Network Access Control Method and System Based on Automatic Discovery and Linkage of Switching Devices

Through the network access control method that automatically discovers and switches, combined with terminal network fingerprint analysis and network topology analysis, the problem of lack of multi-dimensional traffic legitimacy verification in the existing technology is solved, and more efficient and accurate network access control is achieved.

CN115550020BActive Publication Date: 2025-06-13中孚安全技术有限公司 +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211170685.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-23
Publication Date
2025-06-13
Estimated Expiration
2042-09-23

AI Technical Summary

Technical Problem

The existing network access control technology lacks traffic legitimacy verification based on multi-dimensional information such as network fingerprints, which poses security risks and is difficult to effectively deal with the diversity and unknown risks of terminal access.

Method used

The network access control method based on the linkage of automatic discovery and switching devices is adopted, and through terminal network fingerprint analysis, graph database comparison, network topology analysis and other technologies, the linkage between device discovery and switch is realized, and multi-dimensional traffic legitimacy verification is carried out.

Benefits of technology

It improves the adaptability and accuracy of network access control to different scenarios, enhances the detection and blocking capabilities of illegal access devices, and reduces security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115550020B_ABST
    Figure CN115550020B_ABST
Patent Text Reader

Abstract

The present disclosure provides a network access control method and system for automatic discovery and linkage of devices, which belongs to the technical field of network access control. The solution realizes the device discovery and switch linkage mechanism by adopting traffic legality verification based on more dimensional information such as network fingerprints, and at the same time, based on the terminal active detection technology and network topology analysis, effectively improving the adaptability and accuracy of network access control to different scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure belongs to the technical field of network access control, and particularly relates to a network access control method and system based on the linkage of automatic discovery and switching devices. Background Art

[0002] The statements in this part only provide background technical information related to the present disclosure and do not necessarily constitute prior art.

[0003] With the continuous deepening and development of informatization construction, information security is also facing increasingly severe tests. External risks are constantly increasing, network attack incidents occur frequently, and network security technologies are gradually maturing. And the terminal network access control technology has currently become an important part of network security technology. On the one hand, it ensures the smooth network access of compliant users, and on the other hand, it eliminates the potential security hazards that may be brought by illegal user access.

[0004] The inventors found that currently, mainstream network access control products basically adopt technologies such as policy routing, mirroring, MVG, 802.1X, DHCP, ARP, and transparent bridges. Most of them use hardware parameters such as IP, MAC, hard disk serial number, and CPU serial number as the identification device identifier, and then achieve the purpose of accessing network resources through processes such as device registration, identity authentication, and security inspection. At the present stage, security tool software is developing rapidly, and hardware information such as IP and MAC is extremely easy to be tampered with and counterfeited. Especially for the network control method based on IP in policy routing, there is a lack of traffic legality verification based on more dimensions such as network fingerprints, which poses great security risks.

[0005] At the same time, under the new situation, terminal access faces unprecedented challenges, with diverse access situations, diverse access devices, more and more BYON, and increasing unknown risks. The typical pain points of terminal access are what devices are accessed, where these devices are, who is using these devices, what resources the devices have accessed, and the security of the devices. Currently, these mainstream technologies can only solve the terminal access problems of some known assets. However, due to "illegal" operations such as privately connecting routers, hubs, and Wi-Fi, the expansion of the network boundary introduces uncertainties, and traditional control technologies are already stretched to solve these pain point problems. Summary of the Invention

[0006] In order to solve the above problems, the present disclosure provides a network access control method and system based on the linkage of automatic discovery and switching devices. By adopting traffic legality verification based on more dimension information such as network fingerprints, and at the same time, based on the terminal active detection technology and network topology analysis method, the device discovery and switch linkage mechanism is realized, effectively improving the adaptability and accuracy of network access control for different scenarios.

