A terminal mac access control method combined with traffic fingerprint and related equipment

CN117675368BActive Publication Date: 2026-07-21NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
Filing Date
2023-12-07
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing network access control methods are poorly suited for dumb terminal devices, have low security performance, and impose excessive network traffic detection load, making it difficult to effectively manage the network access control of dumb terminal devices.

Method used

By verifying the traffic fingerprint of the terminal entity, configuring traffic mirroring policies and baseline analysis using the management and control service entity, monitoring traffic anomalies of the terminal entity, issuing alarms or disconnection commands, and realizing network access control for dumb terminal devices.

Benefits of technology

It improves the accuracy of MAC authentication, enables effective network access control for dumb terminal devices, reduces the performance requirements of management and control service entities, and reduces the risk of data loss and stress on the analysis engine.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117675368B_ABST
    Figure CN117675368B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a terminal MAC access control method combined with traffic fingerprints and related equipment, and relate to the technical field of network security. The method comprises the following steps: confirming the traffic fingerprints of terminal entities that pass MAC authentication; and performing network access management on the terminal entities based on the traffic fingerprints within a detection period of a network access entity. The technical solution of the present application performs management on terminal entities based on traffic fingerprints after the terminal entities pass MAC authentication, thereby improving the accuracy of MAC authentication and achieving network access control on dumb terminal devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and more specifically, to a terminal MAC access control method combining traffic fingerprinting, a terminal MAC access control device combining traffic fingerprinting, an electronic device, and a computer-readable storage medium. Background Technology

[0002] Network security access authentication technology is a network security technology that restricts the network access availability of terminals that comply with security policies by taking appropriate authentication measures on terminals accessing the network.

[0003] Currently, common network access control methods for dumb terminal devices have shortcomings such as poor applicability, low security performance, and excessive network traffic detection load. Therefore, how to provide a control method that can meet the network access requirements of dumb terminal devices is an urgent technical problem to be solved. Summary of the Invention

[0004] The embodiments of this application provide a terminal MAC access control method combining traffic fingerprinting, a terminal MAC access control device combining traffic fingerprinting, an electronic device, and a computer-readable storage medium to realize network access control of dumb terminal devices.

[0005] Other features and advantages of this application will become apparent from the following detailed description, or may be learned in part from practice of this application.

[0006] According to a first aspect of the embodiments of this application, a terminal MAC admission control method combining traffic fingerprinting is provided, including:

[0007] Verify the traffic fingerprint of the terminal entity that has passed MAC authentication;

[0008] During the network access entity detection period, the terminal entity is subject to network access control based on the traffic fingerprint.

[0009] In some embodiments of this application, based on the foregoing scheme, the step of confirming the fingerprint traffic of the terminal entity that has passed MAC authentication includes:

[0010] The management service entity configures traffic mirroring policies, and the network access entity filters terminal entities that pass MAC authentication and completes network traffic replication, which is then routed to the management service entity.

[0011] The management and control service entity performs traffic baseline analysis on the terminal entity to determine the traffic fingerprint.

[0012] In some embodiments of this application, based on the foregoing scheme, the step of controlling the network access of the terminal entity based on the traffic fingerprint during the detection period of the network access entity includes:

[0013] During the detection period of the network access entity, the management and control service entity performs traffic analysis and judgment on the terminal entity based on the traffic fingerprint. When an anomaly is detected, the management and control service entity issues an alarm and / or sends a disconnect command to the network access entity.

[0014] In some embodiments of this application, based on the foregoing scheme, when an anomaly is detected, the management service entity sends a disconnect command to the network access entity, including:

[0015] When a terminal entity does not meet the access requirements, the management service entity sends a disconnect instruction to the network access entity via a RADIUS protocol disconnect message.

[0016] In some embodiments of this application, based on the foregoing scheme, before confirming the traffic fingerprint of the terminal entity that has passed MAC authentication, the following steps are also included:

[0017] The terminal entity sends a request to access the network, and the management service entity performs MAC authentication on the terminal entity.

[0018] In some embodiments of this application, based on the foregoing scheme, the terminal entity sends a request to access the network, and the management service entity performs MAC authentication on the terminal entity, including:

[0019] A pre-connection is established between the terminal entity and the network access entity;

[0020] The terminal entity sends an access message to the network access entity;

[0021] The network access entity encapsulates the access message and transmits it to the control service entity to request MAC authentication.

