Efficient security management and control method, system and equipment for park network and medium

By building a DHCP server and configuring DHCP relay and SNOOPING functions in the campus network, combined with SNMP services and firewall policies, the problems of identity authentication being vulnerable to attacks and low address resource utilization in the campus network are solved, dynamic terminal control and traffic management are achieved, and network security and stability are improved.

CN120602120APending Publication Date: 2025-09-05GUIZHOU WUJIANG HYDROPOWER DEV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510639451.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing campus network management and control technologies have problems such as identity authentication being easily penetrated by ARP attacks, static IP binding strategies leading to low address resource utilization, and insufficient dynamic management of terminals throughout their life cycle.

Method used

By setting up a DHCP server to achieve dynamic binding of IP and MAC addresses, configuring DHCP relay and SNOOPING functions, combining SNMP services to collect device information and synchronize it to the firewall, setting IP-MAC binding policies and dumb terminal isolation mechanisms, dynamic terminal verification and abnormal traffic interception can be achieved.

Benefits of technology

It enhances the network's security defense capabilities, improves IP address management efficiency and network stability, implements refined management and traffic control throughout the terminal life cycle, prevents illegal access, and optimizes address resource utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602120A_ABST
    Figure CN120602120A_ABST
Patent Text Reader

Abstract

The invention discloses an efficient security management and control method, system and device for a park network, and a medium. The method comprises the following steps: building a DHCP server, configuring an action range, an address pool and a security policy, and realizing dynamic binding of an IP and an MAC address; a DHCP relay and an SNOOPING function are configured in a switch, and equipment information is collected and synchronized to a firewall in combination with an SNMP service; an IP-MAC binding strategy, dumb terminal isolation and a dynamic verification mechanism are set in a firewall, terminal legality is compared through cross-three-layer detection, and abnormal traffic is intercepted. Through a triple binding mechanism, a dynamic filter and reserved address configuration, multi-factor authentication of a terminal identity is realized, and the network security defense capability is enhanced; iP address management efficiency and network stability are improved through dynamic allocation of DHCP service and address pool management in combination with SNMP real-time monitoring and a cross-three-layer detection mechanism; through a firewall IP-MAC binding strategy, dumb terminal isolation and a dynamic verification mechanism, terminal full life cycle management and control and refined flow control are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security management technology, and in particular to a method, system, equipment and medium for efficient and secure management and control of a campus network. Background Art

[0002] In recent years, campus network security management technology has gradually evolved towards a dynamic and intelligent direction. Address allocation mechanisms based on the DHCP dynamic host configuration protocol and MAC-IP binding strategies have become mainstream network access control methods, combined with firewall strategies and SNMP protocols to achieve basic network management and control. With the popularization of SDN (Software Defined Network) and zero-trust architecture, the industry has begun to explore multi-factor authentication systems that integrate virtualization platforms. DHCP Snooping dynamic host configuration protocol monitoring technology is used to prevent the injection of illegal DHCP servers. Combined with cross-layer IP-MAC binding, it improves terminal identification accuracy and strengthens network boundary security. The deployment of virtual DHCP services in cloud computing environments has significantly improved address allocation efficiency. However, existing technologies mostly use static binding and decentralized management, failing to effectively integrate the full-link technical elements of terminal authentication, address allocation, and dynamic management and control.

[0003] Existing campus network management and control technologies have single-point vulnerabilities in identity authentication. Traditional MAC-IP binding is susceptible to ARP spoofing attacks, allowing attackers to break through network boundary protections by forging MAC addresses. Existing DHCP snooping technology cannot achieve dynamic linkage between terminal characteristics and network policies. Address resource utilization is low, and static binding policies cause offline device IP addresses to remain for long periods of time, resulting in address pool fragmentation in large campus networks. The existing dynamic allocation mechanism lacks differentiated address recovery algorithms based on terminal type. The management and control dimensions are single, and the SNMP protocol only implements one-way status monitoring, failing to form a closed-loop control with firewall policies. Dumb terminal isolation relies on manual configuration and lacks cross-layer topology awareness capabilities. Summary of the Invention

[0004] In view of the above existing problems, the present invention is proposed.