[0007] According to the first aspect of the embodiments of the present disclosure, a network access control method based on the linkage of automatic discovery and switching devices is provided, including:

[0008] Forward the traffic accessed by the terminals connected to the switch to the access server through the switch;

[0009] The access server forwards or discards the data packets by matching the preset network control policy to implement network access control;

[0010] Among them, the preset network control policy is specifically as follows: for the traffic reported by the terminal to the access server, the terminal network fingerprint analysis method is used for analysis to obtain the unique identifier of the current terminal; based on the obtained unique identifier of the terminal, compare it with the data in the pre-constructed graph database. If the comparison fails, prohibit the current terminal from accessing the network and generate an alarm; at the same time, obtain the VLAN subnet information of the current network through the IP address table and routing table of the default gateway, and match the VLAN subnet information of all devices through the IP and subnet mask; based on the correspondence between the IP and the VLAN subnet, construct the relationship between the switch and each terminal in the current network; based on the relationship between the switch and the terminal, analyze the current network topology structure. When multiple devices appear under a switch port, it is determined as an illegally accessed device and its network access is blocked.

[0011] Further, the terminal network fingerprint analysis method is specifically as follows: collect terminal information based on the traffic uploaded by the terminal to the access server, and construct a terminal relationship network based on the collected terminal information; perform marking processing on the terminal relationship network based on the network fingerprint marks marked in the traffic, and use asset discovery scanning and ports as auxiliary conditions to realize the construction of the terminal relationship map; based on the terminal relationship map, determine the unique identifier of the terminal through grid clustering.

[0012] Further, the terminal relationship network uses the MAC address as the user identification node and the relationship between the IP and the hard disk serial number as the edge.

[0013] Further, the terminal information of the terminals registered in the current network is persisted in the graph database, including IP, MAC, operating system, open ports, services and versions, browser information, device names, and workgroups.

[0014] Further, the network fingerprint identifier is a unique identifier generated by the access server according to the terminal information uploaded by the terminal through an encryption algorithm when the terminal registers in the access server. At the same time, the network fingerprint identifier is marked in each traffic request header.

[0015] According to the second aspect of the embodiments of the present disclosure, a network access control system based on the linkage of automatic discovery and switching devices is provided, including:

[0016] A data acquisition unit, which is used to forward the traffic accessed by the terminals connected to the switch to the access server through the switch;

[0017] A network access control unit, which is used for the access server to forward or discard data packets by matching preset network control policies, so as to achieve network access control;

[0018] Wherein, the preset network control policy is specifically: for the traffic reported by the terminal to the access server, the terminal network fingerprint analysis method is used for analysis to obtain the unique identifier of the current terminal; based on the obtained unique identifier of the terminal and the data in the pre-constructed graph database for comparison, if the comparison fails, the current terminal network access is prohibited and an alarm is generated; at the same time, the VLAN subnet information of the current network is obtained through the IP address table and routing table of the default gateway, and the VLAN subnet information of all devices is matched through the IP and subnet mask; based on the correspondence between the IP and the VLAN subnet, the relationship between the switch and each terminal in the current network is constructed; based on the relationship between the switch and the terminal, the analysis of the current network topology structure is realized. When multiple devices appear under a switch port, it is determined as an illegal access device and its network access is blocked.

[0019] According to the third aspect of the embodiments of the present disclosure, an electronic device is provided, including a memory, a processor, and a computer program running on the memory. When the processor executes the program, the network access control method based on automatic discovery and switch device linkage is implemented.

[0020] According to the fourth aspect of the embodiments of the present disclosure, a non-transitory computer-readable storage medium is provided, on which a computer program is stored. When the program is executed by a processor, the network access control method based on automatic discovery and switch device linkage is implemented.

[0021] Compared with the prior art, the beneficial effects of the present disclosure are:

[0022] The present disclosure provides a network access control method and system based on automatic discovery and switch device linkage. The solution realizes the device discovery and switch linkage mechanism by adopting traffic legality verification based on more dimensional information such as network fingerprints, and at the same time, based on the terminal active detection technology and network topology analysis method, effectively improves the adaptability and accuracy of network access control for different scenarios.

[0023] The advantages of the additional aspects of the present disclosure will be partially given in the following description, partially become obvious from the following description, or be understood through the practice of the present disclosure. Description of the Drawings

[0024] The accompanying drawings forming a part of this disclosure are used to provide a further understanding of the disclosure. The schematic embodiments and descriptions thereof of the disclosure are used to explain the disclosure and do not unduly limit the disclosure.

