Unlock instant, AI-driven research and patent intelligence for your innovation.

SDN-based dynamic anti-MAC address spoofing method

A MAC address and dynamic technology, applied in transmission systems, electrical components, etc., can solve the problems of being prone to errors and not easy enough, achieving the effect of management and configuration and intelligence, simple management and configuration, and anti-MAC address spoofing throughout the network.

Active Publication Date: 2020-04-17
湖州帷幄知识产权运营有限公司
View PDF6 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

To implement manual static binding, the network administrator needs to manually enter the user's MAC address and port number into the network. For a large-scale network, this work is obviously not easy. It is necessary to manually configure static binding on all switches in the forwarding path. binding relationship, so it is very error-prone

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • SDN-based dynamic anti-MAC address spoofing method
  • SDN-based dynamic anti-MAC address spoofing method
  • SDN-based dynamic anti-MAC address spoofing method

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0034] based on the following Figure 3 ~ Figure 4 , specifically explain the preferred embodiment of the present invention.

[0035] Such as image 3 As shown, the present invention provides a kind of dynamic anti-MAC address spoofing method based on SDN, comprises the following steps:

[0036] Step S1, connect the switches in the entire network to the SDN controller, and establish a dynamic network based on SDN.

[0037] Step S2, the SDN controller reports the MAC address information, switch port information and network topology information (the network topology information includes the link connection structure of the switch and the information exchange rate, and the network topology information is calculated according to the LLDP message) in real time. Calculate the forwarding path of the message, and obtain the corresponding relationship between the MAC addresses on all the switches on the forwarding path and the switch ports.

[0038] Step S3, the SDN controller dynam...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

An SDN-based method for dynamically preventing MAC address spoofing comprises the steps as follows: connecting interchangers in whole network to an SDN controller, establishing a dynamic network based on the SDN, calculating a forward path of a message in real time according to MAC address information, interchanger port information and network topology information, which are reported by interchangers with the SDN controller, obtaining a corresponding relation of the MAC address and a interchanger port on all interchangers on the forward path, issuing real-time dynamic condition of a binding relation to the interchangers on the forward path via a flow table instruction set with the SDN controller, updating a target MAC address and a port binding relational table on the interchangers and binding the MAC address and the interchanger port. Using an SDN frame to sense forward path and network change of the message, the SDN-based method for dynamically preventing MAC address spoofing of the invention realizes the dynamic binding of the MAC address and the interchanger port so as to prevent the MAC address spoofing in whole network to enable management and configuration of the whole network to be simple and intelligent so as to effectively managing the whole SDN network.

Description

technical field [0001] The invention relates to a dynamic anti-MAC address spoofing method based on SDN (Self-Defending Network, Self-Defending Network). Background technique [0002] Traditional switches rely on the MAC address table (a Layer 2 forwarding table that maintains the mapping relationship between MAC addresses, VLANs, and ports, which is the basis for fast forwarding of Layer 2 packets) to forward data packets. A single-address message with a specific destination MAC address will not be simply copied to other ports like the Hub, but will only be sent to the corresponding learning port. Hackers use forged MAC messages to allow the switch to learn the wrong mapping relationship between MAC addresses, VLANs, and ports, resulting in the failure of data packets to be forwarded to the correct destination address. [0003] Traditional switches support the binding of MAC addresses and ports to solve this potential security risk, such as figure 1 As shown, on switch S2...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06
CPCH04L63/0876H04L63/1466
Inventor 翟跃
Owner 湖州帷幄知识产权运营有限公司