WO2020168682A1 - 基于自治系统的网络空间坐标系创建方法及装置 - Google Patents

基于自治系统的网络空间坐标系创建方法及装置 Download PDF

Info

Publication number
WO2020168682A1
WO2020168682A1 PCT/CN2019/097739 CN2019097739W WO2020168682A1 WO 2020168682 A1 WO2020168682 A1 WO 2020168682A1 CN 2019097739 W CN2019097739 W CN 2019097739W WO 2020168682 A1 WO2020168682 A1 WO 2020168682A1
Authority
WO
WIPO (PCT)
Prior art keywords
coordinate system
cyberspace
dimensional
network
network space
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2019/097739
Other languages
English (en)
French (fr)
Inventor
王继龙
庄姝颖
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Tsinghua University
Original Assignee
Tsinghua University
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Tsinghua University filed Critical Tsinghua University
Publication of WO2020168682A1 publication Critical patent/WO2020168682A1/zh
Priority to US17/385,950 priority Critical patent/US11943249B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1433Vulnerability analysis
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06TIMAGE DATA PROCESSING OR GENERATION, IN GENERAL
    • G06T17/00Three-dimensional [3D] modelling for computer graphics
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/09Mapping addresses
    • H04L61/25Mapping addresses of the same type
    • H04L61/2503Translation of Internet protocol [IP] addresses
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5007Internet protocol [IP] addresses
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/12Discovery or management of network topologies
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/14Network analysis or design
    • H04L41/145Network analysis or design involving simulating, designing, planning or modelling of a network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/04Processing captured monitoring data, e.g. for logfile generation
    • H04L43/045Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1458Denial of Service

