Data link layer analysis method in industrial field network address conflict environment

By deploying customized acquisition modules and dynamic time block analysis methods at the data link layer, combining multi-rule exception detection and VLAN isolation, the accuracy and real-time problems of address conflict detection in industrial field networks are solved, and efficient network management and troubleshooting are achieved.

CN120128573AActive Publication Date: 2025-06-10南京迅集科技有限公司

Patent Information

Application Number
CN202510615679.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-06-10
Estimated Expiration
2045-05-14

AI Technical Summary

Technical Problem

It is difficult to accurately detect complex network conflicts in existing industrial field networks, especially in high-speed and high-load environments. The lack of in-depth analysis of burst traffic, timeliness characteristics and protocol-level semantics, resulting in poor detection accuracy and real-timeness.

Method used

Deploy a customized acquisition module at the data link layer, capture the original data frames of the physical port in real time, extract timing characteristics and protocol semantics, and identify burst traffic patterns through dynamic time block analysis. Based on the high-grained data set of multi-dimensional features, a multi-rule set is designed for abnormal detection, partition conflict domains and isolate address conflicts through VLAN.

Benefits of technology

It realizes timely and precise detection and isolation of address conflicts in industrial site networks, improves the real-time and accuracy of network management, and enhances the reliability, stability and security of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128573A_ABST
    Figure CN120128573A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of intelligence, and discloses a data link layer analysis method in an industrial field network address conflict environment. Comprising the following steps: deploying a customized acquisition module at a data link layer, capturing an original data frame in real time, and extracting time sequence features and protocol semantics; the time sequence features and the protocol semantics are combined into a high-granularity data set with multi-dimensional features; designing a multi-rule set based on the high-granularity data set of the multi-dimensional features, and performing anomaly detection to obtain an abnormal data frame data set; dividing a conflict domain according to a time window on the basis of the abnormal data frame data set, calculating the proportion of the total flow and the broadcast flow in the conflict domain, judging whether an address conflict problem exists in the conflict domain or not according to the proportion of the total flow and the broadcast flow, and if the address conflict problem exists, performing isolation by using a VLAN (Virtual Local Area Network); in the isolated conflict domain, establishing a communication relation graph in the network to visualize a conflict source; and the stability and the safety of the industrial field network are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent technologies, and specifically to a data link layer parsing method in an industrial field network address conflict environment. Background Art

[0002] Existing data link layer parsing methods in an industrial field network address conflict environment usually rely on static address conflict detection mechanisms, mainly making judgments through simple ARP table scanning and static rules, ignoring the dynamic changes in timing characteristics and traffic patterns; existing methods often have difficulty accurately detecting complex network conflicts, especially in high-speed and high-load industrial network environments; due to the lack of in-depth analysis of burst traffic, timeliness characteristics, and protocol layer semantics, the accuracy and real-time performance of existing methods are poor, prone to missing potential conflict sources, and unable to effectively cope with complex dynamic network environments; therefore, existing methods often have difficulty providing timely and accurate conflict source identification and isolation measures in dealing with large-scale and high-rate industrial networks.

[0003] In view of this, the present invention proposes a data link layer parsing method in an industrial field network address conflict environment to solve the above problems. Summary of the Invention

[0004] In order to overcome the above defects of the prior art, for the purpose of achieving the above object, the present invention provides the following technical solution: A data link layer parsing method in an industrial field network address conflict environment, including: Step S1, deploy a customized acquisition module at the data link layer, capture the original data frames of the physical ports in real time, extract the timing characteristics and protocol semantics; and merge the timing characteristics, protocol semantics, and basic information data into a high-granularity data set with multi-dimensional features; Among them, the timing characteristics include frame interval, aging distribution characteristics of the frame interval, and burst traffic pattern; the burst traffic pattern is obtained by calculating through the dynamic time block analysis method; in the dynamic time block analysis method, define a dynamic time slice, calculate the number and transmitted bytes of the original data frames in the dynamic time slice, and calculate the frame density and traffic volume; judge whether it is a burst traffic pattern based on the frame density and traffic volume; Among them, the dynamic time slice is set by dynamically evaluating the network load and dividing it into a low-load or high-load state, and setting the time slice according to the low-load or high-load state and the state between low load and high load; Step S2, based on the high-granularity data set with multi-dimensional features, design a multi-rule set, use multiple rules for anomaly detection, and perform marking to obtain an abnormal data frame data set; Step S3: Based on the abnormal data frame dataset, divide the conflict domain according to the time window, calculate the total traffic and the broadcast traffic ratio in the conflict domain, and determine whether there is an address conflict problem in the conflict domain by the total traffic and the broadcast traffic ratio. If there is an address conflict problem, use VLAN for isolation; for the isolated conflict domain, visualize the conflict source by establishing a communication relationship graph in the network.

[0005] Further, the specific acquisition method of the customized acquisition module includes: Step a1: Hardware interface and network adaptation: Use the Intel X520-DA2 dual-port 10G Ethernet network card as the physical interface of the acquisition module; the network interfaces are configured as eth1 and eth2; Step a2: Configure data link layer capture: Set the network card to Promiscuous mode to capture the frames passing through the network card; use the libpcap library to capture the raw data frames at the data link layer; Step a3: Data traffic filtering and preprocessing: Integrate the filtering rules to capture Modbus / TCP or Profinet protocol frames; Extract and record the following frame header information, including: source MAC address, destination MAC address, frame type, timestamp; Use the CRC check technology to verify the integrity of the frame and discard the frames that fail the check; Step a4: Data storage and buffering: Real-time store the captured raw data frames into a 2TB SSD hard disk; adopt the FIFO buffer mechanism to delete the oldest data when the buffer exceeds the threshold; Step a5: Data transmission interface design: Use a 10G Ethernet interface to transmit the captured raw data frames to the upper-layer analysis system in real time; Use the UDP protocol to package and send the data frames to the analysis server.

