Precise affiliation discrimination method for surveying and mapping nodes of cyberspace surveying and mapping platform
By deploying honeypot nodes in the public IPv4 space and generating false HTTP responses of encrypted tags, combining API and web crawling technology decryption and database query, the problem of inaccurate home judgment of surveying and mapping nodes on the network space surveying and mapping platform is solved, and accurate home judgment and network security protection are achieved.
Patent Information
- Application Number
- CN202510557336.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-08-05
AI Technical Summary
It is difficult for the prior art to achieve accurate attribution judgment of surveying and mapping nodes of cyberspace surveying and mapping platforms, especially when the surveying and mapping nodes do not disclose the information of their surveying and mapping platform and lack clear domain name identification, traditional methods cannot accurately judge their behavior and purpose.
Deploy honeypot nodes in the public IPv4 space to capture the detection data packets of the surveying and mapping platform, generate false HTTP responses with encrypted tags, and obtain the response information of the surveying and mapping platform through API technology or web crawler technology. After decrypting the tag, it combines with database query to achieve accurate attribution judgment.
It realizes that without interfering with the conventional workflow of the surveying and mapping platform, accurately identify the IP address of the surveying and mapping nodes, ensure data concealment and security, improve discrimination efficiency, support large-scale data capture and analysis, and improve network security defense capabilities.
Smart Images

Figure CN120433979A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of surveying and mapping node identification, and in particular to a method for accurately identifying the ownership of surveying and mapping nodes on a cyberspace surveying and mapping platform. Background Art
[0002] The rapid development and widespread promotion of cyberspace mapping technology have greatly promoted people's comprehensive understanding of various network resources and their attributes, and also provided great convenience for attackers to draw "attack surface maps", which will seriously endanger the country's cyberspace security. A large number of illegal cyberspace mapping activities at home and abroad have wantonly stolen key information from my country's network, posing a serious threat to the security of critical information infrastructure. Traditional IP address attribution can only determine the IP's location information such as country, region, city, longitude and latitude, autonomous system and domain name information, but this information is not sufficient to determine the behavior and purpose of the IP in cyberspace. Therefore, the invention of accurate attribution determination of mapping nodes on the cyberspace mapping platform is of great significance.
[0003] Existing technologies analyze the IP addresses of surveying and mapping nodes, using methods such as reverse DNS, WHOIS, or machine learning clustering to determine their ownership. Existing technologies rely on the information contained in the IP addresses of surveying and mapping nodes themselves, but when surveying and mapping nodes neither disclose the mapping platform they belong to nor lack clear domain name identifiers, accurate ownership determination becomes difficult. Summary of the Invention
[0004] The present application aims to solve one of the technical problems in the related art at least to a certain extent.
[0005] To this end, the first purpose of this application is to propose a method for accurately identifying the ownership of mapping nodes in a cyberspace mapping platform.
[0006] The second objective of this application is to provide an electronic device.
[0007] The third object of this application is to provide a computer-readable storage medium.
[0008] A fourth object of this application is to provide a computer program product.
[0009] To achieve the above objectives, the first embodiment of the present application proposes a method for accurately determining the ownership of mapping nodes on a cyberspace mapping platform, comprising:
[0010] Deploy at least one honeypot node in the public IPv4 space, wherein the honeypot node is used to capture a probe data packet from the cyberspace mapping platform, wherein the probe data packet includes the IP address, port, and probe initiation timestamp of the probe initiator;
[0011] In response to the network space mapping platform actively initiating mapping of the honeypot node deployed on the public network, the honeypot node generates a false HTTP response with an encryption tag when receiving a detection data packet, and returns the false HTTP response to the network space mapping platform;
[0012] The honeypot node saves the captured detection data packet information into the database;
[0013] In response to the cyberspace mapping platform publishing the response information of the honeypot node, the response information on the cyberspace mapping platform page is obtained through API technology or web crawler technology;
[0014] Decrypt the encrypted label in the public response information, and determine the IP address of the mapping node corresponding to the response information based on the detection data queried from the database, so as to achieve accurate ownership identification of the mapping node of the cyberspace mapping platform.
