CN114866295A - Method for constructing bad site service IP pool and acquiring and analyzing IP main body attribute data - Google Patents

Method for constructing bad site service IP pool and acquiring and analyzing IP main body attribute data Download PDF

Info

Publication number
CN114866295A
CN114866295A CN202210417058.0A CN202210417058A CN114866295A CN 114866295 A CN114866295 A CN 114866295A CN 202210417058 A CN202210417058 A CN 202210417058A CN 114866295 A CN114866295 A CN 114866295A
Authority
CN
China
Prior art keywords
bad
service
address
site
pool
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN202210417058.0A
Other languages
Chinese (zh)
Other versions
CN114866295B (en
Inventor
张兆心
孟月阳
柴婷婷
赵东
陈俊仁
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Harbin Institute of Technology Weihai
Original Assignee
Harbin Institute of Technology Weihai
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Harbin Institute of Technology Weihai filed Critical Harbin Institute of Technology Weihai
Priority to CN202210417058.0A priority Critical patent/CN114866295B/en
Publication of CN114866295A publication Critical patent/CN114866295A/en
Application granted granted Critical
Publication of CN114866295B publication Critical patent/CN114866295B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/30Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02DCLIMATE CHANGE MITIGATION TECHNOLOGIES IN INFORMATION AND COMMUNICATION TECHNOLOGIES [ICT], I.E. INFORMATION AND COMMUNICATION TECHNOLOGIES AIMING AT THE REDUCTION OF THEIR OWN ENERGY USE
    • Y02D30/00Reducing energy consumption in communication networks
    • Y02D30/50Reducing energy consumption in communication networks in wire-line communication networks, e.g. low power modes or reduced link rate

Landscapes

  • Engineering & Computer Science (AREA)
  • Technology Law (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention provides a method for constructing a bad site service IP pool and acquiring and analyzing IP main body attribute data, which comprises the following steps: step S1, constructing a bad information site service IP pool; step S2, monitoring bad sites and IP addresses in the bad information site service IP pool; and step S3, analyzing the reason that the IP address provides service for the bad site. The method solves the problem that the distribution conditions of the service IP address bearing entity, the network space and the geographic space of the bad site are unclear, and can analyze data on attributes such as geographic information, service information and the like of the IP address for providing service for the bad site in space and time, deduce a network main body of the IP address, further obtain reason analysis that the IP address provides service for the bad site, and effectively improve timeliness and accuracy of monitoring the bad site.

