (Synchronize Sequence Numbers) is a key flag used to establish a connection in the TCP protocol. TCP ACK response is an important mechanism in the TCP protocol for confirming the successful reception of data. When the receiving end successfully receives the data packet sent by the sending end, it will send an ACK (Acknowledgment) data packet to the sending end as a response to confirm the successful reception of the data. TCP RST (Reset) response is a mechanism in the TCP protocol for abnormally terminating a connection.

[0070] Specifically, for the routing and forwarding problems of probe messages, especially ICMP request messages and TCP messages, in this embodiment, when constructing the link - layer and IP - layer data in the probe message template, the IP address of the scanning port is selected as the source IP address, the MAC address of the scanning port is selected as the source MAC address, the MAC address of the gateway is selected as the destination MAC address, and 0 is temporarily used as the destination IP address. Among them, the scanning port is the only port through which the scanning device communicates with the gateway during device deployment. Therefore, in the probe message template, the information of the sending party is fixed, while the information data position of the destination device can be 0 and can be set according to the actual information of the destination device. Further, when generating the current probe message by changing the destination device information in the probe message template, it is necessary to regenerate the check value of the current probe message to ensure the integrity and security of the current probe message.

[0071] Regarding the handshake and timing issues of TCP type scanning, TCP type scanning can include TCP port scanning and banner scanning. Since in the TCP protocol standard, the seq value and ack value can be calculated based on the request-response packet length, if the seq value of the probe packet during fixed-port scanning by the scanning device is detected, the entire timing can be predicted. Therefore, in this embodiment, when constructing the initial probe packet for TCP port scanning, the seq value of the initial probe packet can be set to 0, and if the length of the response packet sent by the device to be scanned can be predicted, the seq value and ack value of other subsequent probe packets can be determined in advance by calculation. Among them, the seq value is an identifier used for data communication and can represent the order of data sending or receiving. In the TCP protocol, data transmission can be carried out sequentially according to the size of the seq value. The ack value is a sequence number used by the receiving end to confirm that the data has been successfully received. In the TCP protocol, the ack value can represent the sequence number of the first data byte expected to receive the next packet segment from the other party, and this sequence number is calculated by adding 1 to the seq value in the previous data packet received by the receiving end.

[0072] However, in banner scanning, since the connection closure in banner scanning is achieved by means of socket (sending fin / ack to achieve connection closure: sending a packet with the fin flag bit set to 1 and receiving a response packet with the ack flag bit set to 1 to achieve connection closure, and the fin flag bit indicates the end of the TCP connection). Since this embodiment abandons the support of socket, if fin / ack is used to achieve connection closure, the seq value and ack value of fin / ack need to be calculated based on the response packet data length. However, the length of the response packet of the probe packet in banner scanning cannot be predicted. Therefore, the seq value and ack value of fin / ack are difficult to fix. Therefore, this embodiment chooses to replace fin / ack with rst to achieve connection closure. Even if the seq value of rst does not meet the timing requirements, the TCP connection can still be closed.

[0073] Therefore, in the TCP type scanning task, when the scanning tool needs to stop the current scanning task for the current port to be scanned, it can send a probe end packet to the gateway, so that the gateway sends a probe end packet to the current port to be scanned. Specifically, the probe end packet can be a probe packet with the rst flag bit set to 1.

[0074] Since the TCP scan is initiated and ended by the scanning device, and the entire scanning process is controlled by the scanning device. Therefore, if the scanning device fixes a scanning process for each scanning type, asynchronous timing control can be achieved through the close cooperation of the sending module and the receiving module, thus eliminating the need for socket support. Therefore, before the sending module prepares to construct a probe message, it is necessary to determine with the receiving module whether there is a message that needs to be responded to, and then determine the current execution step based on the judgment result (select to construct a probe message or select to construct a response message). The specific process can be as follows:

[0075] Before reading the packetized probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool, check whether there is a notification event in the shared memory. The notification event is: a prompt for the scanning tool to send a response message of the scanning tool to the first scanning port, and the notification event carries: the type of the response message returned by the first scanning port and the information of the first scanning port;

