计算机应用 ›› 2019, Vol. 39 ›› Issue (5): 1385-1388.DOI: 10.11772/j.issn.1001-9081.2018111960

• 网络空间安全 • 上一篇    下一篇

网络匿名扫描系统设计及优化

何云华1, 牛童1, 刘天一1, 肖珂1, 芦翔2   

  1. 1. 北方工业大学 信息学院, 北京 100144;
    2. 中国科学院 信息工程研究所, 北京 100195
  • 收稿日期:2018-09-20 修回日期:2019-01-03 发布日期:2019-05-14 出版日期:2019-05-10
  • 通讯作者: 肖珂
  • 作者简介:何云华(1987-),男,湖北荆门人,讲师,博士,CCF会员,主要研究方向:物联网安全、隐私保护、区块链;牛童(1999-),男,北京人,硕士研究生,主要研究方向:匿名扫描;刘天一(1999-),男,北京人,硕士研究生,主要研究方向:匿名扫描;肖珂(1980-),男,吉林松原人,教授,博士,主要研究方向:物联网安全、工控安全;芦翔(1985-),男,北京人,教授,博士,主要研究方向:物联网安全。
  • 基金资助:
    国家自然科学基金资助项目(61802005,61702503);国家重点研发计划项目(2017YFB0802300);北京市自然科学基金资助项目(4184085)。

Design and optimization of network anonymous scanning system

HE Yunhua1, NIU Tong1, LIU Tianyi1, XIAO Ke1, LU Xiang2   

  1. 1. School of Information Science and Technology, North China University of Technology, Beijing 100144, China;
    2. Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100195, China
  • Received:2018-09-20 Revised:2019-01-03 Online:2019-05-14 Published:2019-05-10
  • Supported by:
    This work is partially supported by the National Natural Science Foundation of China (61802005, 61702503), the National Key R&D Program of China (2017YFB0802300), the Beijing Natural Science Foundation (4184085).

摘要: 针对网络扫描工具在进行扫描时面临的溯源问题,提出了一种匿名网络扫描系统。首先将匿名系统与网络扫描工具结合以实现匿名扫描;然后在现有匿名系统的基础上实现了该系统的本地私有化;接着通过流量分析发现,Nmap的多进程扫描因为代理链的原因会变成单进程扫描而导致其扫描扫描性能较低;最后提出了一种基于多Namp进程并发的性能优化方案,将总体扫描任务分割为多个扫描任务,并分配给多个单独的Nmap进程并行运行。实验结果表明,该性能优化方案的扫描时延接近正常扫描情况下的时延,达到了提高匿名扫描系统性能的目的。因此,该优化后的网络匿名扫描系统在阻碍溯源的同时提升了扫描效率。

关键词: 匿名服务发现, 网络扫描, 性能优化, 洋葱路由

Abstract: An anonymous network scanning system was proposed for traceability problem faced by network scanning tools during scanning. Firstly, the anonymous system was combined with the network scanning tool to implement anonymous scanning. Then, the local privatization of the system was implemented based on existing anonymous system. Thirdly, through traffic analysis, it was found that Nmap's multi-process scanning would become a single-process scan due to proxy chain, resulting in lower scan scan performance. Finally, a performance optimization scheme based on multi-Namp process concurrency was proposed, which divided the overall scan task into multiple scan tasks and assigned them to multiple separate Nmap processes in parallel. The experimental results show that the scanning delay of the performance optimization scheme is close to that of the normal scanning system, and achieves the purpose of improving the performance of the anonymous scanning system. Therefore, the optimized network anonymous scanning system hinders the traceability and improves the scanning efficiency.

Key words: anonymous service discovery, network scanning, network proxy, The onion routing (Tor)

中图分类号: