Non-intrusive network IP address connectivity detection method

Through a non-invasive IP address connectivity detection method and the deployment of the detection end and the receiving end, the problem of the inability to accurately detect IP address connectivity anomalies in the existing technology is solved, timely discovery and processing are achieved, and the accuracy and efficiency of detection are improved.

CN120675976APending Publication Date: 2025-09-19STORY CLOUD NETWORK (HANGZHOU) NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510771474.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing technologies cannot accurately detect abnormal IP address connectivity without relying on the cooperation of the device where the target IP address is located and the intermediate routing nodes. In particular, when the target IP address is blocked by a firewall in a specific area, it cannot be discovered and handled in a timely manner.

Method used

A non-invasive detection method is adopted. By deploying at the detection end and the receiving end, a stateless protocol is used to construct a data packet and modify the source IP address. The detection end sends the data packet to the receiving end, and the receiving end records the results to determine the abnormal connectivity of the IP address. The regional firewall deployment environment is used for detection.

Benefits of technology

It enables timely detection and handling of IP address connectivity anomalies without intruding into target devices, reducing customer complaints and impact on business reputation, and improving detection accuracy and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675976A_ABST
    Figure CN120675976A_ABST
Patent Text Reader

Abstract

The invention relates to the field of network information security, in particular to a non-intrusive network IP address connectivity detection method. The method comprises a detection end and a receiving end, the detection end is deployed in a network routing environment identical to a to-be-detected IP address, a detection data packet with a source IP address being the to-be-detected IP address is constructed, and the detection data packet is sent to the detection end of a network environment (such as cross-border and cross-provincial) which can be accessed only through a regional firewall. Whether connectivity abnormity exists in the to-be-detected IP address is judged according to a result of detecting whether the data packet is received, and more detailed statistical data can be provided or reported to an alarm platform according to the result. Compared with a traditional detection method, the non-intrusive network IP address connectivity detection method has the advantages that on the premise that the method does not depend on to-be-detected network IP address equipment and even a to-be-detected network IP address user does not know, under the condition that ICMP and other protocols are forbidden for a target IP address or a detection port is not opened, the connectivity of the to-be-detected network IP address can be detected in a non-intrusive mode, and the connectivity of the to-be-detected network IP address can be detected. Therefore, accurate detection of the abnormal connectivity state of the target IP address is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network information security, and in particular to a non-intrusive network IP address connectivity detection method for diagnosing whether a specific IP address is blocked by an operator's ingress and egress firewalls in a specific geographical range, resulting in connectivity anomalies. Background Art

[0002] Currently, due to network security reviews required by laws and regulations or other reasons, telecom operators in countries and regions around the world have deployed firewall devices, namely "regional firewalls", at the entrances and exits of network links at geographical boundaries to varying degrees. This is to block the passage of data packets from network IP addresses that contain harmful content or violate relevant laws and regulations, resulting in abnormal connectivity between the network IP address and other network areas. Summary of the Invention

[0003] The inventors discovered that in this network environment, companies such as basic network access providers, cloud computing service providers, network IP address leasing companies, or similar entities do not have the right to know whether their network IP addresses are blocked by firewalls in specific regions, when blocking measures were taken, or when the blocking measures can be lifted. Therefore, when these IP addresses with connectivity anomalies are recycled and reallocated to new users, they may lead to customer complaints, unnecessary idle costs, and even more seriously, damage business reputation. If connectivity anomalies in their network IP addresses could be detected, alerted, and addressed as soon as they occur, this would greatly improve the previously passive situation.

[0004] It should be noted that according to the network IP address protocol standard, the source IP address encapsulated in the data packet should be the real IP address of the device sending the data packet. This ensures that the reply data packet sent by the other party after receiving the data packet can be received by the device that originally sent the data packet.

[0005] Therefore, existing IP address connectivity diagnosis methods usually use end-to-end active detection or path tracing, which cannot accurately detect abnormal connectivity status of the target IP address when the target IP address prohibits protocols such as ICMP or does not open the detection port without relying on the cooperation of the device where the target IP address is located and the intermediate routing nodes.

[0006] However, due to the reasons mentioned above, only non-intrusive detection methods are allowed in certain scenarios.

[0007] Therefore, the present invention addresses the deficiencies in the prior art and provides a non-invasive method for detecting network IP address connectivity. Summary of the Invention

[0008] In order to address the defects of the prior art, the purpose of the present invention is to provide a non-invasive network IP address connectivity detection method to solve the detection difficulties and poor detection effects that cannot be overcome using the prior art.

[0009] To achieve the above objectives, the detection method provided by the present invention needs to include three independent entities:

[0010] Detection end: The active party that performs detection, deployed on an independent computing node that is not the device where the target IP is located.

[0011] Regional firewall: A network security device that takes blocking measures that cause abnormal connectivity of the IP address to be detected.

[0012] Receiving end: A monitoring node deployed in a network area different from the IP to be detected (a network environment that requires access through a regional firewall, such as a cross-border / cross-provincial environment).

[0013] The detection method provided by the present invention comprises the following steps:

[0014] S1. Deploy the detection terminal in the same network routing environment as the IP address to be detected;

[0015] S2. Deploy the receiving end in a network environment that can only be accessed through a regional firewall;

[0016] S3. Configure the network IP address or IP address segment to be detected and the receiving end IP address on the detection end.

[0017] S4. Configure the network IP address or IP address segment to be detected on the receiving end;

[0018] S5. The detection end periodically constructs a specific data packet, modifies the source IP address of the data packet to the IP address to be detected, and then sends it to the receiving end;

[0019] S6. The receiving end records the result of each IP address to be detected based on whether the detection data packet of the network IP address to be detected is received;

[0020] S7, if the network IP address to be detected has connectivity anomalies, the receiving end cannot receive the detection data packet from the network IP address within the set period threshold, step S6 will successfully record the network IP address with connectivity anomalies and perform the remaining detection tasks;

[0021] S8. If the network IP address to be detected has no connectivity anomaly, the receiving end will receive at least one detection data packet from the network IP address within the set period threshold. Step S6 will successfully record the network IP address without connectivity anomaly and perform the remaining detection tasks.

[0022] Preferably, the receiving end in step S2 can be deployed independently as one unit or distributed as multiple units, and various methods can be used to aggregate the detection results recorded in step S6 to improve the accuracy of the detection results and the reliability of the detection system.

[0023] Preferably, the detection end configuration described in step S3 can additionally configure a verification token carried by the detection packet sent, and the same verification token should also be configured at the receiving end in step S4 to filter data packets and messages not sent by the detection end and not required for detection, thereby improving the processing efficiency of the receiving end.

[0024] Preferably, the data packet construction and sending in step S5 should adopt a stateless protocol (such as UDP) and as small a data packet payload as possible to reduce the impact on the device where the network IP address to be detected is located and the occupation of network resources by the detection system.

[0025] Preferably, the data packet construction and sending frequency described in step S5 can allow for custom configuration to meet different requirements for detection speed and efficiency in different scenarios and needs.

[0026] Preferably, in steps S7 and S8, an additional statistical information overview can be provided for IP addresses with and without connectivity anomalies, and the information can also be reported to other systems or platforms in other ways as needed to meet the functional requirements of data statistics, active reporting, etc. after discovering IP addresses with connectivity anomalies in different scenarios.

[0027] Optionally, the receiving end in step S6 may customize the settings to reply or not reply packets with specific or non-specific content to the network IP address to be detected according to actual needs, depending on whether the detection packet of the network IP address to be detected is received. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] FIG1 is a non-intrusive network IP address connectivity detection method according to an embodiment of the present invention; DETAILED DESCRIPTION

[0029] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0030] Referring to Figure 1, in an embodiment of the present invention, a non-invasive network IP address connectivity detection method is provided. The detection system includes a detection end, a regional firewall, and a receiving end. The detection end is a device that is physically independent of the host computer where the IP address to be detected is located, and the detection end is deployed in the same network routing environment as the IP address to be detected (under the same router). The regional firewall is a network security device that takes blocking measures to cause connectivity anomalies in the IP address to be detected. The receiving end is deployed in a network environment that can only be accessed through the regional firewall, and is connected to an alarm platform to regularly report statistical information on connectivity anomalies.

[0031] Example 1

[0032] The IP address of the network to be tested is located in Country A;

[0033] S1. Deploy the detection terminal in a network routing environment within country A that has the same IP address as the one to be detected.

[0034] S2. Deploy the receiving end within Country B (through Country A's regional firewall);

[0035] S3. Configure the network IP address or IP address segment to be detected and the receiving end IP address on the detection end.

[0036] S4. Configure the network IP address or IP address segment to be detected on the receiving end;

[0037] S5. The detection end periodically constructs a specific data packet, modifies the source IP address of the data packet to the IP address to be detected, and then sends it to the receiving end;

[0038] S6. The receiving end records the result of each IP address to be detected based on whether the detection data packet of the network IP address to be detected is received;

[0039] S7, if the network IP address to be detected has connectivity anomalies, the receiving end cannot receive the detection data packet from the network IP address within the set period threshold, step S6 will successfully record the network IP address with connectivity anomalies and perform the remaining detection tasks;

[0040] S8, if the network IP address to be detected does not have connectivity anomalies, the receiving end will receive at least one detection data packet from the network IP address within the set period threshold, step S6 will successfully record the network IP address without connectivity anomalies and perform the remaining detection tasks;

[0041] S9. The detection end summarizes the detection result data from the last report to the present according to actual needs based on the set periodic threshold and reports it to the alarm platform.