[0015] Optionally, the honeypot node generates a false HTTP response with an encryption tag when receiving the probe data packet, and returns the false HTTP response to the cyberspace mapping platform, including:
[0016] generating an encryption tag based on the IP address, port, and timestamp in the probe data packet;
[0017] Encrypting the encryption tag using symmetric encryption technology to generate encrypted tag information;
[0018] Embed the encrypted tag information into the corresponding field of the fake HTTP response;
[0019] Return a fake HTTP response with an encrypted tag to the cyberspace mapping platform.
[0020] Optionally, in response to the cyberspace mapping platform publishing the response information of the honeypot node, obtaining the response information on a webpage of the cyberspace mapping platform by using an API technology or a web crawler technology includes:
[0021] In response to the honeypot node being detected, the cyberspace mapping platform publishes the response information of the honeypot node and searches for the honeypot node on each cyberspace mapping platform through a mapping platform aggregate search program;
[0022] The query interface provided by the cyberspace mapping platform is called through the API interface to obtain the response information of the honeypot node; if the cyberspace mapping platform does not provide an API interface or the API interface cannot obtain the response information, the response information of the honeypot node is directly captured from the cyberspace mapping platform page through web crawler technology.
[0023] Optionally, the decryption of the encrypted tag in the public response information and the determination of the IP address of the mapping node corresponding to the response information based on the detection data queried from the database to achieve accurate attribution determination of the mapping node of the cyberspace mapping platform include:
[0024] Decrypt the encrypted tag in the public response information and restore the original information in the encrypted tag;
[0025] According to the decrypted label information, query the database for a corresponding detection data record, wherein the detection data record includes detection data packet information related to the response information;
[0026] The decrypted label information is associated with the IP address, port and detection initiation timestamp in the queried detection data packet information to determine the IP address of the mapping node corresponding to the response information, thereby realizing accurate identification of the ownership of the mapping node of the cyberspace mapping platform.
[0027] To achieve the above-mentioned purpose, a second embodiment of the present application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor;
[0028] The memory stores computer-executable instructions;
[0029] The processor executes the computer-executable instructions stored in the memory to implement the method as described in any one of the first aspects above.
[0030] To achieve the above-mentioned purpose, the third aspect embodiment of the present application proposes a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the method as described in any one of the above-mentioned first aspects.
[0031] To achieve the above-mentioned purpose, the fourth embodiment of the present application proposes a computer program product, including a computer program, which implements the method as described in any one of the above-mentioned first aspects when executed by a processor.
[0032] The technical solutions provided by the embodiments of this application bring at least the following beneficial effects:
[0033] By deploying honeypot nodes in the public IPv4 network and capturing probe packets from the surveying and mapping platform, this approach accurately identifies and attributes the IP address of each surveying and mapping node, overcoming the inaccurate attribution inherent in traditional methods due to the concealed nature of the probe platform. By encrypting the tag information using the symmetric AES encryption technology within the fake HTTP responses generated by the honeypot, the true information of the surveying and mapping nodes is not directly exposed, ensuring data confidentiality and security. This technical solution accurately attributes surveying and mapping nodes without disrupting the regular workflow of the surveying and mapping platform, demonstrating strong compatibility and adaptability. Leveraging existing surveying and mapping platforms and cyberspace surveying and mapping technologies, this approach eliminates the need to modify the platform's behavior. Through automated capture, decryption, and database query processes, this solution rapidly attributes surveying and mapping nodes, reducing manual intervention and complex steps, and significantly improving identification efficiency. This technical solution supports large-scale data capture and analysis through the deployment of multiple honeypot nodes, adapting to various scales of cyberspace surveying and mapping needs. Furthermore, it offers flexible access to response information from the surveying and mapping platform through APIs or web crawlers, demonstrating strong scalability. Finally, by accurately identifying the ownership of surveying and mapping nodes, this technical solution can provide effective information support for network security protection, helping network administrators and security experts identify potential malicious surveying and mapping activities, thereby improving overall network security defense capabilities.