[0022] The control service entity performs MAC authentication based on the received encapsulated access message and feeds back the processing result to the network access entity.

[0023] In some embodiments of this application, based on the foregoing scheme, after the terminal entity passes MAC authentication, the method further includes:

[0024] During the detection period, if the network access entity does not receive traffic from the terminal entity, it sends the first ARP request to the terminal entity.

[0025] If the terminal entity does not respond after the detection period ends and the network access entity does not receive traffic from the terminal entity, then a second ARP request is sent to the terminal entity.

[0026] If the terminal entity does not respond, then the terminal entity's access to the network is terminated.

[0027] According to a second aspect of the embodiments of this application, a terminal MAC access control device combining traffic fingerprinting is provided, including: a network access entity and a management and control service entity;

[0028] The network access entity is connected to the control service entity;

[0029] The network access entity obtains the access request of the terminal entity and transmits it to the management and control service entity, which performs MAC authentication based on the access request.

[0030] The network access entity obtains the traffic of the terminal entity, and the management and control service entity monitors the traffic of the terminal entity and issues management and control instructions.

[0031] According to a third aspect of the embodiments of this application, an electronic device is provided, characterized in that it includes a memory and a processor;

[0032] The memory is used to store computer instructions;

[0033] The processor is configured to invoke computer instructions in the memory to cause the electronic device to perform the method described in the first aspect above.

[0034] According to a fourth aspect of the embodiments of this application, a computer-readable storage medium is provided, the storage medium storing computer instructions that cause the computer instructions to perform the method described in the first aspect above.

[0035] The technical solution of this application, after successful MAC authentication of the terminal entity, manages the terminal entity based on traffic fingerprinting, which improves the accuracy of MAC authentication and realizes network access control for dumb terminal devices.

[0036] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0037] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. It is obvious that the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort. In the drawings:

[0038] Figure 1 A schematic diagram of the architecture of a terminal MAC admission control device incorporating traffic fingerprinting according to an embodiment of this application is shown;

[0039] Figure 2A schematic flowchart of a terminal MAC admission control method incorporating traffic fingerprinting according to an embodiment of this application is shown.

[0040] Figure 3 A schematic diagram of a MAC authentication process according to an embodiment of this application is shown.

[0041] Figure 4 A schematic diagram of traffic monitoring and control according to an embodiment of this application is shown;

[0042] Figure 5 A schematic diagram of an electronic device structure according to an embodiment of this application is shown;

[0043] Figure 6 A schematic diagram of the structure of a computer system suitable for implementing the electronic device of the present application is shown. Detailed Implementation

[0044] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this invention, and not all of them. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.

[0045] Furthermore, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. Numerous specific details are provided in the following description to give a thorough understanding of embodiments of this application. However, those skilled in the art will recognize that the technical solutions of this application can be practiced without one or more of the specific details, or other methods, components, apparatuses, steps, etc., can be employed. In other instances, well-known methods, apparatuses, implementations, or operations are not shown or described in detail to avoid obscuring various aspects of this application.

[0046] It should be noted that "and / or" describes the relationship between related objects, indicating that there can be three kinds of relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0047] The following detailed description of some embodiments of this application will be provided in conjunction with the accompanying drawings. Unless otherwise specified, the following embodiments and features can be combined with each other.

[0048] like Figure 1 The diagram shows an architecture schematic of a terminal MAC admission control device incorporating traffic fingerprinting according to an embodiment of this application.

[0049] like Figure 1 As shown, the entire device is divided into two parts: a network access entity (composed of an access authentication entity and a traffic monitoring entity) and a management and control service entity.

[0050] It should be noted that in this application, the terminal entity is a controlled entity requesting network access. This technical solution primarily targets dumb terminal devices, such as cameras, network printers, IP phones, and other network devices. Once the terminal entity is powered on and running, it negotiates with the connected network access entity, triggering the network access entity to initiate authentication based on the terminal entity's information. After successful authentication, the terminal entity formally accesses the local area network (LAN) and receives and sends service data within the LAN.

