Network reconstruction method, system and device based on SDN technology, and storage medium

By assigning virtual IP addresses to network devices in the same LAN and modifying their IP addresses to enable them to transmit data through layer three switches, the problem of inability to monitor network attack behaviors between network devices is solved, and monitoring of attack behaviors and flooding problems are reduced.

CN119996377APending Publication Date: 2025-05-13北京卫达信息技术有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510035954.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art cannot monitor network attacks between multiple network equipment layer 2 switches within the same LAN.

Method used

By obtaining DHCP data packets sent by multiple network devices, and assigning virtual IP addresses to multiple network devices based on the DHCP data packets and the preset address database, and modifying their IP addresses, so that network devices can transmit data through layer three switches, thereby realizing the monitoring of network attack behavior by the network defense system.

Benefits of technology

The monitoring of network attack behavior between multiple network equipment layer 2 switches in the same LAN is realized, which improves the problem of unmonitorable monitoring, and reduces the occurrence of flooding problems by cleaning up the MAC address library.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996377A_ABST
    Figure CN119996377A_ABST
Patent Text Reader

Abstract

The invention relates to a network reconstruction method, system and device based on an SDN technology, and a storage medium. The method comprises the following steps: acquiring DHCP data packets sent by a plurality of network devices; according to the DHCP data packet and a preset address library, virtual IP addresses are allocated to the plurality of network devices; and modifying the IP addresses of the plurality of network devices according to the virtual IP addresses. The problem that the network attack behavior occurring among the two-layer switches of the multiple network devices in the same local area network cannot be monitored is solved, and the network attack behavior monitoring method and device have the effect of monitoring the network attack behavior occurring among the two-layer switches of the multiple network devices in the same local area network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data processing, and in particular to a network reconstruction method, system, device and storage medium based on SDN technology. Background Art

[0002] For multiple network devices in the same LAN, data transmission between them is carried out through the Layer 2 switch, not through the Layer 3 switch. Since the Layer 3 switch is located in the core network layer and is the target of network hacker attacks, network defense systems are mostly set up in the Layer 3 switch. For example, in terms of software, a highly reliable firewall is configured to block unidentified data packets, thereby ignoring the attack behavior on the Layer 2 switch.

[0003] The above-mentioned existing technical solutions have the following defects: it is impossible to monitor network attack behaviors occurring between layer 2 switches of multiple network devices in the same local area network. Summary of the invention

[0004] In order to improve the problem of being unable to monitor network attack behaviors occurring between layer 2 switches of multiple network devices in the same local area network, the present application provides a network reconstruction method, system, device and storage medium based on SDN technology.

[0005] In a first aspect of the present application, a network reconstruction method based on SDN technology is provided. The method comprises: Get DHCP packets sent by multiple network devices; Allocating virtual IP addresses to the plurality of network devices according to the DHCP data packet and a preset address library; The IP addresses of the plurality of network devices are modified according to the virtual IP address.

[0006] It can be seen from the above technical solution that DHCP data packets sent by multiple network devices are obtained; virtual IP addresses are allocated to multiple network devices according to the DHCP data packets and the preset address library; and the IP addresses of network devices are modified according to the virtual IP addresses. By modifying the IP addresses of network devices in the same local area network, the network devices can realize data transmission between devices through the three-layer switch, achieving the effect of the network defense system set in the three-layer switch monitoring the network attack behavior between network devices, and improving the problem of being unable to monitor the network attack behavior between the two-layer switches of multiple network devices in the same local area network.

[0007] In a possible implementation, each of the network devices corresponds to a virtual IP address, the virtual IP address includes a network number and a host number, and the network numbers of the virtual IP addresses are all different.