[0076] If there is a notification event in the shared memory, determine the target type of the scanning task according to the type of the response message returned by the first scanning port, and read the packetized first probe message template corresponding to the target type of the scanning task from the first memory buffer of the scanning tool;

[0077] Set the destination device information carried in the first probe message template to the information of the first scanning port to generate the first probe message for the first scanning port, and generate the checksum value of the first probe message;

[0078] Use the first probe message as the response message of the scanning tool, and send the first probe message and the checksum value of the first probe message to the gateway through the scanning port. The gateway then sends the first probe message and the checksum value of the first probe message to the first scanning port.

[0079] Wherein, the first scanning port may be a port to which the scanning tool sends a response message according to the response message returned by the scanning tool after the scanning tool sends a detection message. After the receiving module receives the response message, it can determine whether the sending module needs to send a response message according to the solidified scanning process and the scanning task being executed. For example, in ICMP scanning, since the ICMP request is an inquiry request sent to the device to be scanned, it only checks whether the device to be scanned can respond to the ICMP request. Therefore, when the receiving module receives the ICMP request, it is not necessary to send a subsequent response message according to the scanning process. In TCP port scanning, when the receiving module receives syn / ack, the sending module needs to send an rst message according to the scanning process to close the connection. In banner scanning, when the receiving module receives ack or psh / ack respectively, the sending module needs to send a banner detection message or an rst message according to the scanning process. Wherein, the syn flag is used to synchronize the sequence number, which is a handshake signal used when TCP establishes a connection. Syn / ack can mean: confirming that the connection request from the sender has been received. The psh flag is used to notify the receiver to hand over the data to the upper-layer application for processing as soon as possible. psh / ack can mean that the data packet contains data that needs to be processed as soon as possible, and confirms receipt of the data, and expects the sender to continue sending subsequent data.

[0080] Specifically, if it is determined that the sending module needs to send a response message, the receiving module can store a notification event in the shared memory, which carries the source IP address, source port and returned response message type of the scanning device that needs to send the response message, so that the sending module can construct the response message. For example, in banner scanning, if the receiving module receives ack, the source IP address, source port and ack information can be sent to the sending module through the shared memory, and the sending module can determine that the corresponding banner scanning type detection message needs to be sent according to the ack information.

[0081] Therefore, before the sending module is ready to build a detection message each time, it is necessary to first determine whether there is a notification event in the shared memory. If it is determined through the shared memory that there is a notification event, the sending module can first suspend the construction of the detection message and build a response message instead. For example, for device 1, device 2, and device 3, the detection message of device 1 is first built and handed over to the gateway to send to device 1. Before preparing to build the detection message of device 2, it is necessary to read the shared memory to determine whether there is a notification event. If there is a notification event related to device 1 in the shared memory, the response message of device 1 is first built, and after the response message is sent by the gateway, the detection message of device 2 is built and handed over to the gateway for sending.

[0082] S15. Send the current detection message and the check value to the gateway through the scanning port, so that the gateway sends the current detection message and the check value to the current port to be scanned, and then return to execute the step of reading the encapsulated detection message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool.

[0083] Among them, the gateway can be a local gateway in the same network as the scanning device. After the sending module completes the construction of the current detection message and the generation of the check value, it will default to send the current detection message and the check value to the gateway, and the gateway will replace the scanning device to perform routing queries and address resolutions, etc. If the device to be scanned is a device in the local network, the gateway will directly forward the current detection message and the check value to the device to be scanned in the local network; if the device to be scanned is a device in other networks, the gateway will send the current detection message and the check value to the gateway of other networks, and the gateway of other networks will forward the current detection message and the check value to the device to be scanned.

[0084] When returning to execute the step of reading the encapsulated detection message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool, if all devices or ports to be scanned in the current scanning task have been scanned, the sending module can feedback information indicating the end of the execution of the scanning task to the upper-layer scanning application program.