[0025] Figure 1 It is a schematic diagram of network access control in the existing method described in the embodiments of this disclosure;

[0026] Figure 2 It is a schematic diagram of the processing flow of the network access control method based on automatic discovery and switch device linkage described in the embodiments of this disclosure;

[0027] Figure 3 It is a schematic diagram of the processing flow of the network traffic detection and analysis module described in the embodiments of this disclosure;

[0028] Figure 4 It is a schematic diagram of the processing flow of the terminal automatic detection and analysis module described in the embodiments of this disclosure;

[0029] Figure 5 It is a schematic diagram of the processing flow of the switch linkage device discovery module described in the embodiments of this disclosure. Detailed implementation manners

[0030] The following further describes the present disclosure in conjunction with the accompanying drawings and embodiments.

[0031] It should be noted that the following detailed descriptions are all illustrative and are intended to provide further explanations of the present disclosure. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present disclosure belongs.

[0032] It should be noted that the terms used herein are only for describing specific implementation manners and are not intended to limit the exemplary embodiments according to the present disclosure. As used herein, unless the context clearly indicates otherwise, the singular forms are also intended to include the plural forms. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0033] Without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other.

[0034] Embodiment 1:

[0035] The purpose of this embodiment is to provide a network access control method based on automatic discovery and switch device linkage.

[0036] A network access control method based on automatic discovery and switch device linkage includes:

[0037] Forward the traffic accessed by the terminals connected to the switch through the switch to the access server;

[0038] The access server forwards or discards the data packets by matching the preset network control policy to achieve network access control;

[0039] Among them, the preset network control policy is specifically as follows: for the traffic reported by the terminal to the access server, the terminal network fingerprint analysis method is used for analysis to obtain the unique identifier of the current terminal; based on the obtained unique identifier of the terminal and the data in the pre-constructed graph database for comparison, if the comparison fails, the current terminal network access is prohibited and an alarm is generated; at the same time, obtain the VLAN subnet information of the current network through the IP address table and routing table of the default gateway, and match the VLAN subnet information of all devices through the IP and subnet mask; based on the correspondence between the IP and the VLAN subnet, construct the relationship between the switch and each terminal in the current network; based on the relationship between the switch and the terminal, analyze the current network topology structure, and when multiple devices appear under a switch port, it is determined as an illegal access device and its network access is blocked.

[0040] Further, the terminal network fingerprint analysis method is specifically as follows: collect terminal information based on the traffic uploaded by the terminal to the access server, and construct a terminal relationship network based on the collected terminal information; mark the terminal relationship network based on the network fingerprint marks marked in the traffic, and use asset discovery scanning (that is, discover assets in the network: including but not limited to PCs, printers, and IP phones) and ports as auxiliary conditions to realize the construction of the terminal relationship map; based on the terminal relationship map, determine the unique identifier of the terminal through grid clustering.

[0041] Further, the terminal relationship network uses the MAC address as the user identification node and the relationship between the IP and the hard disk serial number as the edge.

[0042] Further, the terminal information of the registered terminals in the current network is persisted in the graph database, including IP, MAC, operating system, open ports, services and versions, browser information, device name, and workgroup.

[0043] Further, the network fingerprint identifier is a unique identifier generated by the access server according to the terminal information uploaded by the terminal through an encryption algorithm when the terminal registers in the access server. At the same time, the network fingerprint identifier is marked in each traffic request header.

[0044] Further, the terminal information includes but not limited to device IP, MAC address, operating system, open ports, services and versions, browser information, device name, and workgroup.

[0045] Specifically, for the sake of easy understanding, the solution of this embodiment will be described in detail with reference to the accompanying drawings as follows:

[0046] In the existing network access control method, a firewall is usually used to isolate the Internet and the internal network. For example Figure 1 The core switch 1 is connected to the resource server and the access server. At the same time, switches 1 and 2 are connected under the core switch 1 to complete network port expansion. Terminals 1, 2, and 3 are respectively connected to switches 1 and 2. Usually, the core switch 1 forwards the access traffic of the terminal to the access server by setting access control policies such as dot1x, policy routing, and port mirroring. The access server matches the network control policy to forward or discard the data packet, thereby achieving the access control effect.