[0034] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:
[0036] Figure 1 A flowchart of a method for accurately determining the ownership of mapping nodes on a cyberspace mapping platform provided in an embodiment of the present application;
[0037] Figure 2 A flowchart of a method for accurately determining the ownership of mapping nodes on a cyberspace mapping platform provided in an embodiment of the present application. DETAILED DESCRIPTION
[0038] The following describes in detail embodiments of the present application. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.
[0039] In order to solve the technical problem that most network space mapping platforms do not disclose the mapping nodes they use during network mapping, the present application provides a method for accurately identifying the ownership of mapping nodes on a network space mapping platform. Figure 1 and Figure 2 This is a flow chart of a method for accurately identifying the ownership of a network space mapping platform mapping node provided in an embodiment of the present application. Figure 1 and Figure 2 As shown, the method includes the following steps:
[0040] Step 101: deploy at least one honeypot node in the public IPv4 space. The honeypot node is used to capture detection data packets from the cyberspace mapping platform. The detection data packets include the IP address, port and detection initiation timestamp of the detection initiator.
[0041] In this embodiment, step 101 describes in detail how to deploy honeypot nodes in the public IPv4 space to capture probe packets from the cyberspace mapping platform. The core purpose of this step is to attract and record probes from the mapping platform through the deployment of honeypot nodes, providing basic data for subsequent attribution determination.
[0042] In this embodiment of the present application, the honeypot node is deployed in the public IPv4 space to ensure that it can be detected by the cyberspace mapping platform. The deployment location is chosen based on its direct exposure to the external network environment, so that the detection behavior of the mapping platform can trigger the capture of the honeypot node without any obstacles.
[0043] It's understandable that the probe packets received by the honeypot node contain the following key information: the surveying platform's IP address (src_ip), port number (src_port), and the probe initiation timestamp (timestamp). This information helps identify the probe source and provides a basis for subsequent attribution determination. The source of the probe packet (i.e., the surveying platform's IP address) and its initiation time and port number form the basis for accurate attribution determination.
[0044] By deploying honeypot nodes in the public IPv4 space, this application can effectively capture and record all detection activities from the cyberspace mapping platform. The advantage of this deployment method is that it does not require any modifications to the mapping platform itself, and can leverage the capture capabilities of the honeypot nodes to indirectly collect the mapping platform's detection data, enhancing the compatibility and operability of this method.
[0045] It's important to note that honeypot node deployment isn't a single requirement; it can be flexibly expanded based on actual needs. Deployment can be single or multiple, and the specific number of honeypot nodes can be adjusted based on needs. Parallel deployment of multiple honeypot nodes can cover a wider range of public IPv4 space, further improving the coverage and accuracy of capturing surveying and mapping platform detection packets. By enabling multiple nodes to work together, it can effectively handle large-scale surveying and mapping platform detection activities and enhance the accuracy of attribution determination.
[0046] In summary, step 101 successfully captures probe packets from the cyberspace mapping platform by deploying honeypot nodes in the public IPv4 space. This provides critical raw data for subsequent encryption label generation, false response generation, and accurate attribution determination. This step is a crucial foundational step in the entire technical solution, ensuring the smooth implementation of the subsequent identification process.
[0047] Step 102, in response to the cyberspace mapping platform actively initiating mapping of the honeypot node deployed on the public network, the honeypot node generates a false HTTP response with an encryption tag when receiving the detection data packet, and returns the false HTTP response to the cyberspace mapping platform.
[0048] In the embodiment of the present application, step 102 describes in detail how the honeypot node responds to the detection initiated by the cyberspace mapping platform and generates a fake HTTP response with an encrypted tag. This process can be done by Figure 2 Implementation of honeypot-based traffic collection and response module.
