ARP Attack Defense Method, Data Sending End, and Data Receiving End
By generating ARP request frames containing fake addresses and broadcasting them, the problem of data leakage in network devices in ARP attacks is solved, the information security risks are reduced and the attacker identification is realized.
Patent Information
- Application Number
- CN202510435882.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-04-09
AI Technical Summary
In the prior art, network equipment is prone to data leakage when it is attacked by ARP, which poses a major information security risk.
By obtaining the data transmission requirements, the real IP address and MAC address of the target data receiver are read according to the preset ARP table entry. If the acquisition fails, an ARP request frame containing a false address is generated and sent to the network device through broadcast.
It effectively avoids ARP attacks from the data sending end, reduces information security risks, and facilitates identification of attackers.
Smart Images

Figure CN119945807B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to an ARP attack defense method, a data sender, and a data receiver. Background Art
[0002] An ARP (Address Resolution Protocol) attack is a network attack method against the ARP protocol in a local area network (LAN). If a network device in a local area network wants to communicate with other network devices, it needs to know the IP (Internet Protocol) address and MAC (Media Access Control) address of the other party.
[0003] When a network device needs to send data, if the MAC address of the target data receiver is not in its ARP table entry, it needs to send an ARP request to all network devices in the network architecture through the ARP protocol to obtain the MAC address of the target data receiver. At this time, the attacker forges an ARP response frame, causing the current network device to transmit the data that was originally intended to be transmitted to the target data receiver to the attacker, resulting in data leakage and posing a serious threat to information security. Summary of the Invention
[0004] This application provides an ARP attack defense method, a data sender, and a data receiver to solve the technical problem that network devices are prone to data leakage and pose a large information security risk when being attacked by ARP in related technologies.
[0005] An ARP attack defense method provided by this application is applied to a data sender, and the method includes:
[0006] Obtain a data sending requirement;
[0007] According to the data sending requirement, read data from a preset ARP table entry to obtain the real IP address and real MAC address of the target data receiver;
[0008] If the acquisition of the real MAC address of the target data receiver fails, generate an ARP request frame based on the false address of the preset data sender, the real address of the data sender, and the real IP address of the target data receiver;
[0009] Send the ARP request frame to the network devices in the current network architecture in a broadcast manner.
[0010] In some embodiments of the present application, the ARP request frame includes a source MAC address field, a source IP address field, a destination MAC address field, a destination IP address field, and a custom field. The source MAC address field is a false MAC address of the data sender, the source IP address field is a false IP address of the data sender, the destination MAC address field is empty, and the destination IP address field is the real IP address or false IP address of the target data receiver;
[0011] If the destination IP address field is the real IP address of the target data receiver, the custom field includes the real IP address and real MAC address of the data sender;
[0012] If the destination IP address field is the false IP address of the target data receiver, the custom field includes the real IP address and real MAC address of the data sender, and the real IP address of the target data receiver.
[0013] In some embodiments of the present application, the custom field further includes an encrypted asset identification code of the target data receiver stored in advance;
[0014] The encrypted asset identification code is used to match with the self - asset identification code pre - stored in the target data receiver after decryption, so as to feedback the real MAC address of the target data receiver to the data sender when the matching is successful.
[0015] In some embodiments of the present application, it further includes:
[0016] If an ARP response frame is received, the real MAC address of the target data receiver is obtained by parsing the ARP response frame;
[0017] Based on the real MAC address of the target data receiver, the ARP entry is updated;
[0018] Based on the updated ARP entry, data is sent.
[0019] In some embodiments of the present application, the real IP address, real MAC address of the data sender, and the real IP address of the target data receiver are all encrypted addresses.
[0020] In some embodiments of the present application, before the ARP request frame is sent to network devices in the current network architecture by broadcasting, it further includes:
[0021] If the Organizationally Unique Identifier is included in the ARP request frame, delete the Organizationally Unique Identifier in the ARP request frame, or adjust the Organizationally Unique Identifier in the ARP request frame from its original position to the custom field.
[0022] The present application also provides an Address Resolution Protocol (ARP) attack defense method, which is applied to a data receiving end and includes:
[0023] Receiving an ARP request frame sent by a data sending end, where the ARP request frame is obtained by using the Address Resolution Protocol (ARP) attack defense method described in any one of the above;
[0024] By parsing the ARP request frame, obtaining the real IP address of the target data receiving end in the ARP request frame and the encrypted asset identification code of the target data receiving end, where the encrypted asset identification code is pre-stored by the data sending end and added to the ARP request frame;
[0025] Decrypting the encrypted asset identification code to obtain the decrypted identification code;
[0026] If the decrypted identification code is the same as the self-asset identification code pre-stored by the current data receiving end, and the real IP address of the target data receiving end is the same as the real IP address of the current data receiving end, then generate an ARP response frame based on the real MAC address of the current data receiving end;
[0027] Sending the ARP response frame to the data sending end.
[0028] In some embodiments of the present application, generating an ARP response frame based on the real MAC address of the current data receiving end includes:
[0029] Generating the ARP response frame based on the real MAC address, real IP address, false MAC address, false IP address of the current data receiving end, and the real MAC address, real IP address, false MAC address, false IP address of the data sending end.
[0030] The present application also provides a data sending end, including:
[0031] A requirement collection module, configured to obtain a data sending requirement;
[0032] A data reading module, configured to read data from a preset ARP entry according to the data sending requirement to obtain the real IP address and real MAC address of the target data receiving end;
[0033] A message generation module, configured to generate an ARP request frame based on a preset false address of the data sender, the real address of the data sender, and the real IP address of the target data receiver if the acquisition of the real MAC address of the target data receiver fails;
[0034] A data sending module, configured to send the ARP request frame to network devices in the current network architecture in a broadcast manner.