[0051] It should be noted that in this application, the network access entity is the control subject of the access control system, mainly including the access switch (defined as the access authentication entity) that connects dumb terminal devices, and the aggregation switch (defined as the traffic monitoring entity) in the local area network.

[0052] Within the access authentication entity, the MAC authentication method is configured uniformly. The access authentication entity is both the initiator and the implementer of the authentication result. After obtaining the necessary authentication information, the port of the dumb terminal device encapsulates the data and sends it to the management service entity; simultaneously, the access authentication entity also performs port switching actions based on the authentication result returned from the management service entity.

[0053] In the traffic monitoring entity, by configuring mirrored traffic, all traffic from dumb terminal devices that flows through the aggregation switch for business processing is copied to the management and control service entity for analysis.

[0054] It should be noted that in this application, the control service entity is the brain of the entire access authentication process, responsible for deciding whether a particular dumb terminal device can access the local area network. It also provides users with a visual interface and audit log services to monitor the status of all dumb terminal devices on the local area network. The services provided by the control service entity mainly include: authentication management, traffic monitoring and analysis, terminal management, and audit logging.

[0055] The authentication management service is responsible for processing the MAC authentication messages initiated by the access authentication entity and returning the authentication result when a dumb terminal device accesses the local area network. Simultaneously, when the traffic monitoring and analysis service detects abnormal service access from a dumb terminal device, it will isolate the abnormal dumb terminal device by sending an offline message.

[0056] The mechanism of the traffic monitoring and analysis service is as follows: Given the relatively fixed service traffic of dumb terminal devices, for a single dumb terminal device or a group of dumb terminal devices with similar service traffic, the five-tuple information of their service traffic is collected and recorded during their normal operation to serve as a traffic baseline. In subsequent traffic monitoring and analysis, if a dumb terminal exhibits access traffic that does not conform to its baseline, it will be judged as abnormal access behavior.

[0057] Terminal management records and displays the IP and MAC addresses used by terminals when accessing the network, access switch information, and terminal traffic characteristics. It also allows for the distribution of network access policies to terminal devices. Terminals can be queried based on display criteria. Terminal management also provides group management functionality, enabling categorized management and display of terminals according to their type, network address, etc.

[0058] Audit logs include access logs, fault logs, and operation logs. Access logs record terminal device on / off status and authentication failure information. Fault logs record abnormal information during the operation of various system components. Operation logs record configuration management and other operations performed by users.

[0059] See Figure 2 The diagram shows a schematic flowchart of a terminal MAC admission control method incorporating traffic fingerprinting according to an embodiment of this application.

[0060] like Figure 2 As shown, a terminal MAC access control method combining traffic fingerprinting is illustrated, specifically including steps S100 to S200.

[0061] Step S100: Confirm the traffic fingerprint of the terminal entity that has passed MAC authentication.

[0062] Understandably, terminal entities that have passed MAC authentication are already allowed to access the network, and the obtained traffic fingerprint is used to subsequently manage the network access status of the terminal entities.

[0063] In some feasible embodiments, based on the foregoing scheme, the step of confirming the fingerprint traffic of the terminal entity authenticated by MAC includes:

[0064] The management service entity configures traffic mirroring policies, and the network access entity filters terminal entities that pass MAC authentication and completes network traffic replication, which is then routed to the management service entity.

[0065] The management and control service entity performs traffic baseline analysis on the terminal entity to determine the traffic fingerprint.

[0066] Understandably, traditional network traffic monitoring functions typically route traffic data from all terminal entities to the management service entity via port mirroring. This places very high performance demands on the management service entity and carries risks such as data loss and potential engine crashes due to excessive pressure. In this embodiment, the network access method of terminal entities is analyzed. Through flow mirroring configuration and flow classification technology, the traffic data of MAC-authenticated terminal entities can be accurately located and routed to the management service entity. This reduces the software and hardware requirements of the management service entity and minimizes the chance of risks escalating into problems.

[0067] Continue to refer to Figure 2 In step S200, during the detection period of the network access entity, the terminal entity is controlled for network access based on the traffic fingerprint.

[0068] Understandably, this application incorporates terminal traffic monitoring into the periodic detection process following successful MAC authentication. Based on the detection of terminal liveness, it further monitors and judges the terminal traffic fingerprint, thereby improving the accuracy of MAC authentication and eliminating the risk of MAC address forgery.