[0085] Further, during the sending process of the detection message, the specific routing judgment process can be as follows: when sending the current detection message and the check value to the gateway, the MAC address of the scanning port can be used as the destination MAC address to ensure that the current detection message and the check value can be sent out from the only deployed scanning port; the MAC address of the gateway can be used as the destination MAC address to ensure that the current detection message and the check value can be sent to the gateway, and the IP address of the device to be scanned can be used as the destination IP, which can ensure that after the gateway receives the current detection message and the check value, it will forward them to the device to be scanned; using the only configurable IP address allowed by the scanning port as the source IP address can ensure that the response message of the device to be scanned can be transmitted back.

[0086] The embodiment of the present application provides a network asset scanning method. This method constructs in advance, in the first memory buffer, probe message templates corresponding to various types of scanning tasks with the scanning task type as the dimension. The data of each layer required by it has been encapsulated in advance, eliminating the need to copy data each time. The corresponding probe message template can be determined according to the type of the scanning task executed each time. Moreover, since the IP address of the scanning port where the scanning tool is connected to the gateway is fixed and unique, the sender information of the probe message in the memory buffer is fixed. Only the destination device information in the probe message needs to be modified and the corresponding check value needs to be generated. Therefore, when constructing the probe message, there is no need to reconstruct the data structure of the probe message each time and copy the data of each layer required accordingly. Only the probe message template corresponding to the scanning task type needs to be obtained from the first memory buffer, and the destination device information therein is modified and the check value is generated. In this method, the gateway sends the probe message to the port to be scanned, and the gateway takes over tasks such as routing query and address resolution. In summary, this method can effectively reduce the operating pressure of the scanning tool.

[0087] Furthermore, the simplification of the construction process of the probe message and the execution of the sending of the probe message by the gateway can both reduce the thread concurrency of the operating system, thereby reducing the CPU consumption time. And this embodiment switches between the user mode and the kernel mode with the scanning task as the dimension, effectively reducing the number of switches between the user mode and the kernel mode, thereby reducing the number of context information switches of the operating system and further reducing the CPU consumption time.

[0088] In a possible implementation, the network asset scanning method may further include steps one to three:

[0089] Step one: Receive the response message of the currently to-be-scanned port sent by the gateway;

[0090] Step two: If the response message is an invalid message, discard the response message;

[0091] Step three: If the response message is a valid message, extract at least part of the data in the response message according to the type of the current scanning task, and save the extracted data in the second memory buffer of the scanning tool.

[0092] Among them, the response message can include a valid message and an invalid message. A valid message can be a message containing meaningful or available data for this scanning task, while an invalid message can be a message that does not contain valid information (meaningless for this scanning task). For example, in the scanning task of banner scanning, the device to be scanned often returns a response message with an empty payload value (indicating the actual information transmitted) after receiving a probe message, and this response message is meaningless for banner scanning, so it is an invalid message. Another example is that in the scanning task of port scanning, an unopened port of the device to be scanned can respond with an rst message. During penetration testing scanning, this rst message can help the scanner determine whether there is a firewall device in the middle. Therefore, this rst message is a valid message for penetration testing scanning. If it is port scanning, since the purpose of port scanning is to obtain device information through ports, and even if an rst message is received, the result is still that device information cannot be obtained. Therefore, the rst message is an invalid message for port scanning.

[0093] After the receiving module of the scanning tool receives the response message sent by the device to be scanned (the gateway receives the response message and then sends it to the receiving module), it can first filter the response message to reduce the number of subsequent data copies. Specifically, the receiving module can discard invalid messages, extract partial data of the valid message, and save the extracted partial data in the second memory buffer. Among them, when the receiving module extracts the data of the valid response message, since the scanning task may only need partial data in the response message and not all the data in the response message, and different types of scanning tasks can correspond to different partial data in the message. For example, in host discovery scanning, only the source IP address of the response message may be needed, and in port scanning, only the source IP address and source port of the response message may be needed. Therefore, this embodiment can extract partial data in the valid response message corresponding to the type of scanning task currently being executed, rather than extracting all the data in the response message, reducing the subsequent data copy volume.