[0035] This application also provides a data receiver, including:
[0036] A message receiving module, configured to receive an ARP request frame sent by a data sender, where the ARP request frame is obtained by using the address resolution protocol ARP attack defense method described in any one of the above;
[0037] A message parsing module, configured to parse the ARP request frame to obtain the real IP address of the target data receiver in the ARP request frame and the encrypted asset identification code of the target data receiver, where the encrypted asset identification code is pre-stored by the data sender and added to the ARP request frame;
[0038] A decryption module, configured to decrypt the encrypted asset identification code to obtain the decrypted identification code;
[0039] A response module, configured to generate an ARP response frame based on the real MAC address of the current data receiver if the decrypted identification code is the same as the self-asset identification code pre-stored by the current data receiver, and the real IP address of the target data receiver is the same as the real IP address of the current data receiver;
[0040] A data sending module, configured to send the ARP response frame to the data sender.
[0041] Advantages of the embodiments of the present application: The ARP attack defense method, data sender, and data receiver provided by the embodiments of the present application obtain data sending requirements; read data from a preset ARP entry according to the data sending requirements to obtain the real IP address and real MAC address of the target data receiver; if the real MAC address of the target data receiver fails to be obtained, an ARP request frame is generated based on the false address of the preset data sender, the real address of the data sender, and the real IP address of the target data receiver; and the ARP request frame is sent to network devices in the current network architecture in a broadcast manner. By generating an ARP request frame based on the true and false addresses of the data sender, this method can prevent an attacker from accurately identifying the real address of the data sender in the ARP request frame, thereby avoiding the data sender from being attacked by ARP and reducing information security risks. Moreover, in the above manner, it is also convenient to identify the attacker. It can be understood that if the attacker sends an ARP response frame to the false address in the ARP request frame, by monitoring the network device corresponding to the false address and parsing the ARP response frame received by the network device, the address of the attacker can be identified, thus realizing attacker identification. Description of the Drawings
[0042] Figure 1 It is an exemplary schematic diagram of the vehicle network architecture provided by an embodiment of the present application;
[0043] Figure 2 It is an interaction schematic diagram between the CDC (Cockpit Domain Controller, intelligent cockpit) and other network devices in the vehicle network architecture provided by an embodiment of the present application;
[0044] Figure 3 It is a flowchart of the ARP attack defense method applied to the data sender provided by an embodiment of the present application;
[0045] Figure 4 It is a format schematic diagram of an Ethernet frame (Eth Frame) containing OUI (Organizationally Unique Identifier) information in the related art;
[0046] Figure 5 It is an exemplary format schematic diagram of an Ethernet frame in the ARP attack defense method provided by an embodiment of the present application;
[0047] Figure 6 It is an exemplary schematic diagram of an ARP entry in the ARP attack defense method provided by an embodiment of the present application;
[0048] Figure 7 Schematic diagram of the address storage area of each network device in the ARP attack defense method provided by an embodiment of the present application;
[0049] Figure 8 Schematic diagram of the process of sending an Ethernet frame in the ARP attack defense method provided by an embodiment of the present application;
[0050] Figure 9 Schematic diagram of the process of receiving an Ethernet frame in the ARP attack defense method provided by an embodiment of the present application;
[0051] Figure 10 Schematic diagram of the process of the ARP attack defense method applied to the data receiving end provided by an embodiment of the present application;
[0052] Figure 11 Schematic diagram of the structure of the data sending end provided by an embodiment of the present application;
[0053] Figure 12 Schematic diagram of the structure of the data receiving end provided by an embodiment of the present application;
[0054] Figure 13 Schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0055] The following uses specific specific examples to illustrate the implementation manners of the present application. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0056] It should be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present application in a schematic manner. Therefore, only the components related to the present application are shown in the diagrams, rather than being drawn according to the number, shape, and size of the components in actual implementation. The types, quantities, and proportions of the components in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.
[0057] In the following description, a large number of details are discussed to provide a more thorough explanation of the embodiments of the present application. However, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present application difficult to understand.
[0058] The ARP attack defense method, data sender, and data receiver provided in this application can be applied to many fields, such as vehicle network architectures, enterprise networks, and the Internet of Things, etc. Taking the vehicle network architecture as an example below, the ARP attack defense method, data sender, and data receiver provided in this application will be explained.
[0059] Please refer to Figure 1 , Figure 1 for an exemplary display of the vehicle network architecture (electronic and electrical architecture). As Figure 1 shown, this vehicle network architecture adopts an Ethernet ring network architecture design. The advantages of the ring network architecture are that it supports SOA (Service-Oriented Architecture) serviceization and communication channel protection, and moreover, it supports each ECU (Electronic Control Unit) component to be connected nearby according to function classification, saving wiring harness costs. Figure 1 In, the CDC can be connected to the cloud, such as the OTA (Over-The-Air) cloud platform, etc., through a 4G / 5G or WIFI (Wireless Fidelity) channel, so as to realize the communication between the vehicle system and the outside world. VIU1, VIU2, VIU3, and VIU4 (VIU represents Virtual Input Unit, that is, virtual input unit) are connected through Ethernet to form a ring network structure. VIU1, VIU2, VIU3, and VIU4 are respectively connected with relevant ECU components below (such as Figure 1 the ECU1-1......ECU1-n, ECU2-1......ECU2-n, ECU3-1......ECU3-n, ECU4-1......ECU4-n in, n represents the number of ECU components related to VIU). Each ECU component can be a network device supporting Ethernet or a network device not supporting Ethernet (such as supporting CAN communication). In addition, this vehicle network architecture also includes a VDC (Virtual Data Center). The VDC can also establish communication with VIUs, such as VIU1, VIU2, etc. It should be mentioned that Figure 1 in, US represents Universal Serial, that is, a general serial interface. UMC represents USB Modem Controller, that is, USB modem controller interface, Figure 1 UMC0, UMC1, UMC2, UMC3, UMC4, and UMC5 in represent different USB modem controller interfaces.