Definitions

  • the feedback of this application belongs to the technical field of cyberspace modeling and visualization, and particularly relates to a method and device for creating a cyberspace coordinate system based on an autonomous system.
  • the feedback of this application aims to solve one of the technical problems in related technologies at least to a certain extent.
  • one purpose of the feedback of this application is to propose a method for creating a cyberspace coordinate system based on an autonomous system, which can visualize multidimensional information in cyberspace based on a uniform and constant backplane, including AS (Autonomous System) topology, IP Address composition, network resource element information and hierarchical structure, etc., and is suitable for a variety of cyberspace security attacks and visualization of network management scenarios.
  • AS Autonomous System
  • Another purpose of the feedback of this application is to propose a network space coordinate system creation device based on an autonomous system.
  • one embodiment of the present application provides a method for creating a cyberspace coordinate system based on an autonomous system, including: determining a cyberspace coordinate system; constructing a three-dimensional cyberspace coordinate system framework; and according to the cyberspace coordinate system Constructing a network space map model with the framework of the three-dimensional network space coordinate system; designing an application scene corresponding to the constructed network space map model, and visualizing the application scene.
  • the method for creating a cyberspace coordinate system based on an autonomous system in the feedback embodiment of this application proposes a two-dimensional cyberspace coordinate system framework design scheme based on an autonomous system number (ASN, Autonomous System Number), and selects the Hilbert mapping algorithm to achieve one Dimension ASN ascends the visualization. Then, it is determined that the time sequence of the IP address allocation under the AS is orthogonal to the AS address as the third-dimensional basic vector, constructs a three-dimensional network space coordinate system framework, and analyzes and maps the key attribute IP address of the network space.
  • ASN autonomous system number
  • ASN Autonomous System Number
  • a network space map model to support the visual expression of network space, support multi-scale traversal of network space and network space object positioning based on the rectangular tree diagram, and express the original elements of network space in a hierarchical and scalable manner, such as network composition and network under AS
  • it supports the visualization of network topology, introduces the concept of topology thematic map, and uses force-oriented algorithms to visualize the AS topology relationship in network space.
  • the method for creating a cyberspace coordinate system based on the autonomous system of the foregoing embodiment fed back according to this application may also have the following additional technical features:
  • the cyberspace coordinate system is a two-dimensional coordinate system
  • the determining the cyberspace coordinate system includes: mapping a one-dimensional autonomous system number to a two-dimensional coordinate according to a preset algorithm Space; the mapping of a one-dimensional autonomous system number to a two-dimensional coordinate space according to a preset algorithm includes: using the Hilbert mapping algorithm to perform an ascending mapping of the autonomous system number, and determining that the coordinates of the network space coordinate system collectively represent the attributes of the network space autonomous system.
  • the construction of the framework of the three-dimensional network space coordinate system includes: taking the IP address allocation time sequence under the autonomous system as the third-dimensional basic vector orthogonal to the autonomous system address, and comparing the network Analysis and mapping of the key attributes of the space IP address.
  • the network space coordinate system frame is a three-dimensional coordinate system, including a third-dimensional coordinate axis perpendicular to the basic vector of the two-dimensional autonomous system;
  • IP address allocation time sequence under the autonomous system as the third-dimensional basic vector orthogonal to the autonomous system address includes:
  • the third coordinate axis perpendicular to the two-dimensional coordinate system represents the time sequence of IP address allocation under the autonomous system, and the positive direction represents the sequence increment;
  • the analysis and mapping of the key attribute IP address of the cyberspace includes:
  • Network space is modeled by defining a three-dimensional coordinate system space, and any network space resource element is located based on the key identification IP address of communication; among them, Z-axis mapping is described as the time allocated for all IP addresses under the jurisdiction of an autonomous system Perform ascending sorting, sort the IP address from smallest to largest in decimal at the same allocation time, and map the serial number to the third dimensional coordinate system;
  • the IP address is analyzed and mapped.
  • the constructing a network space map model according to the network space coordinate system and the three-dimensional network space coordinate system framework includes:
  • the design of the application scenario corresponding to the construction of the cyberspace map model and the visualization of the application scenario include:
  • the coordinates in the three-dimensional coordinate system of the autonomous system-based cyberspace are calculated according to the mapping algorithm to visualize the real-time attack scenario.
  • the flying line indicates the attack direction, and the thickness of the line indicates the attack traffic;
  • the coordinates in the AS-based cyberspace three-dimensional coordinate system are calculated according to the mapping algorithm, and the thickness of the line indicates the attack frequency.
  • a network space coordinate system creation device based on an autonomous system, which includes: a determination module for determining a network space coordinate system; a first building module for constructing a three-dimensional The network space coordinate system framework; the second construction module, used to construct the network space map model according to the network space coordinate system and the three-dimensional network space coordinate system framework; the design visualization module, used to design the corresponding network space map model And visualize the application scenarios.
  • the autonomous system-based cyberspace coordinate system creation device of the present application feedback embodiment proposes a two-dimensional cyberspace coordinate system framework design scheme based on the autonomous system number as the base vector, and selects the Hilbert mapping algorithm to realize one-dimensional ASN ascending visualization. Then, it is determined that the time sequence of the IP address allocation under the AS is orthogonal to the AS address as the third-dimensional basic vector, constructs a three-dimensional network space coordinate system framework, and analyzes and maps the key attribute IP address of the network space.
  • a network space map model to support the visual expression of network space, support multi-scale traversal of network space and network space object positioning based on the rectangular tree diagram, and express the original elements of network space in a hierarchical and scalable manner, such as network composition and network under AS
  • it supports the visualization of network topology, introduces the concept of topology thematic map, and uses force-oriented algorithms to visualize the AS topology relationship in network space.
  • the apparatus for creating a cyberspace coordinate system based on the autonomous system of the foregoing embodiment fed back according to the present application may also have the following additional technical features:
  • the cyberspace coordinate system is a two-dimensional coordinate system
  • the determining module is specifically configured to: map a one-dimensional autonomous system number to a two-dimensional coordinate space according to a preset algorithm
  • the mapping of a one-dimensional autonomous system number to a two-dimensional coordinate space according to a preset algorithm includes: using the Hilbert mapping algorithm to perform an ascending mapping of the autonomous system number, and determining that the coordinates of the network space coordinate system collectively represent the attributes of the network space autonomous system.
  • the first building module is specifically used to: use the time sequence of IP address allocation under the autonomous system as the third dimensional basic vector orthogonal to the autonomous system address, and to compare the network space The key attribute IP address is analyzed and mapped.
  • the second building module is specifically used to: determine that the cyberspace hierarchical structure is divided into three layers: autonomous system, network, and IP; and define the cyberspace sphere model.
  • FIG. 1 is a flowchart of a method for creating a cyberspace coordinate system based on an autonomous system according to an embodiment of the present application
  • FIG. 2 is a diagram of mapping a one-dimensional ASN of a specified range to a two-dimensional coordinate space according to the Hilbert mapping algorithm according to an embodiment of the present application;
  • FIG. 3 is a schematic diagram of the framework of an AS-based three-dimensional coordinate system in cyberspace according to an embodiment of the present application
  • FIG. 4 is a schematic flowchart of a method for creating an AS-based cyberspace coordinate system according to a specific embodiment of the present application
  • FIG. 5 is a schematic diagram showing the hierarchical and multi-scale expression of the original elements of the network space in the network space map model fed back according to an embodiment of the present application;
  • FIG. 6 is a topology thematic map that intuitively expresses the AS topology connection relationship based on the force-oriented algorithm in the network space model according to an embodiment of the present application;
  • FIG. 7 is a schematic structural diagram of a device for creating a multi-dimensional map showing cyberspace based on an AS-based cyberspace coordinate system according to an embodiment of the present application
  • FIG. 8 is a mapping diagram of a key attribute IP address of a network space in a three-dimensional coordinate system according to an embodiment of the present application.
  • FIG. 9 is a schematic diagram of a real-time attack scenario module of a cyberspace map fed back according to an embodiment of the present application.
  • FIG. 10 is a schematic diagram of a DDOS attack scenario module of a cyberspace map feeding back an embodiment according to the present application;
  • Fig. 11 is a schematic structural diagram of an apparatus for creating a cyberspace coordinate system based on an autonomous system according to an embodiment of the present application.
  • Fig. 1 is a flowchart of a method for creating a cyberspace coordinate system based on an autonomous system according to an embodiment of the present application.
  • the method for creating a cyberspace coordinate system based on an autonomous system includes the following steps:
  • step S101 the cyberspace coordinate system is determined.
  • the cyberspace coordinate system is a two-dimensional coordinate system.
  • determining the network space coordinate system includes: mapping the one-dimensional autonomous system number to the two-dimensional coordinate space according to a preset algorithm.
  • Map the one-dimensional autonomous system number to the two-dimensional coordinate space according to the preset algorithm including: adopting the Hilbert mapping algorithm to map the autonomous system number (ASN, Autonomous System Number) in ascending dimensions, and determine the coordinates of the network space coordinate system to collectively represent the network space autonomy System attributes, similar to the expression of national information by latitude and longitude in a geospatial model.
  • ASN Autonomous System Number
  • the network space coordinate system uses an AS (Autonomous System, autonomous system) number as the basic vector, and maps the one-dimensional ASN to the two-dimensional coordinate system according to a preset algorithm.
  • AS Autonomous System, autonomous system
  • step S102 a three-dimensional network space coordinate system frame is constructed.
  • it includes: taking the time sequence of IP address allocation under the autonomous system as the third-dimensional basic vector orthogonal to the autonomous system address, and analyzing and mapping the key attribute IP address of the network space.
  • the third-dimensional basic vector is determined to construct a network space coordinate system frame orthogonal to the time sequence of IP address allocation under the AS and the AS address, and the network space key attribute IP address is analyzed and mapped.
  • the framework of the cyberspace coordinate system is a three-dimensional coordinate system, including a third-dimensional coordinate axis perpendicular to the basic vector of the two-dimensional autonomous system; the IP address assignment time sequence under the AS is taken as the third-dimensional basic vector orthogonal to the AS address, including :
  • the third coordinate axis perpendicular to the two-dimensional coordinate system represents the time sequence of IP address allocation under AS, and the positive direction represents the sequence increment;
  • any network space resource element can be located based on the key identification IP address of the communication.
  • the Z-axis mapping is described as sorting all the IP addresses under the jurisdiction of an AS in ascending order according to the assigned time. Under the same assignment time, they are sorted according to the decimal system of the IP address from small to large, and the sequence number is mapped to the third coordinate system.
  • the above-mentioned Hilbert algorithm and Z-axis mapping algorithm positioning coordinates (x, y, z) analyze and map the IP address;
  • the IP address is analyzed and mapped.
  • a network space map model is constructed according to the network space coordinate system and the three-dimensional network space coordinate system framework.
  • constructing a cyberspace map model according to the cyberspace coordinate system and the three-dimensional cyberspace coordinate system framework includes: determining that the cyberspace hierarchy is divided into three layers: autonomous system, network, and IP; Define the cyberspace ball model.
  • the constructed network space map model intuitively expresses the network hierarchical structure and AS topology connection relationship.
  • step S104 an application scenario corresponding to the network space map model is designed and constructed, and the application scenario is visualized.
  • AS is analogous to the country
  • the network corresponds to the province and city
  • IP address is equivalent to the house number, based on the rectangular tree diagram
  • hierarchical and multi-scale Express the original elements of the cyberspace, such as the network composition under the AS and the IP composition under the network, to meet the visualization and positioning needs of different levels of managers.
  • Network space sphere mode to realize network topology visualization. Take AS topology as an example. According to the number of IP addresses under the jurisdiction of the AS and BGP data, the force-oriented algorithm is used to map the AS to the new three-dimensional coordinates (X, Y, Z). The size of the space sphere represents the number of IP addresses, and the flying line represents the topological connection. relationship.
  • the space ball mode is also suitable for AS internal network topology and IP topology to realize space unit and space link management.
  • the design and construction of the application scenario corresponding to the network space map model and the visualization of the application scenario include: calculating the attack source and destination IP addresses based on the mapping algorithm in the autonomous system
  • the coordinates in the cyberspace three-dimensional coordinate system visualize real-time attack scenarios.
  • the flying line represents the attack direction, and the thickness of the line represents the attack traffic; for the attack source and destination IP addresses, the coordinates in the AS-based cyberspace three-dimensional coordinate system are calculated according to the mapping algorithm ,
  • the thickness of the line indicates the frequency of attacks.
  • designing map application scenarios and implementing visualization includes two scenarios:
  • Scenario 1 Real-time attack scenario in cyberspace.
  • the coordinates (X, Y, Z) in the AS-based cyberspace three-dimensional coordinate system are calculated according to the mapping algorithm to visualize the real-time attack scenario, the flying line indicates the attack direction, and the thickness of the line indicates the attack traffic.
  • AS Use AS as the granularity to observe network attack traffic characteristics, analyze attack behaviors, and assist security analysts to better understand and prevent attacks.
  • Scenario 2 DDOS attack scenario in cyberspace.
  • the coordinates (X, Y, Z) in the AS-based cyberspace three-dimensional coordinate system are calculated according to the mapping algorithm, and the thickness of the line indicates the attack frequency.
  • the AS, network, and IP address information of the attack source and target can be obtained through different levels, which can quickly locate security issues and perform vulnerability diagnosis and repair.
  • thematic map can visually display the topological path of the attack experience, realize the topological traceability and discovery of the attack source, and guide the change of the connectivity of the Internet infrastructure when a network security attack occurs.
  • the method first determines the network space coordinate system structure based on the AS number (ASN). Considering that the network space is a virtual information space, the free flow of massive information constitutes the instantaneous diversity of the network space, and the selection can constantly represent the origin of the network space The basic vector is very important for building a network space map model.
  • Autonomous system as a collection of networks and IP addresses under the control of a management agency, is equivalent to a country in geographic space, and is the basic unit of business exchanges and communications between domains in cyberspace.
  • the Hilbert mapping algorithm is selected to realize one-dimensional ASN ascending visualization, and at the same time, the network space coordinate system frame with the IP address allocation time series under AS as the third-dimensional basic vector is constructed to express the key attribute of network space information communication—IP address information.
  • the one-dimensional ASN of the specified range is mapped to the two-dimensional coordinate space according to the Hilbert mapping algorithm.
  • Autonomous system as a collection of networks and IP addresses under the control of a management agency, is equivalent to a country in geographic space, and is the basic unit of business exchanges and communications between domains in cyberspace.
  • the Hilbert mapping algorithm as an ascending algorithm, can map a specified range of one-dimensional ASN numbers to a two-dimensional coordinate system space, better guarantee the proximity of ASN, and construct the basic two-dimensional plane of the network space coordinate system.
  • the specified ASN range is [0,2 2n-1 ], and the corresponding Hilbert mapping algorithm order is n.
  • Figure 2 shows the two-dimensional coordinate space obtained by mapping the specified ASN ranges as [0,3], [0,15], [0,63], and [0,255]. Applying the above algorithm to the entire ASN space [0,65535] for ascending dimension mapping, the corresponding Hilbert order n is equal to 8, and the two-dimensional coordinate system of the network space based on AS can be determined.
  • Figure 3 is a schematic diagram of the framework of an AS-based network space three-dimensional coordinate system according to an embodiment of the present application.
  • the time sequence of assigning IP addresses under the AS As the third dimension, the basic vector is orthogonal to the AS address, and the positive direction indicates that the sequence is increasing.
  • the Z-axis mapping algorithm is defined as follows:
  • the unallocated IP address allocation time is defined as MAXINT>max ⁇ T 1 , T 2 , T 3 , T4, T 5 , T 6 ,..., T n ⁇ ;
  • IP addresses under the AS are sorted in ascending order according to the assigned time. Under the same assigned time, they are sorted according to the decimal number of the IP address from smallest to largest, and a new IP address sequence ⁇ NIP 1 , NIP 2 , NIP 3 , NIP 4 is obtained , NIP 5 , NIP 6 , ..., NIP n ⁇ , the serial number is mapped to the third dimensional coordinate system.
  • Fig. 4 is a schematic flowchart of a method for creating a cyberspace coordinate system based on AS according to a specific embodiment of the present application.
  • the method for creating an AS-based cyberspace coordinate system includes the following steps:
  • the network space coordinate system is a two-dimensional coordinate space obtained based on the above-mentioned Hilbert mapping algorithm, and ASN is used as a basic vector to represent the elements of the network space autonomous system.
  • cyberspace is a virtual information space, in which massive amounts of information flow freely to form instantaneous diversity of cyberspace, choosing a basic vector that can constantly characterize the origin of cyberspace is essential for establishing a cyberspace map model.
  • Autonomous system as a collection of networks and IP addresses under the control of a management agency, is equivalent to a country in geographic space, and is the basic unit of business exchanges and communications between domains in cyberspace.
  • an AS-based two-dimensional coordinate system of cyberspace is constructed, and a unified and constant backplane is determined to display the elements of the cyberspace autonomous system.
  • the IP address is used as the only fingerprint assigned when the device is connected to the network, providing the location of the host in the cyberspace and the network interface identification, It is the key identifier of all cyberspace resource elements.
  • this application feeds back that the time sequence of IP address allocation under AS is added on the basis of the two-dimensional coordinate system as the third-dimensional vector orthogonal to it to construct a three-dimensional network space coordinate system framework to express IP information.