Description

Method for constructing bad site service IP pool and acquiring and analyzing IP main body attribute data
Technical Field
The invention relates to the field of IP address research in a computer network, in particular to a method for constructing a bad site service IP pool and acquiring and analyzing IP main body attribute data.
Background
With the rapid development of the internet, websites have gradually become the most convenient and fast bridge for providing services for various industries and communicating data and information. Meanwhile, the bad sites spreading the bad information such as pornography, gambling, fraud and the like in the internet threaten the cultural safety, the economic safety and the social safety, so the discovery and the monitoring of the bad sites are particularly important. The IP address is the key basic content in the computer network, and can play a timely and accurate role in discovering and monitoring bad sites aiming at the analysis of the IP address network main body attribute and the identification of social entities behind the IP address.
At present, most of researches on IP address network main body attribute analysis aim at the aspects of IP geographical positioning, IP port openness and the like, and the technical problems of limited IP geographical positioning technical precision, lack of positioning space-time distribution of IP addresses and capability of establishing connection analysis exist, and the service information of the IP addresses and the social entities behind the IP addresses are less involved.
Disclosure of Invention
The invention provides a method for constructing a service IP pool of a bad site and acquiring and analyzing IP body attribute data, aiming at the technical problems of limited IP geographical positioning technology precision, lack of positioning space-time distribution of IP addresses and capability of establishing connection analysis in the analysis of the network body attributes of the current IP addresses.
Therefore, the technical scheme of the invention is that the method for constructing the bad site service IP pool and acquiring and analyzing the IP main body attribute data comprises the following steps:
step S1, constructing a bad information site service IP pool, acquiring a large number of service IP addresses bearing bad information site services, generating an IP address main body attribute for each IP address, and further constructing the bad information site service IP pool;
step S2, monitoring bad sites and IP addresses in a bad information site service IP pool, and monitoring the bad sites and the IP addresses in the bad information site service IP pool for a long time, wherein the monitoring of whether domain name DNS analysis is available and analysis results are carried out on the bad sites, monitoring of main body attribute change is carried out on service IP, whether the domain name of the bad sites can be analyzed, whether the analysis IP addresses change and whether contents can be accessed, whether connection can be established for the IP addresses, whether open ports change, and the space-time distribution of the affiliated autonomous system and network service provider as well as geographic positioning are obtained;
and step S3, analyzing the reason that the IP address provides service for the bad site, deducing the network main body of the IP address by using the attribute information of the IP address main body and the distribution condition and the rule of the geographic position, analyzing the reason that the IP address provides service for the bad site, storing the reason into a service IP pool of the bad information site, finding the change rule of the service IP address according to the monitoring result and the service information provided by the IP address, deducing the network main body of the IP address, and further obtaining the reason analysis that the IP address provides service for the bad site.
Further, the step S1 of constructing the malicious information site service IP pool includes the following steps:
step S11, IP positioning benchmark judgment technology based on route characteristic identification and cleaning optimization of a plurality of manufacturer positioning data realize high-precision IP geographical position analysis;
step S12, establishing a data fingerprint database for IP use scene analysis, and realizing the analysis of the use scene through the targeted active spy analysis;
step S13, collecting domain names and links of bad sites;
step S14, acquiring a bad site domain name and a webpage link from a bad site list;
step S15, analyzing all bad site domain names in the list, obtaining site DNS information and IP addresses and storing data, performing DNS analysis on the bad site domain names and obtaining site contents, extracting graph bed links and outer links in the site contents and performing DNS analysis;
step S16, crawling bad site web page links, obtaining web page snapshots and contents, extracting out links from the web page contents, performing DNS analysis on domain names in the out links, and storing analysis results;
and step S17, collecting the main body attribute data of the IP address generated and stored in the steps S15 and S16, storing the main body attribute and the attribute change condition of the bad site service IP in a bad information site service IP pool.
Further, the method for implementing step S17 includes the following steps:
step a, determining an autonomous system, a network service provider and a country to which an IP address belongs by using autonomous system data;