[0060] Figure 1An exemplary display of the general framework of the vehicle network architecture is provided. Figure 2 Then, a further exemplary display of the interaction between CDC and other network devices in the vehicle network architecture is provided. Please refer to Figure 2 , Figure 2 where CDC is respectively connected to VIU1, VIU2, VIU3, VIU4, and VDC. Moreover, in addition to the Figure 1 OTA cloud platform shown, CDC can also interact with the TSP (Telematics Service Provider) cloud platform. As Figure 2 shown, each network device, such as CDC, VDC, VIU1, VIU2, VIU3, and VIU4, etc., has corresponding IP addresses and MAC addresses. Figure 2 An exemplary display of the IP addresses and MAC addresses of each network device is provided in
[0061] Assume Figure 2The CDC in it needs to send data to the VDC. Usually, the CDC needs to look up the IP address and MAC address of the VDC in its preset ARP entry. If the MAC address of the VDC does not exist in this ARP entry, it is necessary to generate an ARP request frame through the ARP protocol. This ARP request frame includes: source MAC address, source IP address, destination MAC address, and destination IP address, etc. It can be understood that the source MAC address here is the real MAC address of the CDC, the source IP address is the real IP address of the CDC, the destination MAC address is empty, and the destination IP address is the real IP address of the VDC. In the case of generating an ARP request frame, the CDC broadcasts this ARP request frame to all network devices within the network architecture. When each network device receives this ARP request frame, it will parse this ARP request frame to obtain the destination IP address in this ARP request frame. The destination IP address is matched with the real IP address of the network device itself. If the match is successful, the real MAC address of itself is fed back to the CDC. Based on this feedback, the CDC updates the data in its ARP entry and uses this for subsequent data transmission. During this process, an attacker (such as a Hacker) will also receive this ARP request frame. Therefore, after the VDC feeds back its MAC address, the attacker can forge an ARP response frame and transmit this forged ARP response frame to the CDC to complete an ARP attack. It can be understood that since the update principle of the ARP entry in the network device is the "later arrival takes precedence" principle, after the CDC receives the forged ARP response frame, it will update the address of the VDC in the ARP entry of the CDC to the address forged by the attacker. This results in the interruption of normal communication between the CDC and the VDC, and moreover, information leakage will occur in the CDC, and in serious cases, it may even lead to major safety accidents in the vehicle, etc. In order to avoid this situation, the ARP attack defense method, data sender, and data receiver provided in this application obtain the data sending requirement; according to the data sending requirement, read data from the preset ARP entry to obtain the real IP address and real MAC address of the target data receiver; if the real MAC address of the target data receiver fails to be obtained, an ARP request frame is generated based on the false address of the preset data sender, the real address of the data sender, and the real IP address of the target data receiver; the ARP request frame is sent to the network devices in the current network architecture in a broadcast manner. Through the above method, the ARP attack risk of the data sender is reduced, and data leakage and the like are avoided.
[0062] The following will be combined with Figures 3 to 13 to explain the ARP attack defense method, data sender, and data receiver provided in this application.
[0063] Please refer to Figure 3 andFigure 3 The flowchart of the ARP attack defense method applied to the data sending end provided by an embodiment of the present application is shown as Figure 1 shown. The method includes:
[0064] S310: Obtain the data sending requirement.
[0065] S320: According to the data sending requirement, read data from the preset ARP entry to obtain the real IP address and real MAC address of the target data receiving end.
[0066] In some examples of this embodiment, the ARP entry includes the real IP addresses and real MAC addresses of multiple network devices.
[0067] S330: If the acquisition of the real MAC address of the target data receiving end fails, generate an ARP request frame based on the false address of the preset data sending end, the real address of the data sending end, and the real IP address of the target data receiving end.
[0068] It can be understood that by generating the ARP request frame based on the true and false addresses of the data sending end, the attacker cannot accurately identify the real address of the data sending end in the ARP request frame, thereby avoiding the data sending end from being attacked by ARP and effectively reducing the information security risk.
[0069] In some examples of this embodiment, the ARP request frame in step S330 includes: a source MAC address field, a source IP address field, a destination MAC address field, a destination IP address field, and a custom field, etc. Here, the source MAC address field is the false MAC address of the data sending end, the source IP address field is the false IP address of the data sending end, the destination MAC address field is empty, and the destination IP address field is the real IP address of the target data receiving end. The custom field includes: the real IP address and real MAC address of the data sending end, etc. In this way, the attacker cannot identify the real IP address and real MAC address of the data sending end, avoiding the data sending end from being attacked by ARP and at the same time avoiding data leakage. It can be understood that since the positions of the original "source MAC address" and "source IP address" are both replaced with false addresses, even if the attacker receives the ARP request frame, the address parsed for the data sending end is also a false address, thereby avoiding the data sending end from being attacked by ARP.