[0008] In a possible implementation, allocating virtual IP addresses to the plurality of network devices according to the DHCP data packet and a preset address library includes: The address library includes a plurality of IP addresses, each of which includes a network number and a host number, and the IP addresses are grouped according to the network number; The DHCP data packet includes the network number of the IP address to be assigned; Determine whether there is a binding identifier for a group in the address library whose network number is equal to the network number of the IP address to be allocated; If yes, randomly obtain a group without a binding identifier in the address library, bind the group to the network device corresponding to the IP address to be assigned, and the group has a binding identifier corresponding to the network device corresponding to the IP address to be assigned; If not, binding the packet to the network device corresponding to the IP address to be assigned; The virtual IP address is any IP address in the group corresponding to the network device to which the IP address is to be assigned.

[0009] In a possible implementation, an information data packet sent by the network device is obtained, where the information data packet includes MAC address information; Obtain a pre-stored MAC address library, wherein the MAC address library includes a MAC address, a storage time of the MAC address, and a usage count of the MAC address; Calculating a first storage ratio between a preset storage number of the MAC address library and a stored number of the MAC addresses; When the first storage ratio is higher than a storage threshold, the MAC address library is cleaned up based on an address library cleanup rule.

[0010] In a possible implementation, when the first storage ratio is higher than a storage threshold, clearing the MAC address library based on an address library clearing rule includes: Deleting the MAC addresses whose storage time is less than the time threshold in the MAC address library, and calculating the second storage ratio after deletion; When the second storage threshold is less than the storage threshold, the cleaning of the MAC address library is completed.

[0011] In a possible implementation, the method further includes: When the second storage threshold is greater than or equal to the storage threshold, deleting the MAC address whose usage count is less than the usage threshold, and calculating a third storage ratio after deletion; When the third storage ratio is less than the storage threshold, completing the cleaning of the MAC address library; When the third storage ratio is greater than or equal to the storage threshold, continue to delete the MAC addresses whose storage time is less than the time threshold, or continue to delete the MAC addresses whose usage times are less than the usage threshold, and complete the cleaning of the MAC address library.

[0012] In a possible implementation, the first storage ratio=the stored number of the MAC addresses / the preset stored number.

[0013] In a second aspect of the present application, a network reconstruction system based on SDN technology is provided. The system includes: A data acquisition module is used to acquire DHCP data packets sent by multiple network devices; An address allocation module, used for allocating virtual IP addresses to the plurality of network devices according to the DHCP data packet and a preset address library; The address modification module is used to modify the IP addresses of the multiple network devices according to the virtual IP address.

[0014] In a third aspect of the present application, an electronic device is provided, which includes a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the program, the method described above is implemented.

[0015] In a fourth aspect of the present application, a computer-readable storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the method according to the first aspect of the present application is implemented.

[0016] In summary, the present application includes at least one of the following beneficial technical effects: 1. By modifying the IP addresses of network devices in the same LAN, network devices can transmit data between devices through the three-layer switch, achieving the effect of the network defense system set in the three-layer switch monitoring network attack behaviors between network devices, and improving the problem of being unable to monitor network attack behaviors between two-layer switches of multiple network devices in the same LAN; 2. By calculating and determining the storage ratio of the MAC address database, when the storage ratio reaches the storage threshold, the MAC address database is cleaned up, which can reduce the occurrence of flooding problems to a certain extent. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 It is a flow chart of the network reconstruction method based on SDN technology provided in this application.

[0018] Figure 2 It is a structural diagram of a network reconstruction system based on SDN technology provided in this application.

[0019] Figure 3 It is a structural schematic diagram of the electronic device provided by this application.

[0020] In the figure, 200 is a network reconstruction system based on SDN technology; 201 is a data acquisition module; 202 is an address allocation module; 203 is an address modification module; 301 is a CPU; 302 is a ROM; 303 is a RAM; 304 is an I / O interface; 305 is an input part; 306 is an output part; 307 is a storage part; 308 is a communication part; 309 is a drive; 310 is a removable medium. DETAILED DESCRIPTION

[0021] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0022] In addition, the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article, unless otherwise specified, generally means that the associated objects before and after are in an "or" relationship.