  • a certain IP address 166.111.8.2 belongs to AS4538.
  • the plane coordinates (24,76) are obtained. All the IP addresses under the jurisdiction of AS4538 are sorted in chronological order according to the above Z-axis mapping algorithm, and 166.11.8.2.
  • the time sequence number 8902 will be used as the Z-axis representation of the IP address, so in the three-dimensional coordinate system (24, 76, 8902) will be the only representation of the IP address, and at the same time it will identify the only networked device in the global Internet space, expressing the network Spatial resource information.
  • the IP address space is too large to be fully expressed, and it is difficult to find a better visualization solution for the 2 32 or 4 billion address space.
  • the discontinuous allocation of IP address segments results in scattered IP addresses in the same AS.
  • the IP address segments under it include 101.4.0.0/14, 101.5.0.0/16, 101.77.0.0/16, 111.186.0.0/15 , 114.212.0.0/16, etc.
  • the same AS is scattered in various positions of the IP address coordinate system, and the expression effect is not good.
  • the AS-based cyberspace coordinate system can intuitively express IP granularity, it lacks a hierarchical presentation of cyberspace details. It is difficult to meet the needs of multi-scale traversal and object positioning in cyberspace. Integrating the idea of geographic map model to construct a network space map model, taking into account the different visualization needs of different users for network space object distribution, resource information, connection relations, etc., it needs to meet the scalability and hierarchical map characteristics.
  • the second largest space parallel to geographic space there are corresponding geographic maps and thematic maps in geographic space that can scale mountains, rivers, and city streets.
  • the network space map model also needs to design some thematic map modules to achieve specific network details. Multi-dimensional display, this article takes the topology thematic map as an example to design and explain.
  • the network space needs to be divided into a hierarchical structure first, and the three levels of cyberspace hierarchical structure are determined by referring to the geographic map model: AS, network, IP, AS Analogous to the country, the network corresponds to the province and city, and the IP address is equivalent to the house number.
  • AS geographic map model
  • IP IP
  • AS Analogous to the country
  • the network corresponds to the province and city
  • the IP address is equivalent to the house number.
  • the method based on the rectangular tree diagram supports multi-scale traversal and object positioning in network space.
  • support for object positioning in cyberspace abstracts the resource hierarchical structure of AS, network, and IP addresses in cyberspace into a tree.
  • the root node represents all resources in a cyberspace, and multiple representations are obtained by dividing the cyberspace according to AS AS sub-nodes, large and small networks under AS can be used as the division and extension of AS nodes.
  • the natural structure of the tree can be used to express the inclusion relationship between networks, such as Cernet (China Education and Research Computer Network, China Education and The Research Network includes the campus networks of more than 100 colleges and universities such as the backbone network, Tsinghua University, Peking University, Wuhan University, Zhengzhou University, and Hunan University.
  • Each campus network may also be divided into different regional LANs, such as Purcell LAN under the Tsinghua campus network, and then use IP resources as leaf nodes to fill the network nodes to construct a network space resource tree.
  • Rectangular tree diagram as a chart structure to realize the intuitive visualization of the hierarchical structure, uses rectangles to represent the nodes in the tree hierarchical structure, and the hierarchical relationship between parent and child is expressed by the metaphor of nesting between rectangles.
  • the design map application scenarios include real-time cyberspace attack scenarios and DDOS (Distributed Denial of Service, Distributed Denial of Service) attack scenarios.
  • the aforementioned cyberspace map models respectively define concepts such as the AS-based cyberspace base coordinate system, cyberspace map hierarchical structure, and topology thematic maps. Then, on this basis, the data statistics results are visualized to present cyberspace security scenarios in multiple dimensions.
  • Scenario 1 Real-time cyberspace attack scenario, collect the global Internet real-time attack data in the honeypot, and obtain the coordinates (X, Y, Z) in the AS-based cyberspace three-dimensional coordinate system according to the above mapping algorithm for the attack source and destination IP addresses ), visualize real-time attack scenarios, the flying line indicates the attack direction, and the thickness of the line indicates the attack traffic.
  • AS Use AS as the granularity to observe network attack traffic characteristics, analyze attack behaviors, and assist security analysts to better understand and prevent attacks.
  • Scenario 2 Cyberspace DDOS attack scenario, based on the data of a DDOS attack on the Tsinghua server, the coordinates (X, Y, Z) in the three-dimensional coordinate system of the cyberspace based on AS are calculated according to the mapping algorithm for the attack source and destination IP addresses, The thickness of the line indicates the frequency of attacks.
  • AS, network, and IP address information of attack sources and targets can be obtained through different levels and expansions, which can quickly locate security issues and perform vulnerability diagnosis and repair.
  • thematic map can visually display the topological path of the attack experience, realize the topological traceability and discovery of the attack source, and guide the change of the connectivity of the Internet infrastructure when a network security attack occurs.
  • FIG 5 it is a schematic diagram of the network space map model based on the hierarchical and multi-scale representation of the network space original elements. Specifically, click on AS4538 in the AS-based network space map to visualize the network space resource composition under the AS node. First, visualize all large networks under AS4538. Here only the Cernet network is included. The size of the rectangle represents its The scale of the number of IP addresses is 17170688, and then expand down to visualize the distribution of the small campus network under the Cernet network node as shown in Figure 5(a). The campus network nodes are orthogonal and do not overlap. The number of IP addresses under /32 passes through the rectangle In terms of size, the label presents specific network information.
  • the IP address range under the jurisdiction of Guangzhou Normal University campus network GUANGZTC-CN is 202.192.32.0-202.192.47.0, which contains 3840 IP addresses.
  • a certain campus network administrator can click on the campus network to enter the IP level, and visualize the IP resource nodes under the campus network node, as shown in Figure 5(b) shows the IP address information under GUANGZTC-CN, according to different resources
  • the degree of attention of the managed personnel is different, and weights are assigned to the resources that different IP addresses belong to.
  • the server is 3, the host is 1, and the printer is 2, and the size of the rectangle is used to distinguish.
  • the above network space map model only realizes multi-scale visualization and positioning of network resource objects.
  • topological connection is an important attribute of network space, it is often used to express the connection relationship of network space units and realize space unit and space link management. It is necessary to introduce the concept of topology thematic map to realize topology visualization and display the topology connection structure.
  • Research is mainly carried out from the AS layer, network layer, and IP layer.
  • Each network space unit can be composed of network space subunits, and the network space can be divided and reduced in dimension , To achieve multi-level and fine-grained cognition in cyberspace.
  • the topology connection relationship for a certain AS can be directly represented by flying lines in the AS-based network space coordinate system, based on BDP (Business Data Platform, commercial data platform) data draws the topological connection relationship of a certain AS.
  • BDP Business Data Platform, commercial data platform
  • an additional network space sphere model can be designed as a topology topic
  • the map uses a new mapping algorithm to remap AS to a three-dimensional space, and hopes to find a new arrangement to make the crossing between flying lines as few as possible.
  • the force-oriented algorithm calculates the position of the mobile node of the combined force of gravity and repulsion for each node, and considers applying it to the AS topology thematic map visualization to present a more reasonable layout.
  • AS node can be used as the node set N in the force-oriented algorithm, and the BGP connection between ASs is used as the edge and V.
  • the specific algorithm is implemented as follows:
  • AS is a global routing strategy unit, and its traffic relationship defines a high-level global Internet topology.
  • the force-oriented algorithm is used to map the AS to the new three-dimensional coordinates (X, Y, Z).
  • the size of the space ball indicates the number of IP addresses.
  • the topological connection directly connected to it will be displayed.
  • the flying line indicates the topological connection relationship, and the thickness of the line indicates the traffic information.
  • thematic topology map is also suitable for The internal network topology of the AS and the IP topology under the network guide network managers to change the connectivity of the Internet infrastructure when they are under security attacks, assist in checking the hardware configuration, determine where to add new routes, and find bottlenecks and faults in the network.
  • the feedback of this application is to construct a network space coordinate system framework from the original network characteristics AS, IP address, etc. as the entry point, establish a network space map model, and realize the visualization of multi-dimensional information in network space based on a unified and constant backplane, including AS topology, IP address composition, and network Resource element information and hierarchical structure, etc., intuitively and effectively express the network space.
  • a map device that displays cyberspace in multiple dimensions, and apply it to visualization scenarios such as cybersecurity attacks and network management, filling the gaps in spatial theoretical models in cyberspace research, and promoting the development of cyberspace security and surveying and mapping.
  • the feedback of this application also designs a device for creating a multidimensional map showing cyberspace based on the AS cyberspace coordinate system.
  • FIG. 7 it is a schematic diagram of the structure of the map creation device, including:
  • the determination module 1 is used to determine the network space coordinate system based on AS, and realize the analysis and mapping of the IP address of network space elements;
  • Creation module 2 is used to create a network space map model and determine the three layers of the network space hierarchy: AS, network, and IP. Based on a rectangular tree diagram, it is hierarchical and scalable to express the original elements of the network space;
  • Topology thematic map module 3 defines the network space sphere mode to display the topology thematic map, and uses the force-oriented algorithm to map the AS to the new three-dimensional coordinates (X, Y, Z) to realize network space unit and link management;
  • Real-time attack scenario module 4 used to visualize real-time attack scenarios in the cyberspace map model, to help security analysts better understand and prevent attacks;
  • DDOS attack scenario module 5 is used to visualize real-time attack scenarios in the network space map model, which can quickly locate security problems and perform vulnerability diagnosis and repair.
  • the cyberspace coordinate system is a three-dimensional coordinate system.
  • the determining module 1 is specifically used for: constructing a three-dimensional coordinate system of the network space, mapping the AS to the two-dimensional coordinate space according to the above-mentioned preset algorithm, and determining the time sequence of IP address assignment under the AS as the third-dimensional basic vector and AS address Orthogonal.
  • the IP address coordinates (x, y, z) are located based on the Hilbert algorithm and the Z-axis mapping algorithm to realize the analysis and mapping of key attribute IP addresses.
  • Figure 8 it is the mapping of the key attribute IP address of the network space in the three-dimensional coordinate system.
  • Figure 8 analyzes and maps the global IP address space (2 32 ), first locate the ASN to which the IP address belongs, and then locate the coordinates (X, Y, Z) according to the above-mentioned ASN2xy algorithm and the Z-axis mapping algorithm.
  • AS Use the AS as the basis to express the IP address elements of the network space.
  • the cyberspace map model is built on the AS-based cyberspace coordinate system.
  • the creation module 2 is specifically used for: constructing a network space map model, supporting the needs of network space multi-scale traversal, network topology visualization, and network space object positioning.
  • the hierarchical structure is comparable to the geographic map model, AS is analogous to the country, the network corresponds to the provinces and cities, and the IP address is equivalent to the house number.
  • the topology thematic map module 3 is specifically used for: realizing topology visualization of different hierarchical structures.
  • the force-oriented algorithm is used to map the AS to the new three-dimensional coordinates (X, Y, Z), the size of the space ball indicates the number of IP addresses, and the flying line indicates the topological connection relationship.
  • Instruct network managers to change the connectivity of the Internet infrastructure when they are under security attacks, assist in checking the hardware configuration, determine where to add new routes, and discover bottlenecks and faults in the network.
  • the real-time attack scenario module 4 is specifically used to: visualize real-time attack scenarios in the network map model, including the AS-based cyberspace coordinate system and topology thematic map, by observing network attack traffic characteristics at the granularity of AS, and analyzing attack behaviors. Topological traceability and discovery of attack sources help security analysts better understand and prevent attacks.
  • FIG. 9 it is a schematic diagram of the real-time attack scenario module of the cyberspace map.
  • the global real-time attack scenario is visualized on the AS-based cyberspace coordinate system.
  • the attack source and destination IP addresses are based on The above mapping algorithm obtains the coordinates (X, Y, Z) in the three-dimensional coordinate system of the AS-based cyberspace, the flying line represents the attack direction, the thickness of the line represents the attack traffic, and additional attack data analysis.
  • the IP is stacked on the corresponding AS.
  • the large AS launches attacks from multiple IP particles and has large firepower.
  • the thickness of the line represents the attack.
  • FIG. 9(b) is the real-time attack scenario drawn on the AS topology thematic map. Some large central ASs are often both the initiator of real-time attacks and the attack targets of other ASs. Click on the AS to display the topological connections between them. , Realize the topological traceability and discovery of the attack source.
  • the DDOS attack scenario module 5 is specifically used to visualize the DDOS attack scenario in the network map model. Compared with the geographic map, the AS, network, and IP address information of the attack source and target can be obtained through different levels to quickly locate security issues. And perform vulnerability diagnosis and repair. At the same time, shielding the data packets sent from the attack source IP address is also an effective defense against DDOS behavior.
  • FIG 10 is a schematic diagram of a network space map DDOS attack scenario module according to an embodiment of the present application.
  • the DDOS attack scenario on the Tsinghua server is visualized on the AS-based cyberspace coordinate system.
  • the DDOS puppet host and the destination IP address calculate its coordinates (X, Y, Z) in the three-dimensional coordinate system of the AS-based cyberspace.
  • the flying line indicates the attack direction, the thickness of the line indicates the attack traffic, and additional attack data analysis.
  • the AS where the click puppet host is located can be expanded layer by layer based on the rectangular tree diagram to display the network information of the attack source.
  • Figure 10(b) draws the DDOS attack scenario on the AS topology thematic map. By viewing the topological connection of many puppet hosts, the possible location of the attacker is analyzed according to the cross information, so as to realize the source traceability and discovery of the attacker. In addition, understand the target The topology of the host can guide managers to change the connectivity of the Internet infrastructure in the event of a security attack.
  • the three-dimensional coordinate system of the cyberspace is constructed orthogonally by determining the AS number (ASN) and the IP address allocation time sequence under the AS to realize the uniqueness of the cyberspace
  • ASN AS number
  • IP address allocation time sequence under the AS to realize the uniqueness of the cyberspace
  • the precise positioning and description of the IP address can be compared to the network space coordinate system based on the IP address, which can better solve the essential problems of the network space, such as the large IP address space, the expression effect caused by the discontinuous allocation of the IP segment under the AS and the network Bad.
  • the idea of integrating geographic map models is used to construct a network space map model, which supports multi-scale traversal in network space, network topology visualization, and network space object positioning.
  • a network space map model which supports multi-scale traversal in network space, network topology visualization, and network space object positioning.
  • the feature of scalable and hierarchical map is realized, and thematic map module is designed to realize the multidimensional display of network topology details .
  • this application feedback also completes the real-time attack and DDOS design and visualization implementation of map application security scenarios.
  • the intuitive renderings are convenient for managers to analyze traffic and realize the topological traceability and discovery of attack sources.
  • it provides a unified backplane for the visualization of multi-dimensional information in cyberspace, which fills in the gaps in the theoretical model of cyberspace maps.
  • Fig. 11 is a schematic structural diagram of an apparatus for creating a cyberspace coordinate system based on an autonomous system according to an embodiment of the present application.
  • the apparatus for creating a cyberspace coordinate system based on an autonomous system includes: a determining module 100, a first building module 200, a second building module 300, and a design visualization module 400.
  • the determining module 100 is used to determine the cyberspace coordinate system.
  • the first construction module 200 is used to construct a three-dimensional network space coordinate system frame.
  • the second construction module 300 is used to construct a network space map model according to the network space coordinate system and the three-dimensional network space coordinate system framework.
  • the design visualization module 400 is used for designing and constructing application scenarios corresponding to the network space map model, and visualizing the application scenarios.
  • the creation device can visualize multi-dimensional information in cyberspace based on a uniform and constant backplane, including AS topology, IP address composition, network resource element information and hierarchical structure, etc., and is suitable for the visualization of multiple cyberspace security attacks and network management scenarios.
  • the network space coordinate system is a two-dimensional coordinate system
  • the determining module is specifically used to: map the one-dimensional autonomous system number to the two-dimensional coordinate space according to a preset algorithm;
  • the algorithm maps the one-dimensional autonomous system number to the two-dimensional coordinate space, including: using the Hilbert mapping algorithm to perform ascending mapping of the autonomous system number, and determining the network space coordinate system coordinates to collectively represent the network space autonomous system attributes.
  • the first building module is specifically used to: use the IP address allocation time sequence under the autonomous system as the third dimensional basic vector orthogonal to the autonomous system address, and determine the key attributes of the network space IP address analysis and mapping.
  • the second building module is specifically used to: determine that the cyberspace hierarchical structure is divided into three layers: autonomous system, network, and IP; and define the cyberspace ball mode.
  • the device for creating a cyberspace coordinate system based on an autonomous system has specific advantages compared with the traditional geographic coordinate system, topological coordinate system, and IP address-based cyberspace coordinate system. It can be based on
  • the multi-dimensional information visualization of the network space of the unified constant backplane includes AS topology, IP address composition, network resource element information and hierarchical structure, etc., and is suitable for the visualization of multiple cyberspace security attacks and network management scenarios.
  • first and second are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features. Therefore, the features defined with “first” and “second” may explicitly or implicitly include at least one of the features. In the description of feedback in this application, “multiple” means at least two, such as two, three, etc., unless otherwise specifically defined.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Graphics (AREA)
  • Geometry (AREA)
  • Software Systems (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