[0070] S340: Send the ARP request frame to the network devices in the current network architecture by broadcasting.
[0071] It can be understood that the ARP request frame is encapsulated into an Ethernet frame and the Ethernet frame is sent to each network device in the current network architecture in a broadcast manner, so as to achieve the broadcast of the ARP request.
[0072] In some examples of this embodiment, when a network device receives an ARP request frame, it can parse the ARP request frame to obtain the real IP address of the target data receiver. The real IP address of the target data receiver is matched with its own real IP address. If the match is successful, an ARP response frame is generated based on its own real MAC address and the ARP response frame is sent to the data sender. When the data sender receives the ARP response frame, it parses the ARP response frame to obtain the real MAC address of the target data receiver and updates the real MAC address to its ARP entry. Subsequently, data transmission is performed based on the addresses in the ARP entry.
[0073] In order to prevent an attacker from obtaining the address information of the data receiver through the ARP request frame, in some embodiments, the destination IP address field is the false IP address of the target data receiver. On this basis, the custom field includes the real IP address and real MAC address of the data sender, and the real IP address of the target data receiver.
[0074] In some examples of this embodiment, the ARP request frame includes: a source MAC address field, a source IP address field, a destination MAC address field, a destination IP address field, and a custom field, etc. Here, the source MAC address field is the false MAC address of the data sender, the source IP address field is the false IP address of the data sender, the destination MAC address field is empty, and the destination IP address field is the false IP address of the target data receiver. The custom field includes: the real IP address and real MAC address of the data sender, and the real IP address of the target data receiver, etc.
[0075] It can be understood that by writing the false IP address into the destination IP address field of the ARP request frame, it is possible to prevent an attacker from obtaining the real IP address of the target data receiver by parsing the ARP request frame and avoid disclosing the address of the target data receiver.
[0076] In order to further improve the security level of the ARP request frame and improve the defense against ARP attacks, in some embodiments, the custom field further includes the encrypted asset identification code of the target data receiver stored in advance. In some instances of this embodiment, the encrypted asset identification code is stored in advance in the preset address storage area of each device (data sender and data receiver).
[0077] The encrypted asset identification code is used to match with the self - asset identification code pre - stored in the target data receiver after decryption, so that when the matching is successful, the real MAC address of the target data receiver is fed back to the data sender.
[0078] It can be understood that after receiving the ARP request frame, the data receiver will decrypt the encrypted asset identification code in the ARP request frame, and match the decrypted identification code with the self - asset identification code pre - stored. If the matching is successful, an ARP response frame is sent to the data sender to feed back the real MAC address of the target data receiver to the data sender.
[0079] In some examples of this embodiment, the ARP request frame generated in the above - mentioned manner includes: a source MAC address field, a source IP address field, a destination MAC address field, a destination IP address field, and a custom field, etc. Here, the source MAC address field is the false MAC address of the data sender, the source IP address field is the false IP address of the data sender, the destination MAC address field is empty, and the destination IP address field is the false IP address of the target data receiver. The custom field includes: the real IP address of the data sender, the real MAC address, the real IP address of the target data receiver, and the encrypted asset identification code of the target data receiver.
[0080] It can be understood that by adding the encrypted asset identification code of the target data receiver to the custom field of the ARP request frame, the security of the ARP request process can be further improved. For the data receiver, compared with the method of only matching the destination IP address, the method of matching the self - asset identification code with the decrypted identification code can improve the accuracy of the ARP response more.
[0081] In some examples of this embodiment, the encrypted asset identification code can be encrypted and generated based on information such as the ID (Device Identifier) of each network device in the current network architecture. Each network device corresponds to a unique encrypted asset identification code. By pre - generating the corresponding encrypted asset identification code for each network device in the network architecture, it is convenient for the network device to add the encrypted asset identification code when generating the ARP request frame to further improve data transmission security.
[0082] In some embodiments, the method further includes:
[0083] First, if the ARP response frame is received, the real MAC address of the target data receiver is obtained by parsing the ARP response frame.
[0084] Second, based on the real MAC address of the target data receiver, the ARP entry is updated.
[0085] III. Based on the updated ARP entry, data is sent.
[0086] It can be understood that through the above steps, a closed-loop of the ARP request process can be better achieved.
[0087] In some embodiments, the real address of the data sending end and the real IP address of the target data receiving end are both encrypted addresses.
[0088] It can be understood that by encrypting (encrypting and compressing) the real address of the data sending end and the real IP address of the target data receiving end, the security of data transmission can be effectively improved.
[0089] In the related art, some ARP request frames also include the OUI information of the data sending end and / or the target data receiving end. An attacker can easily obtain the above OUI information by parsing the packet, resulting in the leakage of the OUI information. To avoid leaking the OUI information, in some embodiments, before sending the ARP request frame to the network devices in the current network architecture by broadcast, the method further includes:
[0090] If the ARP request frame contains an organizationally unique identifier, delete the organizationally unique identifier in the ARP request frame, or adjust the organizationally unique identifier in the ARP request frame from its original position to the custom field. For example: adjust the organizationally unique identifier from its original position to the end of the custom field, etc.
[0091] It can be understood that by deleting the organizationally unique identifier in the ARP request frame or adjusting the organizationally unique identifier from its original position to the custom field, it is possible to avoid providing an attack target for the attacker, that is, to prevent the attacker from identifying the OUI information and causing information leakage.