[0005] Therefore, the present invention provides a method and system for efficient and secure campus network management and control to solve the following problems: the existing campus network management and control technology has identity authentication that is easily penetrated by ARP attacks, the static IP binding strategy leads to low address resource utilization, and how to achieve dynamic management and control of terminals throughout their entire life cycle.

[0006] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0007] In the first aspect, the present invention provides a method for efficient and secure management and control of campus networks, including: building a DHCP server, configuring scopes, address pools, and security policies to achieve dynamic binding of IP and MAC addresses; configuring DHCP relay and SNOOPING functions on switches, collecting device information in combination with SNMP services and synchronizing it to firewalls; setting IP-MAC binding policies, dumb terminal isolation, and dynamic verification mechanisms on firewalls, and intercepting abnormal traffic by comparing terminal legitimacy across three layers of detection.

[0008] As a preferred solution of the campus network efficient and secure management and control method described in the present invention, the following is described: setting up a DHCP server includes deploying an operating system based on the enterprise's existing virtualization cloud platform, installing DHCP service functions, creating a scope corresponding to the intranet segment, configuring the address pool, reserved addresses and scope options; adding a list of allowed MAC addresses to the filter, allowing only terminals in the list to obtain IP addresses; and strengthening server security through host hardening and antivirus software.

[0009] As a preferred solution of the campus network efficient and secure management and control method described in the present invention, the implementation of dynamic binding of IP and MAC addresses includes enabling the MAC address and IP binding function in the scope of the DHCP server, and fixedly assigning a unique IP address to a specific MAC address through reserved address configuration; when a terminal first accesses the network, the DHCP server matches the filter list based on the MAC address, and if the match is successful, the reserved IP is assigned, otherwise the assignment is rejected.

[0010] As a preferred solution of the campus network efficient and secure management method described in the present invention, the configuration of DHCP relay includes enabling the DHCP relay agent function on the three-layer switch, specifying the authorized DHCP server address, and opening the forwarding of the UDP port.

[0011] As a preferred solution of the campus network efficient and secure management method described in the present invention, the configuration of the SNOOPING function includes enabling DHCP SNOOPING on the access layer switch, setting the trusted port to only allow authorized DHCP servers to respond, and blocking interference from illegal servers.

[0012] As an optimal solution for the efficient and secure campus network management and control method described in the present invention, the method of collecting device information in combination with the SNMP service includes starting the SNMP v2c service in the core switch, configuring the community word and trap receiving address, obtaining the terminal IP-MAC information in real time and synchronizing it to the firewall.

[0013] As a preferred solution of the campus network efficient and secure management and control method described in the present invention, the method includes: intercepting abnormal traffic includes the firewall comparing the terminal IP-MAC information through cross-three-layer detection, and discarding the data packet if it is inconsistent with the binding list; the terminal releases and re-acquires the IP through the command line.

[0014] In a second aspect, the present invention provides an efficient and secure campus network management and control system, including: an address binding module, an information collection module, and an abnormality interception module; the address binding module is used to build a DHCP server, configure scopes, address pools, and security policies, and realize dynamic binding of IP and MAC addresses; the information collection module is used to configure DHCP relay and SNOOPING functions on the switch, and collect device information in combination with SNMP services and synchronize it to the firewall; the abnormality interception module is used to set IP-MAC binding policies, dumb terminal isolation, and dynamic verification mechanisms on the firewall, and intercept abnormal traffic by comparing the legitimacy of the terminal through cross-three-layer detection.

[0015] In a third aspect, the present invention provides an electronic device, comprising:

[0016] memory and processor;

[0017] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the method for efficient and secure management and control of the campus network are implemented.

[0018] In a fourth aspect, the present invention provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the method for efficient and secure management and control of a campus network.

[0019] Compared with the prior art, the present invention has the following beneficial effects: the present invention builds a zero-information dynamic authentication system by combining the triple binding mechanism of DHCP SNOOPING, IP and MAC with dynamic filters and reserved address configuration, realizes multi-factor authentication of terminal identity, and enhances network security defense capability; through the dynamic allocation and address pool management of DHCP services, combined with SNMP real-time monitoring and cross-layer three detection mechanism, improves IP address management efficiency and network stability; through the firewall IP-MAC binding strategy, dumb terminal isolation and dynamic verification mechanism, realizes terminal full life cycle management and refined traffic control; through DHCP relay to allocate IP across network segments, switch SNOOPING to block illegal servers, and firewall linked to SNMP data, realizes multi-segment collaborative management and resistance to near-source attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0021] Figure 1 The figure is a schematic diagram of the overall process of the method for efficient and secure management and control of a campus network according to an embodiment of the present invention.