一种基于自治系统的网络空间坐标系创建方法及装置,其中,方法包括:确定网络空间坐标系;构建三维网络空间坐标系框架;根据网络空间坐标系和三维网络空间坐标系框架构建网络空间地图模型;设计构建网络空间地图模型对应的应用场景,并对应用场景进行可视化处理。可基于统一恒定背板的网络空间多维信息可视化包括AS拓扑,IP地址构成,网络资源要素信息及层次化结构等,并适用于多种网络空间安全攻击及网络管理场景可视化。

Description

基于自治系统的网络空间坐标系创建方法及装置
相关申请的交叉引用
本申请要求清华大学于2019年02月21日提交的、发明名称为“基于自治系统的网络空间坐标系创建方法及装置”的、中国专利申请号“201910128925.7”的优先权。
技术领域
本申请反馈属于网络空间建模和可视化技术领域,特别涉及一种基于自治系统的网络空间坐标系创建方法及装置。
背景技术
网络空间作为“人造”的数字化、信息化、智能化的虚拟空间,目前已经被各个国家广泛关注并上升到国家安全层面。美国在《网络空间安全国家战略》明确了网络空间安全的战略地位,并将网络空间定义为“确保国家关键基础设施正常运转的‘神经系统’和国家控制系统”。《英国网络安全战略》认为网络空间是由数字网络构成互动域,用于存储、修改和传输信息,是国家的重要战略资源载体。
近年来,我国在《国家网络空间安全战略》定义网络空间包括互联网、通信网、计算机系统、自动化控制系统、数字设备及其承载的应用、服务和数据等组成,并积极推进网络空间安全领域的研究。与此同时,其作为平行于地理空间的第二大空间,正在深刻影响人们的生产和生活方式。
但是目前关于网络空间的研究比较局限,究其原因在于尚未建立基本的概念模型和空间理论基础,受限于传统地理坐标系和网络拓扑坐标系缺乏从本源角度表达网络空间的模型和工具。
其中,建立空间模型最根本的任务是构建网络空间坐标系,以地理空间为例,地图学研究通过投影映射将三维球面转换成二维平面,以经度和纬度作为基础向量构建二维地理坐标系,形成地理空间统一绘制背版。对于网络空间而言,传统基于成熟理论模型如地理坐标系和拓扑坐标系的研究只能将网络空间映射到其他空间来表达单一维度的信息,比如地理特性、拓扑关系等,无法提供恒定、全面、直观描述和表达网络空间的方法。亟需构建网络空间特有的坐标体系架构和地图模型,实现空间建模和网络场景可视化。
发明内容
本申请反馈旨在至少在一定程度上解决相关技术中的技术问题之一。
为此,本申请反馈的一个目的在于提出一种基于自治系统的网络空间坐标系创建方法,该方法可基于统一恒定背板的网络空间多维信息可视化包括AS(Autonomous System,自治系统)拓扑,IP地址构成,网络资源要素信息及层次化结构等,并适用于多种网络空间安全攻击及网络管理场景可视化。
本申请反馈的另一个目的在于提出一种基于自治系统的网络空间坐标系创建装置。
为达到上述目的,本申请反馈一方面实施例提出了一种基于自治系统的网络空间坐标系创建方法,包括:确定网络空间坐标系;构建三维网络空间坐标系框架;根据所述网络空间坐标系和所述三维网络空间坐标系框架构建网络空间地图模型;设计所述构建网络空间地图模型对应的应用场景,并对所述应用场景进行可视化处理。
本申请反馈实施例的基于自治系统的网络空间坐标系创建方法,通过提出以自治系统编号(ASN,Autonomous System Number)为基础矢量的二维网络空间坐标系框架设计方案,选取Hilbert映射算法实现一维ASN升维可视化。然后,确定将该AS下的IP地址分配时间序列作为第三维基础矢量与AS地址正交,构建三维网络空间坐标系框架,并对网络空间关键属性IP地址进行分析和映射。再构建网络空间地图模型支持网络空间的可视化表达,基于矩形树图的方式支持网络空间多尺度遍历及网络空间对象定位,层次化、可伸缩表达网络空间本源要素如AS下的网络构成及网络下的IP构成,同时支持网络拓扑可视化,引入拓扑专题地图的概念,采用力导向算法对网络空间AS拓扑关系进行可视化呈现。最终,设计地图应用场景并实现可视化,申请反馈一款多维展现网络空间的地图装置。
另外,根据本申请反馈上述实施例的基于自治系统的网络空间坐标系创建方法还可以具有以下附加的技术特征:
进一步地,在本申请反馈的一个实施例中,所述网络空间坐标系为二维坐标系,所述确定网络空间坐标系,包括:根据预设算法将一维自治系统编号映射到二维坐标空间;所述根据预设算法将一维自治系统编号映射到二维坐标空间,包括:采用Hilbert映射算法对自治系统编号进行升维映射,确定网络空间坐标系坐标共同表示网络空间自治系统属性。
进一步地,在本申请反馈的一个实施例中,所述构建三维网络空间坐标系框架,包括:将自治系统下的IP地址分配时间序列作为第三维基础矢量与自治系统地址正交,并对网络空间关键属性IP地址进行分析和映射。
进一步地,在本申请反馈的一个实施例中,所述网络空间坐标系框架为三维坐标系,包括与二维自治系统基础矢量垂直的第三维坐标轴;
所述将自治系统下的IP地址分配时间序列作为第三维基础矢量与自治系统地址正交, 包括:
与二维坐标系垂直的第三坐标轴表示自治系统下IP地址分配的时间序列,正方向表示序列递增;
所述对网络空间关键属性IP地址进行分析和映射,包括:
通过定义三维坐标系空间建模网络空间,基于通信的关键标识IP地址定位任何一个网络空间资源要素;其中,Z轴映射算描述为对某一自治系统下所管辖的所有IP地址按照分配的时间进行递增排序,同一分配时间下按照IP地址十进制从小到大排序,序列号映射到第三维坐标系;
根据Hilbert算法和Z轴映射算法定位坐标对IP地址进行分析和映射。
进一步地,在本申请反馈的一个实施例中,所述根据所述网络空间坐标系和所述三维网络空间坐标系框架构建网络空间地图模型,包括:
确定网络空间层次结构划分为三层:自治系统、网络、IP;
定义网络空间球模式。
进一步地,在本申请反馈的一个实施例中,所述设计所述构建网络空间地图模型对应的应用场景,并对所述应用场景进行可视化处理,包括:
对于攻击源和目的IP地址根据映射算法计算在基于自治系统的网络空间三维坐标系中的坐标,可视化实时攻击场景,飞线表示攻击方向,线的粗细表示攻击流量;
对于攻击源和目的IP地址根据映射算法计算在基于AS的网络空间三维坐标系中的坐标,线的粗细表示攻击频率。
为达到上述目的,本申请反馈另一方面实施例提出了一种基于自治系统的网络空间坐标系创建装置,包括:确定模块,用于确定网络空间坐标系;第一构建模块,用于构建三维网络空间坐标系框架;第二构建模块,用于根据所述网络空间坐标系和所述三维网络空间坐标系框架构建网络空间地图模型;设计可视化模块,用于设计所述构建网络空间地图模型对应的应用场景,并对所述应用场景进行可视化处理。
本申请反馈实施例的基于自治系统的网络空间坐标系创建装置,通过提出以自治系统编号为基础矢量的二维网络空间坐标系框架设计方案,选取Hilbert映射算法实现一维ASN升维可视化。然后,确定将该AS下的IP地址分配时间序列作为第三维基础矢量与AS地址正交,构建三维网络空间坐标系框架,并对网络空间关键属性IP地址进行分析和映射。再构建网络空间地图模型支持网络空间的可视化表达,基于矩形树图的方式支持网络空间多尺度遍历及网络空间对象定位,层次化、可伸缩表达网络空间本源要素如AS下的网络构成及网络下的IP构成,同时支持网络拓扑可视化,引入拓扑专题地图的概念,采用力导向算法对网络空间AS拓扑关系进行可视化呈现。最终,设计地图应用场景并实现可视化, 申请反馈一款多维展现网络空间的地图装置。
另外,根据本申请反馈上述实施例的基于自治系统的网络空间坐标系创建装置还可以具有以下附加的技术特征:
进一步地,在本申请反馈的一个实施例中,所述网络空间坐标系为二维坐标系,所述确定模块,具体用于:根据预设算法将一维自治系统编号映射到二维坐标空间;所述根据预设算法将一维自治系统编号映射到二维坐标空间,包括:采用Hilbert映射算法对自治系统编号进行升维映射,确定网络空间坐标系坐标共同表示网络空间自治系统属性。
进一步地,在本申请反馈的一个实施例中,所述第一构建模块,具体用于:将自治系统下的IP地址分配时间序列作为第三维基础矢量与自治系统地址正交,并对网络空间关键属性IP地址进行分析和映射。
进一步地,在本申请反馈的一个实施例中,所述第二构建模块,具体用于:确定网络空间层次结构划分为三层:自治系统、网络、IP;定义网络空间球模式。
本申请反馈附加的方面和优点将在下面的描述中部分给出,部分将从下面的描述中变得明显,或通过本申请反馈的实践了解到。
附图说明
本申请反馈上述的和/或附加的方面和优点从下面结合附图对实施例的描述中将变得明显和容易理解,其中:
图1为根据本申请反馈一个实施例的基于自治系统的网络空间坐标系创建方法流程图;
图2为根据本申请反馈一个实施例的根据Hilbert映射算法将指定范围的一维ASN映射到二维坐标空间图;
图3为根据本申请反馈一个实施例的以AS为基础的网络空间三维坐标系框架示意图;
图4为根据本申请反馈一个具体实施例的基于AS的网络空间坐标系的创建方法的流程示意图;
图5为根据本申请反馈一个实施例的网络空间地图模型中基于矩形树图层次化、多尺度表达网络空间本源要素示意图;
图6为根据本申请反馈一个实施例的网络空间模型中基于力导向算法直观表达AS拓扑连接关系的拓扑专题地图;
图7为根据本申请反馈一个实施例的基于AS的网络空间坐标系的一款多维展现网络空间的地图的创建装置的结构示意图;
图8为根据本申请反馈一个实施例的网络空间关键属性IP地址在三维坐标系中的映射图;
图9为根据本申请反馈一个实施例的网络空间地图实时攻击场景模块示意图;
图10为根据本申请反馈一个实施例的网络空间地图DDOS攻击场景模块示意图;
图11为根据本申请反馈一个实施例的基于自治系统的网络空间坐标系创建装置结构示意图。
具体实施方式
下面详细描述本申请反馈的实施例,所述实施例的示例在附图中示出,其中自始至终相同或类似的标号表示相同或类似的元件或具有相同或类似功能的元件。下面通过参考附图描述的实施例是示例性的,旨在用于解释本申请反馈,而不能理解为对本申请反馈的限制。
下面参照附图描述根据本申请反馈实施例提出的基于自治系统的网络空间坐标系创建方法及装置。
首先将参照附图描述根据本申请反馈实施例提出的基于自治系统的网络空间坐标系创建方法。
图1为根据本申请反馈一个实施例的基于自治系统的网络空间坐标系创建方法流程图。
如图1所示,该基于自治系统的网络空间坐标系创建方法包括以下步骤:
在步骤S101中,确定网络空间坐标系。
进一步地,在本申请反馈的一个实施例中,网络空间坐标系为二维坐标系。
其中,确定网络空间坐标系,包括:根据预设算法将一维自治系统编号映射到二维坐标空间。
根据预设算法将一维自治系统编号映射到二维坐标空间,包括:采用Hilbert映射算法对自治系统编号(ASN,Autonomous System Number)进行升维映射,确定网络空间坐标系坐标共同表示网络空间自治系统属性,类似地理空间模型中经纬度对国家信息的表达。
具体地,确定网络空间坐标系采用AS(Autonomous System,自治系统)编号作为基础矢量,根据预设算法将一维ASN映射到二维坐标系。
在步骤S102中,构建三维网络空间坐标系框架。
进一步地,在本申请反馈的一个实施例中,包括:将自治系统下的IP地址分配时间序列作为第三维基础矢量与自治系统地址正交,并对网络空间关键属性IP地址进行分析和映射。
具体地,确定第三维基础矢量将该AS下的IP地址分配时间序列与AS地址正交构建网络空间坐标系框架,并对网络空间关键属性IP地址进行分析和映射。
进一步地,网络空间坐标系框架为三维坐标系,包括与二维自治系统基础矢量垂直的 第三维坐标轴;将该AS下的IP地址分配时间序列作为第三维基础矢量与AS地址正交,包括:
与二维坐标系垂直的第三坐标轴表示的是AS下IP地址分配的时间序列,正方向表示序列递增;
对网络空间关键属性IP地址进行分析和映射,包括:
通过定义三维坐标系空间建模网络空间,能够基于通信的关键标识IP地址定位任何一个网络空间资源要素。其中Z轴映射算描述为对某一AS下所管辖的所有IP地址按照分配的时间进行递增排序,同一分配时间下按照IP地址十进制从小到大排序,序列号映射到第三维坐标系,可根据上述Hilbert算法和Z轴映射算法定位坐标(x,y,z)对IP地址进行分析和映射;
根据Hilbert算法和Z轴映射算法定位坐标对IP地址进行分析和映射。
在步骤S103中,根据网络空间坐标系和三维网络空间坐标系框架构建网络空间地图模型。
