Method, device and equipment for locating illegal DHCP server and storage medium

CN117914554BActive Publication Date: 2026-10-09SHENZHEN FENGRUNDA TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202311830454.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2026-10-09
Estimated Expiration
2043-12-28

AI Technical Summary

Technical Problem

[0005]本发明的主要目的在于提供一种非法DHCP服务器的定位方法,旨在解决现有的拦截手段只能通过在局域网中的部分节点进行识别和拦截,并不能定位干扰DHCP服务器在网络链路上的位置,进而无法从根源节点或路径上拦截和切断非法信息的传播的技术问题

Benefits of technology

[0016] This invention utilizes a switch with DHCP snooping enabled to monitor and acquire DHCP protocol messages in the data streams of all physical ports. It identifies and parses the DHCP server's protocol messages to obtain communication path information and generate a tracking and location table. This table is then uploaded to the network management system. Based on the tracking and location table, the network management system performs topology discovery on the illegal DHCP server, draws a communication path diagram of the illegal DHCP server, and cuts off the communication connection with the illegal DHCP server at its source. This achieves source tracing and interception of illegal DHCP servers in the network link, preventing further forwarding and propagation of illegal DHCP protocol messages and maintaining healthy network communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117914554B_ABST
    Figure CN117914554B_ABST
Patent Text Reader

Abstract

The present application belongs to the network monitoring technical field, disclose a kind of positioning method, device, equipment and storage medium of illegal DHCP server.The present application is by opening the switch of DHCP detection function, monitors and obtains the DHCP protocol message in all physical port data stream, determines DHCP server protocol message and carries out analysis, obtains communication path information and generates tracking positioning table, tracking positioning table is uploaded to network management system, network management system according to tracking positioning table, topology discovery is carried out to the illegal DHCP server, and the communication path graph of illegal DHCP server is drawn, according to the communication path graph of the illegal DHCP server, the communication connection of illegal DHCP server is cut off from the source of communication path.It is realized that the illegal DHCP server is traced in network link, and further forwarding propagation of illegal DHCP protocol message is avoided from the source, and network communication health is maintained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network monitoring technology, and in particular to a method, apparatus, device, and storage medium for locating illegal DHCP servers. Background Technology

[0002] When multiple DHCP servers exist on a network, clients may encounter abnormal situations when obtaining IPv4 addresses. To ensure that only legitimate DHCP servers can assign IPv4 addresses to clients, the data communications industry typically employs various technical methods to address this issue.

[0003] In the data communications industry, this is typically achieved by configuring switch ports as trusted ports to ensure that only DHCP messages received on those trusted ports from legitimate DHCP servers are forwarded. Alternatively, a trusted DHCP server list can be configured on the switch to ensure that only DHCP messages from servers with specified IP addresses are forwarded. Setting trusted ports or a trusted DHCP server list effectively ensures that only legitimate DHCP servers in the network can assign IPv4 addresses to clients.

[0004] However, existing interception methods can only identify and intercept some nodes in the local area network. They cannot locate the position of the interfering DHCP server on the network link, nor can they intercept and cut off the spread of illegal information from the root node or path. The only way to find and solve the problem is to manually analyze network devices one by one. Summary of the Invention

[0005] The main objective of this invention is to provide a method for locating illegal DHCP servers, aiming to solve the technical problem that existing interception methods can only identify and intercept some nodes in a local area network, but cannot locate the location of the interfering DHCP server on the network link, and thus cannot intercept and cut off the spread of illegal information from the root node or path.

[0006] To achieve the above objectives, the present invention provides a method for locating illegal DHCP servers, the method comprising the following steps: By enabling the DHCP listening function on the switch, the DHCP protocol messages in the data stream of all physical ports are monitored and obtained to determine the DHCP server protocol messages. The DHCP server protocol message is parsed to obtain the communication path information of the DHCP server protocol message; Based on the communication path information, a tracking and location table for illegal DHCP servers is obtained; The tracking and location table is uploaded to the network management system. Based on the tracking and location table, the network management system performs topology discovery on the illegal DHCP server and draws a communication path diagram of the illegal DHCP server. According to the communication path diagram of the illegal DHCP server, the communication connection with the illegal DHCP server is cut off at the source of the communication path.

[0007] Optionally, the step of monitoring and acquiring DHCP protocol messages in the data stream of all physical ports through the switch with DHCP listening enabled, and determining the DHCP server protocol message, includes: Based on the list of trusted DHCP servers, the DHCP protocol messages in the data stream are identified and recorded. For DHCP servers with no records identified, early warning information is generated and uploaded to the network management system. The switch broadcasts the list of trusted DHCP servers within its DHCP domain according to a synchronization protocol, thereby enabling real-time synchronization and updating of the list of trusted DHCP servers for all switches in the domain.

