An ARP blocking verification method, system, device and storage medium

By pre-blocking the device in the LAN and crawling the mirror traffic packets for parsing, the problem of inaccurate ARP blocking verification in complex LANs is solved, and accurate evaluation of ARP blocking situation and quantitative verification of the effect is achieved.

CN115834445BActive Publication Date: 2025-07-11SHENZHEN ZHUTAI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211221797.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-08
Publication Date
2025-07-11
Estimated Expiration
2042-10-08

AI Technical Summary

Technical Problem

The prior art cannot accurately verify the ARP blocking situation in complex LANs, especially when the equipment is diverse and the distribution is complex, resulting in inaccurate verification results.

Method used

By pre-blocking different types of host devices in the LAN, grab mirror traffic packets and parsing them, we can determine whether the blocking situation is consistent with expectations, and use the network security system server equipment to continuously broadcast the ARP answer packet, and use the source IP, destination IP, source MAC and destination MAC in the mirror traffic packet for quantitative calculations to distinguish between fraudulent MAC and real MAC.

Benefits of technology

Accurate verification of ARP blocking conditions in the entire LAN is achieved, the accuracy of verification results is improved, and the ARP blocking effect can be quantitatively evaluated without manual verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834445B_ABST
    Figure CN115834445B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of computer technology, and provides an ARP blocking verification method, system, device and storage medium. The method includes the following steps: S1: Block at least one host device of each different type in the local area network to be verified in advance; S2: Capture the mirror traffic data packets formed by the mirror traffic of all host devices in the local area network to be verified; S3: Analyze the mirror traffic data packets to verify whether the blocking situation conforms to the expectation: if so, the blocking verification is correct, otherwise, the blocking verification is incorrect. In a complex network environment, it can better verify the ARP blocking situation in the entire local area network, without the need for manual verification of the ARP blocking situation in the entire local area network, improving the accuracy of the ARP blocking verification result, and can better know the quality of the ARP blocking effect.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer technology, and particularly relates to an ARP blocking verification method, system, device and storage medium. Background Art

[0002] Currently, the test of ARP (Address Resolution Protocol) blocking usually uses PING (Packet Internet Groper) to clarify the blocking situation of the blocked devices, and it is often a point-to-point verification. When the network environment is complex, such as the number of devices increases and the types of devices increase, it is very difficult to clarify the ARP blocking situation in the entire local area network, and it is impossible to determine whether other devices in the local area network are affected. In addition, due to the increase in the number of blocked devices, the increase in the types of blocked devices, and the distribution of blocked devices in each network segment, it is also very difficult to clarify whether the blocked devices are really blocked, and the blocking verification is not accurate enough.

[0003] Moreover, the general PING verifies the blocking situation manually. This method can only verify the scenario where there are only a few devices in the local area network. When there are thousands or tens of thousands of devices in the local area network, the timeliness and feasibility of this verification will be unacceptable (at this time, partial verification is often adopted, that is, only verify the blocking situation of some of the blocked devices and unblocked devices); the situation of devices in a complex local area network is often complex, which will also lead to inaccurate verification results of the ARP blocking situation, so it is very difficult to verify the ARP blocking effect. Summary of the Invention

[0004] The purpose of the present invention is to provide an ARP blocking verification method, system, device and storage medium, aiming to solve the problem that due to the existing technology being unable to provide an ARP blocking verification method, the verification result of the ARP blocking situation is not accurate enough, so it is very difficult to verify the ARP blocking effect.

[0005] On the one hand, the present invention provides an ARP blocking verification method, and the method includes the following steps:

[0006] S1: Block at least one host device of each different type in the local area network to be verified in advance;

[0007] S2: Capture the mirror traffic data packets formed by the mirror traffic of all host devices in the local area network to be verified;

[0008] S3: Analyze the mirror traffic data packets to verify whether the blocking situation conforms to the expectation: if so, the blocking verification is correct, otherwise, the blocking verification is incorrect.

[0009] Preferably, in S1, it includes: continuously broadcasting ARP reply packets in the local area network to be verified through a network security system server device to block different types of host devices in the local area network to be verified.

[0010] Preferably, in S2, it includes: all the host devices receive the ARP reply packets and return reply messages, mirror all the reply messages to obtain mirror traffic and form mirror traffic data packets.

[0011] Preferably, in S2, it further includes: capturing the mirror traffic data packets in the local area network to be verified within a preset time.