[0022] Figure 2 This is a schematic diagram of the overall process of the campus network efficient and secure management and control system according to an embodiment of the present invention. DETAILED DESCRIPTION

[0023] To make the above-mentioned objects, features, and advantages of the present invention more clearly understood, the following detailed description of the specific embodiments of the present invention is given in conjunction with the accompanying drawings. It is obvious that the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in this field without creative work should fall within the scope of protection of the present invention.

[0024] Example 1, with reference to Figure 1 , as an embodiment of the present invention, provides a method for efficient and secure management and control of a campus network, comprising:

[0025] S1: Set up a DHCP server, configure scopes, address pools, and security policies, and implement dynamic binding of IP and MAC addresses;

[0026] S2: Configure DHCP relay and SNOOPING functions on the switch, and use SNMP services to collect device information and synchronize it to the firewall;

[0027] S3: Set up IP-MAC binding policies, dumb terminal isolation, and dynamic verification mechanisms on the firewall to detect and compare the legitimacy of terminals across three layers and intercept abnormal traffic.

[0028] It should be noted that the campus network carries core business systems such as power dispatching, security monitoring, and production management. If its network suffers an ARP spoofing attack, resulting in communication interruption of the industrial control system, it may directly cause abnormal shutdown of the generator set, causing risks to the stability of the regional power grid. At the same time, sensitive data such as production operation data, user privacy information, and intellectual property information flowing within the campus network are at potential risk of being maliciously stolen; therefore, efficient and secure management and control of the campus network is very important.

[0029] Therefore, in response to the above-mentioned problems of identity authentication being vulnerable to attacks, low address resource utilization, and a single dimension of campus management and control, through steps S1-S3, a DHCP server is set up to implement dynamic binding of IP and MAC addresses, and intelligent isolation and dynamic access control of dumb terminals are achieved; DHCP relay and SNOOPING functions are configured, and the firewall is linked to SNMP data to simplify network architecture management and ensure compliance of address allocation; IP-MAC binding strategy, dumb terminal isolation, and dynamic verification mechanism ensure strict access control, prevent non-intelligent devices from accessing the Internet and becoming a springboard for intranet penetration, and optimize network resource allocation.

[0030] Example 2, reference Figure 1 , is an embodiment of the present invention. Based on the above embodiment, a method for efficient and secure management and control of a campus network is provided.

[0031] In the embodiment of the present application, setting up the DHCP server in step S1 includes the following steps A1-A3:

[0032] A1: Deploy an operating system based on the enterprise's existing virtualized cloud platform, install the DHCP service, create a scope corresponding to the intranet segment, and configure the address pool, reserved addresses, and scope options.

[0033] A2: Add a list of allowed MAC addresses in the filter to allow only terminals in the list to obtain IP addresses;

[0034] A3: Strengthen server security through host hardening and antivirus software.

[0035] Specifically, in step A1, add the DHCP server role in Server Manager. After completing the installation, enter the DHCP management console and establish a scope by selecting the IPv4 node.

[0036] Establishing a scope includes entering the scope name, setting the address pool range, subnet mask, and lease duration;

[0037] Configure the default gateway and DNS server address in the scope;

[0038] In step A2, create a list of allowed MAC addresses under the filter, enter the MAC addresses of authorized terminals, and set the permission for only terminals in the list to obtain IP address permissions.

[0039] In step A3, restrict access from unauthorized IP addresses and ports through group policies or manually configure firewall rules.

[0040] In an optional implementation, the restriction of unauthorized IP and port access in step A3 can also be achieved by deploying a port-based network access control protocol, requiring terminal devices to be authenticated by certificates, MAC addresses, or usernames and passwords before they can access the network. Unauthenticated devices will be isolated in the guest VLAN or directly denied connection.