[0094] If the amount of data stored in the second memory buffer exceeds the preset threshold, the receiving module aggregates the extracted data stored in the second memory buffer and uploads the aggregated extracted data to the data processing module. If no response message from the device port is received or no data upload is performed within the preset time, the extracted data stored in the second memory buffer is aggregated and the aggregated extracted data is uploaded.

[0095] Among them, the preset threshold can be a value configured in advance by a person. Data aggregation may refer to the process of combining multiple data into a unified data set according to certain rules and methods. Since the scanning tasks are executed serially and only the same type of scanning task is executed each time, the packets received by the receiving module are all response packets of the same type of scanning task. Therefore, in this embodiment, the partial data of multiple valid response packets in the second memory buffer can be aggregated first, and then the aggregated data can be uniformly uploaded to the data processing module, which can reduce both the amount of copied data and the number of copy operations.

[0096] Furthermore, in a high-concurrency scenario, a large number of response packets can be obtained in a short period of time. The processes such as data extraction from the response packets and data copying after data extraction can each be regarded as a thread. Therefore, the processing of a large number of response packets can also involve frequent context switching of multiple threads. The filtering of response packets in this embodiment can reduce the number of response packets to be processed, and the aggregated upload of data can also reduce the number of data uploads, thereby effectively reducing the overhead such as thread context switching and the number of memory copy operations, and effectively improving the processing performance.

[0097] Since in actual application scenarios, it is inevitable that the data stored in the second memory buffer does not exceed the preset threshold, making it difficult to trigger the aggregated upload. Therefore, to make this part of the data trigger the aggregated upload, it can be achieved by setting a timer. Specifically, in this embodiment, timing starts after each completion of the aggregated upload of data. When a response packet from the device port is received or data aggregated upload occurs, timing can start again after the aggregated upload. When no response packet from the device port is received or no data aggregated upload occurs within the preset time, all the current data saved in the second memory buffer can be aggregated and the aggregated data can be uploaded. Of course, when the current type of scanning task ends, all the current data in the second memory buffer can also be aggregated and the aggregated data can be uploaded.

[0098] So far, a specific embodiment is provided to illustrate the solution in this embodiment. Its device deployment method is as follows: The scanning tool in the scanning device is communicatively connected to the gateway through a scanning port. A scanning port has a fixed and unique IP address. The scanning tool is communicatively connected to the device ports of multiple devices to be scanned through the gateway. First, the scanning tool needs to be initialized and configured. The specific process can be as follows:

[0099] Load the send_pkg kernel driver module (transmission module): Pass the IP address and MAC address of the scanned port to the send_pkg module through the insmod loading parameters. During the loading and initialization operations of the send_pkg module, a first memory buffer can be applied for and a skb_buff can be constructed in the first memory buffer. Among them, skb_buff is a data structure of the probe packet constructed corresponding to different scan task types (such as ICMP requests, TCP SYN, TCP ACK, TCP RST, and various TCP PSH / ACK types). Among them, the insmod loading parameters can be: the parameters passed when using the insmod command, and the insmod command is usually used to add device drivers or extend kernel functions.

[0100] Load the pf_ring_fast kernel driver module (reception module), and the pf_ring_fast module can be obtained by secondary development based on the open-source pf_ring.ko in pf_ring. During the loading and initialization operations of pf_ring_fast, a second memory buffer can be applied for and the array in the second memory buffer can be initialized so that the data in the second memory buffer can be saved in the form of dpkg_data. Among them, pf_ring can be a general data packet capture tool that transmits all the data of the data packet to the application program for various needs.

[0101] Create shared memory between the send_pkg module and the pf_ring_fast module for the pf_ring_fast module to send notification events to the send_pkg module to synchronize TCP status information.

[0102] Therefore, in this embodiment, the scanning tool in the scanning device can include a transmission module (send_pkg), a first memory buffer, a reception module (pf_ring_fast), a second memory buffer, and shared memory. Then the running process of the scanning tool can include: configuring the scan task, configuring content distribution, the transmission module sending the probe packet, the reception module receiving the response packet, and processing the response packet data.