[0008] Optionally, parsing the DHCP server protocol message to obtain the communication path information of the DHCP server protocol message includes: Extract the option fields related to the message path from the DHCP server message. The option fields include at least the DHCP server identifier and the next-hop IP address. Based on the DHCP server identifier and the next-hop IP address, determine the distance metric of the illegitimate DHCP server; The option fields and distance metrics related to the communication path in the DHCP server message are used as communication path information.

[0009] Optionally, obtaining the tracking and location table of illegal DHCP servers based on the communication path information includes: Based on the communication path information, determine the receiving physical port name and Layer 3 interface IP address of the illegal DHCP server; The DHCP server identifier, receiving physical port name, Layer 3 interface IP address, next-hop IP address, and distance metric are filled into the initial tracking and location table to obtain the tracking and location table of the illegal DHCP server.

[0010] Optionally, the step of uploading the tracking and location table to the network management system, and the network management system performing topology discovery on the illegal DHCP server based on the tracking and location table, and drawing a communication path diagram of the illegal DHCP server, includes: The network management system performs topology analysis on the tracking and location tables from multiple switches to obtain the connection method between the transmitting node of the DHCP protocol message and each node. Based on the connection method between the transmission node and each node, calculate and draw the network topology within the DHCP domain; The network topology is visualized to obtain the communication path diagram of the illegal DHCP server.

[0011] Optionally, severing the communication connection with the illegal DHCP server from its source, based on the communication path diagram of the illegal DHCP server, includes: Based on the communication path diagram of the illegal DHCP server, determine the switch that is closest to the illegal DHCP server on the communication path diagram; Based on the warning information and the tracking and location table, determine the physical port on the nearest switch that is communicating with the illegal DHCP server; By intercepting DHCP protocol messages in the data stream of the physical port, the communication connection with the illegal DHCP server is cut off at the source.

[0012] Optionally, intercepting DHCP protocol messages in the physical port data stream to cut off the communication connection with the illegal DHCP server at the source includes: When the distance metric determines that the illegal DHCP server and the switch are in the same subnet segment, modify the ACL rules of the switch. Based on the modified ACL rules, the switch automatically filters DHCP protocol messages transmitted by the illegal DHCP server.

[0013] Furthermore, to achieve the above objectives, the present invention also proposes a device for locating illegal DHCP servers, the device comprising: The data flow monitoring module is used to monitor and acquire DHCP protocol messages in the data flow of all physical ports through switches with DHCP listening function enabled, and to determine the DHCP server protocol messages. The communication analysis module is used to parse the DHCP server protocol messages to obtain the communication path information of the DHCP server protocol messages; The communication analysis module is also used to obtain a tracking and location table of illegal DHCP servers based on the communication path information. The communication analysis module is also used to upload the tracking and location table to the network management system. The network management system performs topology discovery on the illegal DHCP server based on the tracking and location table and draws a communication path diagram of the illegal DHCP server. The communication control module is used to cut off the communication connection with the illegal DHCP server according to the communication path diagram of the illegal DHCP server.

[0014] Furthermore, to achieve the above objectives, the present invention also proposes a device for locating illegal DHCP servers. The device for locating illegal DHCP servers includes: a memory, a processor, and a program for locating illegal DHCP servers stored in the memory and executable on the processor. The program for locating illegal DHCP servers is configured to implement the steps of the method for locating illegal DHCP servers as described in any one of the claims.

[0015] Furthermore, to achieve the above objectives, the present invention also proposes a storage medium storing a program for locating illegal DHCP servers, wherein when the program for locating illegal DHCP servers is executed by a processor, the steps of the method for locating illegal DHCP servers are implemented.

[0016] This invention utilizes a switch with DHCP snooping enabled to monitor and acquire DHCP protocol messages in the data streams of all physical ports. It identifies and parses the DHCP server's protocol messages to obtain communication path information and generate a tracking and location table. This table is then uploaded to the network management system. Based on the tracking and location table, the network management system performs topology discovery on the illegal DHCP server, draws a communication path diagram of the illegal DHCP server, and cuts off the communication connection with the illegal DHCP server at its source. This achieves source tracing and interception of illegal DHCP servers in the network link, preventing further forwarding and propagation of illegal DHCP protocol messages and maintaining healthy network communication. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of the structure of the device for locating illegal DHCP servers in the hardware operating environment involved in the embodiments of the present invention. Figure 2 This is a flowchart illustrating the first embodiment of the method for locating illegal DHCP servers according to the present invention. Figure 3 This is a flowchart illustrating the second embodiment of the method for locating illegal DHCP servers according to the present invention. Figure 4 This is a flowchart illustrating the third embodiment of the method for locating illegal DHCP servers according to the present invention. Figure 5 This is a flowchart illustrating the fourth embodiment of the method for locating illegal DHCP servers according to the present invention. Figure 6 This is a structural block diagram of the first embodiment of the illegal DHCP server locating device of the present invention. Detailed Implementation

[0018] It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the invention.

[0019] Reference Figure 1 , Figure 1 This is a schematic diagram of the structure of the device for locating illegal DHCP servers in the hardware operating environment involved in the embodiments of the present invention.

[0020] like Figure 1 As shown, the device for locating the illegal DHCP server may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to establish communication between these components. The user interface 1003 may include a display screen or an input unit such as a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wireless-Fidelity (Wi-Fi) interface). The memory 1005 may be a high-speed random access memory (RAM) or a stable non-volatile memory (NVM), such as a disk drive. The memory 1005 may also optionally be a storage device independent of the aforementioned processor 1001.

[0021] Those skilled in the art will understand that Figure 1 The structure shown does not constitute a limitation on the device for locating illegitimate DHCP servers and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0022] like Figure 1 As shown, the memory 1005, which serves as a storage medium, may include an operating system, a network communication module, a user interface module, and a program for locating illegal DHCP servers.

[0023] exist Figure 1In the illegal DHCP server location device shown, the network interface 1004 is mainly used for data communication with the network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and memory 1005 in the illegal DHCP server location device of the present invention can be set in the illegal DHCP server location device, and the illegal DHCP server location device calls the illegal DHCP server location program stored in the memory 1005 through the processor 1001 and executes the illegal DHCP server location method provided in the embodiment of the present invention.

[0024] This invention provides a method for locating illegal DHCP servers, referring to... Figure 2 , Figure 2 This is a flowchart illustrating the first embodiment of a method for locating an illegal DHCP server according to the present invention.

[0025] In this embodiment, the method for locating the illegal DHCP server includes the following steps: Step S10: By using a switch with DHCP listening enabled, monitor and obtain DHCP protocol messages in the data streams of all physical ports to determine the DHCP server protocol messages.

[0026] It's important to note that not all switches within a local area network (LAN) necessarily have DHCP snooping capabilities. This task can only be accomplished by switches that have and have DHCP snooping enabled. DHCP snooping refers to network devices (including routers or switches) continuously listening for DHCP requests and responses on the network. When a network device with DHCP auto-acquisition enabled joins or leaves the LAN, it sends a DHCP request to obtain an available IP address and other configuration information. The DHCP server function on the network device receives these requests and allocates addresses and configuration information to the requester based on pre-configured rules and address pools.

[0027] It is understandable that DHCP protocol messages are transmitted in a specific format within a data stream. DHCP protocol messages are typically encapsulated using UDP (User Datagram Protocol) and use IPv4 or IPv6 as the network layer protocol. Therefore, by following a specific monitoring pattern, DHCP protocol messages within the port data stream can be identified.

[0028] It should be understood that before the network is set up, the node devices in the local area network will be distributed a list of trusted DHCP servers by the corresponding network device management system or administrator. The node devices participating in the listening will identify DHCP server protocol messages in the data stream through the list of trusted DHCP servers, allow communication of recorded protocol messages in the local area network, and intercept and record DHCP server protocol messages that are not recorded in the list. These unrecorded DHCP protocol messages are suspected to be sent by an illegal DHCP server.

[0029] Step S20: Parse the DHCP server protocol message to obtain the communication path information of the DHCP server protocol message.

[0030] It's important to note that the DHCP protocol message format includes various fields used to convey network configuration information such as IP address allocation, subnet mask, gateway, and DNS server. The source address refers to the IP address of the message sender, identifying the message's origin; the destination address refers to the IP address of the message receiver, identifying the message's destination; the port number identifies the sender and receiver's ports (the default ports for DHCP are 67 and 68, used for communication between the server and client); the opcode indicates the message type, such as DHCP request or DHCP response; and DHCP options carry various configuration information, such as the IP address allocation request, assigned IP address, subnet mask, gateway, and DNS server.

[0031] Understandably, by parsing some fields in the DHCP protocol message, the association between the DHCP server's IP address and the physical port that received the DHCP server's protocol message can be recorded during the specific transmission process. Through this association and other information, the tracking and location table of illegal DHCP servers can be further determined.

[0032] It should be understood that the fields used by the switch in this invention for parsing packets have different meanings. For example, the DHCP Server Identifier is usually used to represent the IP address of the server that sent the DHCP packet, the Next server IP address represents the IP address of the next server in the DHCP protocol, the Relay agent IP address represents the IP address of the DHCP relay agent, and the Hops field is usually used to indicate the number of relay agents the packet passes through from the client to the DHCP server. The value of Hops is incremented by 1 for each relay agent passed through. This part can help determine whether the DHCP packet has passed through multiple relay agents and the number of these agents.

[0033] Step S30: Obtain the tracking and location table of the illegal DHCP server based on the communication path information.