[0041] In another optional implementation, the restriction of unauthorized IP and port access in step A3 can also be achieved by configuring a port security policy on the access layer switch to limit each port to only allow access from a specific MAC address. If the limit is exceeded, the port will be closed or an alarm will be sent.

[0042] In the embodiment of the present application, implementing the dynamic binding of IP and MAC addresses in step S1 includes enabling the MAC address and IP binding function in the scope of the DHCP server, and fixedly assigning a unique IP address to a specific MAC address through reserved address configuration;

[0043] When a terminal accesses the network for the first time, the DHCP server matches the filter list based on the MAC address. If the match is successful, the reserved IP address is assigned; otherwise, the assignment is rejected.

[0044] Specifically, in the DHCP management console, create a target scope reservation;

[0045] Establishing a target scope reservation includes setting the reservation name, setting the IP address to be bound, setting the terminal MAC address, and authorizing support for both IP-MAC types;

[0046] When a terminal sends a DHCP request, the server checks whether the MAC address is in the filter list or reserved list. If so, an IP address is assigned; otherwise, the request is discarded and a log is recorded.

[0047] In the embodiment of the present application, configuring the DHCP relay in step S2 includes enabling the DHCP relay agent function on the layer 3 switch, specifying the authorized DHCP server address, and enabling forwarding of the UDP port;

[0048] In the embodiment of the present application, configuring the SNOOPING function in step S2 includes enabling DHCP SNOOPING on the access layer switch, setting the trusted port to only allow authorized DHCP servers to respond, and blocking interference from illegal servers.

[0049] Specifically, in order to enable clients in different network segments to obtain IP addresses from the DHCP server through a three-layer switch, it is necessary to configure a DHCP relay in the network device. At the same time, in order to prevent the existence and address allocation of unauthorized DHCP servers, the DHCP SNOOPING function of the network device is configured, and the trusted port is configured to implement network collection and secure forwarding applications to ensure that office computers in each network segment can obtain compliant IP addresses from authorized DHCP servers.

[0050] DHCP relay configuration includes the following steps:

[0051] B1: Define DHCP Server;

[0052] B2: Open the UDP port for DHCP packets on the switch;

[0053] B3: Enable DHCP relay configuration on the Layer 3 interface.

[0054] DHCP service snooping configuration includes the following steps C1-C2:

[0055] C1: Enable DHCP SNOOPING on the central switch and the intervening switches;

[0056] C2: Enable DHCP SNOOPING on the trusted interface.

[0057] In the embodiment of the present application, collecting device information in combination with the SNMP service in step S2 includes starting the SNMP v2c service on the core switch, configuring the community word and the trap receiving address, obtaining the terminal IP-MAC information in real time and synchronizing it to the firewall;

[0058] Specifically, SNMP service configuration includes the following steps D1-D2:

[0059] D1: Enable SNMP on the Layer 3 core switch;

[0060] D2: SNMP information is sent to the firewall that receives SNMP.

[0061] In the embodiment of the present application, intercepting abnormal traffic in step S3 includes the firewall comparing the terminal IP-MAC information through cross-layer three detection, and discarding the data packet if it is inconsistent with the binding list; the terminal releases and re-acquires the IP through the command line.

[0062] Specifically, by configuring interfaces and security zones on the intranet firewall, connecting the Internet interface to the relevant security zone, customizing the addition of IP address groups and servers, configuring IP-MAC binding policies in the policy configuration, adding the IP and MAC addresses of the Internet that are allowed to access to the binding list, and restricting the intranet dumb terminals from accessing the Internet in the IP address policy;

[0063] Among them, dumb terminals include non-intelligent devices such as printers and cameras;

[0064] Configure SNMP active detection, configure cross-layer 3 IP-MAC binding configuration, set the host address, OID, SNMP version and community word;

[0065] The firewall algorithm compares the relevant IP address and MAC address information through the cross-layer three detection results;

[0066] The firewall policy compares the information with the binding list to see if they are consistent. If they are consistent, the terminal is allowed to access the Internet. If they are inconsistent, the relevant data packets are discarded and the terminal is denied access to the Internet.

[0067] In an optional implementation, abnormal traffic can also be intercepted through the ARP active detection mechanism. The ARP active scanning module is enabled on the firewall, and ARP request broadcast packets are periodically sent to the access layer switch. The ARP response packets returned by the switch are parsed, and the terminal IP-MAC correspondence is extracted to establish a real-time mapping table, which is then hashed and compared with the IP-MAC binding list issued by the DHCP server.