进一步地,在本申请反馈的一个实施例中,根据网络空间坐标系和三维网络空间坐标系框架构建网络空间地图模型,包括:确定网络空间层次结构划分为三层:自治系统、网络、IP;定义网络空间球模式。
具体地,构建的网络空间地图模型,直观表达网络层次结构及AS拓扑连接关系。
在步骤S104中,设计构建网络空间地图模型对应的应用场景,并对应用场景进行可视化处理。
设计基于AS的网络空间坐标系构建网络空间地图模型,支持网络空间的可视化表达,支持网络空间多尺度遍历、网络拓扑可视化、网络空间对象定位等需求。实现层次化、可伸缩的地图特性,满足从不同的层次展现网络空间对象分布情况的可视化需求。同时引入拓扑专题地图的概念进行网络拓扑可视化。
满足网络空间多尺度遍历、对象定位、网络拓扑可视化等需求,包括:
确定网络空间层次结构划分三层:AS、网络、IP,比照地理地图模型,AS类比于国家,网络对应省市,IP地址相当于住宅的门牌号,基于矩形树图的方式层次化、多尺度表达网络空间本源要素如AS下的网络构成及网络下的IP构成,满足不同级别管理人员的可视化及定位需求。
定义网络空间球模式实现网络拓扑可视化。以AS拓扑为例,根据AS管辖的IP地址数量以及BGP数据,采用力导向算法将AS映射到新的三维坐标(X,Y,Z),空间球大小表示IP地址数量,飞线表示拓扑连接关系。空间球模式同样适用于AS内部网络拓扑,及IP拓扑,实现空间单元和空间链路管理。
进一步地,在本申请反馈的一个实施例中,设计构建网络空间地图模型对应的应用场景,并对应用场景进行可视化处理,包括:对于攻击源和目的IP地址根据映射算法计算在 基于自治系统的网络空间三维坐标系中的坐标,可视化实时攻击场景,飞线表示攻击方向,线的粗细表示攻击流量;对于攻击源和目的IP地址根据映射算法计算在基于AS的网络空间三维坐标系中的坐标,线的粗细表示攻击频率。
具体地,设计地图应用场景并进行可视化实现包括两个场景:
场景1:网络空间实时攻击场景。对于攻击源和目的IP地址根据映射算法计算在基于AS的网络空间三维坐标系中的坐标(X,Y,Z),可视化实时攻击场景,飞线表示攻击方向,线的粗细表示攻击流量。以AS为粒度观察网络攻击流量特性,分析攻击行为,协助安全分析人员更好的认识和防范攻击。
场景2:网络空间DDOS攻击场景。对于攻击源和目的IP地址根据映射算法计算在基于AS的网络空间三维坐标系中的坐标(X,Y,Z),线的粗细表示攻击频率。相比于地理地图而言,通过不同层次展开获取攻击源和目标的AS、网络、IP地址信息,可快速定位安全问题并进行漏洞诊断和修复。
此外,在拓扑专题地图中绘制上述攻击场景,可直观展现攻击经历的拓扑路径,实现对攻击源的拓扑溯源和发现,指导受到网络安全攻击时更改互联网基础设施的连接性。
该方法首先确定以AS编号(ASN)为基础矢量的网络空间坐标系架构,考虑到网络空间是一个虚拟的信息空间,其中海量信息自由流动构成网络空间瞬时多样,选择可恒定表征网络空间本源的基础向量对于建立网络空间地图模型而言至关重要。
自治系统(AS)作为处于一个管理机构控制之下的网络和IP地址的集合相当于地理空间中的国家,是网络空间域间业务往来和通信的基本单位。选取Hilbert映射算法实现一维ASN升维可视化,同时构建以AS下的IP地址分配时间序列为第三维基础矢量的网络空间坐标系框架,用于表达网络空间信息通信的关键属性—IP地址信息。
下面结合附图及具体实施例对本申请反馈的基于自治系统的网络空间坐标系创建方法进行详细说明。
如图2所示,为根据Hilbert映射算法将指定范围的一维ASN映射到二维坐标空间。自治系统(AS)作为处于一个管理机构控制之下的网络和IP地址的集合相当于地理空间中的国家,是网络空间域间业务往来和通信的基本单位。Hilbert映射算法作为一种升维算法可将指定范围的一维ASN编号映射到二维坐标系空间,较好的保证ASN的邻近性,构建网络空间坐标系的基础二维平面。
首先简要介绍Hilbert映射算法,其中,阶数表示Hilbert映射的展开程度以及所能表示的范围。将ASN映射到二维坐标(X,Y)的算法流程如下:
Figure PCTCN2019097739-appb-000001
Figure PCTCN2019097739-appb-000002
Figure PCTCN2019097739-appb-000003
指定ASN范围为[0,2 2n-1],对应的Hilbert映射算法阶数为n。图2分别展示了指定ASN范围为[0,3],[0,15],[0,63],[0,255]映射得到的二维坐标空间。将上述算法应用于整个ASN空间[0,65535]进行升维映射,对应的Hilbert阶数n等于8,可确定以AS为基础的网络空间二维坐标系。
图3为根据本申请反馈一个实施例的以AS为基础的网络空间三维坐标系框架示意图,如图3所示,在上述二维坐标系的基础上,将该AS下的IP地址分配时间序列作为第三维基础矢量与AS地址正交,正方向表示序列递增。具体地,Z轴映射算法定义如下:
S1:设某一AS下所管辖的IP地址有n个{IP 1,IP 2,IP 3,IP 4,IP 5,IP 6,…,IP n},同时采集对应的分配时间{T 1,T 2,T 3,T4,T 5,T 6,…,T n},精确到秒;
S2:未分配的IP地址分配时间定义为MAXINT>max{T 1,T 2,T 3,T4,T 5,T 6,…,T n};
S3:针对该AS下的所有IP地址按照分配的时间进行递增排序,同一分配时间下按照IP地址的十进制从小到大排序,得到新的IP地址序列{NIP 1,NIP 2,NIP 3,NIP 4,NIP 5,NIP 6,…,NIP n},序列号映射到第三维坐标系。
如图3所示Z=10000表示某一IP地址在根据分配时间排序得到的新的IP地址序列中位于第10000位。
图4为根据本申请反馈一个具体实施例的基于AS的网络空间坐标系的创建方法的流程示意图。
如图4所示,本实施例提供的基于AS的网络空间坐标系的创建方法,包括以下步骤:
(1)确定网络空间坐标系采用AS编号(ASN)作为基础矢量,根据预设算法将一维ASN映射到二维坐标系。
在本实施例中,网络空间坐标系为基于上述Hilbert映射算法得到的二维坐标空间,以ASN作为基础矢量表征网络空间自治系统要素。
具体地,考虑到网络空间是一个虚拟的信息空间,其中,海量信息自由流动构成网络空间瞬时多样,选择可恒定表征网络空间本源的基础向量对于建立网络空间地图模型而言至关重要。
自治系统(AS)作为处于一个管理机构控制之下的网络和IP地址的集合相当于地理空间中的国家,是网络空间域间业务往来和通信的基本单位。
根据上述Hilbert映射算法构建以AS为基础的网络空间二维坐标系,确定统一、恒定的背板展现网络空间自治系统要素。
(2)构建三维网络空间坐标系框架,确定将该AS下的IP地址分配时间序列作为第三维基础矢量与AS地址正交,并对网络空间关键属性IP地址进行分析和映射。
具体地,考虑到二维坐标系局限于自治系统要素的表达,而在网络空间中,IP地址作为设备连接到网络时分配的唯一指纹,提供了主机在网络空间中的位置和网络接口标识,是所有网络空间资源要素的关键标识。
因此,本申请反馈在二维坐标系的基础上添加AS下的IP地址分配时间序列作为第三维矢量与之正交,构建三维网络空间坐标系框架表达IP信息。
举例来说,某一IP地址166.111.8.2属于AS4538,根据ASN2xy算法得到平面坐标(24,76)将AS4538下管辖的所有IP地址依据上述Z轴映射算法先按照时间序排序,将166.111.8.2分配时间的排序号8902将作为该IP地址的Z轴表示,于是在三维坐标系中(24,76,8902)将作为该IP地址的唯一表示,同时标识到全球互联网空间的唯一联网设备,表达网络空间资源信息。
具体地,相较于以IP地址为基础矢量的网络空间坐标系能够较好解决网络空间本质问题,例如IP地址空间过大难以全面表达,2 32约40亿地址空间难以寻求较好的可视化方案;IP地址段分配不连续造成同一AS下IP地址分散,以AS4538为例,其下的IP地址段包括101.4.0.0/14、101.5.0.0/16、101.77.0.0/16、111.186.0.0/15、114.212.0.0/16等,在可视化过 程中同一AS分散在IP地址坐标系各个位置,表达效果不佳。
(3)构建网络空间地图模型,支持网络空间的可视化表达,满足网络空间多尺度遍历、对象定位、网络拓扑可视化等需求。
具体地,以AS为基础的网络空间坐标系虽然可以直观的表达IP粒度,但是缺乏对网络空间细节的层次化呈现。难以满足网络空间多尺度遍历、对象定位等需求。融合地理地图模型的思想构建网络空间地图模型,考虑到不同用户对网络空间对象分布情况、资源信息、连接关系等不同的可视化需求,需要满足可伸缩、层次化的地图特性。同时其作为平行于地理空间的第二大空间,地理空间中有相应的地理地图和专题地图可伸缩表达山川、河流、城市街道,网络空间地图模型也需要设计一些专题地图模块来实现特定网络细节的多维展示,本文以拓扑专题地图为例进行设计和阐述。
具体地,支持网络空间多尺度遍历,满足可伸缩、层次化的地图特性需要先对网络空间进行层次结构的划分,参照地理地图模型确定网络空间层次结构划分三层:AS、网络、IP,AS类比于国家,网络对应省市,IP地址相当于住宅的门牌号。其中,基于矩形树图的方式支持网络空间多尺度遍历、对象定位,通过对网络空间资源要素层层展开,细粒度可视化某一AS下的网络构成,网络下的IP资源构成,可以方便不同级别的网络管理人员进行资产管理和运营维护。
具体地,支持网络空间对象定位将网络空间中AS,网络,IP地址的资源层次结构抽象为一颗树,根节点整表示个网络空间中所有资源,根据AS对网络空间进行划分得到多个表示AS含义的子节点,AS下大大小小的网络可以作为AS节点的划分和延伸,树的天然结构可以用来表达网络之间存在包含关系,例如Cernet(中国教育和科研计算机网,China Education and Research Network)网络下包含骨干网、清华、北大、武汉大学、郑州大学、湖南大学等一百多所高校的校园网。每个校园网内部还可能划分不同的区域局域网,如清华校园网下的赛尔公司局域网,然后以IP资源作为叶子结点对网络结点进行填充构造网络空间资源树。矩形树图作为实现层次结构直观可视化的图表结构,采用矩形的方式来表示树形层次结构中的节点,父子之前的层次关系通过矩形之间的相互嵌套隐喻表达。
(4)设计地图应用场景并进行可视化实现,申请反馈一款多维展现网络空间的地图装置。
具体地,设计地图应用场景包括网络空间实时攻击场景和DDOS(分布式拒绝服务,Distributed Denial of Service))攻击场景。上述网络空间地图模型分别定义了以AS为基础的网络空间基坐标系、网络空间地图层次结构、拓扑专题地图等概念,接下来在此基础上可视化数据统计结果,多维呈现网络空间安全场景。
场景1:网络空间实时攻击场景,采集蜜罐中全球互联网实时攻击数据,并对于攻击源 和目的IP地址根据上述映射算法获取在基于AS的网络空间三维坐标系中的坐标(X,Y,Z),可视化实时攻击场景,飞线表示攻击方向,线的粗细表示攻击流量。以AS为粒度观察网络攻击流量特性,分析攻击行为,协助安全分析人员更好的认识和防范攻击。
场景2:网络空间DDOS攻击场景,基于清华服务器受到的一次DDOS攻击数据,对于攻击源和目的IP地址根据映射算法计算在基于AS的网络空间三维坐标系中的坐标(X,Y,Z),线的粗细表示攻击频率。相比于地理地图而言,通过不同层次化、伸缩展开获取攻击源和目标的AS、网络、IP地址信息,可快速定位安全问题并进行漏洞诊断和修复。
此外,在拓扑专题地图中绘制上述攻击场景,可直观展现攻击经历的拓扑路径,实现对攻击源的拓扑溯源和发现,指导受到网络安全攻击时更改互联网基础设施的连接性。
如图5所示,为网络空间地图模型中基于矩形树图层次化、多尺度表达网络空间本源要素示意图。具体表示在以AS为基础的网络空间地图中点击AS4538后可视化该AS节点下的网络空间资源构成,首先对AS4538下的所有大型网络进行可视化,这里只包含Cernet网络,其中,矩形的大小表示其IP地址的数量规模为17170688,然后向下展开可视化Cernet网络节点下小型校园网分布如图5(a)所示,校园网络节点正交且不重合,其下/32的IP地址数量通过矩形的大小来表示,标签呈现具体的网络信息,eg.广州师范大学校园网GUANGZTC-CN管辖的IP地址范围为202.192.32.0-202.192.47.0,包含3840个IP地址数量。接下来某一校园网管理人员可通过点击该校园网进入到IP层次,可视化该校园网节点下的IP资源节点,如图5(b)表示GUANGZTC-CN下的IP地址信息,根据不同的资源受管理人员的关注度不同,对不同的IP地址所属资源赋予权重,eg.服务器为3,主机为1,打印机为2,采用矩形的大小进行区分表示。