[0069] In some feasible embodiments, based on the foregoing scheme, the step of controlling the network access of the terminal entity based on the traffic fingerprint during the detection period of the network access entity includes:

[0070] During the detection period of the network access entity, the management and control service entity performs traffic analysis and judgment on the terminal entity based on the traffic fingerprint. When an anomaly is detected, the management and control service entity issues an alarm and / or sends a disconnect command to the network access entity.

[0071] Understandably, when a control service entity detects an anomaly, it can choose to issue a warning, send a disconnect command, or issue a disconnect command at the same time as issuing a warning.

[0072] In some feasible embodiments, based on the foregoing scheme, when an anomaly is detected, the management service entity sends a disconnect command to the network access entity, including:

[0073] When a terminal entity does not meet the access requirements, the management service entity sends a disconnect instruction to the network access entity via a RADIUS protocol disconnect message.

[0074] It should be noted that Radius stands for Remote Authentication Dial-In User Service. The disconnect message uses the UDP (User Datagram Protocol) protocol on port 3799. The DM message contains the request type, error code, and disconnection reason, as well as attribute values ​​related to network access, such as the access authentication entity address and port.

[0075] The management service entity adds inter-process communication with the Radius service in the traffic monitoring and analysis service, transmitting control commands through the system's RPC remote call protocol. After receiving the network disconnection message from the traffic monitoring and analysis service, the Radius service constructs a DM message, sends it to the access authentication entity, terminates the authentication session, and realizes the function of actively kicking the terminal entity offline.

[0076] In some feasible embodiments, based on the foregoing scheme, before confirming the traffic fingerprint of the terminal entity authenticated by MAC, the following steps are also included:

[0077] The terminal entity sends a request to access the network, and the management service entity performs MAC authentication on the terminal entity.

[0078] Understandably, MAC authentication is a prerequisite for controlling the traffic of terminal entities.

[0079] It should be noted that MAC in this application refers to Media Access Control Address. MAC authentication is an authentication method that controls a user's network access permissions based on the interface and MAC address. It does not require the user to install any client software.

[0080] In some feasible embodiments, based on the foregoing scheme, the terminal entity sends a request to access the network, and the management service entity performs MAC authentication on the terminal entity, including:

[0081] A pre-connection is established between the terminal entity and the network access entity;

[0082] The terminal entity sends an access message to the network access entity;

[0083] The network access entity encapsulates the access message and transmits it to the control service entity to request MAC authentication.

[0084] The control service entity performs MAC authentication based on the received encapsulated access message and feeds back the processing result to the network access entity.

[0085] In some feasible embodiments, based on the foregoing scheme, after the terminal entity passes MAC authentication, the method further includes:

[0086] During the detection period, if the network access entity does not receive traffic from the terminal entity, it sends the first ARP request to the terminal entity.

[0087] If the terminal entity does not respond after the detection period ends and the network access entity does not receive traffic from the terminal entity, then a second ARP request is sent to the terminal entity.

[0088] If the terminal entity does not respond, then the terminal entity's access to the network is terminated.

[0089] It should be noted that ARP refers to Address Resolution Protocol.

[0090] Understandably, after MAC authentication, the terminal entity begins to access the network. However, if the network access entity does not receive any traffic from the terminal entity during the access process, it indicates that there is a problem with the terminal entity and it needs to be disconnected.

[0091] In summary, the technical solution of this application does not change the existing network topology configuration and has good compatibility; it is applicable to most commercially procured switches and has no special requirements for the switches; it is applicable to dumb terminal devices that cannot install authentication agent software, and provides a method for dumb terminal network access control to assist in network asset mapping.

[0092] Below is a specific implementation example.

[0093] See Figure 3 The diagram illustrates a MAC authentication process.

[0094] See Figure 4 The diagram illustrates a traffic monitoring and control system.

[0095] like Figure 3 , Figure 4 As shown, this example provides a terminal MAC access control method that combines traffic fingerprinting, which includes two parts: MAC authentication and traffic monitoring.

