Data interaction method, system and switch of reinforced switch
By analyzing the ARP message format and content, calculating the evaluation value of the sender's IP address, and evaluating its legitimacy, the problem of ARP spoofing attacks is resolved, and the data interaction security and stability of the reinforced switch are improved.
Patent Information
- Application Number
- CN202511062871.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-31
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-07-31
AI Technical Summary
Existing ruggedized switches are vulnerable to ARP spoofing attacks due to the lack of an authentication mechanism in the ARP protocol, which can lead to communication interruptions, data leakage, and network paralysis, affecting the security and stability of data interaction.
By capturing ARP messages in real time, analyzing the message format and content, calculating the high-frequency response, mapping anomaly, traffic anomaly and discrimination coefficient of the sender IP address, the legitimacy of each sender IP address is evaluated to prevent attacks from forged ARP messages.
Effectively prevent ARP spoofing attacks, control the scope of attack impact, improve the security and stability of data interaction, and ensure normal data interaction of legitimate IP addresses.
Smart Images

Figure CN120582905B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data interaction technology, and in particular to a data interaction method, system, and switch for a reinforced switch. Background Art
[0002] As industrial-grade network equipment, the core function of a ruggedized switch is to ensure the continuity, stability, and security of data exchange. During operation, the core data exchange process of a ruggedized switch relies heavily on the ARP protocol to dynamically map IP addresses to MAC addresses, thereby enabling communication between the network layer and the data link layer.
[0003] However, since the ARP protocol itself lacks an authentication mechanism, attackers can forge ARP packets, impersonate the IP addresses of legitimate devices, and tamper with the ARP cache tables of network devices, causing communication interruptions or data leaks. Secondly, attackers can exhaust the switch's cache resources by sending a large number of forged ARP request packets, triggering broadcast flooding, causing network congestion or even paralysis, thereby affecting the security and stability of switch data interaction. Summary of the Invention
[0004] In order to solve the above technical problems, a data interaction method, system and switch of a reinforced switch are provided to solve the existing problems.
[0005] The solution to the technical problem of this application is to provide a data interaction method, system and switch for a reinforced switch, including the following steps:
[0006] In a first aspect, an embodiment of the present application provides a data interaction method for a reinforced switch, the method comprising the following steps:
[0007] Capture ARP messages in real time on ruggedized switches and, based on the message format, obtain the Ethernet source MAC address, operation type, sender MAC address, sender IP address, and sending time of each ARP message during each monitoring period. Based on the operation type of the ARP message, classify the ARP message into ARP request messages and ARP response messages.
[0008] For all ARP messages in each monitoring period, analyze the number of ARP request messages and ARP response messages corresponding to each sending IP address, as well as the difference in the number of ARP messages sent by each sending IP address in adjacent monitoring periods, and calculate the high-frequency responsiveness of each sending IP address in each monitoring period;
[0009] The mapping anomaly degree of each sending IP address in each monitoring period is obtained by the number of sending MAC addresses mapped to each sending IP address and the matching status with the Ethernet source MAC address. Combined with the high-frequency response, the first evaluation value of each sending IP address in each monitoring period is determined;
[0010] Analyze the discrete time intervals at which different ARP request messages corresponding to each sender IP address are responded to, as well as the number of ARP request messages responded to, calculate the traffic anomaly degree of each sender IP address in each monitoring period, and combine the relevant information of the sender MAC addresses mapped to different sender IP addresses to obtain the second evaluation value of each sender IP address in each monitoring period;
[0011] Based on the first evaluation value and the second evaluation value, the discrimination coefficient of each sending IP address in each monitoring period is obtained, and the legitimacy of each sending IP address is evaluated. The reinforced switch allows legal IP addresses to interact with data.