通过层次化、可伸缩的直观表达可以呈现网络空间细粒度的资源信息,满足不同级别管理人员的可视化需求。
具体地,上述网络空间地图模型只实现了网络资源对象的多尺度可视化及定位,考虑到拓扑连接作为网络空间重要属性,常用于表达网络空间单元的连接关系,实现空间单元和空间链路管理,需要引入拓扑专题地图的概念实现拓扑可视化、展现拓扑连接结构,主要从AS层、网络层、IP层开展研究,每个网络空间单元可以由网络空间子单元构成,进而将网络空间剖分降维,实现网络空间多层次、细粒度的认知。
具体地,支持拓扑可视化,设计拓扑专题地图实现特定网络细节的多维展示时,针对某一AS的拓扑连接关系可以在以AS为基础的网络空间坐标系中直接通过飞线表示,基于BDP(Business Data Platform,商业数据平台)数据绘制某一AS的拓扑连接关系。但是考虑到全球网络单元之间的拓扑连接关系较为复杂,绘制全网拓扑可能出现飞线之间交叉严重导致可视化效果不佳,在这种情况下可以额外设计一种网络空间球模式作为拓扑专题地 图,采用新的映射算法将AS重新映射到三维空间,并且希望寻求一种新的排列方式使得飞线之间的交叉尽可能少。其中,力导向算法作为一种经典的图布局算法,通过对每个节点计算出引力和斥力综合的合力移动节点的位置,考虑将其应用于AS拓扑专题地图可视化呈现较为合理的布局。
进一步地,将AS节点可以作为力导向算法中的节点集N,AS之间的BGP连接作为边及V,具体的算法实现如下:
Figure PCTCN2019097739-appb-000004
如图6所示,为网络空间模型中基于力导向算法直观表达AS拓扑连接关系的拓扑专题地图。AS作为全球的路由策略单元,其流量往来关系定义了高级别的全球互联网拓扑。
如图6所示,以AS拓扑为例,根据AS管辖的IP地址数量以及BGP(Border Gateway Protocol,边界网关协议)数据,采用上述力导向算法将AS映射到新的三维坐标(X,Y,Z),空间球大小表示IP地址数量规模,当选择特定的AS后,显示与其直连的拓扑连,其中飞线表示拓扑连接关系,线的粗细表示流量信息,此外,拓扑专题地图同样适用于AS内部网络拓扑,及网络下的IP拓扑,指导网络管理人员在受到安全攻击时更改互联网基础设施的连接性,协助检查硬件配置情况,确定新路由添加位置,发现网络中的瓶颈和故障等。
本申请反馈从网络本源特征AS,IP地址等为切入点构建网络空间坐标系框架,建立网络空间地图模型,实现基于统一恒定背板的网络空间多维信息可视化,包括AS拓扑,IP地址构成,网络资源要素信息及层次化结构等,直观有效的表达网络空间。相比基于IP地址和逻辑端口的网络空间坐标体系架构创建方法,能够较好的解决网络本质问题AS、网络下IP段分配不连续造成的可视化效果不佳,直观表达网络层次结构及AS拓扑连接关系。此外,申请反馈一款多维展现网络空间的地图装置,将其应用于网络安全攻击,网络管理等可视化场景,填补网络空间研究领域空间理论模型的空白,促进网络空间安全及测绘领域的发展。
本申请反馈还设计基于AS的网络空间坐标系的一款多维展现网络空间的地图的创建装置。
如图7所示,为地图的创建装置的结构示意图,包括:
确定模块1,用于确定以AS为基础的网络空间坐标系,实现对网络空间要素IP地址的分析和映射;
创建模块2,用于创建网络空间地图模型,确定网络空间层次结构划分三层:AS、网络、IP,基于矩形树图的方式层次化、可伸缩表达网络空间本源要素;
拓扑专题地图模块3,定义网络空间球模式展现拓扑专题地图,采用力导向算法将AS映射到新的三维坐标(X,Y,Z),实现网络空间单元和链路管理;
实时攻击场景模块4,用于在网络空间地图模型中可视化实时攻击场景,协助安全分析人员更好的认识和防范攻击;
DDOS攻击场景模块5,用于在网络空间地图模型中可视化实时攻击场景,可快速定位安全问题并进行漏洞诊断和修复。
进一步地,网络空间坐标系为三维坐标系。
进一步地,确定模块1具体用于:构建网络空间三维坐标系,将AS根据上述预设算法映射到二维坐标空间,确定将该AS下的IP地址分配时间序列作为第三维基础矢量与AS地址正交。基于Hilbert算法和Z轴映射算法定位IP地址坐标(x,y,z),实现对关键属性IP地址进行分析和映射。
具体地,如图8所示,为网络空间关键属性IP地址在三维坐标系中的映射,通过定义三维坐标系空间建模网络空间,可实现基于通信的关键标识IP地址定位任何一个网络空间资源要素。图8对全球IP地址空间(2 32)进行分析和映射,首先定位IP地址所属ASN,然后根据上述ASN2xy算法和Z轴映射算法定位到坐标(X,Y,Z)。以AS为基础矢量表达网络空间IP地址要素。
进一步地,网络空间地图模型建立在基于AS的网络空间坐标系上。
创建模块2具体用于:构建网络空间地图模型,支持网络空间多尺度遍历、网络拓扑可视化、网络空间对象定位等需求。层次结构比照地理地图模型,AS类比于国家,网络对应省市,IP地址相当于住宅的门牌号。基于矩形树图的方式层次化、可伸缩表达网络空间本源要素如AS下的网络构成及网络下的IP构成,满足不同级别管理人员的可视化需求。
进一步地,拓扑专题地图模块3具体用于:实现不同层次结构的拓扑可视化。以AS层为例,根据AS管辖的IP地址数量以及BGP数据,采用力导向算法将AS映射到新的三维坐标(X,Y,Z),空间球大小表示IP地址数量,飞线表示拓扑连接关系。指导网络管理人员在受到安全攻击时更改互联网基础设施的连接性,协助检查硬件配置情况,确定新路由添加位置,发现网络中的瓶颈和故障等。
实时攻击场景模块4具体用于:在网络地图模型中可视化实时攻击场景,包括以AS为基础的网络空间坐标系和拓扑专题地图,通过在AS为粒度观察网络攻击流量特性,分析攻击行为,实现对攻击源的拓扑溯源和发现,协助安全分析人员更好的认识和防范攻击。
如图9所示,为网络空间地图实时攻击场景模块示意图,如图9(a)所示,在以AS为基础的网络空间坐标系上可视化全球实时攻击场景,对于攻击源和目的IP地址根据上述映射算法获取在基于AS的网络空间三维坐标系中的坐标(X,Y,Z),飞线表示攻击方向,线的粗细表示攻击流量,附加攻击数据分析。可观察到IP堆叠在相应AS上,有摩天堡垒(大的AS),有小茅草房(小的AS),大的AS从多个IP粒子发起攻击,火力大,这里用线的粗细表示攻击火力,同时受到别的很多AS的攻击(目标也更大);小的AS(小草房)火力弱但是受到的攻击也少,便于在AS为粒度观察网络攻击流量特性,分析攻击行为。图9(b)是将实时攻击场景绘制在AS拓扑专题地图中,一些大的在中心的AS往往既是实时攻击的发起者,也是其他AS的攻击目标,点击AS可显示其之间的拓扑连接,实现对攻击源的拓扑溯源和发现。
DDOS攻击场景模块5具体用于:在网络地图模型中可视化DDOS攻击场景,相比于地理地图而言,通过不同层次展开获取攻击源和目标的AS、网络、IP地址信息,可快速定位安全问题并进行漏洞诊断和修复。同时,屏蔽攻击源IP地址发送的数据包也是实现DDOS行为的有效防范。
图10为根据本申请反馈一个实施例的网络空间地图DDOS攻击场景模块示意图,如图10(a)所示,在以AS为基础的网络空间坐标系上可视化对清华服务器的DDOS攻击场景,对于DDOS傀儡主机和目的IP地址计算其在基于AS的网络空间三维坐标系中的坐标(X,Y,Z),飞线表示攻击方向,线的粗细表示攻击流量,附加攻击数据分析。相比于地理地图只能在地理空间上细化,实现了点击傀儡主机所处的AS可基于矩形树图对其所处的网络空间资源要素层层展开,细粒度呈现攻击源的网络信息、网段信息、IP信息,同时屏蔽 攻击源IP地址段发送的数据包可以进行暂时性防护。图10(b)将DDOS攻击场景绘制在AS拓扑专题地图中,通过查看众多傀儡主机的拓扑连接关系,根据交叉信息分析攻击者可能出现位置,实现对攻击者的溯源和发现,此外,了解目标主机的拓扑情况可指导管理人员在受到安全攻击时更改互联网基础设施的连接性。
根据本申请反馈实施例提出的基于自治系统的网络空间坐标系创建方法,通过确定AS编号(ASN)与AS下的IP地址分配时间序列正交构建网络空间三维坐标系,实现对网络空间中唯一标识IP地址的精准定位和描述,相较于IP地址为基础矢量的网络空间坐标系能够较好解决网络空间本质问题,例如IP地址空间大,AS、网络下IP段分配不连续造成的表达效果不佳。
在上述基础上,融合地理地图模型的思想构建网络空间地图模型,支持网络空间多尺度遍历、网络拓扑可视化、网络空间对象定位。考虑到不同用户对不同网络空间对象(AS、网络、IP)的分布情况、资源信息的可视化需求,实现了可伸缩、层次化的地图特性,并设计专题地图模块来实现网络拓扑细节的多维展示,满足管理人员不同的可视化需求。此外,本申请反馈还完成地图应用安全场景实时攻击和DDOS设计及可视化实现,直观的效果图便于管理人员进行流量分析,实现对攻击源的拓扑溯源和发现。相比于传统基于成熟理论模型的研究提供了一种用于网络空间多维信息可视化的统一背板,填补了网络空间地图理论模型的空白。
其次参照附图描述根据本申请反馈实施例提出的基于自治系统的网络空间坐标系创建装置。
图11为根据本申请反馈一个实施例的基于自治系统的网络空间坐标系创建装置结构示意图。
如图11所示,该基于自治系统的网络空间坐标系创建装置包括:确定模块100、第一构建模块200、第二构建模块300和设计可视化模块400。
其中,确定模块100用于确定网络空间坐标系。第一构建模块200用于构建三维网络空间坐标系框架。第二构建模块300用于根据网络空间坐标系和三维网络空间坐标系框架构建网络空间地图模型。设计可视化模块400用于设计构建网络空间地图模型对应的应用场景,并对应用场景进行可视化处理。
该创建装置可基于统一恒定背板的网络空间多维信息可视化包括AS拓扑,IP地址构成,网络资源要素信息及层次化结构等,并适用于多种网络空间安全攻击及网络管理场景可视化。
进一步地,在本申请反馈的一个实施例中,网络空间坐标系为二维坐标系,确定模块,具体用于:根据预设算法将一维自治系统编号映射到二维坐标空间;根据预设算法将一维 自治系统编号映射到二维坐标空间,包括:采用Hilbert映射算法对自治系统编号进行升维映射,确定网络空间坐标系坐标共同表示网络空间自治系统属性。
进一步地,在本申请反馈的一个实施例中,第一构建模块,具体用于:将自治系统下的IP地址分配时间序列作为第三维基础矢量与自治系统地址正交,并对网络空间关键属性IP地址进行分析和映射。
进一步地,在本申请反馈的一个实施例中,第二构建模块,具体用于:确定网络空间层次结构划分为三层:自治系统、网络、IP;定义网络空间球模式。
需要说明的是,前述对基于自治系统的网络空间坐标系创建方法实施例的解释说明也适用于该实施例的装置,此处不再赘述。
根据本申请反馈实施例提出的基于自治系统的网络空间坐标系创建装置,相比较传统的地理坐标系、拓扑坐标系、IP地址为基础的网络空间坐标系而言具备特定的优越性,可基于统一恒定背板的网络空间多维信息可视化包括AS拓扑,IP地址构成,网络资源要素信息及层次化结构等,并适用于多种网络空间安全攻击及网络管理场景可视化。
此外,术语“第一”、“第二”仅用于描述目的,而不能理解为指示或暗示相对重要性或者隐含指明所指示的技术特征的数量。由此,限定有“第一”、“第二”的特征可以明示或者隐含地包括至少一个该特征。在本申请反馈的描述中,“多个”的含义是至少两个,例如两个,三个等,除非另有明确具体的限定。
在本说明书的描述中,参考术语“一个实施例”、“一些实施例”、“示例”、“具体示例”、或“一些示例”等的描述意指结合该实施例或示例描述的具体特征、结构、材料或者特点包含于本申请反馈的至少一个实施例或示例中。在本说明书中,对上述术语的示意性表述不必须针对的是相同的实施例或示例。而且,描述的具体特征、结构、材料或者特点可以在任一个或多个实施例或示例中以合适的方式结合。此外,在不相互矛盾的情况下,本领域的技术人员可以将本说明书中描述的不同实施例或示例以及不同实施例或示例的特征进行结合和组合。
尽管上面已经示出和描述了本申请反馈的实施例,可以理解的是,上述实施例是示例性的,不能理解为对本申请反馈的限制,本领域的普通技术人员在本申请反馈的范围内可以对上述实施例进行变化、修改、替换和变型。