[0023] Each network device has a corresponding IP address and MAC address. The MAC address is fixed and unique to each network device, while the dynamic IP address refers to the IP address dynamically assigned by the Internet Service Provider (ISP). This type of IP address includes dynamic IP addresses and static IP addresses. Dynamic IP addresses are temporary, and the Internet service provider will assign a new IP address each time you reconnect to the Internet. This can save IP address resources, but it will cause changes in the IP address. Static IP addresses refer to IP addresses manually configured by the network administrator. This IP address is fixed and will not change when you reconnect to the Internet. However, static IP addresses require a large amount of IP address resources, so they are usually only used in special occasions such as servers. Therefore, general network devices use dynamic IP addresses, that is, when you reconnect to the network, the IP address will be modified.

[0024] The IP address includes the network number and the host number. When the network numbers are the same, it means that the network devices are located in the same LAN. For multiple network devices in the same LAN, the data transmission between them is carried out through the layer 2 switch, not through the layer 3 switch. Since the layer 3 switch is at the core of the network layer and is the target of network hacker attacks, most network defense systems are set up in the layer 3 switch. For example, in terms of software, a highly reliable firewall is configured to block unidentified data packets, thereby ignoring the attack behavior on the layer 2 switch. Therefore, it is currently impossible to monitor the network attack behavior between the layer 2 switches of multiple network devices in the same LAN.

[0025] The embodiments of the present application are further described in detail below in conjunction with the drawings in the specification.

[0026] The present invention provides a network reconstruction method based on SDN technology, and the main process of the method is described as follows.

[0027] like Figure 1 As shown: Step S101: Acquire DHCP data packets sent by multiple network devices.

[0028] Specifically, when a network device changes the network to be connected or when the client lease of the IP address expires, the IP address will be changed and a DHCP packet will be sent to obtain a new IP address. The device that performs the network reconstruction method based on SDN technology can be a server or other network device. The device that performs the method obtains DHCP packets sent by multiple network devices, and the above DHCP packets include the network number of the IP address to be assigned.

[0029] Step S102: Allocate virtual IP addresses to multiple network devices according to the DHCP data packet and the preset address library.

[0030] Specifically, the address library includes multiple IP addresses, and the above IP addresses include network numbers and host numbers. The above IP addresses are grouped according to the above network numbers, that is, IP addresses with the same network number are grouped together, and the above network number is used as a group identifier. It is determined whether there is a binding identifier for the group whose network number in the address library is equal to the network number of the IP address to be allocated, that is, whether there is a binding identifier for the group identifier in the address library that is equal to the network number in the IP address to be allocated. The above binding identifier is a unique identifier for a certain network device, and the above unique identifier can be a MAC address of the network device or other identifiers that can uniquely identify the network device.

[0031] If there is a binding identifier, it means that the group identifier has been used by other network devices, so the above network device cannot continue to use the network number of the IP address to be assigned as the network number of the new IP address. For this network device, it is necessary to randomly select a group without a binding identifier in the above address library, bind the above group to the network device corresponding to the above IP address to be assigned, and the above group has a binding identifier corresponding to the network device corresponding to the above IP address to be assigned.

[0032] If there is no binding identifier, it means that no other network device is using the group identifier, so the above network device can continue to use the network number of the IP address to be allocated as the network number of the new IP address, and then bind the above group to the network device corresponding to the above IP address to be allocated.

[0033] The virtual IP address is any IP address in the group corresponding to the network device to be assigned the IP address. Each network device corresponds to a virtual IP address, which includes a network number and a host number. The network numbers of the virtual IP addresses are all different.

[0034] Step S103: modify the IP addresses of multiple network devices according to the virtual IP address.

[0035] Specifically, after determining the network number corresponding to each network device, an IP address can be randomly selected from the address library group corresponding to the network number as the virtual IP address, and the above virtual IP address is sent to the corresponding network device. The network device receives the virtual IP address and completes the modification of the IP address.