[0034] It should be noted that the entries in the tracking and location table should include at least the DHCP server IP address, receiving physical port name, Layer 3 interface IP address, next-hop IP address, and distance metric to ensure that the correct communication path diagram can be drawn subsequently.

[0035] It is understandable that by parsing the DHCP messages monitored in the data stream, the obtained communication path information can be used to generate a tracking and location table for each DHCP server, and then the location of the DHCP server can be determined by using the tracking and location table of the same DHCP server.

[0036] Step S40: Upload the tracking and location table to the network management system. The network management system performs topology discovery on the illegal DHCP server based on the tracking and location table and draws a communication path diagram of the illegal DHCP server.

[0037] It should be noted that the network management system, acting as the host computer, receives the tracking and location tables transmitted back from various monitoring switches or routers. It categorizes DHCP messages with the same content and performs topology discovery based on the tracking and location tables of the same group of DHCP servers. This allows it to obtain the communication path diagram of the monitored illegal DHCP server. The diagram includes the starting point and ending point of the messages sent by the monitored DHCP server in the local area network. The starting point represents the location of the illegal DHCP server.

[0038] As is understandable, topology discovery refers to the process of building a network topology map by collecting and analyzing connection information and topology information between network devices. A network topology map is a graphical representation that describes the connection methods and topology between network devices. Through a network topology map, administrators or management systems can quickly understand and manage network devices and topology.

[0039] It should be understood that topology discovery typically requires collecting basic information about network devices, including IP addresses, MAC addresses, device models, and locations, and establishing the network topology through the connections and interactions between these devices. Various network protocols and technologies are commonly used for topology discovery, such as Link Layer Discovery Protocol (LLDP) and Simple Network Management Protocol (SNMP), to query the status and topology information of network devices. Additionally, typical topology discovery tools include Cacti, Nagios, and SolarWinds, which usually feature graphical interfaces and distributed data acquisition capabilities, facilitating the drawing and monitoring of network topologies.

[0040] Step S50: According to the communication path diagram of the illegal DHCP server, cut off the communication connection with the illegal DHCP server from the source of the communication path.

[0041] It should be noted that, based on the communication path diagram of the illegitimate DHCP server, its connection relationships with other network devices and the network segments or starting interfaces through which data flows can be determined. Depending on the device type and configuration of the interface, appropriate actions can be taken to disconnect the interface or port connected to the illegitimate DHCP server. For example, if the starting interface is on a switch, the port security function of the switch can be configured to disable or close the port connected to the illegitimate DHCP server; if the starting interface is on a router, access control lists (ACLs) or firewall rules can be configured on the router to restrict communication with the illegitimate DHCP server, or the interface connected to the illegitimate DHCP server can be directly closed; alternatively, appropriate policies or rules can be configured to block or drop communication traffic with the illegitimate DHCP server at the starting interface.

[0042] In this embodiment, by enabling DHCP snooping on a switch, DHCP protocol messages in the data streams of all physical ports are monitored and acquired. DHCP server protocol messages are identified, and these messages are parsed to obtain the communication path information of the DHCP server protocol messages. This results in a tracking and location table of illegal DHCP servers, which is uploaded to the network management system. Based on the tracking and location table, the network management system performs topology discovery on the illegal DHCP servers, draws a communication path diagram of the illegal DHCP servers, and then cuts off the communication connection with the illegal DHCP servers at the source of the communication path. This implements a method for source-tracing interception of illegal DHCP servers, effectively preventing the further spread and propagation of information sent by illegal DHCP servers within the local area network.

[0043] Reference Figure 3 , Figure 3 This is a flowchart illustrating the second embodiment of the method for locating illegal DHCP servers according to the present invention.

[0044] Based on the first embodiment described above, step S10 in the method for locating illegal DHCP servers in this embodiment includes: Step S101: Based on the list of trusted DHCP servers, identify and record the DHCP protocol messages in the data stream, and trigger the generation of early warning information for DHCP servers with no record in the identification result and upload it to the network management system.

[0045] It should be noted that the trusted DHCP server list is stored on each switch or router by the LAN system or administrator before the LAN is set up. Based on the trusted DHCP server list, it is possible to identify whether the DHCP protocol messages in the data stream are sent by a legitimate DHCP server.

[0046] Understandably, when each node device detects an unrecorded DHCP server protocol message, it will generate an early warning message and upload it to the network management system. This allows the network management system to accurately discover the illegal DHCP server in subsequent steps based on the node device corresponding to the alarm message, the time of the alarm message, and the tracking and location table.

[0047] Step S102: The switch broadcasts the list of trusted DHCP servers within its DHCP domain according to the synchronization protocol, thereby achieving real-time synchronization and updating of the list of trusted DHCP servers for all switches in the domain.