b, scanning an open port of the IP address by using a port scanning tool;
and c, analyzing the geographic position information of the IP by using the IP geographic position analysis method in the step S1, and analyzing the use scene of the IP address by using the IP use scene analysis fingerprint database in the step S2.
Further, the IP address body attribute includes positioning information, an affiliated autonomous system, an affiliated network service provider, and an IP address application scenario.
Further, the step S2 of monitoring bad sites and IP addresses in the bad information site service IP pool includes the following steps:
step S21, monitoring whether connection, positioning information, an open port, an affiliated autonomous system and other information can be established for the IP address in the service IP pool of the bad information site for a long time, monitoring whether the domain name can be DNS analyzed for the bad site, collecting newly generated IP address main body attribute data, and storing the IP address main body attribute data in the service IP pool of the bad information site;
and S22, collecting data of the geographic position change, the distribution situation, the open port change and the like of the IP main body in the step S21, and analyzing the change rule.
Furthermore, the functional module of the service IP pool construction and IP main body attribute data acquisition and analysis method comprises an IP main body attribute acquisition module and an IP key attribute analysis module, wherein the IP main body attribute acquisition module is used for acquiring the geographical positioning information of an IP address, open ports and service information, an autonomous system and a network service provider which the IP main body attribute acquisition module belongs to, whether the IP address is an IP address of a CDN manufacturer, and the IP main body attribute of an IP address routing path and storing the IP main body attribute into a bad information site service IP pool; and the IP key attribute analysis module analyzes the use scene, the geographical position distribution and the service content of the IP address in the service IP pool of the bad information site.
The method has the advantages that a large number of service IP addresses bearing bad site services are obtained, and IP body attributes such as positioning information, an autonomous system, a network service provider and an IP address application scene are generated for each IP address, so that a service IP pool is constructed. And monitoring bad sites and IP addresses in the service IP pool for a long time to obtain whether domain names of the bad sites can be analyzed, whether the IP addresses change or not and whether the contents can be accessed or not, whether the IP addresses can establish connection or not, whether open ports change or not, and the time-space distribution of the affiliated autonomous system, network service providers and geographical positioning. And finally, discovering a service IP address change rule according to the monitoring result and the service information provided by the IP address, and deducing the network body of the IP address. By the method, the user can perform data analysis on attributes such as geographic information, service information and the like on space and time on the IP address providing service for the bad site, infer the network main body of the IP address, further obtain reason analysis of the IP address providing service for the bad site, and effectively improve timeliness and accuracy of monitoring the bad site.
Drawings
FIG. 1 is a flow chart of the present invention implementing service IP pool construction and IP body attribute data collection and analysis;
fig. 2 is a schematic diagram of functional modules for implementing service IP pool construction and IP body attribute data collection and analysis according to the present invention.
Detailed Description
The present invention will be further described with reference to the following examples.
Fig. 1 is a flowchart of an embodiment of a method for constructing a bad site service IP pool and acquiring and analyzing IP body attribute data according to the present invention, where the method acquires a large number of service IP addresses bearing bad site services, and generates IP body attributes such as positioning information, an owned autonomous system, an owned network service provider, and an IP address application scenario for each IP address, thereby constructing a service IP pool. And monitoring bad sites and IP addresses in the service IP pool for a long time to obtain whether domain names of the bad sites can be analyzed, whether the IP addresses change or not and whether the contents can be accessed or not, whether the IP addresses can establish connection or not, whether open ports change or not, and the time-space distribution of the affiliated autonomous system, network service providers and geographical positioning. And finally, discovering a service IP address change rule according to the monitoring result and the service information provided by the IP address, and deducing the network body of the IP address. The embodiment comprises the following steps:
step S1, constructing bad information site service IP pool
And acquiring a large number of service IP addresses bearing bad information site services, generating an IP address main body attribute for each IP address, and further constructing a bad information site service IP pool. The IP address body attribute comprises positioning information, an affiliated autonomous system, an affiliated network service provider and an IP address application scene.