[0036] It is understandable that data transmission of network devices in the same LAN can be achieved through a layer 2 switch, but for network devices that are not in the same LAN, data transmission between devices must be achieved through a layer 3 switch. Therefore, when the IP address of a network device in the same LAN is modified to an IP address with a different network number, it means that the above network device is not in the same LAN, and a layer 3 switch is required to achieve data transmission between network devices. In this way, the network defense system set in the layer 3 switch can monitor network attack behaviors between network devices.

[0037] During the data exchange process in the Layer 2 switch, when the Layer 2 switch receives a data frame, it first checks the source MAC address and associates it with the interface that receives the data, and updates the associated MAC address and interface information to the MAC address table. Then, it checks the target MAC address, queries the MAC address table, and forwards the data according to the interface corresponding to the target MAC. If there is no target MAC address in the MAC address table or the MAC address table is empty, the Layer 2 switch will forward the data frame through each interface.

[0038] The above MAC address table has a size limit. The size of the MAC address table of different switches is also different. The MAC address table of the access switch is basically around 8K. When this table is full, the switch can no longer update, that is, it can no longer forward data for newly added devices. At this time, when forwarding a data frame, the switch cannot find the corresponding interface of this data frame (the switch does not know which port to send it from), so it will forward this frame through all interfaces. This is flooding.

[0039] Flooding is related to the MAC list. If the specific forwarding port and MAC pairing cannot be found in the MAC table, flooding processing will begin, which can easily cause a broadcast storm.

[0040] In order to reduce the occurrence of flooding, the network reconstruction method based on SDN technology also includes a method for cleaning up the MAC address database: Obtain an information data packet sent by the above network device, the above information data packet includes MAC address information. Obtain a pre-stored MAC address library, the above MAC address library includes a MAC address, a storage time of the MAC address, and a number of times the MAC address is used. The storage time of the above MAC address refers to the time when the MAC address information is stored in the MAC address library when an information data packet is received, the MAC address library does not have the MAC address information in the information data packet, and the MAC address library can still store addresses. The number of times the above MAC address is used refers to the number of times information is sent through the interface corresponding to the MAC address after the MAC address is stored in the MAC address library.

[0041] Calculate the first storage ratio of the preset storage number of the MAC address library and the stored number of the above MAC addresses, the first storage ratio = the stored number of the above MAC addresses / the preset storage number. For example, the MAC address table is 8K, that is, the network device can support the storage of up to 8000 MAC addresses. The above stored number is the number of addresses already stored in the current MAC address table. For example, if the stored number is 6000, then the above first storage ratio is 6000 / 8000=0.75.

[0042] When the first storage ratio is lower than the storage threshold, the MAC address library is cleared based on the address library clearing rule.

[0043] Specifically, delete the MAC addresses whose storage time is less than the time threshold in the MAC address library, and calculate the second storage ratio after deletion; when the second storage threshold is less than the storage threshold, complete the cleaning of the MAC address library. When the second storage threshold is greater than or equal to the storage threshold, delete the MAC addresses whose usage times are less than the usage threshold, and calculate the third storage ratio after deletion; when the third storage ratio is less than the storage threshold, complete the cleaning of the MAC address library; when the third storage ratio is greater than or equal to the storage threshold, continue to delete the MAC addresses whose storage time is less than the time threshold, or continue to delete the MAC addresses whose usage times are less than the usage threshold, and complete the cleaning of the MAC address library.