[0012] Preferably, the calculating of the high frequency responsiveness of each sending end IP address in each monitoring period includes:
[0013] For all ARP messages in each monitoring period, count the number of all ARP response messages and all ARP request messages corresponding to each sender IP address, and record them as the number of responses and the number of requests respectively; calculate the ratio of the number of responses to the number of requests, and record it as the number ratio;
[0014] Counting the number of all ARP messages corresponding to each sender IP address, taking the difference between the number of each sender IP address in each monitoring period and the previous monitoring period, and performing positive mapping on the difference;
[0015] The high frequency responsivity is the product of the quantity ratio and the result of the forward mapping.
[0016] Preferably, obtaining the mapping abnormality degree of each sending end IP address in each monitoring period includes:
[0017] Count the number of all sender MAC addresses mapped to each sender IP address in all ARP packets during each monitoring period, and record it as the mapping number;
[0018] Calculating the cumulative sum of the correlations between all the sender MAC addresses and the Ethernet source MAC address mapped to each sender IP address;
[0019] The mapping abnormality is a ratio of the mapping quantity to the cumulative sum.
[0020] Preferably, the first evaluation value is the product of the high-frequency response and the mapping abnormality.
[0021] Preferably, the calculation of the traffic anomaly degree of each sending end IP address in each monitoring period includes:
[0022] Find the ARP response message that is successfully responded to each ARP request message as a pair of matching messages; count the number of all matching messages corresponding to each sender IP address in all ARP request messages during each monitoring period, and record it as the number of matches;
[0023] Calculate the interval between the sending times of each pair of matching messages, which is recorded as the response time; calculate the dispersion of the response time of all matching messages corresponding to each sending end IP address in each monitoring period;
[0024] The flow anomaly degree is the product of the matching quantity and the discrete degree.
[0025] Preferably, obtaining the second evaluation value of each sending end IP address in each monitoring period includes:
[0026] All the sender MAC addresses mapped to each sender IP address in all ARP messages during each monitoring period are combined into a mapping address vector; the sum of the similarities between each sender IP address and all other sender IP addresses in the mapping address vector is calculated and recorded as the correlation coefficient;
[0027] The second evaluation value is the product of the correlation coefficient and the flow abnormality degree.
[0028] Preferably, the discrimination coefficient is a normalized result of the product of the first evaluation value and the second evaluation value.
[0029] Preferably, the evaluation of the legitimacy of each sending IP address includes: if the average of the discrimination coefficient of each sending IP address in multiple consecutive monitoring time periods is greater than or equal to a preset threshold, then the sending IP address is an illegal IP address; otherwise, the sending IP address is a legal IP address.
[0030] In a second aspect, an embodiment of the present application further provides a data interaction system for a ruggedized switch, the system comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein when the processor executes the computer program, the steps of the data interaction method for a ruggedized switch described in any one of the above items are implemented.
[0031] In a third aspect, an embodiment of the present application further provides a ruggedized switch, wherein the data interaction process of the ruggedized switch is implemented by using any of the steps of the data interaction method for a ruggedized switch described above.
[0032] This application has at least the following beneficial effects:
[0033] This application calculates the high-frequency response of each sending IP address in each monitoring period by analyzing the proportion of ARP response messages corresponding to each sending IP address and the surge in the number of ARP messages sent by each sending IP address. The beneficial effect is that it takes into account the abnormality of the high-frequency response of the sending IP address, and preliminarily evaluates the possibility that the sending IP address is subject to potential ARP spoofing attack risks; obtains the mapping abnormality of each sending IP address in each monitoring period, which has the beneficial effect of taking into account the diversity of MAC addresses mapped by the sending IP address and the mismatch between the mapped MAC address and the Ethernet source MAC address, reflecting the abnormality of the single mapping relationship between each sending IP address and the MAC address, and further evaluating the risk of potential ARP spoofing attack on the sending IP address; determines the first evaluation value of each sending IP address in each monitoring period, which has the beneficial effect of comprehensively evaluating the abnormality of the message behavior of the sending IP address, reflecting the possibility of potential ARP spoofing attack; secondly, calculates the traffic abnormality of each sending IP address in each monitoring period, which has the beneficial effect of taking into account the successful response of different ARP request messages corresponding to the sending IP address. The second evaluation value of each sending IP address in each monitoring period is determined, which has the beneficial effect of considering the possibility of ARP flooding triggered by the attacker and the influence of the attacker's decentralized ARP spoofing on the data interaction process; the discrimination coefficient of each sending IP address in each monitoring period is obtained, and the legitimacy of each sending IP address is evaluated. The reinforced switch allows legitimate IP addresses to interact with data, which has the beneficial effect of comprehensively evaluating the sending IP address due to the attack. The switch can effectively verify the legitimacy of ARP messages sent by the sender's IP address during data interaction. The switch allows legitimate IPs to interact with data and prevents illegal IPs from accessing it. This effectively prevents attackers from impersonating gateways or hosts to send a large number of forged ARP messages, causing tampering with the ARP cache table of network devices and the risk of broadcast flooding. When an attacker conducts an ARP spoofing attack, the switch can promptly and effectively detect and defend against ARP spoofing attacks, control the impact range of ARP spoofing attacks, and improve the security and stability of data interaction on the reinforced switch. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] The data interaction method of a reinforced switch of the present application is further described in detail below with reference to the accompanying drawings.
