Large scale port scanning through tor using parallel Nmap scans to scan large portions of the IPv4 range

Large scale port scanning through tor using parallel Nmap scans to scan large portions of the IPv4 range
复制标题

通过 Tor 进行大规模端口扫描,使用并行 Nmap 扫描来扫描 IPv4 范围的大部分

DOI:
10.1109/isi.2017.8004906
复制
发表时间:
2017
期刊:
2017 IEEE International Conference on Intelligence and Security Informatics (ISI)
影响因子:
--
通讯作者:
Mark W. Patton
Mark W. Patton
中科院分区:
--
文献类型:
--
作者:
Rodney R. Rohrmann;Vincent J. Ercolani;Mark W. Patton

文献摘要

被引文献

相似文献

通过 Tor 执行端口扫描是向目标隐藏源 IP 地址的一种方法。希望获得自己的扫描结果的研究人员可以从扫描方法中受益,这种扫描方法可以帮助他们匿名,免受可能因扫描而进行报复的目标的影响。尽管在扫描过程中提供匿名性很有效,但它无法扩展至扫描多个端口上的整个 IPv4 地址空间,因为通过 Tor 执行扫描需要相当长的时间。本文专门探讨了使用第三方数据源来定位 IPv4 范围内感兴趣的特定区域,然后使用并行扫描仪匿名扫描这些区域,作为匿名收集互联网扫描数据的有效方法。结果证明了该方法的可行性。
Performing port scans through Tor is a way to hide the source's IP address from the target. Researchers hoping to source their own scans benefit from a means of scanning that helps them to anonymize themselves from targets that may potentially retaliate as the result of being scanned. Though effective in providing anonymization during scanning, it is not scalable to the point of scanning the entire IPv4 Address space on multiple ports, as scans take considerably longer to execute through Tor. This paper specifically explores using a third-party data source to target specific areas of interest in the IPv4 range and then scanning those areas anonymously with parallelized scanners as an effective way to anonymously collect internet scan data. The results demonstrate the feasibility of this approach.