[0042] Example 2

[0043] The IP address of the network to be tested is located outside of Country A;

[0044] S1. Deploy the detection terminal in a network routing environment outside of country A with the same IP address as the one to be detected.

[0045] S2. Deploy the receiving end within Country A (through Country A's regional firewall);

[0046] Steps S3 to S9 of the second embodiment are the same as those of the first embodiment.

[0047] The above embodiments are intended to illustrate the present invention, not to limit the present invention. Any solution that is a simple transformation of the present invention falls within the protection scope of the present invention.

Claims

1. A non-intrusive network IP address connectivity detection method, characterized by: In the same network routing environment as the IP address to be detected, a detection device that is physically independent of the device to which the IP address to be detected belongs constructs a detection data packet with the source IP address being the IP address to be detected, and sends it to a monitoring node in a network environment that can only be accessed through a regional firewall. Based on the result of whether the detection data packet is received, it is determined whether there is a connectivity anomaly with the IP address to be detected. This method must include three independent entities: the detection end: the active party that performs the detection, which is an independent computing node deployed on a device other than the device where the target IP address is located; the regional firewall: a network security device that takes blocking measures that cause the connectivity anomaly of the IP address to be detected; Receiving end: Deployed in a monitoring node that belongs to a different network area from the IP to be detected (a network environment that requires access through a regional firewall, such as cross-border / inter-provincial). This method includes the following steps: S1. Deploy the detection terminal in the same network routing environment as the IP address to be detected; S2. Deploy the receiving end in a network environment that can only be accessed through a regional firewall; S3. Configure the network IP address or IP address segment to be detected and the receiving end IP address on the detection end. S4. Configure the network IP address or IP address segment to be detected on the receiving end; S5. The detection end periodically constructs a specific data packet, modifies the source IP address of the data packet to the IP address to be detected, and then sends it to the receiving end; S6. The receiving end records the result of each IP to be detected based on whether the detection data packet of the network IP address to be detected is received; S7, if the network IP address to be detected has connectivity anomalies, the receiving end cannot receive the detection data packet from the network IP address within the set period threshold, step S6 will successfully record the network IP address with connectivity anomalies and perform the remaining detection tasks; S8. If the network IP address to be detected has no connectivity anomaly, the receiving end will receive at least one detection data packet from the network IP address within the set period threshold. Step S6 will successfully record the network IP address without connectivity anomaly and perform the remaining detection tasks.

2. The non-intrusive network IP address connectivity detection method according to claim 1, wherein: The detection end described in step S1 is deployed in the same network routing environment as the IP address to be detected. The network routing environment described in step S1 includes the same gateway as the IP address to be detected and / or the same switch as the IP address to be detected and / or the same upper-layer network routing as the IP address to be detected, so that the detection end can send a detection data packet with the constructed source IP address being the IP address to be detected to the receiving end.

3. The non-intrusive network IP address connectivity detection method according to claim 1, wherein: The network environment described in step S2 that needs to pass through the regional firewall to be accessed is commonly cross-border or cross-provincial relative to the detection terminal.

4. The non-intrusive network IP address connectivity detection method according to claim 1, wherein: The receiving end described in step S2 can be deployed independently as one unit or distributed as multiple units, and various methods can be used to summarize the detection results recorded in step S6 to improve the accuracy of the detection results and the reliability of the detection system.

5. The non-intrusive network IP address connectivity detection method according to claim 1, wherein: The detection end configuration described in step S3 can additionally configure a verification token carried in the detection packet sent. At the same time, the same verification token should be configured at the receiving end in step S4 to filter data packets and messages not sent by the detection end and not required for detection, thereby improving the processing efficiency of the receiving end.

6. The non-intrusive network IP address connectivity detection method according to claim 1, wherein: The data packet construction and sending in step S5 should adopt a stateless protocol (such as UDP) and as small a data packet payload as possible to reduce the impact on the device where the network IP address to be detected is located and the occupation of network resources by the detection system.

7. The non-intrusive network IP address connectivity detection method according to claim 1, wherein: The data packet construction and sending frequency described in step S5 can allow for custom configuration to meet different requirements for detection speed and efficiency in different scenarios and needs.

8. The non-intrusive network IP address connectivity detection method according to claim 1, wherein: In step S6, the receiving end may customize the settings of replying or not replying data packets with specific or non-specific content to the network IP address to be detected according to actual needs, depending on whether the detection data packet of the network IP address to be detected is received.

9. The non-intrusive network IP address connectivity detection method according to claim 1, wherein: In steps S7 and S8, an additional statistical information overview can be provided for IP addresses with or without connectivity anomalies, and can also be reported to other systems or platforms through other means as needed to meet functional requirements such as data statistics and active reporting after discovering IP addresses with connectivity anomalies in different scenarios.