[0035] Figure 1 A flowchart of a data interaction method for a reinforced switch provided in an embodiment of the present application;
[0036] Figure 2 A flowchart of the steps of a method for obtaining the second evaluation value of each sending end IP address in each monitoring period provided in an embodiment of the present application. DETAILED DESCRIPTION
[0037] To make the objectives, technical solutions, and advantages of this application more clearly understood, the following, in conjunction with the accompanying drawings and implementation examples, further describes in detail a data interaction method, system, and switch for a ruggedized switch proposed in this application. It should be understood that the specific embodiments described herein are intended only to explain this application and are not intended to limit this application.
[0038] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs.
[0039] See also Figure 1 , which shows a flowchart of a data interaction method for a reinforced switch provided by an embodiment of the present application, the method comprising the following steps:
[0040] Step 1: Capture ARP messages of the ruggedized switch in real time, and obtain the Ethernet source MAC address, operation type, sender MAC address, sender IP address, and sending time of each ARP message during each monitoring period according to the message format; based on the operation type of the ARP message, divide the ARP message into ARP request messages and ARP response messages.
[0041] During the operation of a ruggedized switch, the core data exchange process relies heavily on the ARP protocol to map IP addresses to MAC addresses, thereby building the ARP cache table. The ARP Address Resolution Protocol is a crucial Ethernet protocol used to map IP addresses to hardware MAC addresses. Because the ARP protocol itself lacks an authentication mechanism, attacks targeting the protocol in Ethernet networks are numerous, and ARP vulnerabilities can be exploited for network eavesdropping and spoofing.
[0042] Secondly, during data exchange, an ARP cache table is constructed to reduce the number of ARP requests and responses. Therefore, during data transmission, the sender queries its own ARP cache table for the destination MAC address. If the query is successful, the data packet is directly encapsulated into an Ethernet frame. If the query fails, an ARP request broadcast message is sent. After the receiver responds to the ARP request, it automatically associates the IP and MAC addresses and stores them in the cache table for future communication. The core idea of ARP spoofing is that an attacker can send forged ARP responses, impersonating a legitimate device on the network, causing other network devices to update their ARP caches and tamper with the ARP caches of network devices. Alternatively, the attacker can frequently send a large number of false ARP request broadcasts, thereby causing broadcast flooding and disrupting or delaying network communications.
[0043] Based on the above analysis, we configured port mirroring on the ruggedized switch to copy the ARP traffic of the port to be monitored to the SPAN port. We then used a packet capture tool to capture ARP packets in real time on the ruggedized switch. This allowed us to obtain every ARP packet within each monitoring period, as well as the time each ARP packet was sent.
[0044] In this embodiment, packet capture is performed using a packet capture tool such as Wireshark or tcpdump. Wireshark and tcpdump are both well-known technologies and will not be described in detail herein.