[0048] It should be noted that, as new network devices are constantly being added and removed during the operation of a local area network (LAN), when some legitimate DHCP servers connect to the LAN, it is necessary to modify the trusted DHCP server list to ensure that legitimate DHCP servers are not deleted as illegitimate DHCP servers due to configuration issues.

[0049] Understandably, when a legitimate DHCP server connects to the local area network, the node devices that connect to the server will broadcast the server information of the legitimate DHCP server within the local area network. Each node device that receives this message will automatically update its locally recorded list of trusted DHCP servers according to the synchronization protocol.

[0050] Based on the first embodiment described above, step S20 in the method for locating illegal DHCP servers in this embodiment includes: Step S201: Extract the option fields related to the message path from the DHCP server message. The option fields include at least the DHCP server identifier and the next-hop IP address.

[0051] It should be noted that the DHCP server identifier is used to identify the IP address of the server that sends the DHCP message. By identifying the DHCP server identifier, the association between the DHCP message and the corresponding server can be established, thereby inferring the communication path and source of the message. The next-hop IP address is used to represent the IP address of the next server in the DHCP protocol. By analyzing the next-hop IP address, the forwarding path of the DHCP message can be inferred, further revealing the communication path information of the illegal DHCP server.

[0052] It is understandable that the option fields related to the message path in the DHCP server message are not limited to the DHCP server identifier and the next-hop IP address.

[0053] Step S202: Determine the distance metric of the illegal DHCP server based on the DHCP server identifier and the next-hop IP address.

[0054] It should be noted that in this step, by comparing the DHCP server identifier obtained in the previous step with the next-hop IP address, if the two are the same, the illegal DHCP server and the switch that detected the illegal DHCP message belong to the same subnet segment. In this case, the distance metric can be set to 1. If the two are different, the distance metric is set to Hops+1 according to the extracted Hops field.

[0055] As is understandable, the Hops field is an option field in the DHCP protocol message, used to indicate the number of relay agents the message passes through from the client to the DHCP server, that is, the number of hops in the message path.

[0056] Step S203: Use the option fields and distance metric related to the communication path in the DHCP server message as communication path information.

[0057] It should be noted that the communication path information should include at least two parts: option fields related to the communication path and distance metric. Otherwise, it will be impossible to accurately establish the transmission path of the message and the association with the server in subsequent steps, thus failing to help determine the location of the illegitimate DHCP server.

[0058] In this embodiment, DHCP protocol messages in the data stream are identified and recorded using a trusted DHCP server list. DHCP servers with no recorded messages are triggered to generate warning information and uploaded to the network management system. Option fields related to the message path in the DHCP server messages are extracted to determine the distance metric of the illegal DHCP server. Finally, the option fields and distance metric related to the communication path in the DHCP server messages are used as communication path information. Furthermore, the trusted DHCP server list is broadcast within the DHCP domain using a synchronization protocol, enabling real-time synchronization and updating of the trusted DHCP server list information for all switches in the domain. Overall, the communication path information obtained through parsing DHCP server messages can better help network administrators quickly and accurately locate illegal DHCP servers and take corresponding measures to block them.

[0059] Reference Figure 4 , Figure 4This is a flowchart illustrating the third embodiment of the method for locating illegal DHCP servers according to the present invention.

[0060] Based on the first embodiment described above, step S30 in the method for locating illegal DHCP servers in this embodiment includes: Step S301: Based on the communication path information, determine the receiving physical port name and Layer 3 interface IP address of the illegal DHCP server.

[0061] It's important to note that a Layer 3 interface IP address typically refers to the IP address of the interface configured on a network device to receive data streams. These interfaces are usually used to receive data sent from other devices and forward and route data according to the rules of network protocols (such as the IP protocol). For example, a router may have multiple interfaces, each with a unique IP address, used to receive and process data streams from different subnets. Network administrators can configure the IP addresses of router interfaces to ensure that the interfaces can communicate correctly with other devices and that network data can be correctly routed to the target devices.

[0062] Step S302: Fill the DHCP server identifier, receiving physical port name, Layer 3 interface IP address, next-hop IP address and distance metric into the initial tracking and location table to obtain the tracking and location table of the illegal DHCP server.

[0063] It should be noted that the entries in the tracking and location table include, but are not limited to, DHCP server identifier, receiving physical port name, Layer 3 interface IP address, next-hop IP address, and distance metric. The complete tracking and location table can be used as the raw data for topology analysis.

[0064] Based on the first embodiment described above, step S40 in the method for locating illegal DHCP servers in this embodiment includes: Step S401: The network management system performs topology analysis on the tracking and location tables from multiple switches to obtain the connection method between the transmitting node of the DHCP protocol message and each node.

[0065] It should be noted that the propagation of the same DHCP server message in a local area network will generate multiple communication path information, which in turn will generate multiple tracking and location tables. This is helpful for drawing a clear and complete communication path diagram in topology analysis.