[0068] In another optional implementation, abnormal traffic can also be intercepted through the 802.1X authentication linkage mechanism. By deploying a RADIUS authentication server, TLS encrypted communication is performed with the DHCP service, 802.1X authentication is enabled on the access switch, and EAP-TLS authentication is configured. When the terminal passes the digital certificate authentication, RADIUS records the binding relationship between its MAC address and the assigned IP address. The firewall obtains the RADIUS binding data in real time through the REST API and stores it in the Redis cache.

[0069] In the embodiment of the present application, the IP-MAC binding policy in step S3 is included in the DHCP server configuration, a unique IP-MAC binding is configured for each authorized terminal in the DHCP server, and only terminals in a predefined MAC address list are allowed to obtain IP addresses;

[0070] In the switch security configuration, if an illegal MAC address is detected, a trap message will be responded to and an alarm log will be generated.

[0071] In the embodiment of the present application, the dumb terminal isolation in step S3 includes identifying non-intelligent devices through the switch or DHCP server log, creating a dumb terminal MAC address group in the firewall, and prohibiting the dumb terminal from accessing the external network.

[0072] In the embodiment of the present application, the dynamic verification mechanism in step S3 includes the firewall obtaining the IP-MAC binding table of the switch via SNMP at regular intervals;

[0073] If the terminal IP or MAC is inconsistent with the binding list, the firewall will generate a log, immediately discard the data packet of the abnormal terminal, and send an SNMP Trap to notify the administrator;

[0074] If the terminal IP is invalid or marked as abnormal, the user needs to release and re-acquire the IP through the command line. When the terminal re-initiates a DHCP request, it must pass the MAC filter and reserved address verification of the DHCP server before it can obtain a new IP.

[0075] It should also be noted that the network terminal of the internal network is configured in DHCP automatic acquisition mode. The network terminal will automatically obtain the authorized IP address from the DHCP server. If the DHCP address of the network terminal is invalid, you can go to Start-Run-CMD and enter the ipconfig / release command at the command prompt to release the DHCP IP address previously obtained by the network terminal and clear the cache, and then use the ipconfig / renew command to re-obtain the IP address that has been authorized and bound to the MAC address.

[0076] In summary, by allowing only authorized terminals to obtain IP addresses, the risk of attackers illegally accessing the network by forging MAC addresses is completely blocked; by binding IP and MAC addresses, the authenticity of the identities of both communicating parties is ensured, communication hijacking due to ARP attacks is avoided, and a zero-trust dynamic authentication system is implemented, network security defense capabilities are enhanced, and the intranet security level is improved.

[0077] By allocating unique authorized IP addresses, network interruptions caused by multi-terminal IP conflicts are avoided, ensuring business continuity. By dynamically releasing offline terminal IP addresses, address pool exhaustion is prevented, optimizing address resource utilization. Through SNMP active detection and logging, abnormal terminals can be quickly located, shortening troubleshooting time.

[0078] The DHCP relay function enables terminals in multiple network segments to uniformly obtain IP addresses from authorized DHCP servers, simplifying network architecture management. The firewall updates the binding list based on real-time SNMP data, automatically intercepting terminal traffic with IP-MAC mismatches, forming a closed-loop protection.

[0079] Example 3, reference Figure 2The above is a schematic scheme of a method for efficient and secure management and control of a campus network. It should be noted that the technical scheme of the system for efficient and secure management of a campus network is the same as the technical scheme of the method for efficient and secure management and control of a campus network. For details not described in detail in the technical scheme of the system for efficient and secure management and control of a campus network in this embodiment, please refer to the description of the technical scheme of the method for efficient and secure management and control of a campus network.

[0080] This embodiment also provides a campus network efficient and secure management and control system, including: an address binding module, an information collection module, and an abnormality interception module.

[0081] Among them, the address binding module is used to build a DHCP server, configure scopes, address pools and security policies, and realize dynamic binding of IP and MAC addresses; the information collection module is used to configure DHCP relay and SNOOPING functions on the switch, and collect device information in combination with SNMP services and synchronize it to the firewall; the abnormal interception module is used to set IP-MAC binding policies, dumb terminal isolation and dynamic verification mechanisms on the firewall, and intercept abnormal traffic by comparing the legitimacy of the terminal through cross-three-layer detection.