[0006] Further, the specific method for real-time capturing the raw data frames of the physical port and extracting the timing characteristics includes: The timing characteristics include frame interval, the aging distribution characteristics of the frame interval, and the burst traffic pattern; Retrieve the timestamp in the raw data frame; calculate the adjacent raw data frame interval for the timestamps corresponding to adjacent raw data frames; Calculate the aging distribution characteristics of the frame interval, including the shortest interval, the longest interval, the average interval, and the interval dispersion; Identify the burst traffic pattern in the data stream through the dynamic time block analysis method; where the data stream consists of multiple raw data frames.

[0007] Further, the specific method for calculating the burst traffic pattern through the dynamic time block analysis method includes: Define dynamic time slices, aggregate the original data frames within the time slices, and obtain the number and transmission byte count of the original data frames in the dynamic time slices; calculate the frame density based on the number of original data frames in the time slices and the time of the dynamic time slices; Calculate the traffic volume based on the transmission byte count in the time slices and the time of the time slices; If the frame density or traffic volume in the Pth time slice exceeds the set limit, then a burst traffic pattern appears in this time slice, triggering an early warning mechanism, and recording the start timestamp and end timestamp of the burst traffic pattern.

[0008] Further, the specific method for defining dynamic time slices includes: Obtain the load metric data of the original data frames, including frame rate, bandwidth utilization rate, and resource occupancy rate; Define the load metric data status classification rules according to the load metric data, including: Low load: frame rate < 40%Thr cur , bandwidth utilization rate < 30%Thr cur , CPU occupancy rate < 50%Thr cur ; High load: frame rate ≥ 60%Thr cur , bandwidth utilization rate ≥ 60%Thr cur , CPU occupancy rate ≥ 70%Thr cur ; Among them, Thr cur is the load threshold, and the progressive threshold update method is used to obtain it; When in low load, set the time slice to W a ; when in high load, set the time slice to W b ; among them, W a and W b are the time slice sizes for low load and high load respectively; For the transitional time slice, that is, the load between low load and high load, set the time slice to W c .

[0009] Further, the specific method for designing a multi-rule set based on the high-granularity data set with multi-dimensional features, performing anomaly detection using multiple rules, and marking to obtain the abnormal data frame data set includes: Rule 1: Filter out ARP data frames according to the frame types in the high-granularity data set with multi-dimensional features; For the same source MAC address in the ARP data frame, obtain the number of ARP requests for the same destination IP address within a dynamic time slice; If the same source MAC sends J ARP requests within the time slice, it is marked as abnormal; Rule 2: For the corresponding destination IP address in the ARP request frame; group by the destination IP address and obtain the source MAC addresses in each group; if the same destination IP address is requested by K source MACs within the time slice, mark the multi-dimensional high-granularity data corresponding to the ARP request as abnormal; Rule 3: For the ARP request frame and the ARP response frame; For each ARP request frame, check whether there is a corresponding ARP response in the next time slice; if the ARP request sent by the source MAC address does not receive a response, it is marked as abnormal; Rule 4: When D source MAC addresses are bound to the same destination IP address, the destination IP address in their ARP requests will be repeated, but the source MAC addresses are different; Obtain the destination IP address and the source MAC address of the ARP request frame; group by the destination IP address and obtain the number of different source MAC addresses in each group; If the same destination IP address corresponds to A source MAC addresses, it is marked as abnormal; Sort the ARP request frames marked as abnormal according to the time stamp to obtain an abnormal event data set, where each group of data is defined as an abnormal data frame.

[0010] Further, based on the abnormal data frame data set, divide the conflict domain according to the time window, calculate the total traffic and the broadcast traffic ratio in the conflict domain, and judge whether there is an address conflict problem in the conflict domain through the total traffic and the broadcast traffic ratio. If there is an address conflict problem, the specific method of using VLAN for isolation includes: Set a fixed time window and define the abnormal data frames corresponding to the abnormal ARP requests within the time window as the same conflict domain; For each conflict domain, calculate the total traffic and the broadcast traffic ratio in the conflict domain; Identify whether there is an address conflict problem in the conflict domain according to the total traffic and the broadcast traffic ratio; Among them, select the total traffic in G historical time windows to calculate the average value and the standard deviation, and calculate the total traffic threshold based on the average value and the standard deviation; select the broadcast traffic ratio in G historical time windows to calculate the average value and the standard deviation, and calculate the broadcast traffic ratio threshold based on the average value and the standard deviation; if the total traffic and the broadcast traffic ratio exceed the total traffic threshold and the broadcast traffic ratio threshold, it means that there is an address conflict problem in the conflict domain; When it is determined that there is an address conflict, the source MAC address in the abnormal data frame in the conflict domain is divided into an independent VLAN for isolation.

[0011] Furthermore, the specific method for obtaining the total traffic and broadcast traffic ratio in each conflict domain includes: The method for obtaining the total traffic includes: using the network packet capture tool Wireshark to obtain the total length of the abnormal data frame; Calculate the comprehensive length of all abnormal data frames in the conflict domain, which is the total traffic; The method for obtaining the broadcast traffic ratio includes: using the traversal method to traverse the destination MAC addresses of the abnormal data frames in the conflict domain to obtain the number of final broadcast frames; Calculate the broadcast traffic ratio based on the ratio of the number of broadcast frames in the conflict domain to the total number of abnormal data frames in the conflict domain.

[0012] Furthermore, the specific method for visualizing the conflict source by establishing a communication relationship graph in the isolated conflict domain includes: In the isolated conflict domain, retrieve the high-granularity data of the multi-dimensional features of the abnormal data frames in the conflict domain, and establish a communication relationship graph in the network; and identify the conflict source in the conflict domain through visualizing the communication relationship graph.

[0013] Furthermore, the specific method for establishing a communication relationship graph in the network includes: The communication relationship graph is composed of nodes and edges; where the source MAC address and the destination IP address are used as nodes, and the timestamp, frame interval, burst traffic pattern, function code, and data field are used as edges; use the NetworkX tool to construct the communication relationship graph.