The method for constructing the bad information site service IP pool comprises the following steps:
step S11, IP positioning benchmark judgment technology based on route characteristic identification and cleaning optimization of a plurality of manufacturer positioning data realize high-precision IP geographical position analysis;
step S12, establishing a data fingerprint database for IP use scene analysis, and realizing the analysis of the use scene through the targeted active spy analysis;
step S13, collecting domain names and links of bad sites;
step S14, acquiring bad site domain names and web page links from the bad site list, and obtaining bad site domain name sets, such as pornographic and gambling domain name sets, to which the user is interested;
step S15, resolving all bad site domain names in the list, obtaining site DNS information and IP addresses and storing data; resolving the IP address by the domain name, extracting the links of a graph bed, an external link and the like, and resolving the IP address of the host domain name: performing DNS analysis on the domain name of the bad site, obtaining site contents, extracting a graph bed link and an external link in the site contents, and performing DNS analysis;
step S16, crawling bad site web page links, obtaining web page snapshots and contents, extracting out links from the web page contents, performing DNS analysis on domain names in the out links, and storing analysis results;
step S17, collecting the main attribute data of the IP address generated and stored in step S15 and step S16, storing the main attribute data of the IP address in a service IP pool, and storing the bad site service IP and the main attribute and attribute change condition thereof, wherein the implementation steps include:
step a, determining an autonomous system, a network service provider and a country to which an IP address belongs by using autonomous system data;
b, scanning an open port of the IP address by using a port scanning tool;
and c, analyzing the geographic position information of the IP by using the IP geographic position analysis method in the step S1, and analyzing the use scene of the IP address by using the IP use scene analysis fingerprint database in the step S2.
Step S2, monitoring bad sites and IP addresses in service IP pool
The method comprises the following steps of monitoring bad sites and IP addresses in a service IP pool for a long time, including monitoring whether domain names can be subjected to DNS analysis and analysis results of the bad sites, monitoring main attribute change of the service IP, and acquiring whether the domain names of the bad sites can be analyzed, whether the analyzed IP addresses change and whether contents can be accessed, whether the IP addresses can establish connection, whether open ports change, and spatial and temporal distribution of affiliated autonomous systems, network service providers and geographical positioning, and comprises the following steps:
step S21, monitoring whether the connection, the positioning information, the open port, the affiliated autonomous system and other information can be established for the IP address in the service IP pool for a long time, monitoring whether the domain name can be DNS analyzed for the bad site, collecting the newly generated IP address main body attribute data, and storing the data in the service IP pool;
and S22, collecting data of the geographic position change, the distribution situation, the open port change and the like of the IP main body in the step S21, and analyzing the change rule.
Step S3, analyzing the reason that the IP address provides service for bad site
And deducing a network main body of the IP address by using the attribute information of the IP address main body and the geographical position distribution condition and rule, analyzing the reason why the IP address provides service for the bad site, and storing the reason into a service IP pool. And discovering a change rule of the service IP address according to the monitoring result and the service information provided by the IP address, deducing a network main body of the IP address, further obtaining reason analysis of the service provided by the IP address for the bad site, and effectively improving timeliness and accuracy of monitoring the bad site.
As shown in fig. 2, the functional modules for implementing the method for constructing the service IP pool and acquiring and analyzing the IP body attribute data of the present invention include an IP body attribute acquisition module and an IP key attribute analysis module.
An IP body attribute acquisition module: the module is used for collecting IP main body attributes such as IP address geographical positioning information, open port and service information, an autonomous system and a network service provider which the module belongs to, whether the IP main body attributes are IP addresses of CDN manufacturers, IP address routing paths and the like, and storing the IP main body attributes into a service IP pool;
IP key attribute analysis module: the module analyzes the usage scenario, geographical location distribution and service content for the IP addresses in the service IP pool.
However, the above description is only exemplary of the present invention, and the scope of the present invention should not be limited thereby, and the replacement of the equivalent components or the equivalent changes and modifications made according to the protection scope of the present invention should be covered by the claims of the present invention.