[0096] like Figure 3 As shown, the MAC authentication process is as follows:

[0097] (1) Establish a pre-connection between the terminal entity and the network access entity before authentication;

[0098] (2) When the network access entity first detects any one of the ARP / DHCP packets of the terminal entity, it triggers MAC authentication of the terminal entity.

[0099] (3) The network access entity processes the user's password using the MD5 challenge word, and encapsulates the processed information and the MD5 challenge word in the Radius authentication request message, and sends it to the management service entity to request MAC authentication of the terminal entity.

[0100] (4) The control service entity uses the received MD5 challenge word to process the corresponding MAC authentication user password in the local database. If it is consistent with the relevant information sent by the network access entity, it sends a Radius authentication success message to the network access entity, indicating that the terminal entity's MAC authentication is successful and the terminal entity is allowed to access the network.

[0101] (5) The network access entity authorizes ports based on the Radius authentication result returned by the control service entity.

[0102] like Figure 4 As shown, the traffic monitoring process is as follows:

[0103] (1) The terminal entity sends a message to trigger MAC authentication. The authentication is successful, and the network access entity starts a probe timer at the same time.

[0104] (2) The management service entity configures the traffic mirroring policy, the traffic monitoring entity filters the terminal entity and completes the network traffic replication, and directs it to the management service entity;

[0105] (3) The management service entity performs traffic baseline analysis to determine the traffic fingerprint for the terminal entity;

[0106] (4) Traffic fingerprint is abnormal, and the control service entity sends a DM message to the network access entity;

[0107] (5) The network access entity notifies the terminal device to go offline, stops authorization for the corresponding port, and deletes the corresponding user from the online list;

[0108] (6) Within a certain number of T time intervals, the network access entity can receive the terminal entity traffic and the corresponding user is online;

[0109] (7) The traffic fingerprint is normal, the terminal entity continues to access the network, the network access entity periodically detects the terminal entity's message status, the terminal entity sends the last message, and at the end of this T time, due to the terminal entity's traffic, the network access entity determines that the corresponding user is online and restarts the timer;

[0110] (8) If the network access entity does not receive traffic from the terminal entity within time T, it sends the first ARP request, but the terminal entity does not respond.

[0111] (9) After time T, no traffic was received from the terminal entity. The network access entity sent a second ARP request, but the terminal entity did not respond.

[0112] (10) After time T, if no traffic is received from the terminal entity, the probe fails and the terminal entity goes offline;

[0113] (11) The network access entity sends a request to the control service entity to stop billing;

[0114] (12) The control service entity sends a stop billing response to the network access entity;

[0115] (13) The network access entity stops authorizing the corresponding port and removes the corresponding user from the online list.

[0116] like Figure 5 As shown, this application embodiment also provides an electronic device 500, including a memory 510, a processor 520, and a computer program 511 stored in the memory 510 and executable on the processor. When the processor 520 executes the computer program 511, it implements the above-mentioned terminal MAC access control method combined with traffic fingerprinting.

[0117] Since the electronic device described in this embodiment is the device used to implement a terminal MAC access control device that combines traffic fingerprinting in the embodiments of this application, those skilled in the art can understand the specific implementation method and various variations of the electronic device in this embodiment based on the method described in the embodiments of this application. Therefore, how the electronic device implements the method in the embodiments of this application will not be described in detail here. Any device used by those skilled in the art to implement the method in the embodiments of this application is within the scope of protection of this application.

[0118] In practice, when the computer program 511 is executed by the processor, it can implement any of the embodiments corresponding to the first aspect.

[0119] Figure 6 A schematic diagram of the structure of a computer system suitable for implementing the electronic device of the present application is shown.

[0120] It should be noted that, Figure 6 The computer system 600 of the electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0121] like Figure 6As shown, the computer system 600 includes a Central Processing Unit (CPU) 601, which can perform various appropriate actions and processes based on programs stored in Read-Only Memory (ROM) 602 or programs loaded from Storage Unit 608 into Random Access Memory (RAM) 603, such as performing the methods described in the above embodiments. The RAM 603 also stores various programs and data required for system operation. The CPU 601, ROM 602, and RAM 603 are interconnected via a bus 604. An Input / Output (I / O) interface 605 is also connected to the bus 604.