[0014] The technical effects and advantages of the data link layer parsing method in the industrial field network address conflict environment of the present invention: The present invention can capture the original data frames in the network in real time by deploying a customized acquisition module in the data link layer, including the data frames captured from the physical port, frame interval, and protocol semantic features; this real-time nature ensures that problems in the network can be discovered and processed in a timely manner, avoiding the possible delay problems of traditional methods; Use the dynamic time block analysis method to identify and analyze the burst traffic pattern. This method determines whether the traffic is abnormal by defining dynamic time slices and calculating the frame density and traffic volume of each slice; this mechanism effectively detects the burst traffic in the network, provides early warnings for network administrators, and helps to take timely measures to prevent network congestion or performance degradation; This solution designs multiple rule sets based on multi-dimensional features for anomaly detection. By analyzing the source MAC address, destination IP address, and frame type of ARP data frames, potential abnormal behaviors can be accurately identified. Through the comprehensive application of these rules, the accuracy of anomaly detection is improved, and false positives and false negatives are reduced. When an address conflict is detected, by dividing the conflict domain into independent VLANs for isolation, the impact of the conflict source on the entire network can be effectively avoided. This method determines whether there is an address conflict problem by precisely calculating the total traffic and broadcast traffic ratio in the conflict domain, avoiding waste of network resources and performance degradation. By establishing a network communication relationship graph, the location of the conflict source and the communication relationships between various nodes in the network can be clearly visualized. This visualization method helps network administrators quickly locate the conflict source and improves the efficiency of fault troubleshooting. Through the dynamic evaluation of load metrics (such as frame rate, bandwidth utilization, CPU occupancy rate, etc.), the size of the time slice can be flexibly adjusted according to the actual network load situation. This flexibility enables this method to maintain good performance under different network load states and adapt to various industrial environments. Through the above-mentioned various technical means, the system can achieve all-round monitoring of the industrial field network, real-time anomaly detection, isolation and location of the conflict source, and fault diagnosis. It greatly enhances the network management and maintenance capabilities and helps network administrators improve the reliability, stability, and security of the network in complex industrial environments. Brief Description of the Drawings

[0015] Figure 1 Schematic diagram of the data link layer parsing method in the industrial field network address conflict environment of the present invention; Figure 2 Schematic diagram of the high-granularity feature acquisition steps of the present invention; Figure 3 Schematic diagram of the data link layer parsing system in the industrial field network address conflict environment of the present invention. Detailed Embodiments

[0016] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0017] Embodiment 1

[0018] Please refer to Figure 1 and Figure 2As shown in the figure, the data link layer parsing method in the industrial field network address conflict environment of this embodiment includes: Step S1: Deploy a customized acquisition module at the data link layer to capture the original data frames of the physical ports in real time, extract the timing features and protocol semantics; and merge the timing features, protocol semantics, and basic information data into a high-granularity data set with multi-dimensional features; Among them, the timing features include frame interval, the aging distribution feature of the frame interval, and the burst traffic pattern; the burst traffic pattern is obtained by calculating through the dynamic time block analysis method; in the dynamic time block analysis method, define a dynamic time slice, calculate the number and transmitted bytes of the original data frames in the dynamic time slice, and calculate the frame density and traffic volume; judge whether it is a burst traffic pattern based on the frame density and traffic volume; Among them, the dynamic time slice is set by dynamically evaluating the network load and dividing it into a low-load or high-load state, and setting the time slice according to the low-load or high-load state and the state between the low-load and high-load; Step S2: Based on the high-granularity data set with multi-dimensional features, design a multi-rule set, use multiple rules for anomaly detection, and perform marking to obtain an abnormal data frame data set; Step S3: Based on the abnormal data frame data set, divide the conflict domain according to the time window, calculate the total traffic and the broadcast traffic ratio in the conflict domain, and judge whether there is an address conflict problem in the conflict domain through the total traffic and the broadcast traffic ratio. If there is an address conflict problem, use VLAN for isolation; for the isolated conflict domain, visualize the conflict source by establishing a communication relationship graph in the network.

[0019] The customized acquisition module is a custom network data capture and analysis tool designed for specific application scenarios and performance requirements; compared with general packet capture tools (such as tcpdump, Wireshark, etc.), the customized acquisition module often has higher flexibility, pertinence, and efficiency, and can meet the specific requirements in the industrial environment; The specific acquisition method of the customized acquisition module includes: Step a1: Hardware interface and network adaptation: Use the Intel X520-DA2 dual-port 10G Ethernet network card as the physical interface of the acquisition module to support high-speed data capture; the network interfaces are configured as eth1 and eth2 to capture data streams from multiple network ports simultaneously; Step a2: Configure data link layer capture: Set the network card to Promiscuous mode to capture the frames passing through the network card; use the libpcap library to capture the original data frames at the data link layer to ensure that all network traffic including control frames and data frames can be captured; Step a3: Data traffic filtering and pre - processing: Integrate filtering rules to filter out low - priority data frames unrelated to the protocol and capture Modbus / TCP or Profinet protocol frames; Extract and record the following frame header information, including: source MAC address, destination MAC address, frame type, timestamp (the exact time at capture, in milliseconds); Use CRC check technology to verify the integrity of the frame and discard frames that fail the check; Step a4: Data storage and buffering Store the captured raw data frames in a 2TB SSD hard drive in real - time; adopt a FIFO caching mechanism to delete the oldest data when the cache exceeds the threshold; The storage format is a PCAP file to ensure compatibility with existing analysis tools.

[0020] Step a5: Design of data transmission interface: Use a 10G Ethernet interface to transmit the captured raw data frames to the upper - layer analysis system in real - time; Use the UDP protocol to package and send the data frames to the analysis server to ensure low - latency data transmission; Using a customized acquisition module to collect raw data frames has significant advantages; this module is based on a high - performance Intel X520 - DA2 dual - port 10G Ethernet network card, which can capture data frames in real - time in a high - speed and high - traffic industrial network environment and capture all network traffic through Promiscuous mode; the integrated traffic filtering and pre - processing functions ensure that only data frames related to industrial protocols are captured, reducing data redundancy and improving analysis efficiency; CRC check is used to ensure data integrity, and the data is stored in a 2TB SSD hard drive in real - time, supporting the PCAP format to ensure compatibility with analysis tools; in addition, the 10G Ethernet interface and UDP protocol provide low - latency and high - efficiency data transmission, enabling the collected data to be quickly transmitted to the upper - layer analysis system to achieve real - time monitoring and rapid response, and overall improving the efficiency of network management and fault diagnosis.

