ARP attack defense method, data sending end and data receiving end
By generating ARP request frames containing false addresses and broadcasting and sending them, the data leakage problem caused by ARP attacks is solved, information security risks are reduced, and the security of network devices is improved.
Patent Information
- Application Number
- CN202510435882.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-04-09
AI Technical Summary
Network devices are prone to data leakage when they are attacked by ARP, which poses a major information security risk.
By obtaining the data transmission requirements, the preset ARP table entry is read to obtain the real IP address and MAC address of the target data receiver. If the acquisition fails, an ARP request frame containing a false address is generated and sent to the network device through broadcast.
It effectively avoids attackers identifying the real address of the data sending end, reducing the risk of ARP attacks, avoiding data leakage, and improving information security.
Smart Images

Figure CN119945807A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to an ARP attack defense method, a data sending end, and a data receiving end. Background Art
[0002] ARP (Address Resolution Protocol) attack is a network attack method targeting the ARP protocol in the local area network (LAN). If a network device in a LAN wants to communicate with other network devices, it needs to know the other party's IP (Internet Protocol) address and MAC (Media Access Control) address.
[0003] When a network device needs to send data, if its ARP table entry does not contain the MAC address of the target data receiver, it needs to send an ARP request to all network devices in the network architecture through the ARP protocol to obtain the MAC address of the target data receiver. At this time, the attacker forges the ARP response frame to make the current network device transmit the data that was originally required to be transmitted to the target data receiver to the attacker, resulting in data leakage and posing a serious threat to information security. Summary of the invention
[0004] The present application provides an ARP attack defense method, a data sending end, and a data receiving end to solve the technical problem in the related art that network devices are prone to data leakage when subjected to ARP attacks, which poses a great information security risk.
[0005] The present application provides an address resolution protocol ARP attack defense method, which is applied to a data sending end, and the method includes: Get data sending requirements; According to the data transmission requirement, the preset ARP table entry is read to obtain the real IP address and real MAC address of the target data receiving end; If the real MAC address of the target data receiving end fails to be obtained, an ARP request frame is generated based on the preset false address of the data sending end, the real address of the data sending end, and the real IP address of the target data receiving end; The ARP request frame is sent to the network devices in the current network architecture by broadcasting.
[0006] In some embodiments of the present application, the ARP request frame includes a source MAC address field, a source IP address field, a destination MAC address field, a destination IP address field and a custom field, the source MAC address field is a false MAC address of the data sending end, the source IP address field is a false IP address of the data sending end, the destination MAC address field is empty, and the destination IP address field is a real IP address or a false IP address of the target data receiving end; If the destination IP address field is the real IP address of the target data receiving end, the custom field includes the real IP address and real MAC address of the data sending end; If the destination IP address field is a false IP address of the target data receiving end, the custom field includes the real IP address and real MAC address of the data sending end, and the real IP address of the target data receiving end.
[0007] In some embodiments of the present application, the custom field further includes a pre-stored encrypted asset identification code of the target data receiving end; The encrypted asset identification code is used to match the self-asset identification code pre-stored by the target data receiving end after decryption, so that the real MAC address of the target data receiving end is fed back to the data sending end when the match is successful.
[0008] In some embodiments of the present application, it also includes: If an ARP response frame is received, the real MAC address of the target data receiving end is obtained by parsing the ARP response frame; Based on the real MAC address of the target data receiving end, the ARP table entry is updated; Data is sent based on the updated ARP entry.
[0009] In some embodiments of the present application, the real IP address and real MAC address of the data sender, and the real IP address of the target data receiver are all encrypted addresses.
[0010] In some embodiments of the present application, before sending the ARP request frame to the network device in the current network architecture by broadcasting, it also includes: If the ARP request frame contains an organization unique identifier, the organization unique identifier in the ARP request frame is deleted, or the organization unique identifier in the ARP request frame is adjusted from an original position to the custom field.
[0011] The present application also provides an Address Resolution Protocol ARP attack defense method, which is applied to a data receiving end and includes: Receiving an ARP request frame sent by a data sending end, wherein the ARP request frame is obtained by using the address resolution protocol ARP attack defense method as described in any one of the above; By parsing the ARP request frame, the real IP address of the target data receiving end in the ARP request frame and the encrypted asset identification code of the target data receiving end are obtained, where the encrypted asset identification code is pre-stored by the data sending end and added to the ARP request frame; Decrypting the encrypted asset identification code to obtain a decrypted identification code; If the decrypted identification code is the same as the asset identification code pre-stored by the current data receiving end, and the real IP address of the target data receiving end is the same as the real IP address of the current data receiving end, then an ARP response frame is generated based on the real MAC address of the current data receiving end; The ARP response frame is sent to the data sending end.
[0012] In some embodiments of the present application, generating an ARP response frame based on the real MAC address of the current data receiving end includes: The ARP response frame is generated based on the real MAC address, real IP address, false MAC address, false IP address of the current data receiving end, and the real MAC address, real IP address, false MAC address, false IP address of the data sending end.
[0013] The present application also provides a data sending end, including: Demand collection module, used to obtain data sending requirements; A data reading module is used to read data from a preset ARP table entry according to the data transmission requirement to obtain a real IP address and a real MAC address of a target data receiving end; A message generation module, configured to generate an ARP request frame based on a preset false address of the data sending end, a real address of the data sending end, and a real IP address of the target data receiving end if the real MAC address of the target data receiving end fails to be obtained; The data sending module is used to send the ARP request frame to the network equipment in the current network architecture by broadcasting.