[0047] Regarding the problems existing in the prior art, such as Figure 2 As shown, this embodiment provides a network access control method based on automatic discovery and linkage of switching devices, including: forwarding the traffic accessed by the terminals connected to the switch to the access server through the switch; the access server forwards or discards the data packet by matching the preset network control policy to achieve network access control; wherein, the preset network control policy specifically includes the following parts:

[0048] (1) Network traffic detection and analysis module

[0049] In this module, a new terminal network fingerprint analysis method is provided. The NetFlow and other protocols are used to collect network traffic, and the collected traffic is analyzed by this method. As Figure 3 shown, the terminal network fingerprint analysis method is specifically as follows: collecting terminal information and constructing a terminal relationship network, where the terminal relationship network uses the MAC address as the user identification node and the IP and hard disk serial number relationships as the edges; using network fingerprints to perform screening and marking processing on the terminal relationship network; using asset discovery scanning and ports as auxiliary conditions to construct a terminal relationship map; finally, through grid clustering processing, the space is quantified into a limited number of units to form a grid structure. All clustering is performed on the grid, and each object falls into a grid cell. The attribute space corresponding to the grid cell contains the values of the object. Its main advantage is fast processing speed, independent of the number of data objects, and only depends on the number of units in each dimension of the quantified space, thereby quickly determining the unique terminal identifier HOSTID.

[0050] (2) Terminal automatic detection and analysis module

[0051] Usually, most of the traffic-based analysis methods only perform data packet analysis on the local network card traffic, ignoring the relationships between other network entities. Such as Figure 4As shown, the terminal automatic detection and analysis module described in this embodiment puts the analyzed traffic, such as IP, MAC, operating system, open port, service and version, browser information, device name and workgroup, into the graph database (the relationship between data in the graph database is as important as the data). On the user terminal, the client software actively captures the data packet for analysis, captures the device that communicates with the terminal network card, and determines through TCP communication detection that once the connection is established, it will report to the access server and persist in the graph database to provide data support for device identification; the traffic uploaded to the access server is analyzed and compared using the analysis method in the network traffic detection and analysis module, and the comparison results are sent to the client; at the same time, the client software automatically discards and isolates requests from unauthorized terminals, thereby achieving a network blocking effect.

[0052] (III) Linking the device discovery module with the switch

[0053] This module uses the SNMP protocol to analyze the network topology. This analysis method mainly uses the SNMP protocol to access the MIB library in network devices such as switches and routers to obtain relevant information. First, the device is mined through the SNMP three-layer forwarding table of the gateway device, and then supplemented through the local ARP protocol device mining, and finally the device is confirmed to be turned on through ICMP and port scanning. At the same time, according to the private OID of the device, the private MIB file of the device is parsed, the private attributes of the device are obtained, and the general OID is supplemented to obtain information. Then, NMAP is used to perform device fingerprint analysis, establish a device fingerprint library, and more accurately identify device types, models and other information to form a complete device asset library. Provide important data support for equipment legitimacy verification. Specifically, such as Figure 5 As shown, the main steps of this module are as follows:

[0054] Step 1: Obtain the VLAN (subnet) information of the network through the IP address table and routing table of the default gateway;

[0055] Wherein, the step 1 is specifically as follows: for the VLAN set G(V i )={V 1 ,V 2 ,V 3 ,....V i}, where V i Represents a VLAN of a switch; according to the input switch information, aggregate all switch VLANs into a matrix U(v i )=[G v1 ,G v2 ,G v3 ,G vn ];

[0056] Step 2: Obtain the IP information of all devices in the network through the three-layer forwarding table (IP-MAC correspondence table / ARP table), and match the VLAN information of all devices through the IP and subnet mask;

[0057] Among them, the specific content of the said Step 2 is: For the MAC-IP set Among them, represents a MAC-IP correspondence relationship of the switch, and then obtain the set of VLAN information of all devices by matching the IP with the mask:

[0058]

[0059] Step 3: Obtain the information of the subordinate switches and terminals through the secondary forwarding table information of the default gateway. Through the obtained information of the subordinate devices, analyze the superior-subordinate relationship between switches, analyze the list of terminals under the switches, and finally obtain the connection with the gateway device;

[0060] Among them, the specific content of the said Step 3 is: Obtain the information of the subordinate switches and terminals through the secondary forwarding table information of the default gateway to obtain the set Among them, represents the set of all device relationships under the switch, represents S 1 The devices under the switch port. When multiple devices appear under one port, it is recognized as an illegally accessed hub device and thus blocked.

[0061] Step 4: Persist all node information into the database for monitoring and processing.

[0062] Furthermore, the solution described in this embodiment is composed of a management server (i.e., the access server) and terminal software (whose function includes uploading terminal information) during the specific implementation process, and monitors the entire link from terminal registration to identity authentication, security policy check, and terminal network access. When the terminal registers, the terminal software reports the terminal information, forms a unique network fingerprint identifier through an encryption algorithm, and marks this network identifier in each traffic request header. The access server processes it according to traffic analysis combined with control policies.

[0063] Furthermore, in order to prove the feasibility of the solution described in this embodiment, the effects of the solution described in this embodiment are described from different scenario perspectives as follows:

[0064] (1) For IP address spoofing scenarios: Assume that there are two terminals, A and B, where A has passed the security check process and has access to network resources. B is a private terminal and has not installed the patented client software. When B uses A's IP address to access the network, B will fail the verification because the traffic message it carries does not contain the network fingerprint identifier, and will be redirected or discarded by the access server in the solution described in this embodiment, and an alarm will be generated to notify the network administrator.

[0065] (2) For the scenario of accessing a personal computer through a hub or a dumb router: Assume that user A works in the intranet and connects his external network notebook to the internal network through a hub or other means for the convenience of his work. Since A only uses a personal computer to configure the LAN to transmit data, other security software cannot detect it accurately. The solution described in this embodiment is to detect multiple MAC addresses under a switch port at the same time based on the SNMP network topology service, and if they are inconsistent with the network fingerprint data and the registered device of A, an alarm mechanism will be triggered, and the Figure 4 The strategy is linked with the switch to block the network port; on the other hand, through the active detection technology of the client software of the solution described in this embodiment, the private computer connected to it is accurately identified, and the asset information such as the network fingerprint of the private computer is collected by scanning means such as NMAP, and reported to the access server or compared with the local cache fingerprint library, and the strategy issued by the patent system is used to perform alarms, interrupt communications, block network cards, shut down, etc.

[0066] Embodiment 2:

[0067] The purpose of this embodiment is to provide a network access control system based on automatic discovery and switching device linkage.

[0068] A network access control system based on automatic discovery and switching device linkage, comprising:

[0069] A data acquisition unit, configured to forward traffic accessed by a terminal connected to the switch to an admission server via the switch;

[0070] The network access control unit is used to forward or discard data packets by matching the preset network control strategy to the access server, thereby realizing network access control;

[0071] Among them, the specific preset network control strategy is as follows: for the traffic reported by the terminal to the access server, the terminal network fingerprint analysis method is used for analysis to obtain the unique identifier of the current terminal; based on the obtained unique identifier of the terminal, it is compared with the data in the pre-constructed graph database. If the comparison fails, the current terminal network access is prohibited and an alarm is generated; at the same time, the VLAN subnet information under the current network is obtained through the IP address table and routing table of the default gateway, and the VLAN subnet information of all devices is matched through the IP and subnet mask; based on the correspondence between the IP and the VLAN subnet, the relationship between the switch and each terminal in the current network is constructed; based on the relationship between the switch and the terminal, the analysis of the current network topology structure is realized. When multiple devices appear under a switch port, it is determined as an illegally accessed device and its network access is blocked.

[0072] Further, the system in this embodiment corresponds to the method in Embodiment 1, and its technical details have been described in detail in Embodiment 1, so they will not be elaborated here.