[0021] Temporal features mainly focus on the time characteristics of raw data frames, analyzing the time intervals between raw data frames and the burstiness of traffic; this process can help identify periodic traffic and burst traffic patterns, which is crucial for network optimization and traffic monitoring; Capture raw data frames of physical ports in real - time, and the specific ways to extract temporal features include: Temporal features include frame intervals, the aging distribution characteristics of frame intervals, and burst traffic patterns; Retrieve the timestamps in the raw data frames; calculate the adjacent raw data frame intervals based on the timestamps corresponding to adjacent raw data frames; Calculate the time-dependent distribution characteristics of frame intervals, including the shortest interval, the longest interval, the average interval, and the interval divergence; Identify burst traffic patterns in the data stream through dynamic time block analysis; where the data stream consists of multiple original data frames; Among them, the frame interval calculation steps include: Calculate the time interval between adjacent original data frames and count its distribution to detect abnormal traffic; Retrieve the timestamps in the original data frames; Calculate the interval between adjacent original data frames based on the timestamps corresponding to the adjacent original data frames; Example: If the timestamp of frame 1 is t1 = 1633033587.125 (i.e., 12:00:00.125 on October 1, 2023), and the timestamp of frame 2 is t2 = 1633033587.130 (i.e., 12:00:00.130 on October 1, 2023), the frame interval is t2 - t1 = 0.005 seconds (5 milliseconds); Among them, the steps for obtaining the time-dependent distribution characteristics of frame intervals include: The time-dependent distribution characteristics of frame intervals include the shortest interval, the longest interval, the average interval, and the interval divergence; where the shortest interval represents the fastest frame transmission speed in the network; the longest interval represents the slowest frame transmission speed in the network; the average interval is used to reflect the overall transmission rate; The interval divergence is used to measure the volatility of frame intervals, that is, the stability of traffic; The burst traffic pattern refers to an abnormal surge in data traffic in the network during a specific time period, manifested as the sending of a large number of data frames or packets in a short time; this pattern is usually non-periodic, sudden, and much higher than normal traffic; in network monitoring and traffic analysis, burst traffic often means some abnormal behaviors or network problems, such as equipment failures, configuration errors, network attacks, or peak loads in a certain link of normal operations; The steps for the burst traffic pattern include: Identify burst traffic patterns in the data stream through dynamic time block analysis; where the data stream consists of many original data frames; Define dynamic time slices, aggregate and statistically analyze the data stream within the time slices to obtain the number of original data frames and the number of transmitted bytes; calculate the frame density based on the number of original data frames in the time slices and the time of the dynamic time slices; For example: Set the time slice to 10 milliseconds, that is, 0.01 seconds; assume that 50 original data frames are captured within a certain slice, then the frame density is 50 / 0.01 = 5000 frames / second; Calculate the traffic volume based on the number of transmitted bytes in the time slices and the time of the time slices; For example, if the total number of bytes of 50 original data frames in a time slice is 8000 bytes, the traffic volume is 8000 / 0.01 = 800000 bytes per second; If the frame density or traffic volume within a certain time slice exceeds the set limit, a burst traffic pattern appears in this time slice, triggering the warning mechanism, and recording the start timestamp and end timestamp of the burst traffic pattern.

[0022] Traditional methods usually define time slices based on static fixed values; these fixed values are usually set in advance and cannot flexibly adapt to dynamically changing network loads; in this method, the size of the time slice is often fixed and cannot be adaptively adjusted according to the fluctuations of the actual load; due to the lack of a dynamic adjustment mechanism, traditional methods may not be able to effectively handle burst traffic or high load conditions in the case of large load fluctuations, resulting in the time slice being too large or too small, thus affecting the accuracy of data capture and the real-time nature of analysis; The specific ways to define dynamic time slices include: Dynamically evaluate the current network load and divide it into low load or high load states, so as to select appropriate time slices according to the network state; Obtain load metric data, including frame rate, bandwidth utilization rate, and resource occupancy rate; Define the classification rules for load metric data status: Low load: frame rate < 40%Thr cur , bandwidth utilization rate < 30%Thr cur , CPU occupancy rate < 50%Thr cur .

[0023] High load: frame rate ≥ 60%Thr cur , bandwidth utilization rate ≥ 60%Thr cur , CPU occupancy rate ≥ 70%Thr cur .

[0024] Among them, Thr cur is the load threshold, which is obtained using the progressive threshold update method; the formula is: Thr cur = α * Met cur + (1 - α) * Thr pre , α is the update coefficient, Met cur is the metric value, that is, the frame rate, bandwidth utilization rate, or resource occupancy rate, Thr pre is the load threshold of the previous time slice; For low load, set the time slice to W a ; for high load, set the time slice to W b ; among them, W aand W b are the time slice sizes for low load and high load respectively; For the excessive time slice, i.e., the load between low load and high load, the size of the time slice is set to W c , and the formula is: W c =W a +β * (W b -W a ), where β is the control overrate; Among them, the specific steps of the progressive threshold update method are: First, initialize a threshold (historical threshold can also be set), and set an update coefficient; then, collect data in real time, and calculate a new threshold through the weighted average of the current data and the initialized threshold; this new threshold will be updated gradually, rather than relying on a single data point, so as to reflect the gradual change of the updated threshold; In comparison, defining dynamic time slices has significant advantages; by evaluating the network load in real time and dynamically adjusting the time slice size, the actual situation of the network can be reflected more accurately; this method gradually updates the threshold according to the real-time load data, enabling the time slice to be flexibly adjusted between low load and high load, avoiding the limitations brought by fixed thresholds; especially in the case of large network load fluctuations, the progressive update method can adaptively adjust the size of the time slice, thereby improving the accuracy of data capture and the effectiveness of analysis, ensuring more accurate traffic monitoring and problem location.

