首页|一种命令与控制通道管理工具的设计与实现

一种命令与控制通道管理工具的设计与实现

扫码查看
针对网络攻防在隐蔽通信、后渗透攻击、红队操作方面的功能性需求,基于gRPC框架、Protobuf机制、TLS协议设计与实现了集服务端、管理端、植入端于一体的命令与控制(C2)通道管理工具,并通过对该工具的数据交换、安全性、隐蔽性进行评估分析,证明了该管理工具能够实现高效的数据交换和安全隐蔽的网络通信功能,在多种环境下具备良好兼容性与稳定性,提高了网络攻防演练的实效性和组织对网络威胁的防御能力,具有进一步应用推广的价值.
Design and implementation of a command-and-control channel management tool
This paper presented the design and implementation of a command and control(C2)channel management tool tailored to meet the functional requirements of covert communication,post-exploitation attacks,and red team operations in network attack and defense scenarios.Leveraging gRPC framework,Protobuf mechanism,and TLS protocol,we developed an integrated system encom-passing server,management,and implantation terminals.Through the evaluation and analysis of data exchange,security,and conceal-ment of the tool,it is proved that the tool is not only stability and reliability but also could improve the effectiveness of network attack and defense drills and the capability to defend against network threats,so that it is potential for further application and promotion.

network attack and defensecommand and controlgRPC frameworkProtobuf mechanismTLS protocolGo lan-guage

陈春娣、龚忠慧

展开 >

广州商学院 现代信息产业学院,广东 广州 510000

网络攻防 命令与控制 gRPC框架 Protobuf机制 TLS协议 Go语言

2024

网络安全与数据治理
华北计算机系统工程研究所(中国电子信息产业集团有限公司第六研究所)

网络安全与数据治理

影响因子:0.348
ISSN:2097-1788
年,卷(期):2024.43(10)