A method for preventing users from accessing the Internet by privately connecting a router within a local area network
By implementing packet analysis, TTL identification, UA analysis, alarm level division and Internet interception methods in the enterprise LAN, the problem of employees building routers privately to avoid real-name registration is solved, and effective monitoring of users in the LAN and network security is achieved.
Patent Information
- Application Number
- CN202210420014.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-21
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-04-21
AI Technical Summary
In the enterprise LAN, some employees avoid real-name registration of network terminal devices by building routers and sharing hotspots by privately building routers, making it difficult for network administrators to monitor and ensure network security.
Through the four modules of packet analysis and TTL recognition, UA analysis, alarm level division and Internet interception, illegal Internet access behaviors that privately build routers can be automatically detected and identified, and alarm and Internet access interception are carried out to ensure network security.
It effectively prevents users in the LAN from accessing the router privately to the Internet, ensures the network security of the enterprise LAN, and reduces the monitoring pressure of network administrators.
Smart Images

Figure CN115065971B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information network communication, and specifically refers to a method for preventing users from accessing the Internet through a privately connected router within a local area network. Background Art
[0002] With the popularization of mobile intelligent terminals, in addition to office computers, many enterprise local area networks also connect various mobile intelligent terminals, such as: Pad, notebook, mobile phone, etc. To ensure the network security of enterprises, network administrators require real-name registration of all connected terminal devices. However, there are still a small number of employees who evade the real-name registration of network access terminal devices by privately building a router to share a hotspot. In summary, the phenomenon of evading real-name registration and illegally accessing the enterprise network has brought troubles to network administrators. Therefore, the present invention realizes a method for preventing users from accessing the Internet through a privately connected router within a local area network, which supports automatic detection of the illegal behavior of privately building a router to access the Internet, warning, and Internet access interception, so as to ensure the network security of the enterprise local area network. Summary of the Invention
[0003] The present invention aims to solve the above technical problems and provides a method for preventing users from accessing the Internet through a privately connected router within a local area network.
[0004] To solve the above technical problems, the technical solution provided by the present invention is as follows:
[0005] A method for preventing users from accessing the Internet through a privately connected router within a local area network includes packet parsing and TTL identification, UA parsing, warning level classification, and Internet access interception. The method for preventing users from accessing the Internet through a privately connected router within a local area network is as follows:
[0006] S1. Initialize and create caches. The initialization and creation of caches sequentially include an alarm cache list, a user information cache list, and a UA cache list;
[0007] S2. Packet parsing and TTL identification: Continuously capture the traffic of local area network users accessing the Internet, perform packet capture and parsing, and extract the source MAC address, source IP address, and TTL value in the packet for identification;
[0008] S3. Identify whether the TTL is normal. If it is normal, enter UA parsing; if it is abnormal, store it in the alarm cache list;
[0009] S4. UA parsing: Parse the "UA information" in the traffic, first retrieve it in the UA cache list. If there is no "UA information" in the cache, then call the regular library to parse the "operating system name and version" and "APP name and version" in the "UA information", and save the parsed results to the UA cache list;
[0010] S5. Identify whether the "operating system name and version" and "APP name and version" in the user information cache list are the same. If they are different, store them separately in the operating system name and version anomaly in the alarm cache list and the APP name and version anomaly in the alarm cache list.
[0011] S6. Alarm level classification: The alarm level classification is defined according to the number of anomaly categories, and the alarm level is from 1 to 3.
[0012] S7. For LAN users with packet parsing, TTL identification, and UA parsing in Internet access interception, distinguish according to the alarm level. Intercept at level 3, and call back to step S2 for levels 0 - 2.
[0013] After adopting the above structure, the present invention has the following advantages: The method of the present invention mainly includes: packet parsing and TTL identification, UA parsing, alarm level classification, and Internet access interception. Through the cooperation of the four modules, the purpose of preventing users within the LAN from privately accessing the router to access the Internet is achieved.
[0014] As an improvement, the alarm cache list includes: source IP, source MAC, alarm status, TTL alarm, operating system name and version alarm, APP name and version alarm.
[0015] As an improvement, the user information cache list includes: source IP address, source MAC address, packet timestamp, TTL value, operating system name and version, APP name and version.
[0016] As an improvement, the UA cache list includes: source MAC address, source IP address, UA information, operating system name and version, APP name and version.