[0025] The specific ways of protocol semantic feature extraction include: Extract the semantic information of the Modbus protocol from the original data frame, including function code and data field; Modbus TCP ADU location and frame header skipping: The source MAC address and destination MAC address contained in the Ethernet frame header, as well as the IP header and TCP header need to be skipped; specifically, the application data unit (ADU) of Modbus TCP starts from the 7th byte of the TCP header; the ADU structure contains the core data of the Modbus protocol; Ethernet header: 14 bytes (including source and destination MAC addresses, EtherType); IP header: 20 bytes (IPv4 or IPv6); TCP header: 20 bytes (excluding option fields); So starting from the 7th byte is the starting position of the Modbus PDU; Function code extraction: In the Modbus PDU (protocol data unit), the function code is located in the first byte; The method for obtaining the data field in the protocol semantic features is as follows: In the original data frame captured by the customized acquisition module, first load the complete frame into memory through libpcap or the underlying driver, and then parse the Ethernet header, IP header, and transport layer (such as TCP / UDP) header in sequence. After determining the length of each protocol header, locate the payload part behind it; finally, read all the bytes in this payload area as the "data field" feature.

[0026] For a high-granularity data set based on multi-dimensional features, the specific method of designing a multi-rule set, using multiple rules for anomaly detection, and marking to obtain the abnormal data frame data set includes: Rule 1: Filter out ARP data frames according to the frame type in the high-granularity data set of multi-dimensional features; For the same source MAC address in the ARP data frame, obtain the number of ARP requests for the same target IP address within a dynamic time slice; If the same source MAC sends J ARP requests within the time slice, it is marked as abnormal; For example, within 10 seconds, the source MAC address 00:11:22:33:44:55 sent 5 ARP requests (i.e., the frame type is 0*0806) to the target IP address 192.168.1.1; if the number of ARP requests sent by a certain source MAC address within the time slice exceeds a threshold (such as 3 times), it is considered abnormal, so the multi-dimensional high-granularity data corresponding to this ARP request is marked as abnormal; Rule 2: Multiple source MAC addresses are mapped to the same IP address; When multiple devices compete for the same IP address, it will cause ARP requests from different source MAC addresses to point to the same target IP address; For the corresponding target IP address in the ARP request frame; and group by the target IP address, obtain the source MAC addresses in each group; if the same target IP address is requested by K source MACs within the time slice, mark the multi-dimensional high-granularity data corresponding to this ARP request as abnormal; For example: The target IP address 192.168.1.1 was requested by 4 different source MAC addresses: 00:11:22:33:44:55, 00:11:22:33:44:56, 00:11:22:33:44:57, and 00:11:22:33:44:58; if within a time slice (such as within 10 seconds), the same target IP address is requested by multiple source MAC addresses (assuming the threshold K = 3), it means that there is a situation where devices compete for the same IP address, indicating an anomaly, and mark the multi-dimensional high-granularity data corresponding to this ARP request as abnormal; Rule 3: The lack of matching between ARP requests and ARP responses; Under normal circumstances, an ARP request should trigger a corresponding ARP response; if there is no response, it may indicate that a communication failure is caused by an address conflict; For ARP request frames and ARP response frames; For each ARP request frame, obtain whether there is a corresponding ARP response in the next time slice; if the ARP request sent by the source MAC address does not receive a response, mark it as abnormal; For example, 00:11:22:33:44:55 sent 3 ARP requests to 192.168.1.1 at 10:00, 10:10, and 10:20 on April 1, 2025, and the function code is 1; the ARP request frames are recorded as: Sent ARP request at 10:00 on April 1, 2025, Sent ARP request at 10:10 on April 1, 2025, Sent ARP request at 10:20 on April 1, 2025; At 10:30 on April 1, 2025, 66:77:88:99:AA:BB sent an ARP response to 192.168.1.1, and the function code is 2, which means that the reply received the response; if the function code is not 2, it means that the response was not received, and the multi-dimensional high-granularity data corresponding to the ARP request is marked as abnormal; Rule 4: Data field conflict in ARP request: When D source MAC addresses are bound to the same target IP address, the target IP addresses in their ARP requests will be repeated, but the source MAC addresses are different; Obtain the target IP address and source MAC address of the ARP request frame; group by the target IP address, and obtain the number of different source MAC addresses in each group; If the same target IP address corresponds to A source MAC addresses, mark it as abnormal; For example: 192.168.1.1 is used as the target IP address, and there are 4 different source MAC addresses (00:11:22:33:44:55, 00:11:22:33:44:56, 00:11:22:33:44:57, 00:11:22:33:44:58) sending ARP requests in the time slice (assumed to be 15 seconds); this is because multiple devices are competing for the same IP address, resulting in an abnormality, and the multi-dimensional high-granularity data corresponding to the ARP request is marked as abnormal; Through precise multi - rule anomaly detection, various potential abnormal situations in the network can be comprehensively identified and marked, especially those related to the ARP protocol. First, a high - granularity data set based on multi - dimensional features enables more detailed and comprehensive anomaly detection, capable of identifying conflicts and problems in the network from different perspectives. Second, the rule design is flexible and highly targeted, including analyzing situations such as the frequency of ARP requests, multiple source MAC addresses competing for the same IP, mismatches between ARP requests and responses, and data - field conflicts in ARP requests. It can effectively detect address conflicts, device failures, or malicious behaviors in the network. This multi - rule detection mechanism not only improves the accuracy of anomaly detection but also can promptly identify and isolate the problem source, ensuring the stability and security of the network.