[0045] It should be noted that the format of the ARP message strictly complies with the RFC 826 protocol specification. The total length of the ARP message format is 42 bytes, including a 14-byte Ethernet frame header and a 28-byte ARP message body. Among them, the Ethernet frame header contains fields: Ethernet source MAC address, Ethernet destination MAC address and frame type. The Ethernet source MAC address and Ethernet destination MAC address each occupy 6 bytes. The frame type field value is 0×0806, which occupies 2 bytes, used to indicate that the upper layer is running the ARP protocol. The ARP message body contains: hardware type, protocol type, hardware address length, protocol address length, operation type, sender MAC address, sender IP address, destination MAC address, destination IP address. The hardware type field is used to define the network type running the ARP protocol. When the field value is "1", it indicates that the network running the ARP protocol is Ethernet. The hardware type occupies 2 bytes; the protocol type field is used to define which network protocol the upper layer uses. When the field value is "0800", it indicates that the network running the ARP protocol is Ethernet. Indicates that the upper layer uses the IPv4 protocol, and the protocol type occupies 2 bytes; the hardware address length field is used to define the physical address length, and the protocol address length field is used to define the logical address length. The hardware address length and the protocol address length each occupy 1 byte; when the operation type field value is "1", it indicates an ARP request message; when the operation type field value is "2", it indicates an ARP response message, which occupies 2 bytes; the sender MAC address field is used to define the MAC address of the device sending the ARP request, which is the same as the Ethernet source MAC address, and the sender IP address field is used to define the IP address of the device sending the ARP request; the destination MAC address field and the destination IP address field are used to define the destination device MAC address and IP address respectively. The sender MAC address and the destination MAC address each occupy 6 bytes, and the sender IP address and the destination IP address each occupy 4 bytes.
[0046] In this embodiment, the duration of a monitoring period is 1 minute. As other implementation methods, the implementer can set it according to actual conditions. The messages with a byte count of not 42 bytes in each monitoring period are eliminated.
[0047] According to the operation type of each ARP message, the ARP message with the operation type of request is recorded as each ARP request message; the ARP message with the operation type of response is recorded as each ARP response message;
[0048] Thus, the Ethernet source MAC address, operation type, sender MAC address, sender IP address, and sending time of each ARP packet are obtained.
[0049] At this point, all ARP packets and their sending times in each monitoring period are obtained.
[0050] Step 2: For all ARP messages in each monitoring period, analyze the number of ARP request messages and ARP response messages corresponding to each sending IP address, as well as the difference in the number of ARP messages sent by each sending IP address in adjacent monitoring periods, and calculate the high-frequency responsiveness of each sending IP address in each monitoring period; obtain the mapping anomaly of each sending IP address in each monitoring period through the number of sending MAC addresses mapped to each sending IP address and the matching with the Ethernet source MAC address, and determine the first evaluation value of each sending IP address in each monitoring period in combination with the high-frequency responsiveness.
[0051] During data exchange with a ruggedized switch, the ARP protocol lacks an authentication mechanism and the switch dynamically updates the MAC table by default. Attackers can arbitrarily forge IP-MAC pairs, causing an RFC 826 flaw. This causes the mapping between the IP address and the corresponding MAC address declared in the ARP message to conflict with the network topology rules, causing the target device to incorrectly update its ARP cache. At the same time, the attacker can send messages at a high frequency to overwrite the correct mapping of legitimate devices, triggering an ARP flood attack and consuming switch processing resources.
[0052] Secondly, the ARP packets forged by attackers usually modify the MAC address covertly. The more likely the ARP packet is forged by the attacker, the more the MAC address corresponding to the sender's IP address does not match the Ethernet source MAC address. In addition, when the ARP protocol, which has not been verified for legitimacy, faces an attack through forged ARP packets, the same IP address is mapped to multiple MAC addresses in a short period of time, and the differences between the multiple MAC addresses are large. At the same time, when the attacker sends packets at a high frequency, the proportion of response packets sent without request increases, and the number of ARP packets sent corresponding to the same sender IP address increases sharply in different monitoring periods.