[0073] In more embodiments, there is also provided:

[0074] An electronic device includes a memory, a processor, and computer instructions stored on the memory and running on the processor. When the computer instructions are run by the processor, the method described in Embodiment 1 is completed. For the sake of brevity, it will not be elaborated here.

[0075] It should be understood that in this embodiment, the processor may be a central processing unit CPU, and the processor may also be other general-purpose processors, digital signal processors DSP, application-specific integrated circuits ASIC, off-the-shelf programmable gate arrays FPGA or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0076] The memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. A part of the memory may also include a non-volatile random access memory. For example, the memory may also store information about the device type.

[0077] A computer-readable storage medium is used to store computer instructions. When the computer instructions are executed by the processor, the method described in Embodiment 1 is completed.

[0078] The method in the first embodiment can be directly implemented by a hardware processor, or by a combination of hardware and software modules in the processor. The software module can be located in a mature storage medium in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.

[0079] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with this embodiment can be implemented by electronic hardware or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this disclosure.

[0080] The above-mentioned network access control method and system based on automatic discovery and device linkage of an exchange device can be realized and have broad application prospects.

[0081] The above are only the preferred embodiments of this disclosure and are not used to limit this disclosure. For those skilled in the art, various changes and modifications can be made to this disclosure. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this disclosure shall be included within the protection scope of this disclosure.

Claims

1. A network access control method based on the linkage of automatic discovery and switching devices, characterized in that, it includes: Forwarding the traffic accessed by the terminals connected to the switch to the access server through the switch; the access server forwards or discards the data packets by matching the preset network control policy to achieve network access control; wherein, the preset network control policy is specifically: for the traffic reported by the terminal to the access server, analyze it by using the terminal network fingerprint analysis method to obtain the unique identifier of the current terminal; based on the obtained unique identifier of the terminal, compare it with the data in the pre-constructed graph database, if the comparison fails, prohibit the current terminal from accessing the network and generate an alarm; at the same time, obtain the VLAN subnet information of the current network through the IP address table and routing table of the default gateway, and match the VLAN subnet information of all devices through the IP and subnet mask; based on the correspondence between the IP and the VLAN subnet, construct the relationship between the switch and each terminal in the current network; based on the relationship between the switch and the terminal, analyze the current network topology structure, and determine an illegally accessed device when multiple devices appear under a switch port, and block its network access; according to the SNMP network topology service, when it is detected that multiple MAC addresses are detected under a switch network port at the same time and are inconsistent with the original registered devices compared with the network fingerprint data, the alarm mechanism will be triggered, and the switch will be linked to block the network port; Using the NMAP scanning method, collect the network fingerprint asset information of private computers, report it to the access server or compare it according to the local cached fingerprint library, and perform alarm, communication interruption, network card blocking, and shutdown operations according to the issued policy; The preset network access control policy specifically includes the following parts: a network traffic detection and analysis module that uses the NetFlow protocol to collect network traffic and analyzes the collected traffic using the terminal network fingerprint analysis method. The terminal network fingerprint analysis method is specifically as follows: collect terminal information based on the traffic uploaded by the terminal to the access server, construct a terminal relationship network based on the collected terminal information. The terminal information includes but is not limited to device IP, MAC address, operating system, open ports, services and versions, browser information, device name, and workgroup; mark the terminal relationship network based on the network fingerprint marks in the traffic, and use asset discovery scanning and ports as auxiliary conditions to construct a terminal relationship map; based on the terminal relationship map, determine the unique identifier of the terminal through grid clustering; the network fingerprint identifier is a unique identifier generated by the access server through an encryption algorithm according to the terminal information uploaded by the terminal when the terminal registers in the access server. At the same time, the network fingerprint identifier is marked in each traffic request header; a terminal automatic detection and analysis module that actively grabs and analyzes data packets through client software on the user terminal, grabs the devices communicating with this terminal network card, and reports to the access server once a connection is established through TCP communication detection and persists it into the graph database. Analyze and compare the traffic uploaded to the access server using the terminal network fingerprint analysis method, and send the comparison result to the client; a device discovery module linked with the switch that analyzes the network topology structure using the SNMP protocol.