[0082] This embodiment also provides an electronic device suitable for efficient and secure management of campus networks, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute computer-executable instructions, thereby implementing the method for efficient and secure management of campus networks proposed in the above embodiment.

[0083] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, the method for realizing efficient and secure management and control of a campus network as proposed in the above embodiment is implemented.

[0084] The storage medium proposed in this embodiment and the method for realizing efficient and secure management and control of campus networks proposed in the above embodiment belong to the same inventive concept. For technical details not described in detail in this embodiment, please refer to the above embodiment, and this embodiment has the same beneficial effects as the above embodiment.

[0085] Through the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented with the help of software and necessary general hardware, and of course can also be implemented by hardware. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory (FLASH), hard disk or optical disk, etc., including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods of various embodiments of the present invention.

[0086] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A method for efficient and secure management and control of a campus network, characterized in that: include: Set up a DHCP server, configure scopes, address pools, and security policies, and implement dynamic binding of IP and MAC addresses; Configure DHCP relay and SNOOPING functions on the switch, and use SNMP services to collect device information and synchronize it to the firewall; Set up IP-MAC binding policies, dumb terminal isolation, and dynamic verification mechanisms on the firewall to detect and compare the legitimacy of terminals across three layers and intercept abnormal traffic.

2. The method for efficient and secure campus network management and control according to claim 1, wherein: The DHCP server setup includes deploying an operating system based on the enterprise's existing virtualized cloud platform, installing the DHCP service function, creating a scope corresponding to the intranet segment, and configuring the address pool, reserved addresses, and scope options. Add a list of allowed MAC addresses in the filter to allow only terminals in the list to obtain IP addresses; Enhance server security through host hardening and antivirus software.

3. The method for efficient and secure campus network management and control according to claim 2, wherein: The implementation of dynamic binding of IP and MAC addresses includes enabling the MAC address and IP binding function in the scope of the DHCP server and assigning a specific MAC address to a unique IP address through reserved address configuration; When a terminal accesses the network for the first time, the DHCP server matches the filter list based on the MAC address. If the match is successful, the reserved IP address is assigned; otherwise, the assignment is rejected.

4. The method for efficient and secure management and control of a campus network according to claim 3, wherein: The configuration of DHCP relay includes enabling the DHCP relay agent function on the three-layer switch, specifying the authorized DHCP server address, and opening the forwarding of the UDP port.

5. The method for efficient and secure management and control of a campus network according to claim 4, wherein: The configuration of the SNOOPING function includes enabling DHCP SNOOPING on the access layer switch, setting the trusted port to only allow authorized DHCP servers to respond, and blocking interference from illegal servers.

6. The method for efficient and secure management and control of a campus network according to claim 5, wherein: The device information collection in combination with the SNMP service includes starting the SNMP v2c service on the core switch, configuring the community word and the trap receiving address, obtaining the terminal IP-MAC information in real time and synchronizing it to the firewall.

7. The method for efficient and secure management and control of a campus network according to claim 6, wherein: The interception of abnormal traffic includes the firewall comparing the terminal IP-MAC information through cross-layer 3 detection and discarding the data packet if it is inconsistent with the binding list; The terminal releases and reacquires the IP address through the command line.

8. A campus network efficient and secure management and control system, applying the method according to any one of claims 1 to 7, characterized in that: include: Address binding module, information collection module, exception interception module; The address binding module is used to build a DHCP server, configure scopes, address pools and security policies, and implement dynamic binding of IP and MAC addresses; The information collection module is used to configure the DHCP relay and SNOOPING function on the switch, collect device information in conjunction with the SNMP service and synchronize it to the firewall; The abnormal interception module is used to set IP-MAC binding strategy, dumb terminal isolation and dynamic verification mechanism in the firewall, and intercept abnormal traffic by comparing the legitimacy of the terminal through cross-three-layer detection.

9. An electronic device comprising: memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the campus network efficient and secure management and control method described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the method for efficient and secure management and control of a campus network as described in any one of claims 1 to 7.