[0053] First, by analyzing the number of ARP request and response messages corresponding to each sender IP address in all ARP messages during the monitoring period, as well as the changes in the number of ARP messages sent by the same sender IP address during different monitoring periods, the high-frequency responsiveness is calculated. Specifically,
[0054] For all ARP messages in each monitoring period, count the number of all ARP response messages corresponding to each sender IP address and record it as the number of responses;
[0055] Count the number of all ARP request packets corresponding to each sender IP address, and record it as the number of requests;
[0056] Calculate the ratio of the number of responses to the number of requests, and record it as the number ratio;
[0057] It should be noted that if the requested quantity is 0, the quantity ratio is a preset value, and the preset value is 1. As other implementation methods, the implementer can set it according to actual conditions.
[0058] Count the number of all ARP packets corresponding to each sender IP address;
[0059] The difference between the number of each sending end IP address in each monitoring period and the number of the previous monitoring period is calculated, and the difference is positively mapped;
[0060] In this embodiment, the specific process of positive mapping is: positive mapping is performed through an exponential function, assuming that the difference is recorded as ,Will The result is the result of the positive mapping, where is an exponential function with a natural constant as its base; through the process of positive mapping, the relative difference is made to be always greater than 0.
[0061] The product of the quantity ratio and the result of the positive mapping is used as the high-frequency response of each sending end IP address in each monitoring period;
[0062] It should be noted that, the larger the number ratio is, the more response messages actively sent by each sending IP address exceeds the number of request messages, the larger the result of the positive mapping is, the more surge the number of ARP messages sent by the same sending IP address in a short period of time, the greater the obtained high-frequency response is, the more abnormal the high-frequency response is in the sending IP address, and the more likely the sending IP address is to be subject to potential ARP spoofing attack risks.
[0063] Secondly, under normal circumstances, a sender IP address usually corresponds to a valid sender MAC address. However, in the case of an ARP spoofing attack, one IP address may correspond to multiple MAC addresses. The mapping anomaly degree is calculated based on the matching between the sender MAC address corresponding to the sender IP address and the Ethernet source MAC address, as well as the number of all sender MAC addresses corresponding to the sender IP address. Specifically,
[0064] Count the number of all sender MAC addresses mapped to each sender IP address in all ARP packets during each monitoring period, and record it as the mapping number;
[0065] Calculating the cumulative sum of the correlations between all the sender MAC addresses mapped to each sender IP address and the Ethernet source MAC address;
[0066] In this embodiment, the degree of correlation is measured by calculating the cosine similarity between the sender MAC address mapped to each sender IP address and the Ethernet source MAC address, wherein the calculation of the cosine similarity is a well-known technique and will not be described in detail here.
[0067] Calculating a ratio of the mapping quantity to the accumulated sum as the mapping abnormality degree of each sending end IP address in each monitoring period;
[0068] In this embodiment, the The sending IP address is in The calculation formula for the mapping anomaly degree of a monitoring period is:
[0069]
[0070] in, For the The sending IP address is in The mapping anomaly degree of each monitoring period, For the The next monitoring period The number of all sender MAC addresses mapped to the sender IP address, that is, the mapping number, For the The next monitoring period The first mapping of the sender IP address The sending MAC address, For the The next monitoring period The sender IP address corresponds to the Ethernet source MAC address, Indicates the degree of correlation. To preset a value greater than 0, in order to avoid the denominator being 0 when calculating the ratio, a value greater than 0 is preset. The value is 1. As other implementation methods, the implementer can set it according to actual conditions. This embodiment does not impose any special restrictions on this.
[0071] It should be noted that the larger the number of mappings, the more MAC addresses correspond to each sender IP address, and the smaller the cumulative sum, the more the MAC address corresponding to the sender IP address does not match the Ethernet source MAC address, reflecting that the difference between the sender MAC addresses is more significant, and the greater the resulting mapping anomaly, indicating that the single mapping relationship between each sender IP address and MAC address is more likely to be abnormal, reflecting that the sender IP address is more likely to be subject to potential ARP spoofing attack risks.