[0014] The present application also provides a data receiving terminal, comprising: A message receiving module, used for receiving an ARP request frame sent by a data sending end, wherein the ARP request frame is obtained by using the address resolution protocol ARP attack defense method as described in any one of the above items; A message parsing module, used to parse the ARP request frame to obtain the real IP address of the target data receiving end in the ARP request frame, and the encrypted asset identification code of the target data receiving end, where the encrypted asset identification code is pre-stored by the data sending end and added to the ARP request frame; A decryption module, used to decrypt the encrypted asset identification code to obtain a decrypted identification code; A response module, configured to generate an ARP response frame based on the real MAC address of the current data receiving end if the decrypted identification code is the same as the self-asset identification code pre-stored by the current data receiving end, and the real IP address of the target data receiving end is the same as the real IP address of the current data receiving end; A data sending module is used to send the ARP response frame to the data sending end.
[0015] Beneficial effects of the embodiments of the present application: The address resolution protocol ARP attack defense method, data sending end and data receiving end provided in the embodiments of the present application, the method obtains data sending requirements; according to the data sending requirements, the preset ARP table items are read to obtain the real IP address and real MAC address of the target data receiving end; if the real MAC address of the target data receiving end fails to be obtained, then an ARP request frame is generated based on the preset false address of the data sending end, the real address of the data sending end, and the real IP address of the target data receiving end; the ARP request frame is sent to the network device in the current network architecture by broadcasting. The method generates an ARP request frame based on the true and false addresses of the data sending end, which can prevent the attacker from accurately identifying the real address of the data sending end in the ARP request frame, thereby preventing the data sending end from being attacked by ARP and reducing information security risks. Moreover, through the above method, it is also easy to identify attackers. It can be understood that if an attacker sends an ARP response frame to the false address in the ARP request frame, the attacker's address can be identified by monitoring the network device corresponding to the false address and parsing the ARP response frame received by the network device, thereby identifying the attacker. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 An exemplary schematic diagram of a vehicle network architecture provided in an embodiment of the present application; Figure 2 A schematic diagram of the interaction between a CDC (Cockpit Domain Controller, smart cockpit) and other network devices in a vehicle network architecture provided by an embodiment of the present application; Figure 3A flowchart of an Address Resolution Protocol (ARP) attack defense method applied to a data sending end provided in an embodiment of the present application; Figure 4 A schematic diagram of the format of an Ethernet frame (Eth Frame) containing OUI (Organizationally Unique Identifier) information in the related technology; Figure 5 A schematic diagram of an exemplary format of an Ethernet frame in an address resolution protocol ARP attack defense method provided in an embodiment of the present application; Figure 6 An exemplary schematic diagram of an ARP table entry in an address resolution protocol ARP attack defense method provided in an embodiment of the present application; Figure 7 A schematic diagram of the address storage area of each network device in the address resolution protocol ARP attack defense method provided in an embodiment of the present application; Figure 8 A schematic diagram of a process of sending an Ethernet frame in a method for defending against an address resolution protocol ARP attack provided in an embodiment of the present application; Fig. 9 A schematic diagram of a process of receiving an Ethernet frame in a method for defending against an address resolution protocol ARP attack provided in an embodiment of the present application; Fig.10 A flowchart of an Address Resolution Protocol ARP attack defense method applied to a data receiving end provided in an embodiment of the present application; Fig.11 A schematic diagram of the structure of a data sending terminal provided in an embodiment of the present application; Fig.12 A schematic diagram of the structure of a data receiving terminal provided in one embodiment of the present application; Fig.13 A schematic diagram of the structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0017] The following describes the embodiments of the present application through specific examples, and those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict.
[0018] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application, and thus the drawings only show components related to the present application rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed at will, and the component layout may also be more complicated.
[0019] In the following description, a large number of details are discussed to provide a more thorough explanation of the embodiments of the present application. However, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present application difficult to understand.
[0020] The ARP attack defense method, data transmitter, and data receiver provided in this application can be applied to many fields, such as vehicle network architecture, enterprise network, and Internet of Things, etc. The following takes the vehicle network architecture as an example to explain the ARP attack defense method, data transmitter, and data receiver provided in this application.
[0021] Please refer to Figure 1 , Figure 1 The vehicle network architecture (electronic and electrical architecture) is demonstrated in an exemplary manner. Figure 1 As shown in the figure, the vehicle network architecture adopts an Ethernet ring network architecture design. The advantages of the ring network architecture are that it supports SOA (Service-Oriented Architecture) service-oriented architecture and communication channel protection, and supports the nearby access of each ECU (Electronic Control Unit) according to functional classification, saving wiring harness costs. Figure 1 In the system, CDC can be connected to the cloud, such as OTA (Over-The-Air) cloud platform, through 4G / 5G or WIFI (Wireless Fidelity) channels, so as to realize the communication between the whole vehicle system and the outside world. VIU1, VIU2, VIU3, and VIU4 (VIU stands for Virtual Input Unit) are connected through Ethernet to form a ring network structure. VIU1, VIU2, VIU3, and VIU4 are connected to the relevant ECU components (such as Figure 1ECU1-1......ECU1-n, ECU2-1......ECU2-n, ECU3-1......ECU3-n, ECU4-1......ECU4-n, n represents the number of ECUs related to VIU). Each ECU can be a network device that supports Ethernet or a network device that does not support Ethernet (such as supporting CAN communication). In addition, the vehicle network architecture also includes VDC (Virtual Data Center). VDC can also establish communication with VIU, such as VIU1, VIU2, etc. It should be mentioned that Figure 1 The US in the code stands for UniversalSerial, which is a universal serial interface. UMC stands for USB Modem Controller, which is a USB modem controller interface. Figure 1 UMC0, UMC1, UMC2, UMC3, UMC4, and UMC5 represent different USB modem controller interfaces.