[0092] It can also be understood that in the case of not including OUI information, the ARP request frame min (the minimum length of the ARP request frame) = ARP packet (28 bytes (Byte)) + padding (18 bytes) = 46 bytes, Ethernet frame min (the minimum length of the Ethernet frame) = Ethernet destination address (MAC address field for identifying the receiver, 6 bytes) + Ethernet source address (MAC address field for identifying the sender, 6 bytes) + frame type (2 bytes) + ARP request frame min(46 bytes) + Frame Check Sequence (FCS, 4 bytes) = 64 bytes. The ARP packet includes: Hardware Type (2 bytes), Protocol Type (2 bytes), Hardware Address Length (1 byte), Protocol Address Length (1 byte), Operation Code (2 bytes), Source MAC Address (6 bytes), Source IP Address (4 bytes), Destination MAC Address (6 bytes), and Destination IP Address (4 bytes). The custom field in the above embodiments can be placed in the above padding field. If the length of the custom field is less than or equal to the length specified by the above padding field, the custom field is placed at the end of the ARP packet, and based on the difference between the length of the padding field and the length of the custom field, the length of the finally to-be-filled field is obtained. Based on this length, corresponding field filling is performed to generate an ARP request frame, and then a corresponding Ethernet frame is generated. If the length of the custom field is greater than the length specified by the above padding field, it can be made less than or equal to the length specified by the padding field through encryption and compression, so as to complete the generation of the ARP request frame.
[0093] Figure 4 It is a schematic diagram of the format of an Ethernet frame containing OUI information in the related art. Taking the encapsulation structure of IEEE 802.2 (a framework protocol) as an example, the Ethernet frame includes Ethernet Destination Address (6 bytes), Ethernet Source Address (6 bytes), Frame Type (2 bytes), DSAP (Destination Service Access Point, 1 byte), SSAP (Source Service Access Point, 1 byte), Control (control field, 1 byte), OUI information (3 bytes), Protocol ID (2 bytes), ARP packet (28 bytes), Padding (10 bytes), and Frame Check Sequence (4 bytes). The structure of the ARP packet will not be elaborated here. The frame type can be 0x0806, etc. 0x0806 indicates that the Ethernet frame carries ARP data. When the value of the hardware type is 1, it indicates an Ethernet address. When the value of the protocol type is 0x0800, it indicates an IP address. The value of the hardware address length can be 6. The value of the protocol address length can be 4. When the value of the operation code is 1, it indicates a request packet, and when its value is 2, it indicates a response packet, that is, a reply packet.
[0094] Figure 5 It is a schematic diagram of an exemplary format of an Ethernet frame in the ARP attack defense method provided by an embodiment of the present application. Please refer to Figure 5 , this embodiment is in Figure 4The positions of the filled fields shown add custom fields, namely the trusted source MAC address, the trusted source IP address, the trusted MAC destination address, and the trusted IP destination address. Among them, the trusted source MAC address refers to the real MAC address of the data sending end, the trusted source IP address refers to the real IP address of the data sending end, the trusted MAC destination address refers to the encrypted asset identification code of the target data receiving end, and the trusted IP destination address refers to the real IP address of the target data receiving end. By adding the above custom fields, ARP attack prevention can be better achieved. In addition, the trusted source MAC address, the trusted source IP address, the trusted MAC destination address, and the trusted IP destination address in the custom fields are all encrypted and compressed addresses to meet the data length requirements of the ARP request frame and the Ethernet frame. And by encrypting the above trusted addresses, namely the trusted source MAC address, the trusted source IP address, the trusted MAC destination address, and the trusted IP destination address, the security level of the generated Ethernet frame can be improved.
[0095] Figure 6 For an exemplary schematic diagram of the ARP table entry in the ARP attack prevention method provided by an embodiment of this application, please refer to Figure 6 , the ARP table entry includes a corresponding real IP address and a real MAC address. Figure 6 The specific contents in the real IP address and the real MAC address in [[ ]] are only exemplary contents and have no actual reference meaning, so they will not be elaborated here.
[0096] Figure 7 For a schematic diagram of the address storage area of each network device in the ARP attack prevention method provided by an embodiment of this application, please refer to Figure 7 , in the ARP attack prevention method of the above embodiment, a secure and trusted area is separately set in the storage area of the network device. This secure and trusted area includes an encryption and decryption algorithm storage area, an encrypted asset identification code storage area, a trusted IP address storage area, and a trusted MAC address storage area. The storage area of the network device includes: an application program storage area and a boot program storage area. The application program storage area includes a false IP address storage area and a false MAC address storage area.
[0097] Figure 8 For a schematic diagram of the process of sending an ARP request frame in the ARP attack prevention method provided by an embodiment of this application, please refer to Figure 8, assume that host A needs to send data to host C. Then, host A needs to look up the MAC address of host C in its ARP table entry. If the MAC address of host C cannot be found, it is necessary to adopt the ARP attack defense method described in the above embodiment to generate an ARP request frame and encapsulate the ARP request frame to obtain the corresponding Ethernet frame. The Ethernet frame is transmitted to host B and host C by means of broadcasting. It can be understood that although both host B and host C receive the Ethernet frame, only host C will respond to the Ethernet frame.
[0098] Figure 9 The flowchart of receiving an Ethernet frame in the ARP attack defense method provided by an embodiment of the present application is as Figure 9 shown. When host C receives the Ethernet frame, it generates an ARP response frame based on its own true MAC address and feeds back the ARP response frame to host A.
[0099] The ARP attack defense method in the above embodiment will be further explained below with a specific example.