[0012] Preferably, in S3, it includes: obtaining all source IPs, destination IPs, source MACs, and destination MACs by parsing the mirror traffic data packets.

[0013] Preferably, in S3, it further includes: finding the source IP and destination MAC of the blocked host device from all the source IPs, destination IPs, source MACs, and destination MACs, and determining whether the destination MAC of the blocked host device is a fraudulent MAC or a real MAC.

[0014] Preferably, in S3, it further includes: if the destination MAC of the blocked host device is a fraudulent MAC, then quantitatively calculate the fraudulent MAC and all destination MACs to verify the ARP blocking situation.

[0015] On the other hand, the present invention provides an ARP blocking verification system, and the system includes:

[0016] A pre-blocking unit, configured to pre-block at least one host device of different types in the local area network to be verified;

[0017] A mirror data traffic packet capturing unit, configured to capture mirror traffic data packets formed by the mirror traffic of all host devices in the local area network to be verified;

[0018] A mirror data traffic packet verification unit, configured to parse the mirror traffic data packets and determine whether the blocking situation conforms to the expectation: if so, the blocking verification is correct; otherwise, the blocking verification is incorrect.

[0019] On the other hand, the present invention provides an ARP blocking verification device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the method described in any one of the above.

[0020] On the other hand, the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the method described in any one of the above.

[0021] The beneficial effects of the present invention are as follows: Different from the prior art, the ARP blocking verification method of the present invention blocks at least one host device of each different type in the local area network to be verified in advance, and then captures the mirror traffic data packets formed by the mirror traffic of all host devices in the local area network to be verified. By parsing the mirror traffic data packets and determining whether the blocking situation conforms to the expectation, the ARP blocking situation is verified, and the ARP blocking situation in the entire local area network is preferably verified in a quantitative manner. There is no need for manual verification of the ARP blocking situation in the entire local area network, which improves the accuracy of the ARP blocking verification result and can preferably verify the quality of the ARP blocking effect. Description of the Drawings

[0022] Figure 1 is an application scenario diagram of the ARP blocking verification method provided by an embodiment of the present invention;

[0023] Figure 2 is a flowchart of the implementation of the ARP blocking verification method provided by Embodiment 1 of the present invention;

[0024] Figure 3 is a schematic structural diagram of the ARP blocking verification system provided by Embodiment 2 of the present invention;

[0025] Figure 4 is a schematic structural diagram of the ARP blocking verification device provided by Embodiment 3 of the present invention;

[0026] Figure 5 is a schematic diagram of the link layer parsing of the mirror traffic data packet in an embodiment of the present invention;

[0027] Figure 6 is a schematic diagram of the network layer parsing of the mirror traffic data packet in an embodiment of the present invention. Detailed Embodiments

[0028] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0029] Figure 1The figure shows an application scenario diagram of the ARP blocking verification method provided by an embodiment of the present invention. Among them, the network security system server device 10 is used to continuously broadcast ARP reply packets to block different types of host devices in the local area network to be verified, such as blocking any one or more of different types of host devices 31, host device 32, and host device 33.

[0030] Specifically, the network security system server device 10 continuously broadcasts ARP reply packets and transmits them to the host device 31, host device 32, and host device 33 through the core switch 20. The host device 31, host device 32, and host device 33 will all receive the ARP reply packets and return reply messages to the core switch 20. Furthermore, the core switch 20 mirrors the reply messages to obtain mirror traffic and forms mirror traffic data packets, and the parsing and judgment device 40 captures and parses the mirror traffic data packets within a certain preset time in the local area network to be verified to parse out the source IP, destination IP, source MAC, and destination MAC of all host devices, so as to further verify the ARP blocking situation in the local area network to be verified. The parsing and judgment device 40 is an electronic device such as a computer or a tablet with computing, processing, and analysis functions.

[0031] When the host device 31, host device 32, and host device 33 are running, they all have corresponding source IP, destination IP, source MAC, and destination MAC. By searching for the source IP and destination MAC of the blocked host device among all the source IP, destination IP, source MAC, and destination MAC, and then judging whether the destination MAC of the blocked host device is a fraudulent MAC or a real MAC. If the destination MAC of the blocked host device is a fraudulent MAC, then a quantitative calculation is performed on the fraudulent MAC and all the destination MACs to verify the ARP blocking situation.