2. The network access control method based on automatic discovery and switch device linkage according to claim 1, characterized in that, the terminal relationship network uses the MAC address as the user identification node and the IP and hard disk serial number relationship as the edge.

3. The network access control method based on automatic discovery and switch device linkage according to claim 1, characterized in that, the terminal information of the terminals registered in the current network is persisted in the graph database, including IP, MAC, operating system, open ports, services and versions, browser information, device name, and workgroup.

4. A network access control system based on automatic discovery and switch device linkage, characterized in that, comprises: a data acquisition unit for forwarding the traffic accessed by the terminals connected to the switch to the access server through the switch; a network access control unit for the access server to forward or discard data packets by matching the preset network access control policy to achieve network access control; Among them, the specific preset network control strategy is as follows: For the traffic reported by the terminal to the access server, the terminal network fingerprint analysis method is used for analysis to obtain the unique identifier of the current terminal; based on the obtained unique identifier of the terminal, it is compared with the data in the pre-constructed graph database. If the comparison fails, the current terminal network access is prohibited and an alarm is generated; at the same time, the VLAN subnet information under the current network is obtained through the IP address table and routing table of the default gateway, and the VLAN subnet information of all devices is matched through the IP and subnet mask; based on the correspondence between the IP and the VLAN subnet, the relationship between the switch and each terminal in the current network is constructed; based on the relationship between the switch and the terminal, the analysis of the current network topology structure is realized. When multiple devices appear under a switch port, it is determined as an illegally accessed device and its network access is blocked; according to the SNMP network topology service, when multiple MAC addresses are detected under a switch network port at the same time and are inconsistent with the original registered devices compared with the network fingerprint data, the alarm mechanism will be triggered, and the switch will be linked to block this network port; Using the NMAP scanning method, collect the network fingerprint asset information of the private computer, report it to the access server or compare it according to the local cached fingerprint library, and perform alarm, interrupt communication, block the network card, and shut down operations according to the policies issued by this system; The specific preset network control strategy includes the following parts: Network traffic detection and analysis module, which uses the NetFlow protocol to collect network traffic, and uses the terminal network fingerprint analysis method to analyze the collected traffic. The terminal network fingerprint analysis method is specifically as follows: Based on the traffic uploaded by the terminal to the access server, terminal information is collected, and a terminal relationship network is constructed based on the collected terminal information. The terminal information includes but is not limited to device IP, MAC address, operating system, open ports, services and versions, browser information, device name, and workgroup; based on the network fingerprint marks marked in the traffic, the terminal relationship network is marked, and asset discovery scanning and ports are used as auxiliary conditions to realize the construction of the terminal relationship map; the network fingerprint identifier is a unique identifier generated by the access server through an encryption algorithm according to the terminal information uploaded by the terminal when the terminal registers in the access server. At the same time, the network fingerprint identifier is marked in each traffic request header; based on the terminal relationship map, the unique identifier of the terminal is determined through grid clustering; Terminal automatic detection and analysis module, actively capture and analyze data packets on the user terminal through the client software, capture the devices communicating with this terminal network card, and report to the access server once a connection is established through TCP communication detection and store it permanently in the graph database. The traffic uploaded to the access server is analyzed and compared using the analysis method in the network traffic detection and analysis module, and the comparison result is sent to the client; Switch linkage device discovery module, which uses the SNMP protocol to analyze the network topology structure.

5. An electronic device, comprising a memory, a processor, and a computer program running on the memory, wherein when the processor executes the program, it implements a network access control method based on automatic discovery and linkage of switching devices as described in any one of claims 1-3.

6. A non-transitory computer-readable storage medium, on which a computer program is stored, characterized in that, when the program is executed by a processor, it implements a network access control method based on automatic discovery and linkage of switching devices as described in any one of claims 1-3.

Citation Information

Patent Citations

  • Electric power industry ubiquitous Internet of Things security protection gateway system, method and deployment architecture

    CN110958262A

  • Network space data fusion analysis method and system, electronic equipment and storage medium

    CN114817928A