[0103] Configure the scan task, and the configuration content can include: scan task type, IP range to be scanned, scanned port and automatically obtain the IP address and MAC address of the scanned port, local gateway IP address, and the next-hop MAC address of the local gateway.

[0104] Configure content distribution. Send the configuration content to the transmission module and the reception module through the shared memory. Specifically, send the scan task type and the IP range to be scanned to the transmission module, and send the scan task type to the reception module.

[0105] The sending module sends a probe message. After receiving the configuration content, the sending module uses pointer operations with extremely low overhead according to the scan task type to read the skb_buff of the probe message corresponding to the scan task type from the first memory buffer. After obtaining the skb_buff data structure of the probe message, the sending module first uses the data update interface to replace the data content at the corresponding position in the skb_buff (such as the IP address of the destination device, the currently to-be-scanned port of the destination device, etc.), then calls the checksum update interface to update the checksums (check values) of each protocol layer, and finally calls the dev_queue_xmit_scan interface to send the probe message with the replaced data and updated checksum to the gateway, and the gateway sends it out.

[0106] Among them, the dev_queue_xmit_scan interface can be a new interface function obtained by optimizing the dev_queue_xmit of the linux kernel. Since the scan ports in this embodiment are only used to send probe messages, and the scan ports send the probe messages to the gateway one by one in sequence, after the probe message is sent to the gateway through the dev_queue_xmit_scan interface, the gateway can directly send the probe message out without queuing at the gateway. Since the sending module only reads the pre-constructed skb_buff in the first memory buffer through pointers and does not need to go through the cumbersome construction process of the probe message (system calls (runtime environment switching), creating sockets, creating skb_buff, copying the skb_buff multiple times, packet encapsulation at each layer, route query, address resolution, etc.), therefore, after the probe message is successfully sent, only relevant pointer variables and other data can be cleared, and the skb_buff data does not need to be released, reducing the overhead of creating and releasing the probe message.

[0107] If the type of the scanning task is port scanning or banner scanning, there may be response packets in the intermediate process. Therefore, before the sending module sends the probe packet, it is necessary to first read whether there is a notification event in the shared memory to determine the subsequent execution steps. If there is a notification event, according to the response packet type carried by the notification event and the device information for sending the response packet, read the skb_buff of the corresponding probe packet from the first memory buffer, change the data content at the corresponding position in the skb_buff, update the checksum of each protocol layer, and call the dev_queue_xmit_scan interface to send the probe packet with the replaced data and updated checksum as a response packet to the gateway, which is then sent out by the gateway. If there is no notification event and there are still destination devices that have not been scanned, continue to construct the probe packets for the destination devices and execute the scanning task. If there is no notification event and all destination devices have been scanned, feedback the information that the scanning task has been completed to the upper-layer scanning application program.

[0108] The receiving module receives the response packet. After the receiving module obtains the response packet, it first passes through the filtering interface of the response packet to discard the invalid response packets or synchronize the handshake information to the sending module. If it is a valid packet (the response packet that needs to be uploaded to the scanning application program), the response packet processing interface is executed, and the partial valid information corresponding to the scanning task type is extracted from the response packet. The data integration interface is called to store the partial valid information in the second memory buffer. When the data volume in the second memory buffer exceeds the threshold, the response packet data in the second memory buffer is assembled into a specified data format and then the data is put into the ring transmission queue at one time and uploaded to the scanning application program.

[0109] Among them, the response packet receiving and processing process in this embodiment may include pkg_recv (for receiving the response packet), add_skb_to_ring (for caching the response packet), filter_skb_to_ring (for filtering invalid packets), add_pkt_to_ring (for caching valid packets), pkt_handler_fast (for extracting data, storing the data in the buffer array, and data aggregation), copy_data_to_ring_fast (for formatting the data and passing it to the user-mode handler), and pf_ring_recv_fast (for receiving data).

[0110] In this embodiment, filter_skb_to_ring and pkt_handler_fast are added to the original process. filter_skb_to_ring discards invalid response packets in the early stage of response packet processing, and notifies the sending module to send packets of the next process when receiving intermediate process response packets of TCP type scans. pkt_handler_fast extracts partial data from valid response packets according to the scan task type, stores the extracted data in an array in the second memory buffer, aggregates the data according to certain judgment conditions, and passes the aggregated data to the copy_data_to_ring_fast interface.