[0100] Assume that the current network architecture is Figure 2 as shown in the figure. First, establish a communication connection between the CDC and the TSP cloud platform. In the visualization interface of the TSP cloud platform, all network devices (such as all ECU components, etc.) of the target vehicle are determined according to the VIN code (Vehicle Identification Number) of the vehicle. Encryption and decryption algorithms, encrypted asset identification codes (encrypted asset identification codes of all network devices in this network architecture), trusted IP addresses (encrypted IP addresses of this device), and trusted MAC addresses (encrypted MAC addresses of this device) are respectively installed on each network device. The encrypted asset identification codes, trusted IP addresses, and trusted MAC addresses of each network device are unique throughout the network. In addition, the trusted IP addresses and trusted MAC addresses of each network device are allocated by the CDC when the product identification and SOC (System on Chip) identification of the network device are correct, so as to avoid information being stolen by illegal devices and ensure the secure communication of each network device.
[0101] Secondly, assume that the CDC needs to send data to the VDC. Then, the CDC looks up the true IP address and true MAC address of the VDC in its ARP table entry. If the true IP address of the VDC is found and the true MAC address of the VDC cannot be found, an ARP request frame is generated, and then the Ethernet frame to be transmitted is obtained.
[0102] The Ethernet frames generated by the related technology include: FF-FF-FF-FF-FF-FF (Ethernet destination address, FF-FF-FF-FF-FF-FF represents null), 00-00-01-02-03-0a (Ethernet source address), 0x0806 (frame type), DSAP, SSAP, Control, OUI information, Protocol ID, 1 (hardware type, value 1 represents Ethernet address), 0x0800 (protocol type, 0x0800 represents IP address), 6 (hardware address length), 4 (protocol address length), 1 (operation code, 1 represents request message), 00-00-01-02-03-0a (source MAC address), 192.168.69.10 (source IP address), 00-00-00-00-00-00 (destination MAC address), and 192.168.69.5 (destination IP address).
[0103] The Ethernet frames generated by using the ARP attack defense method in the above embodiment include: FF-FF-FF-FF-FF-FF (Ethernet destination address, FF-FF-FF-FF-FF-FF represents null), 00-00-01-02-03-0a (Ethernet source address), 0x0806 (frame type), DSAP, SSAP, Control, OUI information, Protocol ID, 1 (hardware type, value 1 represents Ethernet address), 0x0800 (protocol type, 0x0800 represents IP address), 6 (hardware address length), 4 (protocol address length), 1 (operation code, 1 represents request message), 00-00-02-03-04-0a (source MAC address, fake address), 192.168.68.11 (source IP address, fake address), 00-00-00-00-00-00 (destination MAC address, fake address), 192.168.68.4 (destination IP address, fake address), 00-55-05-00-00-0A (encrypted and compressed trusted source MAC address), 192.168.69.110 (encrypted and compressed trusted source IP address), 192.168.69.105 (encrypted and compressed trusted IP destination address), and the encrypted ECU asset identification code (encrypted and compressed trusted MAC destination address).
[0104] Compared with the Ethernet frames generated by the related technology, in the Ethernet frames generated by using the ARP attack defense method in the above embodiment, the source MAC address, source IP address, destination MAC address, and destination IP address are all replaced with fake addresses. And custom fields are added, namely the trusted source MAC address, trusted source IP address, trusted IP destination address, and trusted MAC destination address.
[0105] Then, send the Ethernet frame generated by using the ARP attack defense method in the above embodiment to all network devices in the network architecture.
[0106] After that, when the VDC receives the Ethernet frame, it parses and replies to the Ethernet frame, that is, based on its own real MAC address, generates an ARP response frame. Feed the ARP response frame back to the CDC. The ARP response frame includes: 00-00-01-02-03-0a (Ethernet destination address), 00-00-01-02-03-05 (Ethernet source address), 0x0806 (frame type), DSAP, SSAP, Control, OUI information, Protocol ID, 1 (hardware type, the value of 1 indicates Ethernet address), 0x0800 (protocol type, 0x0800 indicates IP address), 6 (hardware address length), 4 (protocol address length), 2 (operation code, 2 indicates response message), 00-00-01-02-02-03 (source MAC address, false address), 192.168.69.5 (source IP address, false address), 00-00-01-02-03-0a (destination MAC address, false address), 192.168.69.10 (destination IP address, false address), 00-55-05-00-00-05 (encrypted and compressed trusted source MAC address, real encrypted address), 192.168.69.105 (encrypted and compressed trusted source IP address, real encrypted address), 192.168.69.110 (encrypted and compressed trusted IP destination address, real encrypted address), and 00-55-05-00-00-0A (encrypted and compressed trusted MAC destination address, real encrypted address).
[0107] Finally, the VDC and the CDC update their ARP entries according to the received information. Perform data transmission based on the updated ARP entries.
[0108] Please refer to Figure 10 , this embodiment also provides an ARP attack defense method applied to a data receiving end, and the method includes:
[0109] S1010: Receive an ARP request frame sent by a data sending end, where the ARP request frame is obtained by using the ARP attack defense method described in any one of the above.
[0110] S1020: By parsing the ARP request frame, obtain the real IP address of the target data receiving end in the ARP request frame, and the encrypted asset identification code of the target data receiving end, where the encrypted asset identification code is pre-stored by the data sending end and added to the ARP request frame.
[0111] S1030: Decrypt the encrypted asset identification code to obtain the decrypted identification code.
[0112] S1040: If the decrypted identification code is the same as the self - asset identification code pre - stored in the current data receiving end, and the real IP address of the target data receiving end is the same as the real IP address of the current data receiving end, then generate an ARP response frame based on the real MAC address of the current data receiving end.