[0032] It should be noted that among all the destination MACs (including the destination MAC of the blocked host device), most of the destination MACs are fraudulent MACs in the fraudulent broadcast packets of the ARP reply packets, and a part of them are real MACs in the local area network to be verified. Therefore, it is necessary to judge whether the destination MAC of the blocked host device is a fraudulent MAC or a real MAC to verify the ARP blocking effect.

[0033] The following describes the specific implementation of the present invention in detail in conjunction with specific embodiments:

[0034] Example 1:

[0035] Figure 2 The figure shows the implementation process of the ARP blocking verification method provided by Embodiment 1 of the present invention. For the convenience of description, only the parts related to the embodiments of the present invention are shown. The steps of the specific method are described in detail as follows:

[0036] S1: Block at least one host device of each different type in the local area network to be verified in advance.

[0037] In step S1, the network security system server device 10 continuously broadcasts ARP reply packets in the local area network to be verified. These ARP reply packets are fraudulent broadcast packets, and the fraudulent broadcast packets have fraudulent MACs, which are used to block host devices of different types in the local area network to be verified. Specifically, the network security system server device 10 continuously broadcasts ARP reply packets and transmits them to host devices 31, 32, and 33 of different types through the core switch 20, blocking any one or more of host devices 31, 32, and 33 of different types.

[0038] It should be noted that before executing step S1, it is necessary to ensure that all host devices in the local area network to be verified are working properly.

[0039] S2: Capture the mirror traffic data packets formed by the mirror traffic of all host devices in the local area network to be verified.

[0040] In step S2, host devices 31, 32, and 33 will all receive the ARP reply packets and return reply messages to the core switch 20. Then, the core switch 20 mirrors the reply messages in the local area network to be verified and forms mirror traffic data packets, and then the parsing and judgment device 40 captures the mirror traffic data packets.

[0041] Furthermore, in specific implementation, a time can be preset, and then the ARP blocking situation can be verified by capturing the mirror traffic data packets in the local area network to be verified within the preset time, making the verification result targeted and more accurate.

[0042] Among them, the preset time is a certain time period provided by technical personnel according to verification needs and set by the program, and the mirror traffic data packets within this certain time period will be captured.

[0043] S3: Analyze the mirror traffic data packets to verify whether the blocking situation conforms to the expectation: if so, the blocking verification is correct; otherwise, the blocking verification is incorrect.

[0044] In step S3, the mirror traffic data packets are analyzed and verified through a script (preset parsing and judgment program), and the script is set in the parsing and judgment device 40.

[0045] Specifically, the source MAC and destination MAC can be obtained by parsing the data packet header at the link layer of the mirror traffic data packet. Please refer to Figure 5 ; and the source IP and destination IP can be obtained by parsing the data packet header at the network layer of the mirror traffic data packet. Please refer toFigure 6 。

[0046] By searching for the source IP and destination MAC of the blocked host device among all source IPs, destination IPs, source MACs, and destination MACs, and then determining whether the destination MAC of the blocked host device is a fraudulent MAC or a genuine MAC. If the destination MAC of the blocked host device is a fraudulent MAC, then a quantitative calculation is performed between the fraudulent MAC and all destination MACs to verify the ARP blocking situation.

[0047] In this embodiment, the parsing and judgment device 40 is an electronic device such as a computer or a tablet with computing, processing, and analysis functions.

[0048] It can be understood that in step S3, the "expectation" in "whether it conforms to the expectation" refers to the expected result that is consistent with the device pre-blocked in step S1. If the verified blocked device is consistent with the pre-blocked device, it proves that the blocking verification is correct.

[0049] Example 2:

[0050] Figure 3 The structure of the ARP blocking verification system provided in the second embodiment of the present invention is shown. Using the ARP blocking verification method provided in the first embodiment above, it includes steps S1 - S3. For the sake of convenience of description, only the parts related to the embodiments of the present invention are shown, including:

[0051] A pre-blocking unit 501, configured to pre-block at least one host device of different types in the local area network to be verified;

[0052] A mirror data traffic packet capturing unit 502, configured to capture the mirror traffic data packets formed by the mirror traffic of all host devices in the local area network to be verified;

[0053] A mirror data traffic packet verification unit 503, configured to parse the mirror traffic data packets to verify whether the blocking situation conforms to the expectation: if so, the blocking verification is correct; otherwise, the blocking verification is incorrect.