[0022] Figure 1 The general framework of the vehicle network architecture is demonstrated as an example. Figure 2 The interaction between CDC and other network devices in the vehicle network architecture is further demonstrated. Figure 2 , Figure 2 CDC is connected to VIU1, VIU2, VIU3, VIU4, and VDC respectively. Figure 1 In addition to the OTA cloud platform shown in the figure, CDC can also interact with the TSP (Telematics Service Provider) cloud platform. Figure 2 As shown, each network device, such as CDC, VDC, VIU1, VIU2, VIU3, and VIU4, etc., has a corresponding IP address and MAC address. Figure 2 The IP address and MAC address of each network device are shown as an example. The example address has no actual meaning and will not be repeated here.
[0023] Assumptions Figure 2The CDC in the network needs to send data to the VDC. Normally, the CDC needs to search for the IP address and MAC address of the VDC in its preset ARP table. If the MAC address of the VDC does not exist in the ARP table, it is necessary to generate an ARP request frame through the ARP protocol. The ARP request frame includes: source MAC address, source IP address, destination MAC address, and destination IP address. It can be understood that the source MAC address here is the real MAC address of the CDC, the source IP address is the real IP address of the CDC, the destination MAC address is empty, and the destination IP address is the real IP address of the VDC. When the ARP request frame is generated, the CDC broadcasts the ARP request frame to all network devices in the network architecture. When each network device receives the ARP request frame, it will parse the ARP request frame to obtain the destination IP address in the ARP request frame. The destination IP address is matched with the real IP address of the network device itself. If the match is successful, the real MAC address of the network device itself is fed back to the CDC. Based on the feedback, the CDC updates the data in its ARP table and uses it for subsequent data transmission. During this process, the attacker (such as a hacker) will also receive the ARP request frame. Therefore, after the VDC feeds back its MAC address, the attacker can forge an ARP response frame and transmit the forged ARP response frame to the CDC to complete the ARP attack. It is understandable that since the update principle of the ARP table entries in the network equipment is the "last in, first out" principle, after receiving the forged ARP response frame, the CDC will update the address of the VDC in the CDC's ARP table entry to the address forged by the attacker. This will cause the normal communication between the CDC and the VDC to be interrupted, and the CDC will leak information, which may even cause major safety accidents in vehicles in serious cases. In order to avoid this situation, the ARP attack defense method, data sending end and data receiving end provided by the present application obtain data sending requirements; according to the data sending requirements, the preset ARP table items are read to obtain the real IP address and real MAC address of the target data receiving end; if the real MAC address of the target data receiving end fails to be obtained, an ARP request frame is generated based on the preset false address of the data sending end, the real address of the data sending end, and the real IP address of the target data receiving end; the ARP request frame is sent to the network device in the current network architecture by broadcasting. In the above manner, the risk of ARP attack on the data sending end is reduced, and data leakage is avoided.
[0024] Combine the following Figures 3 to 13 , the ARP attack defense method, data sending end and data receiving end provided in this application are explained.
[0025] See also Figure 3 , Figure 3 A flowchart of an address resolution protocol ARP attack defense method applied to a data sending end provided in an embodiment of the present application is shown in FIG. Figure 1 As shown, the method includes: S310: Obtain data sending requirements.
[0026] S320: Read data from a preset ARP table entry according to data transmission requirements to obtain a real IP address and a real MAC address of a target data receiving end.
[0027] In some examples of this embodiment, the ARP table entry includes real IP addresses and real MAC addresses of multiple network devices.
[0028] S330: If the real MAC address of the target data receiving end fails to be obtained, an ARP request frame is generated based on the preset false address of the data sending end, the real address of the data sending end, and the real IP address of the target data receiving end.
[0029] It can be understood that by generating an ARP request frame based on the true and false addresses of the data sender, the attacker cannot accurately identify the real address of the data sender in the ARP request frame, thereby preventing the data sender from being attacked by ARP and effectively reducing information security risks.
[0030] In some examples of this embodiment, the ARP request frame in step S330 includes: a source MAC address field, a source IP address field, a destination MAC address field, a destination IP address field, and a custom field. Here, the source MAC address field is a false MAC address of the data sending end, the source IP address field is a false IP address of the data sending end, the destination MAC address field is empty, and the destination IP address field is the real IP address of the target data receiving end. The custom field includes: the real IP address and the real MAC address of the data sending end. In this way, the attacker cannot identify the real IP address and the real MAC address of the data sending end, thereby preventing the data sending end from being attacked by ARP and data leakage. It can be understood that since the original "source MAC address" and "source IP address" positions are replaced with false addresses, even if the attacker receives the ARP request frame, the address of the relevant data sending end parsed by it is also a false address, thereby preventing the data sending end from being attacked by ARP.
[0031] S340: Send the ARP request frame to the network devices in the current network architecture by broadcasting.
[0032] It can be understood that the ARP request frame is encapsulated into an Ethernet frame, and the Ethernet frame is sent to each network device in the current network architecture by broadcasting, so as to realize the broadcast of the ARP request.