Claims (6)

1. A method for constructing a bad site service IP pool and acquiring and analyzing IP main body attribute data is characterized by comprising the following steps:
step S1, constructing a bad information site service IP pool, acquiring a large number of service IP addresses bearing bad information site services, generating an IP address main body attribute for each IP address, and further constructing the bad information site service IP pool;
step S2, monitoring bad sites and IP addresses in a bad information site service IP pool, and monitoring the bad sites and the IP addresses in the bad information site service IP pool for a long time, wherein the monitoring of whether domain name DNS analysis is available and analysis results are carried out on the bad sites, monitoring of main body attribute change is carried out on service IP, whether the domain name of the bad sites can be analyzed, whether the analysis IP addresses change and whether contents can be accessed, whether connection can be established for the IP addresses, whether open ports change, and the space-time distribution of the affiliated autonomous system and network service provider as well as geographic positioning are obtained;
and step S3, analyzing the reason that the IP address provides service for the bad site, deducing the network main body of the IP address by using the attribute information of the IP address main body and the distribution condition and the rule of the geographic position, analyzing the reason that the IP address provides service for the bad site, storing the reason into a service IP pool of the bad information site, finding the change rule of the service IP address according to the monitoring result and the service information provided by the IP address, deducing the network main body of the IP address, and further obtaining the reason analysis that the IP address provides service for the bad site.
2. The method for constructing the bad site service IP pool and collecting and analyzing the IP body attribute data according to claim 1, wherein the method comprises the following steps: the step S1 of constructing the malicious information site service IP pool includes the following steps:
step S11, IP positioning benchmark judgment technology based on route characteristic identification and cleaning optimization of a plurality of manufacturer positioning data realize high-precision IP geographical position analysis;
step S12, establishing a data fingerprint database for IP use scene analysis, and realizing the analysis of the use scene through the targeted active spy analysis;
step S13, collecting domain names and links of bad sites;
step S14, acquiring a bad site domain name and a webpage link from a bad site list;
step S15, all bad site domain names in the list are analyzed to obtain site DNS information and IP addresses and store data, the bad site domain names are subjected to DNS analysis to obtain site contents, and graph bed links and outer links in the site contents are extracted and subjected to DNS analysis;
step S16, crawling the bad site web page link, obtaining web page snapshot and content, extracting out-links from the web page content, performing DNS analysis on domain names in the out-links, and storing the analysis result;
and step S17, collecting the main body attribute data of the IP address generated and stored in the steps S15 and S16, storing the main body attribute and the attribute change condition of the bad site service IP in a bad information site service IP pool.
3. The method for constructing the bad site service IP pool and collecting and analyzing the IP body attribute data according to claim 2, wherein the method comprises the following steps: the method for implementing the step S17 includes the following steps:
step a, determining an autonomous system, a network service provider and a country to which an IP address belongs by using autonomous system data;
b, scanning an open port of the IP address by using a port scanning tool;
and c, analyzing the geographic position information of the IP by using the IP geographic position analysis method in the step S1, and analyzing the use scene of the IP address by using the IP use scene analysis fingerprint database in the step S2.
4. The method for constructing the bad site service IP pool and collecting and analyzing the IP body attribute data according to claim 3, wherein the method comprises the following steps: the IP address main body attribute comprises positioning information, an affiliated autonomous system, an affiliated network service provider and an IP address application scene.
5. The method for constructing the bad site service IP pool and collecting and analyzing the IP body attribute data according to claim 4, wherein the method comprises the following steps: in the step S2, the monitoring of the bad site and the IP address in the bad information site service IP pool includes the following steps:
step S21, monitoring whether connection, positioning information, an open port, an affiliated autonomous system and other information can be established for the IP address in the service IP pool of the bad information site for a long time, monitoring whether the domain name can be DNS analyzed for the bad site, collecting newly generated IP address main body attribute data, and storing the IP address main body attribute data in the service IP pool of the bad information site;
and S22, collecting data of the geographic position change, the distribution situation, the open port change and the like of the IP main body in the step S21, and analyzing the change rule.
6. The method for constructing the bad site service IP pool and collecting and analyzing the IP body attribute data according to any one of claims 1 to 5, wherein: the functional module of the service IP pool construction and IP main body attribute data acquisition and analysis method comprises an IP main body attribute acquisition module and an IP key attribute analysis module, wherein the IP main body attribute acquisition module is used for acquiring geographic positioning information of an IP address, open ports and service information, an autonomous system and a network service provider which the IP main body attribute acquisition module belongs to, whether the IP address is an IP address of a CDN manufacturer or not, and IP main body attributes of an IP address routing path and storing the IP main body attributes into a bad information site service IP pool; and the IP key attribute analysis module analyzes the use scene, the geographical position distribution and the service content of the IP address in the service IP pool of the bad information site.
CN202210417058.0A 2022-04-20 2022-04-20 Bad site service IP pool construction and IP main body attribute data acquisition and analysis method Active CN114866295B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202210417058.0A CN114866295B (en) 2022-04-20 2022-04-20 Bad site service IP pool construction and IP main body attribute data acquisition and analysis method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202210417058.0A CN114866295B (en) 2022-04-20 2022-04-20 Bad site service IP pool construction and IP main body attribute data acquisition and analysis method

Publications (2)

Publication Number Publication Date
CN114866295A true CN114866295A (en) 2022-08-05
CN114866295B CN114866295B (en) 2023-07-25

Family

ID=82630775

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202210417058.0A Active CN114866295B (en) 2022-04-20 2022-04-20 Bad site service IP pool construction and IP main body attribute data acquisition and analysis method

Country Status (1)

Country Link
CN (1) CN114866295B (en)