[0054] It should be noted that in the embodiments of the present invention, each unit of the ARP blocking verification system can be implemented by corresponding hardware or software units. Each unit can be an independent software or hardware unit, or can be integrated into a software or hardware unit, which is not used to limit the present invention here.

[0055] Example 3:

[0056] Figure 4 The structure of the ARP blocking verification device provided in the third embodiment of the present invention is shown. For the sake of convenience of description, only the parts related to the embodiments of the present invention are shown.

[0057] The ARP blocking verification device according to an embodiment of the present invention includes a processor 60, a memory 61, and a computer program stored in the memory 61 and executable on the processor 60. When the processor 60 executes the computer program, the steps in the above-mentioned embodiment of the ARP blocking verification method are implemented, for example Figure 2 the steps S1 to S3 shown in. Alternatively, when the processor 60 executes the computer program, the functions of the respective units in the above-mentioned embodiment of the ARP blocking verification system are implemented, for example Figure 3 the functions of the units 501 to 503 shown in.

[0058] The ARP blocking verification device according to an embodiment of the present invention can be a computer network device provided with a processor 60 and a memory 61 and capable of executing a computing program. The steps implemented when the processor 60 in the computer network device executes the computer program to implement the ARP blocking verification method can refer to the description of the foregoing method embodiment and will not be elaborated herein.

[0059] Example 4:

[0060] In an embodiment of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the above-mentioned embodiment of the ARP blocking verification method are implemented, for example, Figure 2 the steps S1 to S3 shown in. Alternatively, when the computer program is executed by a processor, the functions of the respective units in the above-mentioned embodiment of the ARP blocking verification system are implemented, for example Figure 3 the functions of the units 501 to 503 shown in.

[0061] The computer-readable storage medium according to an embodiment of the present invention may include any entity or system, recording medium capable of carrying computer program code, for example, memories such as ROM / RAM, magnetic disks, optical disks, flash memories, etc.

[0062] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. An ARP blocking verification method, characterized in that: The method includes the following steps: S1: Block at least one host device of each different type in the local area network to be verified in advance; In S1, it includes: Continuously broadcast ARP reply packets in the local area network to be verified through a network security system server device to block host devices of different types in the local area network to be verified; S2: Capture the mirror traffic data packets formed by the mirror traffic of all host devices in the local area network to be verified; In S2, it includes: All the host devices receive the ARP reply packets and return reply messages, and mirror all the reply messages to obtain mirror traffic and form mirror traffic data packets; In S2, it also includes: Capture the mirror traffic data packets in the local area network to be verified within a preset time; S3: Analyze the mirror traffic data packets to verify whether the blocking situation conforms to the expectation: If so, the blocking verification is correct; otherwise, the blocking verification is incorrect.

2. The method according to claim 1, characterized in that: In S3, it includes: Obtain all source IPs, destination IPs, source MACs, and destination MACs by analyzing the mirror traffic data packets; 3. The method according to claim 2, wherein: In S3, it also includes: Search for the source IP and destination MAC of the blocked host device from all the source IPs, destination IPs, source MACs, and destination MACs, and determine whether the destination MAC of the blocked host device is a fraudulent MAC or a real MAC; 4. The method according to claim 3, wherein: In S3, it also includes: If the destination MAC of the blocked host device is a fraudulent MAC, perform quantitative calculation on the fraudulent MAC and all destination MACs to verify the ARP blocking situation; 5. An ARP blocking verification system, characterized in that: The system includes: A pre-blocking unit for blocking at least one host device of each different type in the local area network to be verified in advance; It includes: Continuously broadcast ARP reply packets in the local area network to be verified through a network security system server device to block host devices of different types in the local area network to be verified; A mirror data traffic packet capture unit for capturing the mirror traffic data packets formed by the mirror traffic of all host devices in the local area network to be verified; It includes: All the host devices receive the ARP reply packets and return reply messages, and mirror all the reply messages to obtain mirror traffic and form mirror traffic data packets; It also includes: Capture the mirror traffic data packets in the local area network to be verified within a preset time; A mirror data traffic packet verification unit for analyzing the mirror traffic data packets and determining whether the blocking situation conforms to the expectation: If so, the blocking verification is correct; otherwise, the blocking verification is incorrect.

6. An ARP blocking verification device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.

7. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Bypass blocking method and device thereof and storage medium

    CN111478888A

  • ARP spoofing attack detection method and device, computer equipment and storage medium

    CN112738018A