[0017] As an improvement, the interception in step S7 is divided into "TCP packet interception" and "UDP packet interception". BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 is a flowchart of a method for preventing users within a LAN from privately connecting to a router to access the Internet according to the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0019] The following further describes the present invention in detail with reference to the accompanying drawings.
[0020] Combined with the attached Figure 1 , a method for preventing users within a LAN from privately connecting to a router to access the Internet, including packet parsing and TTL identification, UA parsing, alarm level classification, and Internet access interception. The method for preventing users within a LAN from privately connecting to a router to access the Internet is as follows:
[0021] S1. Initialize and create caches. The initialized caches include an alarm cache list, a user information cache list, and a UA cache list in sequence.
[0022] S2. Packet parsing and TTL identification: Continuously capture the traffic of LAN users accessing the Internet, perform packet capture and parsing, extract the source MAC address, source IP address, and TTL value in the packet and identify them.
[0023] S3. Identify whether the TTL is normal. If normal, enter UA parsing; if abnormal, store it in the alarm cache list.
[0024] S4. UA parsing: Parse the "UA information" in the traffic, first retrieve it in the UA cache list. If there is no "UA information" in the cache, then call the regular expression library to parse the "operating system name and version" and "APP name and version" in the "UA information", and save the parsed results to the UA cache list.
[0025] S5. Identify whether the "operating system name and version" and "APP name and version" in the user information cache list are the same. If different, store them in the operating system name and version anomaly in the alarm cache list and the APP name and version anomaly in the alarm cache list respectively.
[0026] S6. Alarm level classification: The alarm level classification is defined according to the number of abnormal categories, and the alarm level is from 1 to 3.
[0027] S7. Internet access interception differentiates LAN users for packet parsing and TTL identification and UA parsing according to the alarm level. Intercept for level 3, and call back to step S2 for levels 0 - 2.
[0028] The alarm cache list includes: source IP, source MAC, alarm status, TTL alarm, operating system name and version alarm, APP name and version alarm.
[0029] The user information cache list includes: source IP address, source MAC address, packet timestamp, TTL value, operating system name and version, APP name and version.
[0030] The UA cache list includes: source MAC address, source IP address, UA information, operating system name and version, APP name and version.
[0031] The interception in step S7 is divided into "TCP packet interception" and "UDP packet interception".
[0032] Packet parsing and TTL identification:
[0033] 1) Perform packet capture and parsing on the traffic of LAN users accessing the Internet, and extract the source MAC address, source IP address, and TTL value in the packet.
[0034] 2) Create a user information cache list indexed by the user's "source Mac address", with fields including "source IP address", "source MAC address", "message timestamp", "TTL value", "operating system name and version", "APP name and version".
[0035] 3) Identify the TTL value, save it in the user information cache, and identify whether the TTL is normal (usually the default TTL for mobile phones and Linux operating systems is 64, and the TTL for different versions of Windows may be 128, 64, 32. Under standard circumstances, the TTL value will decrease by 1 for each router passed). If the TTL is abnormal, record "TTL abnormal" in the alarm cache list.
[0036] UA parsing:
[0037] 1) Analyze the HTTP protocol in the data packet and extract the user-agent field parameter (abbreviation: UA) in the HTTP protocol.
[0038] 2) Create a UA cache list with "UA information" as the index of the UA cache list, and save "source MAC address", "source IP address", "UA information", "operating system name and version", "APP name and version".
[0039] 3) The "UA information" extracted from the HTTP packet is preferentially retrieved in the UA cache list. If the "UA information" is not in the cache, call the regular library to parse the "operating system name and version" and "APP name and version" in the "UA information", and save the parsed results to the UA cache list.
[0040] 4) Take the user's "source MAC address" as the index, extract the "operating system name and version" and "APP name and version" fields in the user information cache list and compare them with the corresponding fields after parsing the "UA information" respectively. If the operating system name and version are different, record "operating system name and version abnormal" in the alarm cache list; if the APP name and version are different, record "APP name and version abnormal" in the alarm cache list.
[0041] Alarm level classification:
[0042] 1) Create an alarm cache list indexed by the user's "source MAC address", with fields including "source IP address", "source MAC address", "alarm status", "TTL alarm", "terminal type (operating system) and version alarm", "APP name and version alarm".