[0033] In some examples of this embodiment, when the network device receives an ARP request frame, it can parse the ARP request frame to obtain the real IP address of the target data receiving end. The real IP address of the target data receiving end is matched with its own real IP address. If the match is successful, an ARP response frame is generated based on its own real MAC address, and the ARP response frame is sent to the data sending end. When the data sending end receives the ARP response frame, it parses the ARP response frame to obtain the real MAC address of the target data receiving end, and updates the real MAC address to its ARP table entry. Data is subsequently transmitted based on the address in the ARP table entry.
[0034] In order to prevent an attacker from obtaining the address information of the data receiving end through an ARP request frame, in some embodiments, the destination IP address field is a false IP address of the target data receiving end. On this basis, the custom field includes the real IP address and real MAC address of the data sending end, and the real IP address of the target data receiving end.
[0035] In some examples of this embodiment, the ARP request frame includes: a source MAC address field, a source IP address field, a destination MAC address field, a destination IP address field, and a custom field, etc. The source MAC address field here is a false MAC address of the data sending end, the source IP address field is a false IP address of the data sending end, the destination MAC address field is empty, and the destination IP address field is a false IP address of the target data receiving end. The custom field includes: the real IP address and real MAC address of the data sending end, and the real IP address of the target data receiving end, etc.
[0036] It can be understood that by writing a false IP address into the destination IP address field in the ARP request frame, it is possible to prevent an attacker from obtaining the real IP address of the target data receiving end by parsing the ARP request frame, thereby preventing the address of the target data receiving end from being leaked.
[0037] In order to further improve the security of the ARP request frame and improve the defense against ARP attacks, in some embodiments, the custom field also includes a pre-stored encrypted asset identification code of the target data receiving end. In some instances of this embodiment, the encrypted asset identification code is pre-stored in a preset address storage area of each device (data sending end and data receiving end).
[0038] The encrypted asset identification code is used to match the self-asset identification code pre-stored by the target data receiving end after decryption, so that the real MAC address of the target data receiving end is fed back to the data sending end when the match is successful.
[0039] It can be understood that after receiving the ARP request frame, the data receiving end will decrypt the encrypted asset identification code in the ARP request frame, and match the decrypted identification code with its own pre-stored asset identification code. If the match is successful, an ARP response frame will be sent to the data sending end to feed back the real MAC address of the target data receiving end to the data sending end.
[0040] In some examples of this embodiment, the ARP request frame generated by the above method includes: a source MAC address field, a source IP address field, a destination MAC address field, a destination IP address field, and a custom field, etc. The source MAC address field here is a false MAC address of the data sending end, the source IP address field is a false IP address of the data sending end, the destination MAC address field is empty, and the destination IP address field is a false IP address of the target data receiving end. The custom field includes: the real IP address of the data sending end, the real MAC address, the real IP address of the target data receiving end, and the encrypted asset identification code of the target data receiving end.
[0041] It is understandable that by adding the encrypted asset identification code of the target data receiving end in the custom field of the ARP request frame, the security of the ARP request process can be further improved. For the data receiving end, the method of matching its own asset identification code with the above decrypted identification code can further improve the accuracy of the ARP response compared to the method of only matching the destination IP address.
[0042] In some examples of this embodiment, the encrypted asset identification code can be generated based on the information such as the ID (Device Identifier) of each network device in the current network architecture, and each network device corresponds to a unique encrypted asset identification code. By pre-generating a corresponding encrypted asset identification code for each network device in the network architecture, it is convenient for the network device to add the encrypted asset identification code when generating an ARP request frame, so as to further improve the security of data transmission.
[0043] In some embodiments, the method further comprises: 1. If the ARP response frame is received, the real MAC address of the target data receiving end is obtained by parsing the ARP response frame.
[0044] 2. Based on the real MAC address of the target data receiving end, the ARP table entry is updated.
[0045] 3. Send data based on the updated ARP table entry.
[0046] It can be understood that through the above steps, the closed loop of the ARP request process can be well implemented.
[0047] In some embodiments, the real address of the data sender and the real IP address of the target data receiver are both encrypted addresses.
[0048] It can be understood that by encrypting (encrypting and compressing) the real address of the data sender and the real IP address of the target data receiver, the security of data transmission can be effectively improved.
[0049] In the related art, some ARP request frames also include OUI information of the data sender and / or the target data receiver. Attackers can easily obtain the above OUI information by parsing the message, thereby causing OUI information leakage. In order to avoid leakage of OUI information, in some embodiments, before sending the ARP request frame to the network device in the current network architecture by broadcasting, the method also includes: If the ARP request frame contains an organization unique identifier, the organization unique identifier in the ARP request frame is deleted, or the organization unique identifier in the ARP request frame is adjusted from the original position to the custom field, for example, the organization unique identifier is adjusted from the original position to the end of the custom field.
[0050] It can be understood that by deleting the organizational unique identifier in the ARP request frame, or adjusting the organizational unique identifier from the original position to a custom field, it is possible to avoid providing an attack target for attackers, that is, to avoid attackers identifying the OUI information and causing information leakage.
