FIELD: information technology.
SUBSTANCE: method for accelerated tunneling of traffic in a distributed network for detonation of malicious software, comprising: a preparatory stage, at which: registering the emitter and the gateway on the central server by issuing a configuration file which is received by the emitter from the central server; and a working step, at which: transmitting a request for the emitter to receive gateway data to a central server, where the emitter is a peer of a distributed network for analyzing malicious content and obtaining encapsulated packets at WireGuard and GRE levels; central server stores a neighbor table and is a server for setting up accelerated tunneling between peers; gateway is a distributed network peer for outgoing traffic packet NAT and incoming traffic packet de-NAT; adding a gateway as a peer to the WireGuard emitter interface; transmitting an ARP sample to a central server; updating the gateway data in the emitter neighbor table; sending outgoing traffic packet to gateway for NAT; extracting potentially malicious content from a packet of incoming traffic; potentially harmful content is analyzed and detonated.
EFFECT: invention discloses a method and a system for accelerated tunneling of traffic in a distributed network for detonation of malicious software.
24 cl, 11 dwg
Authors
Dates
2024-12-26—Published
2023-07-04—Filed