[0043] 2) Identify the number of occurrences where "TTL anomaly", "operating system name and version anomaly", and "APP name and version anomaly" coexist for the same user (indexed by MAC address) in the alarm cache list;
[0044] 3) There is one type of first-level alarm, two types coexisting as second-level alarms, and three types coexisting as third-level alarms (the higher the alarm level, the higher the probability of a user privately connecting to a router).
[0045] Internet access interception:
[0046] 1) Intercept the traffic of users with third-level alarms accessing the Internet. The interception methods can be divided into "TCP packet interception" and "UDP packet interception".
[0047] 2) "TCP packet interception" is to act as a man-in-the-middle attack in the local area network during the three-way handshake of a new TCP connection between two communication parties. Prior to the response speed of the real server, forge the SYN ACK response packet of the server, deceive the client into replying with a packet that the real server cannot recognize, resulting in the failure of establishing a connection through the TCP three-way handshake.
[0048] 3) "UDP packet interception" is to capture the UDP protocol packets of two communication parties and forge abnormal data fragments at the specified positions in the packets, and give a direct reply, thereby causing the application program to have abnormal parsing, so as to achieve the interception of this service based on UDP packet communication.
[0049] In summary, based on the orderly cooperation of the four modules of "packet parsing and TTL identification, UA parsing, alarm level division, and Internet access interception", the goal of intercepting users in the local area network from privately accessing the Internet through a router is achieved, ensuring the network security of the enterprise local area network.
[0050] The above describes the present invention and its implementation manners. This description is not restrictive. What is shown in the drawings is only one of the implementation manners of the present invention, and the actual structure is not limited thereto. Generally speaking, if those of ordinary skill in the art are inspired by it and design similar structural manners and embodiments without creative efforts without departing from the spirit of the present invention, they shall fall within the protection scope of the present invention.
Claims
1. A method for preventing users from accessing the Internet by privately connecting a router within a local area network, characterized in that, It includes packet parsing and TTL identification, UA parsing, alarm level classification, and Internet access interception. The method for preventing users in a local area network from accessing the Internet through unauthorized routers is as follows: S1. Initialize and create caches. The initialization and creation of caches sequentially include an alarm cache list, a user information cache list, and a UA cache list; S2. Packet parsing and TTL identification: Continuously capture the traffic of local area network users accessing the Internet, perform packet capture and parsing, and extract and identify the source MAC address, source IP address, and TTL value in the packet; S3. Identify whether the TTL is normal. If it is normal, proceed to UA parsing; if it is abnormal, store it in the alarm cache list; S4. UA parsing: Parse the "UA information" in the traffic. First, search in the UA cache list. If the "UA information" is not in the cache, call the regular expression library to parse the "operating system name and version" and "APP name and version" in the "UA information", and save the parsed results to the UA cache list; S5. Identify whether the "operating system name and version" and "APP name and version" in the user information cache list are the same. If they are different, store them in the operating system name and version anomaly in the alarm cache list and the APP name and version anomaly in the alarm cache list respectively; S6. Alarm level classification: The alarm level classification is defined according to the number of abnormal categories, and the alarm levels are 1-3; S7. Internet access interception differentiates local area network users for packet parsing and TTL identification and UA parsing according to the alarm level. Intercept for level 3, and callback to step S2 for levels 0-2.
2. The method for preventing users from accessing the Internet through a privately connected router within a local area network according to claim 1, characterized in that: The alarm cache list includes: source IP, source MAC, alarm status, TTL alarm, operating system name and version alarm, APP name and version alarm.
3. A method for preventing users from accessing the Internet by privately connecting a router within a local area network according to claim 1, characterized in that: The user information cache list includes: source IP address, source MAC address, packet timestamp, TTL value, operating system name and version, APP name and version.
4. A method for preventing users from accessing the Internet through a privately connected router within a local area network, characterized in that: The UA cache list includes: source MAC address, source IP address, UA information, operating system name and version, APP name and version.
5. A method for preventing users from accessing the Internet by privately connecting a router within a local area network according to claim 1, characterized in that: The interception in step S7 is divided into "TCP packet interception" and "UDP packet interception".
Citation Information
Patent Citations
Local area network equipment type identification method
CN110336896A
Method for accessing mobile core network through fixed access equipment
CN112135293A