[0051] It is also understandable that, without including OUI information, the ARP request frame min (Minimum length of ARP request frame) = ARP message (28 bytes) + padding (18 bytes) = 46 bytes, Ethernet frame min (Minimum length of Ethernet frame) = Ethernet destination address (used to identify the MAC address field of the receiver, 6 bytes) + Ethernet source address (used to identify the MAC address field of the sender, 6 bytes) + frame type (2 bytes) + ARP request frame min(46 bytes) + frame check sequence (FCS, Frame Check Sequence, 4 bytes) = 64 bytes. The ARP message includes: hardware type (2 bytes), protocol type (2 bytes), hardware address length (1 byte), protocol address length (1 byte), operation code (2 bytes), source MAC address (6 bytes), source IP address (4 bytes), destination MAC address (6 bytes), and destination IP address (4 bytes). The custom field in the above embodiment can be placed in the above padding field. If the length of the custom field is less than or equal to the length specified by the above padding field, the custom field is placed after the ARP message, and the final field length to be filled is obtained based on the difference between the length of the padding field and the length of the custom field. Based on this length, the corresponding field is filled to generate an ARP request frame, and then the corresponding Ethernet frame is generated. If the length of the custom field is greater than the length specified by the above padding field, it can be encrypted and compressed to be less than or equal to the length specified by the padding field, thereby completing the generation of the ARP request frame.
[0052] Figure 4 The following is a schematic diagram of the format of an Ethernet frame containing OUI information in the related art. Taking the IEEE 802.2 (a framework protocol) encapsulation structure as an example, the Ethernet frame includes an Ethernet destination address (6 bytes), an Ethernet source address (6 bytes), a frame type (2 bytes), a DSAP (Destination Service Access Point, 1 byte), a SSAP (Source Service Access Point, 1 byte), a Control (control field, 1 byte), OUI information (3 bytes), a Protocol ID (2 bytes), an ARP message (28 bytes), padding (10 bytes), and a frame check sequence (4 bytes). The structure of the ARP message is not repeated here. The frame type can be 0x0806, etc. 0x0806 indicates that the Ethernet frame carries ARP data. When the value of the hardware type is 1, it indicates an Ethernet address. When the value of the protocol type is 0x0800, it indicates an IP address. The value of the hardware address length can be 6. The value of the protocol address length can be 4. When the value of the operation code is 1, it indicates a request message, and when its value is 2, it indicates a reply message, that is, a response message.
[0053] Figure 5 For an exemplary format diagram of an Ethernet frame in the address resolution protocol ARP attack defense method provided in an embodiment of the present application, please refer to Figure 5 In this embodiment, Figure 4Custom fields are added to the positions of the fill fields shown, namely, the trusted source MAC address, the trusted source IP address, the trusted MAC destination address, and the trusted IP destination address. Among them, the trusted source MAC address refers to the real MAC address of the data sending end, the trusted source IP address refers to the real IP address of the data sending end, the trusted MAC destination address refers to the encrypted asset identification code of the target data receiving end, and the trusted IP destination address refers to the real IP address of the target data receiving end. By adding the above-mentioned custom fields, ARP attack defense can be better achieved. In addition, the trusted source MAC address, the trusted source IP address, the trusted MAC destination address, and the trusted IP destination address in the custom fields are all encrypted and compressed addresses, so as to meet the data length requirements of the ARP request frame and the Ethernet frame. In addition, by encrypting the above-mentioned trusted addresses, namely, the trusted source MAC address, the trusted source IP address, the trusted MAC destination address, and the trusted IP destination address, the security of the generated Ethernet frame can be improved.
[0054] Figure 6 For an exemplary schematic diagram of an ARP table entry in an ARP attack defense method provided in an embodiment of the present application, please refer to Figure 6 , the ARP table entry includes a one-to-one correspondence between the real IP address and the real MAC address. Figure 6 The specific contents of the real IP address and real MAC address are only exemplary and have no actual meaning, so they will not be repeated here.
[0055] Figure 7 For a schematic diagram of the address storage area of each network device in the ARP attack defense method provided in an embodiment of the present application, please refer to Figure 7 In the ARP attack defense method of the above embodiment, a secure and trusted area is separately set in the storage area of the network device. The secure and trusted area includes an encryption and decryption algorithm storage area, an encrypted asset identification code storage area, a trusted IP address storage area, and a trusted MAC address storage area. The storage area of the network device includes: an application storage area and a boot program storage area. The application storage area includes a false IP address storage area and a false MAC address storage area.
[0056] Figure 8 For a flow chart of sending an ARP request frame in an ARP attack defense method provided in an embodiment of the present application, please refer to Figure 8, assuming that host A needs to send data to host C, then host A needs to search for the MAC address of host C in its ARP table. If the MAC address of host C cannot be found, it is necessary to adopt the ARP attack defense method described in the above embodiment to generate an ARP request frame, and encapsulate the ARP request frame to obtain a corresponding Ethernet frame. The Ethernet frame is transmitted to host B and host C by broadcasting. It can be understood that although both host B and host C receive the Ethernet frame, only host C will respond to the Ethernet frame.
[0057] Fig. 9 A schematic diagram of a process of receiving an Ethernet frame in an ARP attack defense method provided in an embodiment of the present application, such as Fig. 9 As shown, when host C receives the Ethernet frame, it generates an ARP response frame based on its own real MAC address and feeds the ARP response frame back to host A.
[0058] The ARP attack defense method in the above embodiment is further explained below with a specific embodiment.