[0044] For example, when the storage threshold is 0.7, the first storage ratio 0.75 is greater than the storage threshold 0.7, and the MAC address library needs to be partially deleted. The MAC addresses whose storage time is less than the time threshold are 5 minutes before the current time, that is, the getTime time function can be used to obtain the time milliseconds from 00:00:00 on January 1, 1970 to the present. The difference obtained by subtracting 300,000 (5 minutes = 300,000 milliseconds) from the above time milliseconds is the time threshold. When the storage time is used as the parameter of the getTime time function in the same way to obtain the corresponding storage time, the storage time with a unified format is compared with the time threshold. When the storage time is less than the time threshold, it means that the MAC address corresponding to the storage time has been added to the MAC address library not long ago, which may be a malicious attack, causing flooding of the Layer 2 switch, so the MAC addresses whose storage time is less than the time threshold are deleted. The second storage ratio after deletion is calculated. If the second storage ratio is less than the storage threshold, it means that the storage space for the remaining MAC addresses in the MAC address library is relatively sufficient, and the MAC address library is not cleaned up. If the second storage ratio is greater than or equal to the storage threshold, it means that the storage space for the remaining MAC addresses in the MAC address library is insufficient, and it is necessary to continue to clean up the MAC addresses in the address library, and delete the MAC addresses whose usage times are less than the usage threshold. The usage times less than the usage threshold means that the usage rate of the MAC address is low, and the impact on the switch after deletion is small. After the deletion is completed, the third storage ratio after deletion is calculated. When the third storage ratio is less than the storage threshold, it means that the storage space for the remaining MAC addresses in the MAC address library is relatively sufficient, and the address library is cleaned up. When the third storage ratio is greater than or equal to the storage threshold, continue to delete the MAC addresses whose storage time is less than the time threshold, or continue to delete the MAC addresses whose usage times are less than the usage threshold, and complete the cleaning of the MAC address library. It can be understood that while deleting the MAC addresses, new MAC addresses may also be stored. When the third storage ratio is greater than or equal to the storage threshold, it may be caused by the newly stored MAC addresses, so repeat the above steps of cleaning up the MAC address library, that is, continue to delete the MAC addresses whose storage time is less than the time threshold, or continue to delete the MAC addresses whose usage times are less than the usage threshold, until the storage ratio calculated after deleting the addresses is less than the storage threshold.

[0045] The present application embodiment provides a network reconstruction system 200 based on SDN technology, referring to Figure 2 , the network reconstruction system 200 based on SDN technology includes: The data acquisition module 201 is used to acquire DHCP data packets sent by multiple network devices; An address allocation module 202, configured to allocate virtual IP addresses to the plurality of network devices according to the DHCP data packet and a preset address library; The address modification module 203 is used to modify the IP addresses of the multiple network devices according to the virtual IP address.

[0046] The data acquisition module is used to execute step S101 of the network reconstruction method based on SDN technology, the address allocation module is used to execute step S102 of the network reconstruction method based on SDN technology, and the address modification module is used for step S103 of the network reconstruction method based on SDN technology. The network reconstruction system also includes an address cleaning module, which is used to execute the method for cleaning the MAC address library. The specific working process of the method for cleaning the MAC address library is specifically described in the network reconstruction method based on SDN technology, which will not be repeated here.

[0047] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the described module can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0048] The present application embodiment discloses an electronic device. Figure 3 The electronic device includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 302 or the program loaded from the storage part 307 to the random access memory (RAM) 303. In the RAM 303, various programs and data required for system operation are also stored. The CPU 301, the ROM 302 and the RAM 303 are connected to each other through a bus. The input / output (I / O) interface 304 is also connected to the bus.

[0049] The following components are connected to the I / O interface 304: an input section 305 including a keyboard, a mouse, etc.; an output section 306 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 307 including a hard disk, etc.; and a communication section 308 including a network interface card such as a LAN card, a modem, etc. The communication section 308 performs communication processing via a network such as the Internet. A drive 309 is also connected to the I / O interface 304 as needed. A removable medium 310, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 309 as needed, so that a computer program read therefrom is installed into the storage section 307 as needed.

[0050] In particular, according to an embodiment of the present application, the above reference flow chart Figure 1The described process can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a machine-readable medium, and the computer program contains program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication part 308, and / or installed from a removable medium 310. When the computer program is executed by a central processing unit (CPU) 301, the above-mentioned functions defined in the device of the present application are executed.