[0066] Step S402: Calculate and draw the network topology within the DHCP domain based on the connection method between the transmission node and each node.

[0067] Understandably, the collected node connection information is used to build a topology data model, which can be a graph structure where devices are represented as nodes and connections are represented as edges. Then, graph theory algorithms, such as depth-first search (DFS), breadth-first search (BFS), or Dijkstra's algorithm, are applied to analyze the connections between nodes in the network, thereby obtaining the network topology. Network topology drawing tools (such as Visio, Draw.io, etc.) or programming drawing libraries are then used to draw the network topology within the DHCP domain.

[0068] Step S403: Visualize the network topology to obtain the communication path diagram of the illegal DHCP server.

[0069] Understandably, visualization refers to clearly marking the connections between devices in a network topology diagram. For example, different symbols or colors can be used to represent the types of devices and their connection methods, making the network topology clearly visible.

[0070] In this embodiment, by determining the receiving physical port name, Layer 3 interface IP address, and some data obtained in the previous steps based on the communication path information, a tracking and location table of the illegal DHCP server is obtained. Then, the network management system performs topology analysis and visualization processing on the tracking and location tables from multiple switches to finally obtain the communication path diagram of the illegal DHCP server. The above steps propose a practical method for transforming basic communication path information into a communication path diagram.

[0071] Reference Figure 5 , Figure 5 This is a flowchart illustrating the fourth embodiment of the method for locating illegal DHCP servers according to the present invention.

[0072] Based on the first embodiment described above, step S50 in the method for locating illegal DHCP servers in this embodiment includes: Step S501: Based on the communication path diagram of the illegal DHCP server, determine the switch that is closest to the illegal DHCP server on the communication path diagram.

[0073] It is understandable that a switch is a data link layer device within a local area network. It learns and maintains a MAC address table to identify the MAC addresses between devices and forwards data frames only to the port connected to the target device. The starting point of data transmission on the communication path diagram is the location of the nearest physical port of the switch to the illegal DHCP server.

[0074] Step S502: Based on the warning information and the tracking and positioning table, determine the physical port on the nearest switch that is communicating with the illegal DHCP server.

[0075] It should be noted that the warning information and tracking location table can display the structure of the entire network and the connection relationship between devices, while the device connection information provides details of the physical port connection of each switch.

[0076] Step S503: Intercept DHCP protocol messages in the physical port data stream to cut off the communication connection with the illegal DHCP server at the source.

[0077] Furthermore, step S503 in the method for locating illegal DHCP servers in this embodiment includes: Step S50301: When it is determined through the distance metric that the illegal DHCP server and the switch are in the same subnet segment, modify the ACL rules of the switch.

[0078] It should be noted that ACL (Access Control List) is a network security configuration tool used to control the flow of data packets on network devices. ACL rules specify how to allow or deny data packets through network devices based on specific conditions in order to provide network security and access control.

[0079] As we can understand, ACL rules match data packets based on certain conditions. These conditions can be based on network packet characteristics such as source IP address, destination IP address, source port, destination port, and protocol type, specifying the action to be taken for packets that meet the conditions. Common actions include permitting and denying, and sometimes logging, redirection, etc. By configuring ACL rules, network administrators can achieve precise control and filtering of data packets, restricting or allowing specific network communication. ACL rules can be used to protect the network from threats such as unauthorized access, DoS attacks, and malware, while also optimizing network performance and ensuring the rational use of network resources.

[0080] Step S50302: Based on the modified ACL rules, the switch automatically filters DHCP protocol messages transmitted by the illegal DHCP server.

[0081] Understandably, based on the actions configured in the modified ACL rules, the switch can choose to "deny" to block packets transmitted by an unauthorized DHCP server from passing through the switch, or it can choose to "drop" to discard the packets and thus not respond to them.

[0082] In this embodiment, by analyzing the communication path map of the illegal DHCP server, the switch closest to the illegal DHCP server on the communication path map is determined. This allows for the identification of the physical port transmitting DHCP protocol messages, and the interception of DHCP protocol messages in the data stream of that physical port. This effectively cuts off the communication connection with the illegal DHCP server at its source. When distance metrics determine that the illegal DHCP server and the switch are on the same subnet, the switch's ACL rules can be modified to allow the switch to automatically filter DHCP protocol messages transmitted by the illegal DHCP server. This automatic filtering of DHCP protocol messages transmitted by illegal DHCP servers allows the switch to process such messages automatically upon receipt, reducing manual intervention by administrators and improving the efficiency and real-time performance of network security control.