[0113] S1050: Send the ARP response frame to the data sending end.
[0114] In some embodiments, generating an ARP response frame based on the real MAC address of the current data receiving end includes:
[0115] Generate the ARP response frame based on the real MAC address, real IP address, false MAC address, false IP address of the current data receiving end, and the real MAC address, real IP address, false MAC address, false IP address of the data sending end.
[0116] It can be understood that by mixing and sending true and false addresses, attackers can be prevented from identifying the real addresses in the ARP response frame, improving information security.
[0117] The data sending end provided by the present application will be described below. The data sending end described below can be correspondingly referred to the ARP attack defense method applied to the data sending end described above.
[0118] Please refer to Figure 11 , the data sending end provided in this embodiment includes:
[0119] A requirement acquisition module 1110, configured to obtain data sending requirements;
[0120] A data reading module 1120, configured to read data from a preset ARP entry according to the data sending requirements to obtain the real IP address and real MAC address of the target data receiving end;
[0121] A packet generation module 1130, configured to generate an ARP request frame based on the false address of the preset data sending end, the real address of the data sending end, and the real IP address of the target data receiving end if the real MAC address of the target data receiving end fails to be obtained;
[0122] A data sending module 1140 is configured to send the ARP request frame to network devices in the current network architecture in a broadcast manner. In this embodiment, the data sender can prevent an attacker from accurately identifying the real address of the data sender in the ARP request frame, thereby avoiding the data sender from being attacked by ARP, reducing information security risks, and having a relatively low cost.
[0123] It should be noted that the data sender provided in the above embodiment and the ARP attack defense method applied to the data sender belong to the same concept. The specific ways in which each module and unit perform operations have been described in detail in the method embodiment, and will not be elaborated here. In practical applications, the data sender provided in the above embodiment can, according to needs, allocate the above functions to different functional modules to complete, that is, divide the internal structure of the system into different functional modules to complete all or part of the functions described above. This is not limited here either.
[0124] Next, the data receiver provided in this application will be described. The data receiver described below can be correspondingly referred to the ARP attack defense method applied to the data receiver described above.
[0125] Please refer to Figure 12 , the data receiver provided in this embodiment includes:
[0126] A packet receiving module 1210 is configured to receive the ARP request frame sent by the data sender, and the ARP request frame is obtained by using the address resolution protocol ARP attack defense method described in any one of the above.
[0127] A packet parsing module 1220 is configured to parse the ARP request frame to obtain the real IP address of the target data receiver in the ARP request frame and the encrypted asset identification code of the target data receiver. The encrypted asset identification code is pre-stored by the data sender and added to the ARP request frame.
[0128] A decryption module 1230 is configured to decrypt the encrypted asset identification code to obtain the decrypted identification code.
[0129] A response module 1240 is configured to, if the decrypted identification code is the same as the self-asset identification code pre-stored by the current data receiver, and the real IP address of the target data receiver is the same as the real IP address of the current data receiver, generate an ARP response frame based on the real MAC address of the current data receiver.
[0130] A data sending module 1250 is configured to send the ARP response frame to the data sender. The data receiver in this embodiment can effectively improve information transmission security and avoid information leakage.
[0131] It should be noted that the data receiving end provided in the above embodiments and the ARP attack defense method applied to the data receiving end belong to the same concept. The specific ways in which each module and unit perform operations have been described in detail in the method embodiments, and will not be elaborated here. In actual application, the data receiving end provided in the above embodiments can allocate the above functions to different functional modules as needed, that is, divide the internal structure of the system into different functional modules to complete all or part of the functions described above, and this will not be limited here either.
[0132] In some embodiments, an electronic device is further provided. The electronic device may be a server, and its internal structure diagram is as Figure 13 shown. The electronic device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile and / or volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the electronic device is used to communicate with an external client through a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the server side of the above method.
[0133] In some embodiments, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented: obtaining a data sending requirement; according to the data sending requirement, reading data from a preset ARP entry to obtain the real IP address and real MAC address of a target data receiving end; if the real MAC address of the target data receiving end fails to be obtained, generating an ARP request frame based on a preset false address of the data sending end, the real address of the data sending end, and the real IP address of the target data receiving end; and sending the ARP request frame to network devices in the current network architecture by broadcasting.
[0134] In some embodiments, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: obtaining a data sending requirement; according to the data sending requirement, reading data from a preset ARP entry to obtain the real IP address and real MAC address of a target data receiving end; if the real MAC address of the target data receiving end fails to be obtained, generating an ARP request frame based on a preset false address of the data sending end, the real address of the data sending end, and the real IP address of the target data receiving end; and sending the ARP request frame to network devices in the current network architecture by broadcasting.
[0135] It should be noted that for the functions or steps that can be implemented by the above-mentioned computer-readable storage medium or electronic device, reference may be made to the relevant descriptions on the server side and the client side in the foregoing method embodiments. To avoid repetition, they will not be described in detail here.
[0136] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of the methods and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0137] The above embodiments are only illustrative of the principles and effects of the present application and are not intended to limit the present application. Any person familiar with this technology can modify or change the above embodiments without departing from the spirit and scope of the present application. Therefore, all equivalent modifications or changes made by those with ordinary knowledge in the technical field without departing from the spirit and technical idea disclosed by the present application should still be covered by the claims of the present application.