[0049] Specifically, step 102 includes the following operations:
[0050] First, cyberspace mapping platforms (such as Censys, ZoomEye, Shodan, FOFA, etc.) will proactively initiate mapping of honeypot nodes deployed in the public IPv4 space. These platforms will use roughly the same detection methods to actively scan devices, ports, and services in the public network through different probes deployed by each platform, thereby collecting device information in the cyberspace. These platforms obtain detailed data about public network devices by detecting the open ports, service types, and other network features of the devices. In the embodiment of the present application, the honeypot node plays an important role in this environment. It collects data from the mapping platform by attracting the detection requests initiated by the mapping platform, and makes false responses based on this.
[0051] It's understandable that cyberspace mapping platforms typically send probe packets containing information such as the source IP address, port number, and probe timestamp. Honeypot nodes, by receiving these probe packets, can capture and extract key data, including the mapping platform's IP address (src_ip), port number (src_port), and probe initiation timestamp (timestamp). This information is not only used for subsequent encrypted label generation but also provides foundational data for accurate attribution determination.
[0052] Next, the honeypot node generates an encrypted tag based on the information in the received probe packet. The generated encrypted tag contains the probe source information from the mapping platform, such as the source IP address, source port, and probe timestamp. This information is encrypted in the tag to ensure data confidentiality and security. It is important to note that during the generation of the encrypted tag, the honeypot node applies symmetric encryption technology (such as AES encryption) to the tag information, ensuring that even if the mapping platform receives the false response, it cannot easily parse the sensitive probe source data.
[0053] The honeypot node then embeds the encrypted tag information into the corresponding fields of a fake HTTP response. These fake responses appear similar to legitimate HTTP responses, but in reality, they carry hidden encrypted tag information. This design ensures that the mapping platform believes its probe has been successfully responded to while also protecting sensitive information from being easily leaked.
[0054] Finally, the honeypot node returns a fake HTTP response with an encrypted tag to the cyberspace mapping platform. Upon receiving this fake response, the mapping platform continues its normal detection process. However, the response it has received does not actually represent real device or service data, but rather an encrypted fake response. This successfully misleads the mapping platform's detection behavior and provides an encrypted tag for subsequent attribution determination.
[0055] Understandably, this process is virtually transparent to the cyberspace mapping platform. Although the platform receives a fake HTTP response, it cannot recognize the encrypted tag within it, nor does it realize that its detection behavior is being masked by the honeypot node. Therefore, the platform continues its detection mission, while the honeypot node successfully redirects its behavior by generating fake responses, while simultaneously protecting the privacy of network devices.
[0056] In summary, step 102 conceals the mapping node's detection behavior by generating a fake HTTP response with an encrypted tag and returning it to the mapping platform. In this way, the honeypot node can effectively guide the mapping platform's detection while providing encrypted, secure response information for subsequent analysis, ensuring the reliability and security of the entire attribution determination process.
[0057] Step 103: The honeypot node saves the captured detection data packet information into a database.
[0058] In the embodiment of the present application, step 103 describes how the honeypot node saves the captured detection data packet information into the database to ensure that all captured data can be effectively integrated by the system and subsequently analyzed. This process can be done by Figure 2 The detection record storage database module shown in is implemented. The core purpose of this process is to provide reliable database support for subsequent attribution discrimination and analysis.
[0059] Specifically, step 103 includes the following operations:
[0060] When a honeypot node receives a probe packet from a cyberspace mapping platform, each captured packet contains key information, such as the mapping platform's IP address (src_ip), port number (src_port), and the timestamp of the probe initiation (timestamp). This information not only records the mapping behavior but also serves as an important basis for subsequent encryption tag generation, false response generation, and attribution determination.
[0061] Next, the honeypot node saves the captured probe packet information to a database in real time. This ensures long-term data storage and traceability, facilitating subsequent data analysis. By storing probe packets in the database, the system can efficiently process data from different surveying platforms and different surveying activities, ensuring data integrity and accuracy.
[0062] In one embodiment of the present application, the honeypot node records the key information of each probe request in the database in JSON format. JSON is a common and efficient data exchange format that can effectively store various types of data and has good compatibility. This format makes data storage and retrieval more convenient, especially when large amounts of probe data need to be analyzed. JSON ensures that the data structure is clear and easy to process.