[0059] Assume that the current network architecture is Figure 2 The architecture shown, then, first, establish a communication connection between CDC and TSP cloud platform. In the visual interface of TSP cloud platform, all network devices (such as all ECU parts, etc.) of the target vehicle are determined according to the VIN code (Vehicle Identification Number) of the vehicle. Encryption and decryption algorithms, encrypted asset identification codes (encrypted asset identification codes of all network devices in the network architecture), trusted IP addresses (encrypted IP addresses of this device), and trusted MAC addresses (encrypted MAC addresses of this device) are installed for each network device. The encrypted asset identification code, trusted IP address, and trusted MAC address of each network device are unique in the entire network. In addition, the trusted IP address and trusted MAC address of each network device are allocated by CDC when the product identification and SOC (System on Chip) identification of the network device are correct, so as to avoid information theft by illegal devices and ensure the secure communication of each network device.
[0060] Secondly, assuming that CDC needs to send data to VDC, CDC searches for VDC's real IP address and real MAC address in its ARP table entry. If it finds VDC's real IP address but fails to find VDC's real MAC address, it generates an ARP request frame and obtains the Ethernet frame to be transmitted.
[0061] The Ethernet frame generated by the related technology includes: FF-FF-FF-FF-FF-FF (Ethernet destination address, FF-FF-FF-FF-FF-FF means empty), 00-00-01-02-03-0a (Ethernet source address), 0x0806 (frame type), DSAP, SSAP, Control, OUI information, Protocol ID, 1 (hardware type, value 1 indicates Ethernet address), 0x0800 (protocol type, 0x0800 indicates IP address), 6 (hardware address length), 4 (protocol address length), 1 (operation code, 1 indicates request message), 00-00-01-02-03-0a (source MAC address), 192.168.69.10 (source IP address), 00-00-00-00-00-00 (destination MAC address), and 192.168.69.5 (destination IP address).
[0062] The Ethernet frame generated by the ARP attack defense method in the above embodiment includes: FF-FF-FF-FF-FF-FF (Ethernet destination address, FF-FF-FF-FF-FF-FF represents null), 00-00-01-02-03-0a (Ethernet source address), 0x0806 (frame type), DSAP, SSAP, Control, OUI information, Protocol ID, 1 (hardware type, value 1 indicates Ethernet address), 0x0800 (protocol type, 0x0800 indicates IP address), 6 (hardware address length), 4 (protocol address length), 1 (operation code, 1 indicates request message), 00-00-02-03-04-0a (source MAC address, false address), 192.168.68.11 (source IP address, false address), 00-00-00-00-00-00 (destination MAC address, false address), 192.168.68.4 (destination IP address, false address), 00-55-05-00-00-0A (encrypted and compressed trusted source MAC address), 192.168.69.110 (encrypted and compressed trusted source IP address), 192.168.69.105 (encrypted and compressed trusted IP destination address), and encrypted ECU asset identification code (encrypted and compressed trusted MAC destination address).
[0063] Compared with the Ethernet frame generated by the related art, the source MAC address, source IP address, destination MAC address, and destination IP address in the Ethernet frame generated by the ARP attack defense method in the above embodiment are replaced with false addresses. In addition, custom fields are added, namely, the trusted source MAC address, the trusted source IP address, the trusted IP destination address, and the trusted MAC destination address.
[0064] Then, the Ethernet frame generated by the ARP attack defense method in the above embodiment is sent to all network devices in the network architecture.
[0065] After that, when the VDC receives the Ethernet frame, it parses and responds to the Ethernet frame, that is, it generates an ARP response frame based on its own real MAC address. The ARP response frame is fed back to the CDC. The ARP response frame includes: 00-00-01-02-03-0a (Ethernet destination address), 00-00-01-02-03-05 (Ethernet source address), 0x0806 (frame type), DSAP, SSAP, Control, OUI information, Protocol ID, 1 (hardware type, value 1 indicates Ethernet address), 0x0800 (protocol type, 0x0800 indicates IP address), 6 (hardware address length), 4 (protocol address length), 2 (operation code, 2 indicates response message), 00-00-01-02-02-03 (source MAC address, false address), 192.168.69.5 (source IP address, false address), 00-00-01-02-03-0a (destination MAC address, false address), 192.168.69.10 (destination IP address, false address), 00-55-05-00-00-05 (encrypted and compressed trusted source MAC address, real encrypted address), 192.168.69.105 (encrypted and compressed trusted source IP address, real encrypted address), 192.168.69.110 (encrypted and compressed trusted IP destination address, real encrypted address), and 00-55-05-00-00-0A (encrypted and compressed trusted MAC destination address, real encrypted address).
[0066] Finally, the VDC and CDC update their ARP entries according to the received information and perform data transmission based on the updated ARP entries.
[0067] Please refer to Fig.10 This embodiment also provides an Address Resolution Protocol ARP attack defense method applied to a data receiving end, the method comprising: S1010: Receive an ARP request frame sent by a data sending end, where the ARP request frame is obtained using the Address Resolution Protocol ARP attack defense method as described in any one of the above.
[0068] S1020: By parsing the ARP request frame, the real IP address of the target data receiving end in the ARP request frame and the encrypted asset identification code of the target data receiving end are obtained. The encrypted asset identification code is pre-stored by the data sending end and added to the ARP request frame.
[0069] S1030: Decrypt the encrypted asset identification code to obtain a decrypted identification code.
[0070] S1040: If the decrypted identification code is the same as the asset identification code pre-stored by the current data receiving end, and the real IP address of the target data receiving end is the same as the real IP address of the current data receiving end, then an ARP response frame is generated based on the real MAC address of the current data receiving end.