[0122] The following components are connected to I / O interface 605: an input section 606 including a keyboard, mouse, etc.; an output section 607 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN (Local Area Network) card, modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to I / O interface 605 as needed. A removable medium 611, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 610 as needed so that computer programs read from it can be installed into storage section 608 as needed.

[0123] Specifically, according to embodiments of this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 609, and / or installed from removable medium 611. When the computer program is executed by central processing unit (CPU) 601, it performs various functions defined in the system of this application.

[0124] It should be noted that the computer-readable medium shown in the embodiments of this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such transmitted data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, etc., or any suitable combination thereof.

[0125] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0126] The units described in the embodiments of this application can be implemented in software or hardware, and the described units can also be located in a processor. The names of these units do not necessarily limit the specific unit itself.

[0127] In another aspect, this application also provides a computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the terminal MAC admission control method combined with traffic fingerprinting described in the above embodiments.

[0128] In another aspect, this application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiments; or it may exist independently and not assembled into the electronic device. The computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to implement the terminal MAC admission control method combined with traffic fingerprinting described in the above embodiments.

[0129] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of this application, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0130] Through the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, touch terminal, or network device, etc.) to execute the method according to the embodiments of this application.

[0131] Other embodiments of this application will readily conceive of by those skilled in the art upon consideration of the specification and practice of the embodiments disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. It should be understood that this application is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A terminal MAC admission control method combining traffic fingerprinting, characterized in that, include: Verify the traffic fingerprint of the terminal entity that has passed MAC authentication; During the detection period of the network access entity, the terminal entity is subject to network access control based on the traffic fingerprint; The traffic fingerprint of the terminal entity that has been verified through MAC authentication includes: The management service entity configures traffic mirroring policies, and the network access entity filters terminal entities that pass MAC authentication and completes network traffic replication, which is then routed to the management service entity. The management and control service entity performs traffic baseline analysis on the terminal entity to determine the traffic fingerprint; The step of controlling network access for the terminal entity based on the traffic fingerprint during the detection period of the network access entity includes: During the detection period of the network access entity, the management and control service entity performs traffic analysis and judgment on the terminal entity based on the traffic fingerprint. When an anomaly is detected, the management and control service entity issues an alarm and / or sends a disconnect command to the network access entity. When an anomaly is detected, the control service entity sends a disconnect command to the network access entity, including: When a terminal entity does not meet the access requirements, the management service entity sends a disconnection instruction to the network access entity via a RADIUS protocol disconnection message. After the terminal entity passes MAC authentication, the following is also included: During the detection period, if the network access entity does not receive traffic from the terminal entity, it sends the first ARP request to the terminal entity. If the terminal entity does not respond after the detection period ends and the network access entity does not receive traffic from the terminal entity, then a second ARP request is sent to the terminal entity. If the terminal entity does not respond, then the terminal entity's access to the network is terminated.

2. The method according to claim 1, characterized in that, Before confirming the traffic fingerprint of the terminal entity that has passed MAC authentication, the following is also included: The terminal entity sends a request to access the network, and the management service entity performs MAC authentication on the terminal entity.

3. The method according to claim 1, characterized in that, The terminal entity sends a request to access the network, and the management service entity performs MAC authentication on the terminal entity, including: A pre-connection is established between the terminal entity and the network access entity; The terminal entity sends an access message to the network access entity; The network access entity encapsulates the access message and transmits it to the control service entity to request MAC authentication. The control service entity performs MAC authentication based on the received encapsulated access message and feeds back the processing result to the network access entity.

4. A terminal MAC access control device combining traffic fingerprinting, applied to the method as described in any one of claims 1-3, characterized in that, include: Network access entities and regulatory service entities; The network access entity is connected to the control service entity; The network access entity obtains the access request of the terminal entity and transmits it to the management and control service entity, which performs MAC authentication based on the access request. The network access entity obtains the traffic of the terminal entity, and the management and control service entity monitors the traffic of the terminal entity and issues management and control instructions.

5. An electronic device, characterized in that, Including memory and processor; The memory is used to store computer instructions; The processor is configured to invoke computer instructions in the memory to cause the electronic device to perform the method as described in any one of claims 1-3.

6. A computer-readable storage medium, characterized in that, The storage medium stores computer instructions that cause the computer instructions to perform the method as described in any one of claims 1-3.