DLCAS: Distributed Large-scale Cyberspace Asynchronous Scanning Framework

Yu Cao, Chen Fu, Xiaowen Quan, Kai Zhou · 2024

Scanning ports and detecting services on ports is of great significance for network security. Existing tools such as Masscan and Nmap allow system administrators to easily probe target hosts to identify potential risks. However, the time taken to scan a large number of hosts is enormous. To reduce the time overhead of large-scale cyberspace scan, we propose the Distributed Large-scale Cyberspace Asynchronous Scanning Framework (DLCAS), which uses RabbitMQ to distribute scanning tasks to multiple hosts and achieves multi-host parallel scanning. In response to slow scan speed of Nmap, this paper combines Masscan and Nmap, and implements an asynchronous scan algorithm for Nmap, conducting experiments on ports 22, 80, and 3306. The results show that increasing the number of coroutines within a certain range can significantly shorten the scan time. To store large-scale host detection results, this paper uses MongoDB sharded cluster to alleviate the storage pressure of single machine and proposes a dotted binary IP indexing strategy to improve query efficiency.

Read the paper · More papers on PaperTik