[0027] Based on the abnormal data - frame data set, divide the conflict domain according to the time window, calculate the total traffic and the proportion of broadcast traffic in the conflict domain, and judge whether there is an address - conflict problem in the conflict domain based on the total traffic and the proportion of broadcast traffic. If there is an address - conflict problem, the specific methods of isolation using VLAN include: Set a fixed time window, and define the abnormal data frames corresponding to the abnormal ARP requests within the time window as the same conflict domain; For each conflict domain, calculate the total traffic and the proportion of broadcast traffic in the conflict domain; The total traffic is the overall traffic within the conflict domain; Proportion of broadcast traffic: Due to a large number of ARP requests caused by address conflicts, the proportion of broadcast traffic within the conflict domain may be relatively high; Identify whether there is an address - conflict problem in the conflict domain based on the total traffic and the proportion of broadcast traffic; Among them, select the total traffic in G historical time windows to calculate the average value and standard deviation, and calculate the total - traffic threshold based on the average value and standard deviation; select the proportion of broadcast traffic in G historical time windows to calculate the average value and standard deviation, and calculate the broadcast - traffic - proportion threshold based on the average value and standard deviation. If the total traffic and the proportion of broadcast traffic exceed the total - traffic threshold and the broadcast - traffic - proportion threshold, it indicates that there is an address - conflict problem in this conflict domain; When it is determined as an address conflict, divide the source MAC addresses in the abnormal data frames in this conflict domain into an independent VLAN for isolation; In an industrial network, address conflicts usually cause a large number of ARP request frames to be broadcast onto the network in an attempt to resolve the conflicting IP addresses. Since ARP requests are broadcast-type frames, when address conflicts occur among multiple devices in the network, a large number of ARP requests and responses are frequently generated, resulting in a significant increase in the proportion of broadcast traffic within the collision domain. In addition, address conflicts also cause network devices to continuously retransmit ARP requests, increasing the total traffic. Therefore, the abnormal increase in the total traffic and the proportion of broadcast traffic within the collision domain is usually an important indication of the existence of address conflicts in the network. By analyzing these traffic characteristics, it is possible to effectively identify and determine whether there is an address conflict problem. The main advantages are that by combining abnormal data frames and traffic analysis, address conflict problems can be effectively identified and isolated. By calculating the total traffic and the proportion of broadcast traffic in the collision domain within a fixed time window, it is possible to accurately determine whether the collision domain has an abnormal increase in traffic due to address conflicts. By comparing with historical data and dynamically adjusting the traffic threshold, the judgment becomes more sensitive and adaptable. In addition, for the identified collision domain, by using VLAN isolation, it is possible to effectively isolate the affected devices from the normal network, reducing network performance degradation and potential security risks. This method can respond to address conflict problems in the network in real time and automatically, improving network stability and security.

[0028] For each collision domain, the specific methods for obtaining the total traffic and the proportion of broadcast traffic in the collision domain include: The method for obtaining the total traffic includes: using the network packet capture tool Wireshark to obtain the total length of the abnormal data frames. Calculate the combined length of all abnormal data frames in the collision domain, which is the total traffic. An original data frame has a set of high-granularity data with multi-dimensional features. A set of high-granularity data with multi-dimensional features includes the source MAC address, destination MAC address, frame type, timestamp, frame interval, the aging distribution characteristics of the frame interval, burst traffic pattern, function code, and data field. Extract ARP request frames according to the frame type and analyze whether the ARP request frames are abnormal. Define the original data frames corresponding to the marked abnormal request frames as abnormal data frames and sort them according to the timestamp to obtain an abnormal event dataset. In the abnormal data frames, use the destination MAC address to determine whether it is a broadcast frame. The destination MAC address of a broadcast frame is FF:FF:FF:FF:FF:FF. The method for obtaining the proportion of broadcast traffic includes: using the traversal method to traverse the destination MAC addresses of the abnormal data frames in the collision domain to obtain the final number of broadcast frames. Calculate the proportion of broadcast traffic based on the ratio of the number of broadcast frames in the collision domain to the total number of abnormal data frames in that collision domain.

[0029] The specific ways to establish the communication relationship graph in the network include: The communication relationship graph is composed of nodes and edges; among them, the source MAC address and the destination IP address are used as nodes, and the timestamp, frame interval, burst traffic pattern, function code, and data field are used as edges; the NetworkX tool is used to construct the communication relationship graph; The main advantages are that it can comprehensively and intuitively display the communication relationships between various nodes in the network by constructing a detailed communication relationship graph; by using the source MAC address and the destination IP address as nodes, and information such as the timestamp, frame interval, burst traffic pattern, function code, and data field as edges, the dynamic characteristics and behavior patterns of network communication can be accurately captured; by using the NetworkX tool, these data can be flexibly processed and analyzed, potential network problems (such as abnormal traffic, malicious attacks, device failures, etc.) can be quickly identified, and strong support can be provided for subsequent network optimization and security protection; in this way, the network behavior can be understood more clearly, and it is helpful for real-time monitoring and historical data analysis.

[0030] In this embodiment, by deploying a customized acquisition module at the data link layer, the original data frames in the network can be captured in real time, including the data frames captured from physical ports, frame intervals, and protocol semantic features; this real-time nature ensures that problems in the network can be discovered and processed in a timely manner, avoiding the possible delay problems of traditional methods; The dynamic time block analysis method is used to identify and analyze the burst traffic pattern; this method determines whether the traffic is abnormal by defining dynamic time slices and calculating the frame density and traffic volume of each slice; this mechanism effectively detects the burst traffic in the network, provides early warnings for network administrators, helps to take timely measures to prevent network congestion or performance degradation; This solution designs multiple rule sets based on multi-dimensional features for anomaly detection; by analyzing the source MAC address, destination IP address, and frame type of ARP data frames, potential abnormal behaviors can be accurately identified; through the comprehensive application of these rules, the accuracy of anomaly detection is improved, and false positives and false negatives are reduced; When an address conflict is detected, by dividing the conflict domain into independent VLANs for isolation, the impact of the conflict source on the entire network can be effectively avoided; this method determines whether there is an address conflict problem by accurately calculating the total traffic and broadcast traffic ratio in the conflict domain, avoiding the waste of network resources and performance degradation; By establishing the network communication relationship graph, the location of the conflict source and the communication relationships between various nodes in the network can be clearly visualized; this visualization means helps network administrators quickly locate the conflict source and improves the efficiency of fault troubleshooting; By dynamically evaluating load metrics (such as frame rate, bandwidth utilization, CPU occupancy, etc.), the time slice size can be flexibly adjusted according to the actual network load situation; this flexibility enables the method to maintain good performance under different network load states and adapt to various industrial environments; Through the above-mentioned various technical means, the system can achieve all-round monitoring of the industrial field network, real-time anomaly detection, isolation and location of the conflict source, and fault diagnosis; it greatly enhances the network management and maintenance capabilities and helps network administrators improve the reliability, stability and security of the network in complex industrial environments.