[0111] The copy_data_to_ring_fast interface is implemented based on the copy_data_to_ring interface of the original process, and can modify the serialization and formatting operations of data transmission. Since the transmission process of pf_ring in the kernel state is modified, the user-space receiving API: pf_ring_recv is correspondingly modified to obtain pf_ring_recv_fast.

[0112] Response packet data processing. The upper-layer scanning application calls the pf_ring_recv_fast interface to read the uploaded response packet data and execute the scanning service processing logic function.

[0113] The above introduces a network asset scanning method provided by an embodiment of the present application. The following will introduce a scanning tool for executing the above network asset scanning method.

[0114] Please refer to Figure 3 , Figure 3 which is a schematic structural diagram of a scanning tool provided by an embodiment of the present application. As Figure 3 shown, the scanning tool communicates with the gateway through a scanning port. A scanning port has a fixed and unique IP address. The scanning tool communicates with the device ports of multiple devices to be scanned through the gateway. The scanning tool may include:

[0115] A response unit 100, configured to obtain a scan task instruction, where the scan task instruction includes: multiple types of scan tasks and the device ports of multiple devices to be scanned corresponding to each type of scan task;

[0116] A sending unit 110, configured to determine one type of scan task in the scan task instruction as the current scan task in a preset order, and perform the following processing on the current scan task:

[0117] Read the packetized probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool. Multiple probe message templates are stored in the first memory buffer, and each probe message template corresponds to a type of scanning task. Determine a device port that has not sent a probe message corresponding to the current scanning task as the current port to be scanned. Set the destination device information carried in the probe message template to the information of the current port to be scanned to generate the current probe message for the current port to be scanned, and generate the check value of the current probe message. Among them, the destination device information carried in different current probe messages is different. Send the current probe message and the check value to the gateway through the scanning port, so that the gateway sends the current probe message and the check value to the current port to be scanned, and return to execute the step of reading the packetized probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool.

[0118] In a possible implementation, the scanning tool may further include a receiving unit, and the receiving unit may be specifically configured as:

[0119] Receive the response message of the current port to be scanned sent by the gateway; if the response message is an invalid message, discard the response message; if the response message is a valid message, extract at least part of the data in the response message according to the type of the current scanning task, and save the extracted data in the second memory buffer of the scanning tool.

[0120] In a possible implementation, the above receiving unit may further be configured as:

[0121] If the amount of data stored in the second memory buffer exceeds the preset threshold, aggregate the extracted data stored in the second memory buffer, and upload the aggregated extracted data to the data processing module.

[0122] In a possible implementation, the above receiving unit may further be configured as:

[0123] If no response message from the device port is received or no data upload is performed within the preset time, aggregate the extracted data stored in the second memory buffer, and upload the aggregated extracted data.

[0124] In a possible implementation, before the sending unit 110 reads the packetized probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool, the sending unit 110 may further be configured as:

[0125] Read whether there is a notification event in the shared memory. The notification event is that the scanning tool is prompted to send a response message of the scanning tool to the first scanning port. The notification event carries: the type of the response message returned by the first scanning port and the information of the first scanning port. If there is a notification event in the shared memory, determine the target type of the scanning task according to the type of the response message returned by the first scanning port, and read the packetized first probe message template corresponding to the target type of the scanning task from the first memory buffer of the scanning tool. Set the destination device information carried in the first probe message template to the information of the first scanning port to generate the first probe message of the first scanning port, and generate the check value of the first probe message. Use the first probe message as the response message of the scanning tool, and send the first probe message and the check value of the first probe message to the gateway through the scanning port, and the gateway sends the first probe message and the check value of the first probe message to the first scanning port.

[0126] In a possible implementation, the sending unit 110 can also be configured as:

[0127] When the scanning tool needs to stop the current scanning task of the current port to be scanned, send a probe end message to the gateway, so that the gateway sends a probe end message to the current port to be scanned.