[0071] S1050: Send the ARP response frame to the data sending end.
[0072] In some embodiments, generating an ARP response frame based on the real MAC address of the current data receiving end includes: The ARP response frame is generated based on the real MAC address, real IP address, false MAC address, false IP address of the current data receiving end, and the real MAC address, real IP address, false MAC address, false IP address of the data sending end.
[0073] It can be understood that by sending a mixture of true and false addresses, it is possible to prevent attackers from identifying the real address in the ARP response frame, thereby improving information security.
[0074] The data sending end provided in the present application is described below. The data sending end described below and the ARP attack defense method applied to the data sending end described above can be referenced to each other.
[0075] Please refer to Fig.11 , the data sending end provided in this embodiment includes: The demand collection module 1110 is used to obtain data transmission requirements; The data reading module 1120 is used to read the preset ARP table entry according to the data transmission requirement to obtain the real IP address and the real MAC address of the target data receiving end; The message generation module 1130 is used to generate an ARP request frame based on the preset false address of the data sending end, the real address of the data sending end, and the real IP address of the target data receiving end if the real MAC address of the target data receiving end fails to be obtained; The data sending module 1140 is used to send the ARP request frame to the network device in the current network architecture by broadcasting. The data sending end in this embodiment can prevent the attacker from accurately identifying the real address of the data sending end in the ARP request frame, thereby preventing the data sending end from being attacked by ARP, reducing information security risks, and having low cost.
[0076] It should be noted that the data sending end provided in the above embodiment and the ARP attack defense method applied to the data sending end belong to the same concept, wherein the specific manner in which each module and unit performs the operation has been described in detail in the method embodiment, and will not be repeated here. In actual application, the data sending end provided in the above embodiment can allocate the above functions to different functional modules as needed, that is, divide the internal structure of the system into different functional modules to complete all or part of the functions described above, and this is not limited here.
[0077] The data receiving end provided in the present application is described below. The data receiving end described below and the ARP attack defense method applied to the data receiving end described above can be referenced to each other.
[0078] Please refer to Fig.12 , the data receiving end provided in this embodiment includes: A message receiving module 1210 is used to receive an ARP request frame sent by a data sending end, wherein the ARP request frame is obtained by using the address resolution protocol ARP attack defense method as described in any one of the above items; The message parsing module 1220 is used to parse the ARP request frame to obtain the real IP address of the target data receiving end in the ARP request frame, and the encrypted asset identification code of the target data receiving end, where the encrypted asset identification code is pre-stored by the data sending end and added to the ARP request frame; A decryption module 1230, used to decrypt the encrypted asset identification code to obtain a decrypted identification code; The response module 1240 is configured to generate an ARP response frame based on the real MAC address of the current data receiving end if the decrypted identification code is the same as the self-asset identification code pre-stored by the current data receiving end, and the real IP address of the target data receiving end is the same as the real IP address of the current data receiving end; The data sending module 1250 is used to send the ARP response frame to the data sending end. The data receiving end in this embodiment can effectively improve the security of information transmission and avoid information leakage.
[0079] It should be noted that the data receiving end provided in the above embodiment and the ARP attack defense method applied to the data receiving end belong to the same concept, wherein the specific manner in which each module and unit performs the operation has been described in detail in the method embodiment, and will not be repeated here. In actual application, the data receiving end provided in the above embodiment can allocate the above functions to different functional modules as needed, that is, divide the internal structure of the system into different functional modules to complete all or part of the functions described above, and this is not limited here.
[0080] In some embodiments, an electronic device is also provided, which may be a server, and its internal structure is shown in FIG. Fig.13 As shown. The electronic device includes a processor, a memory, a network interface and a database connected via a system bus. The processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile and / or volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the electronic device is used to communicate with an external client via a network connection. When the computer program is executed by the processor, the functions or steps on the server side of the above method are implemented.
[0081] In some embodiments, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented: obtaining a data sending demand; reading data from a preset ARP table entry according to the data sending demand to obtain a real IP address and a real MAC address of a target data receiving end; if the real MAC address of the target data receiving end fails to be obtained, an ARP request frame is generated based on a preset false address of the data sending end, the real address of the data sending end, and the real IP address of the target data receiving end; and the ARP request frame is sent to the network device in the current network architecture by broadcasting.
[0082] In some embodiments, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: obtaining a data sending demand; reading data from a preset ARP table entry according to the data sending demand to obtain a real IP address and a real MAC address of a target data receiving end; if the real MAC address of the target data receiving end fails to be obtained, an ARP request frame is generated based on a preset false address of the data sending end, the real address of the data sending end, and the real IP address of the target data receiving end; and the ARP request frame is sent to the network device in the current network architecture by broadcasting.
[0083] It should be noted that the above functions or steps that can be implemented by the computer-readable storage medium or electronic device can refer to the relevant descriptions on the server side and the client side in the aforementioned method embodiment. To avoid repetition, they will not be described one by one here.
[0084] The flow chart and block diagram in the accompanying drawings illustrate the possible implementation architecture, function and operation of the method and computer program product according to various embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment, or a part of a code, and the module, program segment, or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0085] The above embodiments are merely illustrative of the principles and effects of the present application and are not intended to limit the present application. Anyone familiar with the technology may modify or change the above embodiments without violating the spirit and scope of the present application. Therefore, all equivalent modifications or changes made by a person of ordinary skill in the art without departing from the spirit and technical ideas disclosed in the present application shall still be covered by the claims of the present application.