[0031] Embodiment 2

[0032] Please refer to Figure 3 As shown, for the parts not described in detail in this embodiment, refer to the description content of Embodiment 1. A data link layer parsing system in an industrial field network address conflict environment is provided, including: High-granularity feature acquisition module: Deploy a customized acquisition module at the data link layer to capture the original data frames of physical ports in real time, extract timing features and protocol semantics; and merge the timing features, protocol semantics and basic information data into a high-granularity data set with multi-dimensional features; Among them, the timing features include frame interval, aging distribution feature of frame interval and burst traffic pattern; the burst traffic pattern is calculated by the dynamic time block analysis method; in the dynamic time block analysis method, a dynamic time slice is defined, the number of original data frames and the transmitted bytes in the dynamic time slice are calculated, and the frame density and traffic volume are calculated; based on the frame density and traffic volume, it is judged whether it is a burst traffic pattern; Among them, the dynamic time slice is set by dynamically evaluating the network load and dividing it into low-load or high-load states, and according to the low-load or high-load states and the states between low load and high load; Multi-rule anomaly recognition module: Based on the high-granularity data set with multi-dimensional features, design a multi-rule set, use multiple rules for anomaly detection, and perform marking to obtain an abnormal data frame data set; Conflict domain isolation and visualization module: Based on the abnormal data frame data set, divide the conflict domain according to the time window, calculate the total traffic and broadcast traffic ratio in the conflict domain, and judge whether there is an address conflict problem in the conflict domain through the total traffic and broadcast traffic ratio. If there is an address conflict problem, use VLAN for isolation; for the isolated conflict domain, visualize the conflict source by establishing a communication relationship graph in the network.

[0033] Embodiment 3

[0034] This embodiment discloses an electronic device, which includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the operation mode of the data link layer parsing method provided above in the industrial field network address conflict environment.

[0035] Since the electronic device introduced in this embodiment is the electronic device adopted for implementing the data link layer parsing method in the industrial field network address conflict environment of the embodiments of the present application, based on the data link layer parsing method introduced in the embodiments of the present application, those skilled in the art can understand the specific implementation manners and various variations of the electronic device in this embodiment. Therefore, the specific implementation of how this electronic device implements the method in the embodiments of the present application will not be described in detail here. As long as those skilled in the art implement the electronic device adopted for the data link layer parsing method in the industrial field network address conflict environment of the embodiments of the present application, it belongs to the scope of protection of the present application.

[0036] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the actual situation. The preset parameters and threshold selection in the formulas are set by those skilled in the art according to the actual situation.

[0037] The above is only the preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for ordinary technical users in the technical field, several improvements and refinements made without departing from the principle of the present invention should also be regarded as the protection scope of the present invention.

Claims

1. A data link layer parsing method under an industrial field network address conflict environment, characterized in that: include: Step S1: deploy a customized acquisition module at the data link layer to capture the original data frames of the physical port in real time and extract timing features and protocol semantics; And merge the time series features, protocol semantics and basic information data into a high-granularity dataset with multi-dimensional features; Among them, the timing characteristics include frame interval, time distribution characteristics of frame interval and burst traffic mode; the burst traffic mode is calculated by dynamic time block analysis method; in the dynamic time block analysis method, dynamic time slices are defined, the number of original data frames and transmission bytes in the dynamic time slices are calculated, and the frame density and traffic volume are calculated; based on the frame density and traffic volume, it is determined whether it is a burst traffic mode; Among them, dynamic time slicing dynamically evaluates the network load and divides it into low load or high load states, and sets time slices according to the low load or high load state and the state between low load and high load; Step S2: Based on the high-granularity data set with multi-dimensional features, a multi-rule set is designed, and anomaly detection and marking are performed using the multi-rules to obtain anomaly data frame data set; Step S3: Based on the abnormal data frame data set, the conflict domain is divided according to the time window, and the total traffic and broadcast traffic ratio in the conflict domain are calculated. The total traffic and broadcast traffic ratio are used to determine whether there is an address conflict in the conflict domain. If there is an address conflict, VLAN is used for isolation; for the isolated conflict domain, the conflict source is visualized by establishing a communication relationship diagram in the network.

2. The data link layer parsing method under the industrial field network address conflict environment according to claim 1 is characterized in that: The specific method of obtaining the customized acquisition module includes: Step a1: Hardware interface and network adaptation: Use Intel X520-DA2 dual-port 10G Ethernet card as the physical interface of the acquisition module; the network interface is configured as eth1 and eth2; Step a2: Configure data link layer capture: Set the network card to Promiscuous mode to capture frames passing through the network card; use the libpcap library to capture raw data frames at the data link layer; Step a3: Data traffic filtering and pre-processing: Integrated filtering rules to capture Modbus / TCP or Profinet protocol frames; Extract and record the following frame header information, including: source MAC address, destination MAC address, frame type, and timestamp; Use CRC check technology to verify the integrity of the frame and discard frames that fail the check; Step a4: Data storage and buffering: The captured raw data frames are stored in a 2TB SSD hard drive in real time; a FIFO cache mechanism is used to delete the oldest data when the cache exceeds the threshold; Step a5: Data transmission interface design: Use 10G Ethernet interface to transmit captured raw data frames to upper-layer analysis system in real time; Use the UDP protocol to package the data frames and send them to the analysis server.

3. The data link layer parsing method under the industrial field network address conflict environment according to claim 2 is characterized in that: The specific method of capturing the original data frame of the physical port in real time and extracting the timing characteristics includes: The timing characteristics include frame interval, the time distribution characteristics of frame interval and burst traffic pattern; Retrieving the timestamp in the original data frame; calculating the interval between adjacent original data frames based on the timestamps corresponding to the adjacent original data frames; Calculate the temporal distribution characteristics of frame intervals, including the shortest interval, the longest interval, the average interval, and the interval degree divergence; Through dynamic time block analysis, burst traffic patterns in data streams are identified; a data stream is composed of multiple original data frames.

4. The data link layer parsing method under the industrial field network address conflict environment according to claim 3 is characterized in that: The specific method of calculating the burst traffic pattern by the dynamic time block analysis method includes: Define dynamic time slices, aggregate the original data frames in the time slices, and obtain the number of original data frames and the number of transmitted bytes in the dynamic time slices; calculate the frame density based on the number of original data frames in the time slices and the time of the dynamic time slices; The traffic volume is calculated based on the number of transmitted bytes in the time slice and the time of the time slice; If the frame density or traffic volume in the Pth time slice exceeds the set limit, a burst traffic pattern appears in the time slice, triggering the early warning mechanism and recording the start and end timestamps of the burst traffic pattern.