Claims
1. A method for defending against an address resolution protocol ARP attack, characterized in that: Applied to the data sending end, including: Get data sending requirements; According to the data transmission requirement, the preset ARP table entry is read to obtain the real IP address and real MAC address of the target data receiving end; If the real MAC address of the target data receiving end fails to be obtained, an ARP request frame is generated based on the preset false address of the data sending end, the real address of the data sending end, and the real IP address of the target data receiving end; Send the ARP request frame to the network device in the current network architecture by broadcasting; the ARP request frame includes a source MAC address field, a source IP address field, a destination MAC address field, a destination IP address field and a custom field, the source MAC address field is a false MAC address of the data sending end, the source IP address field is a false IP address of the data sending end, the destination MAC address field is empty, and the destination IP address field is a real IP address or a false IP address of the target data receiving end; If the destination IP address field is the real IP address of the target data receiving end, the custom field includes the real IP address and real MAC address of the data sending end; If the destination IP address field is a false IP address of the target data receiving end, the custom field includes the real IP address and real MAC address of the data sending end, and the real IP address of the target data receiving end.
2. The method for defending against Address Resolution Protocol (ARP) attacks according to claim 1, characterized in that: The custom field also includes a pre-stored encrypted asset identification code of the target data receiving end; The encrypted asset identification code is used to match the self-asset identification code pre-stored by the target data receiving end after decryption, so that the real MAC address of the target data receiving end is fed back to the data sending end when the match is successful.
3. The method for defending against Address Resolution Protocol (ARP) attacks according to claim 1, characterized in that: Also includes: If an ARP response frame is received, the real MAC address of the target data receiving end is obtained by parsing the ARP response frame; Based on the real MAC address of the target data receiving end, the ARP table entry is updated; Data is sent based on the updated ARP entry.
4. The method for defending against Address Resolution Protocol (ARP) attacks according to claim 1 or 2, characterized in that: The real IP address and real MAC address of the data sending end, and the real IP address of the target data receiving end are all encrypted addresses.
5. The method for defending against Address Resolution Protocol (ARP) attacks according to any one of claims 1 to 3, characterized in that: Before sending the ARP request frame to the network device in the current network architecture by broadcasting, the method further includes: If the ARP request frame contains an organization unique identifier, the organization unique identifier in the ARP request frame is deleted, or the organization unique identifier in the ARP request frame is adjusted from an original position to the custom field.
6. A method for defending against an address resolution protocol ARP attack, characterized in that: Applied to the data receiving end, including: Receiving an ARP request frame sent by a data sending end, wherein the ARP request frame is obtained by using the address resolution protocol ARP attack defense method according to any one of claims 1 to 5; By parsing the ARP request frame, the real IP address of the target data receiving end in the ARP request frame and the encrypted asset identification code of the target data receiving end are obtained, where the encrypted asset identification code is pre-stored by the data sending end and added to the ARP request frame; Decrypting the encrypted asset identification code to obtain a decrypted identification code; If the decrypted identification code is the same as the asset identification code pre-stored by the current data receiving end, and the real IP address of the target data receiving end is the same as the real IP address of the current data receiving end, then an ARP response frame is generated based on the real MAC address of the current data receiving end; The ARP response frame is sent to the data sending end.
7. The method for defending against Address Resolution Protocol (ARP) attacks according to claim 6, characterized in that: Based on the real MAC address of the current data receiving end, an ARP response frame is generated, including: The ARP response frame is generated based on the real MAC address, real IP address, false MAC address, false IP address of the current data receiving end, and the real MAC address, real IP address, false MAC address, false IP address of the data sending end.
8. A data sending end, characterized in that: include: Demand collection module, used to obtain data sending requirements; A data reading module is used to read data from a preset ARP table entry according to the data transmission requirement to obtain a real IP address and a real MAC address of a target data receiving end; A message generation module, for generating an ARP request frame based on a preset false address of the data sending end, a true address of the data sending end, and a true IP address of the target data receiving end if the true MAC address of the target data receiving end fails to be obtained; the ARP request frame includes a source MAC address field, a source IP address field, a destination MAC address field, a destination IP address field, and a custom field, the source MAC address field is a false MAC address of the data sending end, the source IP address field is a false IP address of the data sending end, the destination MAC address field is empty, and the destination IP address field is a true IP address or a false IP address of the target data receiving end; If the destination IP address field is the real IP address of the target data receiving end, the custom field includes the real IP address and real MAC address of the data sending end; If the destination IP address field is a false IP address of the target data receiving end, the custom field includes the real IP address and real MAC address of the data sending end, and the real IP address of the target data receiving end; The data sending module is used to send the ARP request frame to the network equipment in the current network architecture by broadcasting.
9. A data receiving end, characterized in that: include: A message receiving module, used for receiving an ARP request frame sent by a data sending end, wherein the ARP request frame is obtained by using the address resolution protocol ARP attack defense method according to any one of claims 1 to 5; A message parsing module, used to parse the ARP request frame to obtain the real IP address of the target data receiving end in the ARP request frame, and the encrypted asset identification code of the target data receiving end, where the encrypted asset identification code is pre-stored by the data sending end and added to the ARP request frame; A decryption module, used to decrypt the encrypted asset identification code to obtain a decrypted identification code; A response module, configured to generate an ARP response frame based on the real MAC address of the current data receiving end if the decrypted identification code is the same as the self-asset identification code pre-stored by the current data receiving end, and the real IP address of the target data receiving end is the same as the real IP address of the current data receiving end; A data sending module is used to send the ARP response frame to the data sending end.
Citation Information
Patent Citations
Message processing method and exchange equipment
CN103095584A
Network forwarding method and device for avoiding MAC table item drift
CN119383149A