[0051] It should be noted that the computer-readable medium shown in the present application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0052] The above description is only a preferred embodiment of the present application and an explanation of the technical principles used. Those skilled in the art should understand that the scope of application involved in the present application is not limited to the technical solution formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the aforementioned application concept. For example, the above features are replaced with (but not limited to) technical features with similar functions applied in the present application.

Claims

1. A network reconstruction method based on SDN technology, characterized in that: Based on the DHCP protocol, including: Get DHCP packets sent by multiple network devices; Allocating virtual IP addresses to the plurality of network devices according to the DHCP data packet and a preset address library; The IP addresses of the plurality of network devices are modified according to the virtual IP address.

2. The network reconstruction method based on SDN technology according to claim 1 is characterized in that: Each of the network devices corresponds to a virtual IP address, and the virtual IP address includes a network number and a host number, and the network numbers of the virtual IP addresses are all different.

3. The network reconstruction method based on SDN technology according to claim 1 is characterized in that: The allocating virtual IP addresses to the plurality of network devices according to the DHCP data packet and the preset address library comprises: The address library includes a plurality of IP addresses, each of which includes a network number and a host number, and the IP addresses are grouped according to the network number; The DHCP data packet includes the network number of the IP address to be assigned; Determine whether there is a binding identifier for a group in the address library whose network number is equal to the network number of the IP address to be allocated; If yes, randomly obtain a group without a binding identifier in the address library, bind the group to the network device corresponding to the IP address to be assigned, and the group has a binding identifier corresponding to the network device corresponding to the IP address to be assigned; If not, binding the packet to the network device corresponding to the IP address to be assigned; The virtual IP address is any IP address in the group corresponding to the network device to which the IP address is to be assigned.

4. The network reconstruction method based on SDN technology according to claim 1 is characterized in that: Also includes: Acquire an information data packet sent by the network device, wherein the information data packet includes MAC address information; Obtain a pre-stored MAC address library, wherein the MAC address library includes a MAC address, a storage time of the MAC address, and a usage count of the MAC address; Calculating a first storage ratio between a preset storage number of the MAC address library and a stored number of the MAC addresses; When the first storage ratio is higher than a storage threshold, the MAC address library is cleaned up based on an address library cleanup rule.

5. The network reconstruction method based on SDN technology according to claim 4 is characterized in that: When the first storage ratio is higher than a storage threshold, based on an address library cleaning rule, cleaning the MAC address library comprises: Deleting the MAC addresses whose storage time is less than the time threshold in the MAC address library, and calculating the second storage ratio after deletion; When the second storage threshold is less than the storage threshold, the cleaning of the MAC address library is completed.

6. The network reconstruction method based on SDN technology according to claim 5 is characterized in that: Also includes: When the second storage threshold is greater than or equal to the storage threshold, deleting the MAC address whose usage count is less than the usage threshold, and calculating a third storage ratio after deletion; When the third storage ratio is less than the storage threshold, completing the cleaning of the MAC address library; When the third storage ratio is greater than or equal to the storage threshold, continue to delete the MAC addresses whose storage time is less than the time threshold, or continue to delete the MAC addresses whose usage times are less than the usage threshold, and complete the cleaning of the MAC address library.

7. The network reconstruction method based on SDN technology according to claim 4 is characterized in that: The first storage ratio=the stored number of the MAC addresses / the preset storage number.

8. A network reconstruction system based on SDN technology, characterized in that: include: A data acquisition module is used to acquire DHCP data packets sent by multiple network devices; An address allocation module, used for allocating virtual IP addresses to the plurality of network devices according to the DHCP data packet and a preset address library; The address modification module is used to modify the IP addresses of the multiple network devices according to the virtual IP address.

9. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program which can be loaded by the processor and executes the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: A computer program is stored which can be loaded by a processor and execute the method according to any one of claims 1 to 7.