[0072] Furthermore, based on the high-frequency response and the mapping abnormality, a first evaluation value is determined, specifically:
[0073] The product of the high-frequency response and the mapping abnormality is used as the first evaluation value of each sending end IP address in each monitoring period;
[0074] It should be noted that the larger the first evaluation value is, the higher the frequency of ARP message sending corresponding to the same sending IP address caused by the attacker's ARP spoofing during the monitoring period and the greater the difference in the multi-mapping characteristics of the MAC address, reflecting that there is an obvious abnormality in the message behavior of the sending IP address, and the greater the possibility of potential ARP spoofing attack.
[0075] At this point, the first evaluation value of each sending end IP address in each monitoring period is obtained.
[0076] Step 3: Analyze the discrete time intervals of responses to different ARP request messages corresponding to each sender IP address, as well as the number of responded ARP request messages, calculate the traffic anomaly of each sender IP address in each monitoring period, and combine the relevant information of the sender MAC addresses mapped to different sender IP addresses to obtain the second evaluation value of each sender IP address in each monitoring period.
[0077] Furthermore, the flowchart of the method for obtaining the second evaluation value of each sending end IP address in each monitoring period provided by the embodiment of the present application is as follows: Figure 2 shown.
[0078] During data interaction with a ruggedized switch, when an attacker uses a dispersed ARP spoofing attack, the attacker may simultaneously impersonate multiple network identities and forge ARP packets with multiple IP addresses, causing devices on the network to mistakenly believe that they are legitimate gateways or servers. In this attack, the attacker may impersonate multiple devices at the same time, causing multiple IP addresses to be incorrectly mapped to the same MAC address, causing the MAC mapping detection mechanism for a single IP address to fail and be unable to effectively respond to dispersed ARP spoofing attacks.
[0079] Secondly, the more severe the ARP flooding mechanism triggered by the large number of ARP requests sent by the attacker, the more each device in the network will receive these ARP requests and update its own ARP cache based on the information in the request, making the similarity between the MAC addresses mapped to different IP addresses in the ARP message higher; at the same time, under normal circumstances, there is a clear time interval and matching relationship between ARP requests and responses. However, in an ARP spoofing attack, the attacker hijacks the traffic by forging ARP messages, which will cause the traffic distribution of ARP messages for request and response operations to become unbalanced, resulting in no obvious pattern in the time interval between ARP message responses and requests, resulting in more successful matching of ARP requests and responses.
[0080] Based on the above analysis, the traffic anomaly degree is calculated by analyzing the time interval between responses to the ARP request messages corresponding to each sender IP address and the number of response messages corresponding to successful responses to the ARP request messages. Specifically,
[0081] Find the ARP response message that is successfully responded to each ARP request message as a pair of matching messages;
[0082] Count the number of matching packets corresponding to each sender IP address in all ARP request packets during each monitoring period, and record it as the number of matches;
[0083] Calculate the interval between the sending times of each pair of matching messages and record it as the response duration;
[0084] Calculate the discrete degree of the response time of all matching messages corresponding to each sender IP address in each monitoring period;
[0085] In this embodiment, the degree of dispersion is measured by calculating the approximate entropy of the response time of all matching messages corresponding to each sender IP address in each monitoring period, wherein the calculation of the approximate entropy is a well-known technology and will not be repeated here.
[0086] The product of the number of matches and the discreteness is used as the traffic anomaly degree of each sending end IP address in each monitoring period;
[0087] It should be noted that the larger the number of matches, the more ARP requests are successfully responded to, reflecting that the attacker is more likely to cover more legitimate ARP mappings. The greater the degree of dispersion, the more chaotic the time intervals at which the ARP request packets of the sender's IP address are responded to, and there is no obvious regularity. The attacker's behavior of forging responses is random. The greater the resulting traffic anomaly, the larger the scale of the attacker's forged ARP responses, the more covert the behavior, and the higher the risk of network traffic being hijacked.