[0063] In an embodiment of the present application, the deployment of multiple honeypot nodes enables the entire system to cover a wider range of network space. These honeypot nodes work together to collect detection data from each platform by capturing detection requests initiated by different surveying and mapping platforms (such as Censys, ZoomEye, Shodan, FOFA, etc.). Therefore, when saving data, the honeypot node not only saves the detection data packet of a single node, but also integrates the data from different honeypot nodes. This data integration method can improve the coverage and accuracy of data capture and provide more comprehensive raw data for subsequent analysis.
[0064] It can be understood that by coordinating the deployment of multiple honeypot nodes, this application achieves the collection and integration of extensive detection data. The detection data packets collected by each honeypot node will be saved in the database. The aggregation of all these data will provide rich data support for subsequent attribution discrimination analysis. Honeypot nodes are not only recorders of a single data source, but also basic components for the overall data integration and analysis of the system.
[0065] Furthermore, the database in the embodiments of the present application is not only used to store data packet information, but also provides efficient data support for subsequent queries and analysis. For example, when attribution determination is required, the database can provide stored detection data packet information, which can be compared with the decrypted data from the encrypted tag to help determine the true IP address of the mapping node.
[0066] In summary, step 103 provides solid data support for the entire attribution determination process by storing the captured probe packet information in a database and integrating and analyzing the data through multiple honeypot nodes. This process ensures that all relevant data is systematically stored and accessible at any time, laying the foundation for subsequent analysis and processing.
[0067] Step 104 , in response to the response information of the public honeypot node of the cyberspace mapping platform, the response information in the web page of the cyberspace mapping platform is obtained through API technology or web crawler technology.
[0068] In the embodiment of the present application, step 104 describes in detail how to respond to the response information of the public honeypot node of the cyberspace mapping platform and obtain this information through API technology or web crawler technology.
[0069] Specifically, step 104 includes the following operations:
[0070] First, in response to the honeypot node being detected by the mapping platform, the cyberspace mapping platform will publish the honeypot node's response information. At this time, the relevant information of the honeypot node (such as IP address, port number, service type, operating system information, etc.) will be made public on the mapping platform page for users to query.
[0071] To obtain these public response information, the embodiment of the present application is as follows Figure 2 The aggregate search program shown performs search tasks on different mapping platforms (such as Censys, Shodan, ZoomEye, FOFA, etc.). Through aggregate search, it is possible to ensure that public response information about honeypot nodes is collected from multiple platforms, thereby enhancing the comprehensiveness and accuracy of the data.
[0072] After searching for the response information of the honeypot node, two methods are used in the embodiment of the present application to obtain this information from the cyberspace mapping platform.
[0073] It's understandable that some cyberspace mapping platforms (such as Censys, Shodan, ZoomEye, and FOFA) provide APIs, allowing users to programmatically call these interfaces and retrieve relevant response information. If a cyberspace mapping platform provides an API, honeypot node responses can be retrieved through API calls. This method can efficiently and automatically retrieve large amounts of honeypot node data, avoiding the complexity of manual queries.
[0074] If the cyberspace mapping platform doesn't provide an API, or the provided API is unable to retrieve responses from honeypot nodes, web crawling can be used to obtain responses. Web crawlers can simulate a user accessing the cyberspace mapping platform's webpage and directly capture responses from honeypot nodes. Crawling technology parses the HTML content of webpages, extracts relevant response data, and stores it as usable information. This approach is particularly suitable for platforms where data cannot be accessed through APIs.
[0075] In summary, step 104 searches for honeypot nodes across multiple cyberspace mapping platforms using the mapping platform aggregate search program. After successfully obtaining response information, the required data is further extracted using API technology or web crawler technology. Regardless of whether the mapping platform provides an API interface, the combination of these two technologies ensures that this application can flexibly and efficiently obtain response information from honeypot nodes on different platforms, providing strong data support for subsequent analysis and attribution determination.