[0083] like Figure 6 As shown, the device for locating illegal DHCP servers proposed in this embodiment of the invention includes: The data flow monitoring module 10 is used to monitor and obtain DHCP protocol messages in the data flow of all physical ports through a switch with DHCP listening function enabled, and to determine the DHCP server protocol messages. The communication analysis module 20 is used to parse the DHCP server protocol message to obtain the communication path information of the DHCP server protocol message; The communication analysis module 20 is also used to obtain a tracking and location table of illegal DHCP servers based on the communication path information; The communication analysis module 20 is also used to upload the tracking and location table to the network management system. The network management system performs topology discovery on the illegal DHCP server based on the tracking and location table and draws a communication path diagram of the illegal DHCP server. The communication control module 30 is used to cut off the communication connection with the illegal DHCP server according to the communication path diagram of the illegal DHCP server.

[0084] In one embodiment, the data flow monitoring module 10 is further configured to identify and record DHCP protocol messages in the data flow according to the trusted DHCP server list, and trigger the generation of early warning information for DHCP servers with no record in the identification result and upload it to the network management system; the switch broadcasts the trusted DHCP server list in its DHCP domain according to the synchronization protocol to realize real-time synchronization update of the trusted DHCP server list information of all switches in the domain.

[0085] In one embodiment, the communication analysis module 20 is further configured to extract option fields related to the message path in the DHCP server message, the option fields including at least a DHCP server identifier and a next-hop IP address; determine the distance metric of the illegal DHCP server based on the DHCP server identifier and the next-hop IP address; and use the option fields and distance metric related to the communication path in the DHCP server message as communication path information.

[0086] In one embodiment, the communication analysis module 20 is further configured to determine the receiving physical port name and Layer 3 interface IP address of the illegal DHCP server based on the communication path information; and fill the DHCP server identifier, receiving physical port name, Layer 3 interface IP address, next-hop IP address and distance metric into an initial tracking and location table to obtain the tracking and location table of the illegal DHCP server.

[0087] In one embodiment, the communication analysis module 20 is further configured to perform topology analysis on the tracking and location tables from multiple switches in the network management system to obtain the connection method between the transmission node of the DHCP protocol message and each node; calculate and draw the network topology structure within the DHCP domain based on the connection method between the transmission node and each node; and visualize the network topology structure to obtain the communication path diagram of the illegal DHCP server.

[0088] In one embodiment, the communication control module 30 is further configured to: determine the switch closest to the illegal DHCP server on the communication path map according to the illegal DHCP server's communication path map; determine the physical port on the closest switch that communicates with the illegal DHCP server according to the warning information and the tracking and positioning table; and intercept DHCP protocol messages in the data stream of the physical port to cut off the communication connection with the illegal DHCP server at the source.

[0089] In one embodiment, the communication control module 30 is further configured to modify the ACL rules of the switch when it is determined by the distance metric that the illegal DHCP server and the switch are in the same subnet segment; based on the modified ACL rules, the switch automatically filters the DHCP protocol messages transmitted by the illegal DHCP server.

[0090] Furthermore, to achieve the above objectives, the present invention provides a device for locating illegal DHCP servers. The device includes a memory, a processor, and a program for locating illegal DHCP servers stored in the memory and executable on the processor. The program for locating illegal DHCP servers is configured to implement the steps of the method for locating illegal DHCP servers.

[0091] Furthermore, to achieve the above objectives, the present invention provides a storage medium storing a program for locating illegal DHCP servers, wherein when the program for locating illegal DHCP servers is executed by a processor, the program implements the steps of the method for locating illegal DHCP servers.

[0092] It should be understood that the above are merely illustrative examples and do not constitute any limitation on the technical solution of the present invention. In specific applications, those skilled in the art can make settings as needed, and the present invention does not impose any restrictions on this.

[0093] It should be understood that although the steps in the flowcharts of this application's embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least a portion of the sub-steps or stages of other steps.

[0094] It should be noted that the workflow described above is merely illustrative and does not limit the scope of protection of this invention. In practical applications, those skilled in the art can select some or all of the workflow to achieve the purpose of this embodiment according to actual needs, and no restrictions are imposed here.

[0095] Furthermore, it should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0096] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0097] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as read-only memory (ROM) / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0098] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.

Claims

1. A method for locating an illegal DHCP server, characterized in that, The method for locating the illegal DHCP server includes: By enabling the DHCP listening function on the switch, the DHCP protocol messages in the data stream of all physical ports are monitored and obtained to determine the DHCP server protocol messages. The DHCP server protocol message is parsed to obtain the communication path information of the DHCP server protocol message; Based on the communication path information, a tracking and location table for illegal DHCP servers is obtained; The tracking and location table is uploaded to the network management system. Based on the tracking and location table, the network management system performs topology discovery on the illegal DHCP server and draws a communication path diagram of the illegal DHCP server. According to the communication path diagram of the illegal DHCP server, the communication connection with the illegal DHCP server is cut off from the source of the communication path; The step of parsing the DHCP server protocol message to obtain the communication path information of the DHCP server protocol message includes: Extract the option fields related to the message path from the DHCP server message. The option fields include at least the DHCP server identifier and the next-hop IP address. Based on the DHCP server identifier and the next-hop IP address, determine the distance metric of the illegitimate DHCP server; The option fields and distance metrics related to the communication path in the DHCP server message are used as communication path information.