[0088] Secondly, by analyzing the similarity of all sender MAC addresses mapped to different sender IP addresses and combining it with the traffic anomaly degree, a second evaluation value is calculated, specifically:
[0089] All the sender MAC addresses mapped to each sender IP address in all ARP packets during each monitoring period are combined into a mapping address vector;
[0090] Calculate the sum of the similarities between each sender IP address and all other sender IP addresses, and record it as the correlation coefficient;
[0091] In this embodiment, the similarity degree is calculated by calculating the cosine similarity of the mapping address vectors between each sender IP address and the other sender IP addresses. The calculation of the cosine similarity is a well-known technique and will not be described in detail here.
[0092] Calculating the product of the correlation coefficient and the traffic anomaly degree as a second evaluation value of each sending end IP address in each monitoring period;
[0093] It should be noted that the larger the correlation coefficient, the higher the similarity of the sender MAC addresses mapped to different sender IP addresses, which reflects that the attacker is more likely to trigger ARP flooding. The larger the second evaluation value, the more seriously the data interaction process is affected by the attacker's decentralized ARP spoofing.
[0094] At this point, the second evaluation value of each sending end IP address in each monitoring period is obtained.
[0095] Step 4: Based on the first evaluation value and the second evaluation value, the discrimination coefficient of each sending IP address in each monitoring period is obtained, and the legitimacy of each sending IP address is evaluated. The reinforced switch allows legitimate IP addresses to interact with data.
[0096] Furthermore, based on the first evaluation value and the second evaluation value, a discrimination coefficient is determined to reflect the possibility that each sending end IP address is subject to the risk of ARP spoofing by an attacker, specifically:
[0097] Normalizing the product of the first evaluation value and the second evaluation value as the discrimination coefficient of each sending end IP address in each monitoring period;
[0098] In this embodiment, the sigmoid function is used for normalization processing, wherein the sigmoid function is a well-known technology and will not be described in detail here.
[0099] It should be noted that the discrimination coefficient indicates that the greater the possibility that the sender IP address is abnormal, the greater the possibility of being deceived by the attacker's ARP.
[0100] Then, based on the discrimination coefficient, the legitimacy of the sending IP address is evaluated, specifically:
[0101] If the average of the discrimination coefficients of each sending IP address in a plurality of consecutive monitoring periods is greater than or equal to a preset threshold, the sending IP address is an illegal IP address; otherwise, the sending IP address is a legal IP address;
[0102] In this embodiment, if the average of the discrimination coefficients of each sending IP address in 10 consecutive monitoring periods is greater than or equal to a preset threshold, then the sending IP address is an illegal IP address, where the preset threshold is 0.7. As other implementation methods, the implementer can set it according to actual conditions.
[0103] For legal IP addresses, the rugged switch allows legal IP addresses to exchange data by sending ARP request and response messages. For illegal IP addresses, the firewall of the rugged switch will block the ARP message traffic of illegal IP addresses and not allow illegal IP addresses to exchange data, effectively defending against threats such as ARP spoofing and flooding attacks.
[0104] An embodiment of the present application also provides a data interaction system for a ruggedized switch, comprising a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the steps of any one of the above-mentioned data interaction methods for the ruggedized switch are implemented.
[0105] Based on the same inventive concept as the above method, an embodiment of the present application further provides a ruggedized switch, wherein the data interaction process of the ruggedized switch is implemented by using the steps of any one of the above-mentioned data interaction methods for a ruggedized switch.
[0106] It should be understood that although Figure 1 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. In addition, Figure 1 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.
[0107] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0108] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the present application. It should be noted that a person skilled in the art can make various modifications and improvements without departing from the spirit of the present application. Therefore, any simple modifications, equivalent variations, and modifications to the above embodiments made in accordance with the technical essence of the present application without departing from the content of the present application's technical solution fall within the scope of protection of the present application's technical solution.