[0076] Step 105, decrypt the encrypted tag in the public response information, and determine the IP address of the mapping node corresponding to the response information based on the detection data queried from the database, so as to achieve accurate ownership identification of the mapping node of the cyberspace mapping platform.
[0077] In the embodiment of the present application, step 105 describes in detail how to decrypt the encrypted tag in the public response information and determine the IP address of the mapping node based on the queried detection data, thereby achieving accurate attribution judgment of the mapping node of the cyberspace mapping platform. This process can be achieved through Figure 2 The shown program implementation of the home discriminant analysis.
[0078] Specifically, step 105 includes the following operations:
[0079] In the embodiments of this application, the public response information includes encrypted tags that contain hidden information related to the surveying and mapping platform's detection. For example, the tags may include the surveying and mapping platform's IP address, port number, and detection timestamp. This information is encrypted in the response information to prevent the source information of the surveying and mapping platform from being directly exposed.
[0080] It is understood that the purpose of decrypting these encrypted tags is to recover the original information contained in the tags. The recovered tag information will provide key information about the surveying and mapping platform, such as the surveying and mapping platform's IP address (src_ip), source port number (src_port), and the timestamp of the detection initiation (timestamp). To achieve this, symmetric encryption technology (such as the AES algorithm) is usually used for decryption. During the decryption process, the key is used to recover the original data in the encrypted tag, allowing the surveying and mapping platform's detection source information to be recovered and used for further analysis.
[0081] Next, the embodiment of the present application queries the database for relevant probe data records based on the decrypted tag information. These probe data records contain detailed information about the probe packet associated with the response information, such as the source IP address, source port number, and detection timestamp. This information is compared with the decrypted information in the tag. This probe data can further confirm and verify the accuracy of the response information and help determine the ownership of the surveying node.
[0082] The decrypted tag information is then correlated with the IP address, port number, and probe initiation timestamp in the retrieved probe packet. By comparing the IP address, port number, and timestamp in the decrypted tag with the probe packet information in the database, the IP address of the mapping node corresponding to the response message can be determined. This comparison and correlation process ensures that each response message is accurately matched to a specific mapping node, thereby achieving precise attribution determination.
[0083] It can be understood that, through this approach, the present embodiment of the application can accurately determine the ownership of the mapping nodes of the cyberspace mapping platform. By decrypting the label, querying the detection data in the database, and performing information comparison, the present embodiment of the application can identify the true IP address of the mapping platform, avoiding misjudgments caused by encrypted labels and false responses.
[0084] In summary, step 105 decrypts the encrypted tag in the public response message and combines it with the detection data retrieved from the database to accurately determine the IP address of the surveying and mapping node corresponding to the response message. This process not only effectively protects the surveying and mapping platform's detection source information but also provides reliable data support for subsequent network security analysis and attribution determination.
[0085] In order to implement the above embodiments, the present application also proposes a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the methods provided in the above embodiments.
[0086] In order to implement the above embodiments, the present application also proposes a computer program product, including a computer program, which implements the methods provided by the above embodiments when executed by a processor.
[0087] The collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in this application are in compliance with relevant laws and regulations and do not violate public order and good morals.
[0088] It is important to note that personal information collected from users should be used for legitimate and reasonable purposes and should not be shared or sold beyond these legitimate uses. Furthermore, such collection / sharing should be conducted only after receiving the user's informed consent, including but not limited to notifying the user to read the user agreement / user notice and sign an agreement / authorization that includes the relevant user information before using the feature. Furthermore, any necessary steps must be taken to safeguard and secure access to such personal information and ensure that others with access to personal information comply with its privacy policy and procedures.
[0089] This application contemplates providing implementations that allow users to selectively block the use or access of personal information data. Specifically, this disclosure contemplates providing hardware and / or software to prevent or block access to such personal information data. Risks can be minimized by limiting data collection and deleting data once it is no longer needed. Furthermore, where applicable, such personal information can be de-identified to protect user privacy.