Claims (10)

  1. 一种基于自治系统的网络空间坐标系创建方法,其特征在于,包括以下步骤:
    确定网络空间坐标系;
    构建三维网络空间坐标系框架;
    根据所述网络空间坐标系和所述三维网络空间坐标系框架构建网络空间地图模型;
    设计所述构建网络空间地图模型对应的应用场景,并对所述应用场景进行可视化处理。
  2. 如权利要求1所述的基于自治系统的网络空间坐标系创建方法,其特征在于,所述网络空间坐标系为二维坐标系,所述确定网络空间坐标系,包括:
    根据预设算法将一维自治系统编号映射到二维坐标空间;
    所述根据预设算法将一维自治系统编号映射到二维坐标空间,包括:
    采用Hilbert映射算法对自治系统编号进行升维映射,确定网络空间坐标系坐标共同表示网络空间自治系统属性。
  3. 如权利要求1所述的基于自治系统的网络空间坐标系创建方法,其特征在于,所述构建三维网络空间坐标系框架,包括:
    将自治系统下的IP地址分配时间序列作为第三维基础矢量与自治系统地址正交,并对网络空间关键属性IP地址进行分析和映射。
  4. 如权利要求1所述的基于自治系统的网络空间坐标系创建方法,其特征在于,所述网络空间坐标系框架为三维坐标系,包括与二维自治系统基础矢量垂直的第三维坐标轴;
    所述将自治系统下的IP地址分配时间序列作为第三维基础矢量与自治系统地址正交,包括:
    与二维坐标系垂直的第三坐标轴表示自治系统下IP地址分配的时间序列,正方向表示序列递增;
    所述对网络空间关键属性IP地址进行分析和映射,包括:
    通过定义三维坐标系空间建模网络空间,基于通信的关键标识IP地址定位任何一个网络空间资源要素;其中,Z轴映射算描述为对某一自治系统下所管辖的所有IP地址按照分配的时间进行递增排序,同一分配时间下按照IP地址十进制从小到大排序,序列号映射到第三维坐标系;
    根据Hilbert算法和Z轴映射算法定位坐标对IP地址进行分析和映射。
  5. 如权利要求1所述的基于自治系统的网络空间坐标系创建方法,其特征在于,所述根据所述网络空间坐标系和所述三维网络空间坐标系框架构建网络空间地图模型,包括:
    确定网络空间层次结构划分为三层:自治系统、网络、IP;
    定义网络空间球模式。
  6. 如权利要求1所述的基于自治系统的网络空间坐标系创建方法,其特征在于,所述设计所述构建网络空间地图模型对应的应用场景,并对所述应用场景进行可视化处理,包括:
    对于攻击源和目的IP地址根据映射算法计算在基于自治系统的网络空间三维坐标系中的坐标,可视化实时攻击场景,飞线表示攻击方向,线的粗细表示攻击流量;
    对于攻击源和目的IP地址根据映射算法计算在基于AS的网络空间三维坐标系中的坐标,线的粗细表示攻击频率。
  7. 一种基于自治系统的网络空间坐标系创建装置,其特征在于,包括:
    确定模块,用于确定网络空间坐标系;
    第一构建模块,用于构建三维网络空间坐标系框架;
    第二构建模块,用于根据所述网络空间坐标系和所述三维网络空间坐标系框架构建网络空间地图模型;
    设计可视化模块,用于设计所述构建网络空间地图模型对应的应用场景,并对所述应用场景进行可视化处理。
  8. 如权利要求7所述的基于自治系统的网络空间坐标系创建装置,其特征在于,所述网络空间坐标系为二维坐标系,所述确定模块,具体用于:
    根据预设算法将一维自治系统编号映射到二维坐标空间;
    所述根据预设算法将一维自治系统编号映射到二维坐标空间,包括:
    采用Hilbert映射算法对自治系统编号进行升维映射,确定网络空间坐标系坐标共同表示网络空间自治系统属性。
  9. 如权利要求7所述的基于自治系统的网络空间坐标系创建装置,其特征在于,所述第一构建模块,具体用于:
    将自治系统下的IP地址分配时间序列作为第三维基础矢量与自治系统地址正交,并对网络空间关键属性IP地址进行分析和映射。
  10. 如权利要求7所述的基于自治系统的网络空间坐标系创建装置,其特征在于,所述第二构建模块,具体用于:
    确定网络空间层次结构划分为三层:自治系统、网络、IP;
    定义网络空间球模式。
PCT/CN2019/097739 2019-02-21 2019-07-25 基于自治系统的网络空间坐标系创建方法及装置 Ceased WO2020168682A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US17/385,950 US11943249B2 (en) 2019-02-21 2021-07-27 Cyberspace coordinate system creation method and apparatus based on autonomous system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201910128925.7A CN109981346B (zh) 2019-02-21 2019-02-21 基于自治系统的网络空间坐标系创建方法及装置
CN201910128925.7 2019-02-21