5. The data link layer parsing method under the industrial field network address conflict environment according to claim 4 is characterized in that: The specific method of defining dynamic time slices includes: Obtain load indicator data of the original data frame, including frame rate, bandwidth utilization, and resource occupancy; Define load indicator data status classification rules based on load indicator data, including: Low load: frame rate <40%Thr cur , bandwidth utilization < 30%Thr cur , CPU usage < 50%Thr cur ; High load: frame rate ≥ 60%Thr cur , bandwidth utilization ≥ 60%Thr cur , CPU usage ≥ 70%Thr cur ; Among them, Thr cur is the load threshold, obtained using the progressive threshold update method; When the load is low, set the time slice to W a ; When the load is high, set the time slice to W b ; Among them, W a and W b are the time slice sizes for low load and high load, respectively; For excessive time slices, that is, the load between low load and high load, set the time slice to W c .

6. The data link layer parsing method under the industrial field network address conflict environment according to claim 5 is characterized in that: The specific method of designing a multi-rule set based on the high-granularity data set with multi-dimensional features, using multiple rules to perform anomaly detection and marking, and obtaining an abnormal data frame data set includes: Rule 1: Filter out ARP data frames based on the frame type in the high-granularity dataset with multi-dimensional features; For the same source MAC address in the ARP data frame, obtain the number of ARP requests for the same target IP address within a dynamic time slice; If the same source MAC sends J ARP requests within a time slice, it is marked as abnormal; Rule 2: Target the target IP address in the ARP request frame; group them by target IP address and obtain the source MAC address in each group; if the same target IP address is requested by K source MACs in a time slice, mark the multi-dimensional high-granularity data corresponding to the ARP request as abnormal; Rule 3: For ARP request frames and ARP response frames; For each ARP request frame, check whether there is a corresponding ARP response in the next time slice; if the ARP request sent by the source MAC address does not receive a response, mark it as abnormal; Rule 4: When D source MAC addresses are bound to the same target IP address, the target IP address in the ARP request will be repeated, but the source MAC address will be different; Get the destination IP address and source MAC address of the ARP request frame; group them by destination IP address and get the number of different source MAC addresses in each group; If the same target IP address corresponds to A source MAC addresses, it is marked as abnormal; The ARP request frames marked as abnormal are sorted according to timestamps to obtain an abnormal event data set, where each set of data is defined as an abnormal data frame.

7. The data link layer parsing method under the industrial field network address conflict environment according to claim 6, characterized in that: Based on the abnormal data frame data set, the conflict domain is divided according to the time window, the total flow and broadcast flow ratio in the conflict domain are calculated, and whether there is an address conflict problem in the conflict domain is determined by the total flow and broadcast flow ratio. If there is an address conflict problem, the specific method of using VLAN for isolation includes: Set a fixed time window and define the abnormal data frames corresponding to the abnormal ARP requests within the time window as the same collision domain; For each collision domain, calculate the ratio of total traffic to broadcast traffic in the collision domain; Based on the ratio of total traffic to broadcast traffic, identify whether there is an address conflict in the conflict domain; The total traffic in G historical time windows is selected to calculate the average and standard deviation, and the total traffic threshold is calculated based on the average and standard deviation; the broadcast traffic ratio in G historical time windows is selected to calculate the average and standard deviation, and the broadcast traffic ratio threshold is calculated based on the average and standard deviation; if the total traffic and broadcast traffic ratio exceed the total traffic threshold and the broadcast traffic ratio threshold, it indicates that the conflict domain has an address conflict problem; When an address conflict is determined, the source MAC address in the abnormal data frame in the conflict domain is divided into an independent VLAN for isolation.

8. The data link layer parsing method under the industrial field network address conflict environment according to claim 7, characterized in that: The specific method for calculating the ratio of the total traffic and the broadcast traffic in each conflict domain includes: The method for obtaining the total traffic includes: using the network packet capture tool Wireshark to obtain the total length of the abnormal data frame; Calculate the combined length of all abnormal data frames in the collision domain, which is the total traffic; The broadcast traffic ratio is obtained by: using a traversal method to traverse the target MAC addresses of abnormal data frames in the collision domain to obtain the number of final broadcast frames; The broadcast traffic ratio is calculated based on the ratio of the number of broadcast frames in the collision domain to the total number of abnormal data frames in the collision domain.

9. The data link layer parsing method under the industrial field network address conflict environment according to claim 8, characterized in that: In the isolated conflict domain, a specific method of visualizing the conflict source by establishing a communication relationship diagram in the network includes: For the isolated conflict domain, high-granularity data of multi-dimensional features of abnormal data frames in the conflict domain are retrieved, and a communication relationship diagram in the network is established; and the conflict source in the conflict domain is visually identified through the communication relationship diagram.

10. The data link layer parsing method under the industrial field network address conflict environment according to claim 9, characterized in that: The specific method of establishing the communication relationship diagram in the network includes: The communication relationship graph is composed of nodes and edges. The source MAC address and the destination IP address are used as nodes, and the timestamp, frame interval, burst traffic mode, function code, and data domain are used as edges. The NetworkX tool is used to construct the communication relationship graph.

Citation Information

Patent Citations

  • Slice-based burst traffic detection method and device in PON system

    CN111901707A

  • Network APR attack detection method and device, electronic equipment and storage medium

    CN116545640A

  • 5G communication network operation and maintenance platform based on big data

    CN118524413A

  • Large-scale real-time data link layer simulation method and system

    CN119652448A

  • System and method for resisting pseudo link layer protocol attack in power communication network

    CN119652654A

Cited By

  • Data stream analysis detection method and device for private protocol of gatekeeper isolation component

    CN121441813A

  • Elastic node scheduling method and system for massive Internet of Things terminal data access

    CN122137638A

  • Node elastic scheduling method and system for massive internet of things terminal data access

    CN122137638B