2. The method for locating an illegal DHCP server according to claim 1, characterized in that, The switch with DHCP listening enabled monitors and acquires DHCP protocol messages in the data streams of all physical ports to determine the DHCP server protocol messages, including: Based on the list of trusted DHCP servers, the DHCP protocol messages in the data stream are identified and recorded. For DHCP servers with no records identified, early warning information is generated and uploaded to the network management system. The switch broadcasts the list of trusted DHCP servers within its DHCP domain according to a synchronization protocol, thereby enabling real-time synchronization and updating of the list of trusted DHCP servers for all switches in the domain.

3. The method for locating an illegal DHCP server according to claim 1, characterized in that, The step of obtaining the tracking and location table of illegal DHCP servers based on the communication path information includes: Based on the communication path information, determine the receiving physical port name and Layer 3 interface IP address of the illegal DHCP server; The DHCP server identifier, receiving physical port name, Layer 3 interface IP address, next-hop IP address, and distance metric are filled into the initial tracking and location table to obtain the tracking and location table of the illegal DHCP server.

4. The method for locating an illegal DHCP server according to claim 1, characterized in that, The step involves uploading the tracking and location table to the network management system. Based on the tracking and location table, the network management system performs topology discovery on the illegal DHCP server and draws a communication path diagram of the illegal DHCP server, including: The network management system performs topology analysis on the tracking and location tables from multiple switches to obtain the connection method between the transmitting node of the DHCP protocol message and each node. Based on the connection methods between the transmission nodes and each node, calculate and draw the network topology within the DHCP domain; The network topology is visualized to obtain the communication path diagram of the illegal DHCP server.

5. The method for locating an illegal DHCP server according to claim 2, characterized in that, The step of cutting off the communication connection with the illegal DHCP server from the source of the communication path, based on the communication path diagram of the illegal DHCP server, includes: Based on the communication path diagram of the illegal DHCP server, determine the switch that is closest to the illegal DHCP server on the communication path diagram; Based on the warning information and the tracking and location table, determine the physical port on the nearest switch that is communicating with the illegal DHCP server; By intercepting DHCP protocol messages in the data stream of the physical port, the communication connection with the illegal DHCP server is cut off at the source.

6. The method for locating an illegal DHCP server according to claim 5, characterized in that, The interception of DHCP protocol messages in the physical port data stream, thereby cutting off the communication connection with the illegal DHCP server at the source, includes: When the distance metric determines that the illegal DHCP server and the switch are in the same subnet segment, modify the ACL rules of the switch. Based on the modified ACL rules, the switch automatically filters DHCP protocol messages transmitted by the illegal DHCP server.

7. A device for locating illegal DHCP servers, characterized in that, The device for locating the illegal DHCP server includes: The data flow monitoring module is used to monitor and acquire DHCP protocol messages in the data flow of all physical ports through switches with DHCP listening function enabled, and to determine the DHCP server protocol messages. The communication analysis module is used to parse the DHCP server protocol messages to obtain the communication path information of the DHCP server protocol messages; The communication analysis module is also used to obtain a tracking and location table of illegal DHCP servers based on the communication path information. The communication analysis module is also used to upload the tracking and location table to the network management system. The network management system performs topology discovery on the illegal DHCP server based on the tracking and location table and draws a communication path diagram of the illegal DHCP server. The communication control module is used to cut off the communication connection with the illegal DHCP server according to the communication path diagram of the illegal DHCP server; The communication analysis module is also used to extract option fields related to the message path in the DHCP server message, and the option fields include at least the DHCP server identifier and the next-hop IP address; Based on the DHCP server identifier and the next-hop IP address, determine the distance metric of the illegitimate DHCP server; The option fields and distance metrics related to the communication path in the DHCP server message are used as communication path information.

8. A device for locating illegal DHCP servers, characterized in that, The device for locating illegal DHCP servers includes: a memory, a processor, and a program for locating illegal DHCP servers stored in the memory and executable on the processor, wherein the program for locating illegal DHCP servers is configured to implement the steps of the method for locating illegal DHCP servers as described in any one of claims 1 to 6.

9. A storage medium, characterized in that, The storage medium stores a program for locating illegal DHCP servers. When the program is executed by the processor, it implements the steps of the method for locating illegal DHCP servers as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Detection method and access equipment of DHCP server

    CN101321102A

  • Method for preventing DHCP packet attack based on Snooping technique

    CN101459653A

  • Dynamic host configuration protocol (DHCP) message transmitting method and device

    CN104468467A