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US17/385,950 Continuation US11943249B2 (en) 2019-02-21 2021-07-27 Cyberspace coordinate system creation method and apparatus based on autonomous system

Publications (1)

Publication Number Publication Date
WO2020168682A1 true WO2020168682A1 (zh) 2020-08-27

Family

ID=67077195

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/097739 Ceased WO2020168682A1 (zh) 2019-02-21 2019-07-25 基于自治系统的网络空间坐标系创建方法及装置

Country Status (3)

Country Link
US (1) US11943249B2 (zh)
CN (1) CN109981346B (zh)
WO (1) WO2020168682A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP4354818A4 (en) * 2021-05-31 2024-11-20 Huawei Technologies Co., Ltd. NETWORK TOPOLOGY DISPLAY METHOD AND COMMUNICATION DEVICE

Families Citing this family (16)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109981346B (zh) * 2019-02-21 2020-07-10 清华大学 基于自治系统的网络空间坐标系创建方法及装置
CN112307283B (zh) * 2019-08-01 2022-12-13 中移(苏州)软件技术有限公司 一种信息可视化方法、客户端及计算机可读存储介质
US11876833B2 (en) * 2019-08-15 2024-01-16 Uchicago Argonne, Llc Software defined networking moving target defense honeypot
CN111046260B (zh) * 2019-12-11 2023-04-18 中国兵器工业第五九研究所 一种基于自然环境因素数据的可视化方法
CN111130876B (zh) * 2019-12-20 2021-04-06 北京邮电大学 一种自治域系统在三维地理空间的展示方法及装置
CN113407874A (zh) * 2020-03-16 2021-09-17 北京国双科技有限公司 网络地址展示方法、装置、电子设备及可读存储介质
CN112040017A (zh) * 2020-06-23 2020-12-04 中国信息通信研究院 一种智能电网无线传感器网络IPv6地址分配方法
CN111865698B (zh) * 2020-07-30 2023-10-17 中国电子信息产业集团有限公司第六研究所 一种基于地理信息的自治域级互联网拓扑可视化方法
CN111935331A (zh) * 2020-07-30 2020-11-13 重庆智载科技有限公司 一种网络空间映射方法、可视化方法及系统
CN114124719B (zh) * 2021-10-27 2022-09-20 清华大学 网络空间态势感知方法及装置
CN114285663B (zh) * 2021-12-28 2024-08-02 赛尔网络有限公司 攻击源地址的管理方法、装置、设备和介质
CN114356271B (zh) * 2022-01-11 2023-02-07 中国测绘科学研究院 一种地下空间多维灾情信息多屏联动可视化方法
CN115392020A (zh) * 2022-08-22 2022-11-25 中国人民解放军陆军航空兵学院陆军航空兵研究所 基于层次化分解映射的传动系统总体指标分析方法及系统
CN115311419B (zh) * 2022-10-11 2023-02-07 杭州钛鑫科技有限公司 基于坐标映射降维和参数化配置的三维场景动态组态方法
CN116208503B (zh) * 2023-02-16 2025-12-23 北京理工大学 关联拓扑网络动态特征的互联网自治域类型映射方法
CN118590310B (zh) * 2024-07-31 2024-11-19 国网电商科技有限公司 一种用户攻击行为识别方法、装置、电子设备和存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101557324A (zh) * 2008-12-17 2009-10-14 天津大学 针对DDoS攻击的实时可视化检测方法
CN101938509A (zh) * 2009-06-29 2011-01-05 日电(中国)有限公司 为p2p网络提供节点信息的服务器、方法及系统
CN107623594A (zh) * 2017-09-01 2018-01-23 电子科技大学 一种地理位置信息约束的三维层级网络拓扑可视化方法
CN108023771A (zh) * 2017-12-06 2018-05-11 清华大学 基于ip地址和逻辑端口的网络空间坐标体系架构的创建方法及装置
CN109981346A (zh) * 2019-02-21 2019-07-05 清华大学 基于自治系统的网络空间坐标系创建方法及装置

Family Cites Families (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7092857B1 (en) * 1999-05-24 2006-08-15 Ipcentury Ag Neural network for computer-aided knowledge management
US6535227B1 (en) * 2000-02-08 2003-03-18 Harris Corporation System and method for assessing the security posture of a network and having a graphical user interface
AUPR464601A0 (en) * 2001-04-30 2001-05-24 Commonwealth Of Australia, The Shapes vector
US7529195B2 (en) * 2004-07-30 2009-05-05 Fortiusone, Inc. System and method of mapping and analyzing vulnerabilities in networks
JP4653164B2 (ja) * 2005-04-27 2011-03-16 株式会社サイバー・ソリューションズ ネットワークマップ生成方法
DE602007003849D1 (de) * 2007-10-11 2010-01-28 Mvtec Software Gmbh System und Verfahren zur 3D-Objekterkennung
CN101510291A (zh) * 2008-02-15 2009-08-19 国际商业机器公司 多维数据的可视化方法及装置
CN101887595B (zh) * 2009-05-14 2014-05-28 武汉如临其境科技创意有限公司 基于四叉树索引的三维数字地球空间数据组织渲染方法
US20130321458A1 (en) * 2012-05-30 2013-12-05 Northrop Grumman Systems Corporation Contextual visualization via configurable ip-space maps
CN103646127B (zh) * 2013-11-20 2016-06-29 中国空间技术研究院 卫星轨道姿态可视化三维显示方法
US10375514B2 (en) * 2014-07-29 2019-08-06 GeoFrenzy, Inc. Systems, methods and apparatus for geofence networks
US9912689B2 (en) * 2014-08-27 2018-03-06 icebrg, inc. Anonymized network data collection and network threat assessment and monitoring systems and methods
US10255399B2 (en) * 2016-10-31 2019-04-09 Intel Corporation Method, apparatus and system for automatically performing end-to-end channel mapping for an interconnect

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101557324A (zh) * 2008-12-17 2009-10-14 天津大学 针对DDoS攻击的实时可视化检测方法
CN101938509A (zh) * 2009-06-29 2011-01-05 日电(中国)有限公司 为p2p网络提供节点信息的服务器、方法及系统
CN107623594A (zh) * 2017-09-01 2018-01-23 电子科技大学 一种地理位置信息约束的三维层级网络拓扑可视化方法
CN108023771A (zh) * 2017-12-06 2018-05-11 清华大学 基于ip地址和逻辑端口的网络空间坐标体系架构的创建方法及装置
CN109981346A (zh) * 2019-02-21 2019-07-05 清华大学 基于自治系统的网络空间坐标系创建方法及装置

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP4354818A4 (en) * 2021-05-31 2024-11-20 Huawei Technologies Co., Ltd. NETWORK TOPOLOGY DISPLAY METHOD AND COMMUNICATION DEVICE

Also Published As

Publication number Publication date
US20210360020A1 (en) 2021-11-18
CN109981346A (zh) 2019-07-05
CN109981346B (zh) 2020-07-10
US11943249B2 (en) 2024-03-26

Similar Documents

Publication Publication Date Title
CN109981346B (zh) 基于自治系统的网络空间坐标系创建方法及装置
CN109728934B (zh) 网络空间地图模型创建方法及装置
CN104063466B (zh) 虚拟‑现实一体化的三维显示方法及系统
CN104995870B (zh) 多目标服务器布局确定方法和装置
CN104935462B (zh) 一种端服务器部署方法及装置
CN105160707B (zh) 基于视点索引的三维模型快速可视化方法
CN105430109B (zh) 一种基于流行为特征的互联网数据中心ip地址查找方法
CN102945263B (zh) 一种用于确定多个访问对象之间的访问相关性信息的方法
CN111935331A (zh) 一种网络空间映射方法、可视化方法及系统
CN108023771A (zh) 基于ip地址和逻辑端口的网络空间坐标体系架构的创建方法及装置
CN117714296A (zh) 一种物联网设备拓扑图自动生成方法及系统
CN115855000A (zh) 一种基于图论-时空对象的网络空间测绘表达方法
CN106953741A (zh) 一种面向网络仿真环境的流量回放方法及系统
US20230246925A1 (en) Algorithm-based automatic presentation of a hierarchical graphical representation of a computer network structure
CN115442139B (zh) 一种面向局域网的多层网络拓扑关系构建方法和系统
Huang et al. Design of the server cluster to support avatar migration
CN113726786B (zh) 异常访问行为的检测方法、装置、存储介质及电子设备
Zhao et al. Hmcgeo: Ip region prediction based on hierarchical multi-label classification
US20050204290A1 (en) System and method for generating distributed application and distributed system topologies with management information in a networked environment
CN114417633B (zh) 一种基于平行仿真六元组的网络靶场场景构建方法和系统
CN1964270A (zh) 基于地理位置信息组织和定位的网络设备管理系统及方法
He et al. Research on cyberspace map technology in the electric power industry
Chen et al. Fog computing support scheme based on fusion of location service and privacy preservation for QoS enhancement
CN119676100A (zh) 网络空间地图模型的构建及可视化方法、装置及设备
CN115065608B (zh) 一种网络空间的建模和仿真方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19916039

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19916039

Country of ref document: EP

Kind code of ref document: A1