[0128] An electronic device is also provided in an embodiment of the present application. Refer to Figure 4 As shown, it shows a schematic structural diagram of an electronic device suitable for implementing the electronic device in the embodiment of the present application. The electronic device in the embodiment of the present application can include, but is not limited to, fixed terminals such as mobile phones, laptop computers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), desktop computers, and so on. Figure 4 The electronic device shown is only an example and should not impose any limitations on the functions and usage scopes of the embodiments of the present application.

[0129] As Figure 4 shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 401, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 402 or the program loaded from the storage device 408 into the random access memory (RAM) 403. When the electronic device is powered on, various programs and data required for the operation of the electronic device are also stored in the RAM 403. The processing device 401, the ROM 402, and the RAM 403 are connected to each other through a bus 404. The input / output (I / O) interface 405 is also connected to the bus 404.

[0130] Typically, the following devices can be connected to the I / O interface 405: input devices 406 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; output devices 407 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 408 including, for example, a memory card, a hard disk, etc.; and a communication device 409. The communication device 409 can allow the electronic device to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 4 an electronic device with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices can be implemented or had.

[0131] An embodiment of the present application also provides a computer program product including computer-readable instructions, which, when running on an electronic device, enable the electronic device to implement any one of the network asset scanning methods provided by the embodiments of the present application.

[0132] An embodiment of the present application also provides a computer-readable storage medium carrying one or more computer programs, which, when executed by an electronic device, can enable the electronic device to implement any one of the network asset scanning methods provided by the embodiments of the present application.

[0133] In addition, it should be noted that the scanning tool embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the drawings of the scanning tool embodiments provided by the present application, the connection relationship between the modules indicates that they have a communication connection, which can be specifically implemented as one or more communication buses or signal lines.

[0134] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus necessary general hardware. Of course, it can also be implemented by dedicated hardware including application-specific integrated circuits, dedicated CPUs, dedicated memories, dedicated components, etc. Generally, functions completed by computer programs can be easily implemented by corresponding hardware, and the specific hardware structures used to implement the same function can also be various, such as analog circuits, digital circuits, or dedicated circuits, etc. However, for the present application, in more cases, software program implementation is a better implementation manner. Based on such an understanding, the technical solution of the present application, in essence, or the part that makes a contribution to the prior art, can be embodied in the form of a software product. The computer software product is stored in a readable storage medium, such as a floppy disk, USB flash drive, mobile hard disk, ROM, RAM, magnetic disk, or optical disc of a computer, etc., and includes several instructions to enable a computer device (which can be a personal computer, training device, or network device, etc.) to execute the methods described in various embodiments of the present application.

[0135] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product.

[0136] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a dedicated computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, training device, or data center to another website, computer, training device, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can store, or a data storage device such as a training device or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state disk (SSD)), etc.

[0137] Each embodiment in this specification is described in a related manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiments.

[0138] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the users and the authorization of the users should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0139] The above are only the embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A network asset scanning method, characterized in that, Applied to a scanning tool, the scanning tool is communicatively connected to a gateway through a scanning port, the scanning port has a fixed and unique IP address, and the scanning tool is communicatively connected to device ports of multiple devices to be scanned through the gateway. The network asset scanning method includes: Obtain a scanning task instruction, where the scanning task instruction includes: multiple types of scanning tasks and device ports of multiple devices to be scanned corresponding to each type of scanning task; Determine one type of scanning task in the scanning task instruction as the current scanning task in a preset order, and perform the following processing on the current scanning task: Read a packetized probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool. Multiple probe message templates are stored in the first memory buffer, and each probe message template corresponds to one type of scanning task; Determine a device port that has not sent a probe message corresponding to the current scanning task as the current port to be scanned; Set the destination device information carried in the probe message template to the information of the current port to be scanned to generate a current probe message for the current port to be scanned, and generate a check value for the current probe message. Different current probe messages carry different destination device information; Send the current probe message and the check value to the gateway through the scanning port, so that the gateway sends the current probe message and the check value to the current port to be scanned, and return to execute the step of reading a packetized probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool.