Claims
1. A data interaction method for a reinforced switch, characterized in that: The method comprises the following steps: Capture ARP messages in real time on ruggedized switches and, based on the message format, obtain the Ethernet source MAC address, operation type, sender MAC address, sender IP address, and sending time of each ARP message during each monitoring period. Based on the operation type of the ARP message, classify the ARP message into ARP request messages and ARP response messages. For all ARP messages in each monitoring period, analyze the number of ARP request messages and ARP response messages corresponding to each sending IP address, as well as the difference in the number of ARP messages sent by each sending IP address in adjacent monitoring periods, and calculate the high-frequency responsiveness of each sending IP address in each monitoring period; The mapping anomaly degree of each sending IP address in each monitoring period is obtained by the number of sending MAC addresses mapped to each sending IP address and the matching status with the Ethernet source MAC address. Combined with the high-frequency response, the first evaluation value of each sending IP address in each monitoring period is determined; Analyze the discrete time intervals at which different ARP request messages corresponding to each sender IP address are responded to, as well as the number of ARP request messages responded to, calculate the traffic anomaly degree of each sender IP address in each monitoring period, and combine the relevant information of the sender MAC addresses mapped to different sender IP addresses to obtain the second evaluation value of each sender IP address in each monitoring period; Based on the first evaluation value and the second evaluation value, the discrimination coefficient of each sending IP address in each monitoring period is obtained, and the legitimacy of each sending IP address is evaluated. The reinforced switch allows legitimate IP addresses to interact with data. The calculation of the high frequency response of each sending end IP address in each monitoring period includes: For all ARP messages in each monitoring period, count the number of all ARP response messages and all ARP request messages corresponding to each sender IP address, and record them as the number of responses and the number of requests respectively; calculate the ratio of the number of responses to the number of requests, and record it as the number ratio; Counting the number of all ARP messages corresponding to each sender IP address, taking the difference between the number of each sender IP address in each monitoring period and the previous monitoring period, and performing positive mapping on the difference; The high frequency responsivity is the product of the quantity ratio and the result of the positive mapping; Obtaining the mapping abnormality degree of each sending end IP address in each monitoring period includes: Count the number of all sender MAC addresses mapped to each sender IP address in all ARP packets during each monitoring period, and record it as the mapping number; Calculating the cumulative sum of the correlations between all the sender MAC addresses and the Ethernet source MAC address mapped to each sender IP address; The mapping abnormality is the ratio of the number of mappings to the cumulative sum; The calculation of the traffic anomaly degree of each sending end IP address in each monitoring period includes: Find the ARP response message that is successfully responded to each ARP request message as a pair of matching messages; count the number of all matching messages corresponding to each sender IP address in all ARP request messages during each monitoring period, and record it as the number of matches; Calculate the interval between the sending times of each pair of matching messages, which is recorded as the response time; calculate the dispersion of the response time of all matching messages corresponding to each sending end IP address in each monitoring period; The flow anomaly degree is the product of the matching number and the discrete degree; The discrimination coefficient is a normalized result of the product of the first evaluation value and the second evaluation value.
2. A data interaction method for a reinforced switch according to claim 1, characterized in that: The first evaluation value is a product of the high-frequency response and the mapping abnormality.
3. The data interaction method of a reinforced switch according to claim 1, characterized in that: Obtaining the second evaluation value of each sending end IP address in each monitoring period includes: All the sender MAC addresses mapped to each sender IP address in all ARP messages during each monitoring period are combined into a mapping address vector; the sum of the similarities between each sender IP address and all other sender IP addresses in the mapping address vector is calculated and recorded as the correlation coefficient; The second evaluation value is the product of the correlation coefficient and the flow abnormality degree.
4. The data interaction method of a reinforced switch according to claim 1, characterized in that: The evaluation of the legitimacy of each sending IP address includes: if the average of the discrimination coefficient of each sending IP address in multiple consecutive monitoring periods is greater than or equal to a preset threshold, then the sending IP address is an illegal IP address; otherwise, the sending IP address is a legal IP address.
5. A data interaction system for a reinforced switch, the system comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the steps of the data interaction method for a reinforced switch according to any one of claims 1 to 4 are implemented.
6. A reinforced switch, characterized in that: The data interaction process of the reinforced switch is implemented by using the steps of a data interaction method for a reinforced switch as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Message processing method and device based on openflow channel
CN107707486A
ARP spoofing defense method, system and device
CN113347155A