[0090] In the descriptions of the foregoing embodiments, the reference terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, unless they are mutually inconsistent.
[0091] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of such features. Throughout the description of this application, "plurality" means at least two, for example, two, three, etc., unless otherwise specifically defined.
[0092] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present application belong.
[0093] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and programmable read-only memory (EPROM or flash memory), fiber optic devices, and a portable compact disc read-only memory (CDROM). Furthermore, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or processing it in another suitable manner if necessary, and then storing it in a computer memory.
[0094] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0095] Those skilled in the art will understand that all or part of the steps in the method of the above embodiment can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.
[0096] In addition, the functional units in the various embodiments of the present application may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into a module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.
[0097] The storage medium mentioned above may be a read-only memory, a magnetic disk, or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present application. Persons skilled in the art may make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.
[0098] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this application can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of this application can be achieved. This is not limited herein.
[0099] The above specific embodiments do not constitute a limitation on the scope of protection of this application. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application shall be included within the scope of protection of this application.
Claims
1. A method for accurately identifying the ownership of mapping nodes on a cyberspace mapping platform, characterized in that: include: Deploy at least one honeypot node in the public IPv4 space, wherein the honeypot node is used to capture a probe data packet from the cyberspace mapping platform, wherein the probe data packet includes the IP address, port, and probe initiation timestamp of the probe initiator; In response to the network space mapping platform actively initiating mapping of the honeypot node deployed on the public network, the honeypot node generates a false HTTP response with an encryption tag when receiving a detection data packet, and returns the false HTTP response to the network space mapping platform; The honeypot node saves the captured detection data packet information into the database; In response to the cyberspace mapping platform publishing the response information of the honeypot node, the response information on the cyberspace mapping platform page is obtained through API technology or web crawler technology; Decrypt the encrypted label in the public response information, and determine the IP address of the mapping node corresponding to the response information based on the detection data queried from the database, so as to achieve accurate ownership identification of the mapping node of the cyberspace mapping platform.
2. The method according to claim 1, characterized in that The honeypot node generates a false HTTP response with an encryption tag when receiving a probe data packet, and returns the false HTTP response to the cyberspace mapping platform, including: generating an encryption tag based on the IP address, port, and timestamp in the probe data packet; Encrypting the encryption tag using symmetric encryption technology to generate encrypted tag information; Embed the encrypted tag information into the corresponding field of the fake HTTP response; Return a fake HTTP response with an encrypted tag to the cyberspace mapping platform.
3. The method according to claim 2, characterized in that The step of obtaining the response information on a webpage of the cyberspace mapping platform by using an API technology or a web crawler technology in response to the cyberspace mapping platform publishing the response information of the honeypot node includes: In response to the honeypot node being detected, the cyberspace mapping platform publishes the response information of the honeypot node and searches for the honeypot node on each cyberspace mapping platform through a mapping platform aggregate search program; The query interface provided by the cyberspace mapping platform is called through the API interface to obtain the response information of the honeypot node; if the cyberspace mapping platform does not provide an API interface or the API interface cannot obtain the response information, the response information of the honeypot node is directly captured from the cyberspace mapping platform page through web crawler technology.
4. The method according to claim 3, characterized in that The encrypted tag in the decrypted public response information is then used to determine the IP address of the mapping node corresponding to the response information based on the detection data retrieved from the database, thereby achieving accurate identification of the mapping node on the cyberspace mapping platform, including: Decrypt the encrypted tag in the public response information and restore the original information in the encrypted tag; According to the decrypted label information, query the database for a corresponding detection data record, wherein the detection data record includes detection data packet information related to the response information; The decrypted label information is associated with the IP address, port and detection initiation timestamp in the queried detection data packet information to determine the IP address of the mapping node corresponding to the response information, thereby realizing accurate identification of the ownership of the mapping node of the cyberspace mapping platform.
5. An electronic device, characterized in that: include: a processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 4.
6. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 4 when executed by a processor.
7. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 4 when executed by a processor.