2. The network asset scanning method according to claim 1, wherein The network asset scanning method further includes: Receive a response message of the current port to be scanned sent by the gateway; If the response message is an invalid message, discard the response message; If the response message is a valid message, extract at least part of the data in the response message according to the type of the current scanning task, and save the extracted data in the second memory buffer of the scanning tool.

3. The network asset scanning method according to claim 2, wherein The network asset scanning method further includes: If the amount of data stored in the second memory buffer exceeds a preset threshold, aggregate the extracted data stored in the second memory buffer, and upload the aggregated extracted data to a data processing module.

4. The network asset scanning method according to claim 3, wherein The network asset scanning method further includes: If no response message from the device port is received or no data upload is performed within a preset time, aggregate the extracted data stored in the second memory buffer, and upload the aggregated extracted data.

5. The network asset scanning method according to claim 1, wherein, Before reading a packetized probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool, the network asset scanning method further includes: Read whether there is a notification event in the shared memory. The notification event is: a prompt that the scanning tool needs to send a response message of the scanning tool to the first scanning port. The notification event carries: the type of the response message returned by the first scanning port and the information of the first scanning port; If there is a notification event in the shared memory, determine the target type of the scanning task according to the response message type returned by the first scanning port, and read the packetized first probe message template corresponding to the target type of the scanning task from the first memory buffer of the scanning tool; Set the destination device information carried in the first probe message template to the information of the first scanning port to generate the first probe message of the first scanning port, and generate the check value of the first probe message; Use the first probe message as the response message of the scanning tool, and send the first probe message and the check value of the first probe message to the gateway through the scanning port. The gateway sends the first probe message and the check value of the first probe message to the first scanning port.

6. The network asset scanning method according to claim 1, wherein The network asset scanning method further includes: When the scanning tool needs to stop the current scanning task of the current port to be scanned, send a probe end message to the gateway, so that the gateway sends a probe end message to the current port to be scanned.

7. A scanning tool, characterized in that, The scanning tool is communicatively connected to the gateway through a scanning port. The scanning port has a fixed and unique IP address. The scanning tool is communicatively connected to the device ports of multiple devices to be scanned through the gateway. The scanning tool includes: A response unit, configured to obtain a scanning task instruction, where the scanning task instruction includes: multiple types of scanning tasks and the device ports of multiple devices to be scanned corresponding to each type of scanning task; A sending unit, configured to determine one type of scanning task in the scanning task instruction as the current scanning task in a preset order, and perform the following processing on the current scanning task: Read the packetized probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool. The first memory buffer stores multiple probe message templates, and each probe message template corresponds to one type of scanning task; determine a device port that has not sent a probe message corresponding to the current scanning task as the current port to be scanned; set the destination device information carried in the probe message template to the information of the current port to be scanned to generate the current probe message of the current port to be scanned, and generate the check value of the current probe message, where the destination device information carried in different current probe messages is different; send the current probe message and the check value to the gateway through the scanning port, so that the gateway sends the current probe message and the check value to the current port to be scanned, and return to execute the step of reading the packetized probe message template corresponding to the type of the current scanning task from the first memory buffer of the scanning tool.

8. The scanning tool according to claim 7, wherein, The scanning tool further includes a receiving unit, and the receiving unit is specifically configured as: Receive the response message of the currently to-be-scanned port sent by the gateway; if the response message is an invalid message, discard the response message; if the response message is a valid message, extract at least part of the data in the response message according to the type of the current scanning task, and save the extracted data in the second memory buffer of the scanning tool.

9. An electronic device, characterized in that, Comprising at least one processor and a memory connected to the processor, wherein: The memory is used for storing computer programs; The processor is used for executing the computer program so that the electronic device can implement the network asset scanning method as described in any one of claims 1 to 6.

10. A computer program product, characterized in that, Comprising computer-readable instructions, when the computer-readable instructions run on an electronic device, enabling the electronic device to implement the network asset scanning method as described in any one of claims 1 to 6.