Claims
1. A method for defending against an address resolution protocol ARP attack, characterized in that: Applied to the data sending end, including: Get data sending requirements; According to the data transmission requirement, the preset ARP table entry is read to obtain the real IP address and real MAC address of the target data receiving end; If the real MAC address of the target data receiving end fails to be obtained, an ARP request frame is generated based on the preset false address of the data sending end, the real address of the data sending end, and the real IP address of the target data receiving end; The ARP request frame is sent to the network devices in the current network architecture by broadcasting.
2. The method for defending against Address Resolution Protocol (ARP) attacks according to claim 1, characterized in that: The ARP request frame includes a source MAC address field, a source IP address field, a destination MAC address field, a destination IP address field and a custom field, wherein the source MAC address field is a false MAC address of the data sending end, the source IP address field is a false IP address of the data sending end, the destination MAC address field is empty, and the destination IP address field is a real IP address or a false IP address of the target data receiving end; If the destination IP address field is the real IP address of the target data receiving end, the custom field includes the real IP address and real MAC address of the data sending end; If the destination IP address field is a false IP address of the target data receiving end, the custom field includes the real IP address and real MAC address of the data sending end, and the real IP address of the target data receiving end.
3. The method for defending against Address Resolution Protocol (ARP) attacks according to claim 2, characterized in that: The custom field also includes a pre-stored encrypted asset identification code of the target data receiving end; The encrypted asset identification code is used to match the self-asset identification code pre-stored by the target data receiving end after decryption, so that the real MAC address of the target data receiving end is fed back to the data sending end when the match is successful.
4. The method for defending against Address Resolution Protocol (ARP) attacks according to claim 1, characterized in that: Also includes: If an ARP response frame is received, the real MAC address of the target data receiving end is obtained by parsing the ARP response frame; Based on the real MAC address of the target data receiving end, the ARP table entry is updated; Data is sent based on the updated ARP entry.
5. The method for defending against Address Resolution Protocol (ARP) attacks according to claim 2 or 3, characterized in that: The real IP address and real MAC address of the data sending end, and the real IP address of the target data receiving end are all encrypted addresses.
6. The method for defending against Address Resolution Protocol (ARP) attacks according to any one of claims 2 to 4, characterized in that: Before sending the ARP request frame to the network device in the current network architecture by broadcasting, the method further includes: If the ARP request frame contains an organization unique identifier, the organization unique identifier in the ARP request frame is deleted, or the organization unique identifier in the ARP request frame is adjusted from an original position to the custom field.
7. A method for defending against an address resolution protocol ARP attack, characterized in that: Applied to the data receiving end, including: Receiving an ARP request frame sent by a data sending end, wherein the ARP request frame is obtained by using the address resolution protocol ARP attack defense method according to any one of claims 1 to 6; By parsing the ARP request frame, the real IP address of the target data receiving end in the ARP request frame and the encrypted asset identification code of the target data receiving end are obtained, where the encrypted asset identification code is pre-stored by the data sending end and added to the ARP request frame; Decrypting the encrypted asset identification code to obtain a decrypted identification code; If the decrypted identification code is the same as the asset identification code pre-stored by the current data receiving end, and the real IP address of the target data receiving end is the same as the real IP address of the current data receiving end, then an ARP response frame is generated based on the real MAC address of the current data receiving end; The ARP response frame is sent to the data sending end.
8. The method for defending against Address Resolution Protocol (ARP) attacks according to claim 7, characterized in that: Based on the real MAC address of the current data receiving end, an ARP response frame is generated, including: The ARP response frame is generated based on the real MAC address, real IP address, false MAC address, false IP address of the current data receiving end, and the real MAC address, real IP address, false MAC address, false IP address of the data sending end.
9. A data transmitting end, characterized in that: include: Demand collection module, used to obtain data sending requirements; A data reading module is used to read data from a preset ARP table entry according to the data transmission requirement to obtain a real IP address and a real MAC address of a target data receiving end; A message generation module, configured to generate an ARP request frame based on a preset false address of the data sending end, a real address of the data sending end, and a real IP address of the target data receiving end if the real MAC address of the target data receiving end fails to be obtained; The data sending module is used to send the ARP request frame to the network equipment in the current network architecture by broadcasting.
10. A data receiving end, characterized in that: include: A message receiving module, used for receiving an ARP request frame sent by a data sending end, wherein the ARP request frame is obtained by using the address resolution protocol ARP attack defense method according to any one of claims 1 to 6; A message parsing module, used to parse the ARP request frame to obtain the real IP address of the target data receiving end in the ARP request frame, and the encrypted asset identification code of the target data receiving end, where the encrypted asset identification code is pre-stored by the data sending end and added to the ARP request frame; A decryption module, used to decrypt the encrypted asset identification code to obtain a decrypted identification code; A response module, configured to generate an ARP response frame based on the real MAC address of the current data receiving end if the decrypted identification code is the same as the self-asset identification code pre-stored by the current data receiving end, and the real IP address of the target data receiving end is the same as the real IP address of the current data receiving end; A data sending module is used to send the ARP response frame to the data sending end.
Citation Information
Patent Citations
Method and device for processing address analysis protocol request message
CN101257517A
Message processing method and exchange equipment
CN103095584A
DDoS attack defense method and equipment
CN115766155A
ARP spoofing defense method and system, electronic equipment and storage medium
CN119094212A
Network forwarding method and device for avoiding MAC table item drift
CN119383149A