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090210416A1 (en) * 2007-08-29 2009-08-20 Bennett James D Search engine using world map with whois database search restrictions
US9405903B1 (en) * 2013-10-31 2016-08-02 Palo Alto Networks, Inc. Sinkholing bad network domains by registering the bad network domains on the internet
CN106921662A (en) * 2017-03-01 2017-07-04 北京牡丹电子集团有限责任公司数字电视技术中心 Real-time streams connect life cycle management method
CN108429747A (en) * 2018-03-08 2018-08-21 国家计算机网络与信息安全管理中心 A kind of extensive Web server information collecting method
CN109522504A (en) * 2018-10-18 2019-03-26 杭州安恒信息技术股份有限公司 A method of counterfeit website is differentiated based on threat information
CN111818024A (en) * 2020-06-23 2020-10-23 广州锦行网络科技有限公司 Network asset information collecting and monitoring system
US20210105289A1 (en) * 2019-10-04 2021-04-08 Zscaler, Inc. Web crawler systems and methods to efficiently detect malicious sites

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090210416A1 (en) * 2007-08-29 2009-08-20 Bennett James D Search engine using world map with whois database search restrictions
US9405903B1 (en) * 2013-10-31 2016-08-02 Palo Alto Networks, Inc. Sinkholing bad network domains by registering the bad network domains on the internet
CN106921662A (en) * 2017-03-01 2017-07-04 北京牡丹电子集团有限责任公司数字电视技术中心 Real-time streams connect life cycle management method
CN108429747A (en) * 2018-03-08 2018-08-21 国家计算机网络与信息安全管理中心 A kind of extensive Web server information collecting method
CN109522504A (en) * 2018-10-18 2019-03-26 杭州安恒信息技术股份有限公司 A method of counterfeit website is differentiated based on threat information
US20210105289A1 (en) * 2019-10-04 2021-04-08 Zscaler, Inc. Web crawler systems and methods to efficiently detect malicious sites
CN111818024A (en) * 2020-06-23 2020-10-23 广州锦行网络科技有限公司 Network asset information collecting and monitoring system

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
YOSHIHIRO OHSUMI ETAL: "《A Location Free Network System Applicable to Geographical Terms of the Electronic Journal Site License》", 《2012 IEEE/IPSJ 12TH INTERNATIONAL SYMPOSIUM ON APPLICATIONS AND THE INTERNET》 *
张译心: "《计算机网络安全中的防火墙技术应用探讨》", 《互联网+安全》 *
贾民政;朱元忠;商伟;: "网站IP地理位置定位系统的设计与实现", 北京工业职业技术学院学报, no. 02 *

Also Published As

Publication number Publication date
CN114866295B (en) 2023-07-25

Similar Documents

Publication Publication Date Title
Gregori et al. The impact of IXPs on the AS-level topology structure of the Internet
Yen et al. Host Fingerprinting and Tracking on the Web: Privacy and Security Implications.
US6741990B2 (en) System and method for efficient and adaptive web accesses filtering
Augustin et al. IXPs: mapped?
US7904456B2 (en) Security monitoring tool for computer network
Zirngibl et al. Rusty clusters? dusting an IPv6 research foundation
CN110825950B (en) Hidden service discovery method based on meta search
Gouel et al. IP geolocation database stability and implications for network research
Li et al. Street-Level Landmarks Acquisition Based on SVM Classifiers.
Zembruzki et al. : Measuring centralization of dns infrastructure in the wild
US9973950B2 (en) Technique for data traffic analysis
CN114866295A (en) Method for constructing bad site service IP pool and acquiring and analyzing IP main body attribute data
Dodge et al. Internet-based measurement
CN111614797B (en) Method and system for detecting IP address missing coverage
CN111885220B (en) Active acquisition and verification method for target unit IP assets
KR20010096877A (en) Method and System for Target Marketing Using Internet IP Address
Su et al. Web tracking cartography with dns records
Su et al. Toward accurate inference of web activities from passive dns data
Hou et al. Survey of cyberspace resources scanning and analyzing
US20100198959A1 (en) System and method for tracking individuals on a data network using communities of interest
Liu et al. Street-level landmark mining algorithm based on radar search
KR100952888B1 (en) Statistics system and method for acess dada to website
CN116743707B (en) IP geographic positioning method and device based on active time delay detection
Scott et al. Satellite: Observations of the internet’s star
Zu et al. RLGBG: A Reachable Landmark Grouping Based IP Geolocation Method for Unreachable Target

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant