Ship network storm suppression method and device, electronic equipment and storage medium
By discarding target broadcast messages and allowing the transmission of specific communication messages during ship network storms, the problem of network storms propagating to the power grid is solved, ensuring the communication security and normal function of the power system.
Patent Information
- Application Number
- CN202510763692.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-11-04
AI Technical Summary
Ship network storms can easily spread to the power grid, causing communication outages, and existing technologies are unable to effectively suppress their spread.
When a network storm occurs on a ship, the system receives communication messages transmitted from the platform network to the power network, discards target broadcast messages such as ARP and DHCP broadcast messages, and allows the transmission of non-UDP/FTP messages and specific types of UDP and FTP messages to reduce broadcast message traffic.
Effectively suppress the spread of network storms to the power grid, ensure the communication security and normal function of the power system, and avoid unnecessary broadcast messages from affecting ship safety.
Smart Images

Figure CN120896705A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of ship communication technology, and in particular to a ship network storm suppression method and device, electronic equipment and storage medium. BACKGROUND
[0002] The ship network is an integrated network of the whole ship, involving information interaction between various systems and various devices. Since the power system is related to the safety of the ship and has certain particularity, the power system needs to be networked separately, so the ship network includes a platform network and a power network. The platform network integrates and manages the data communication network of various subsystems (such as power, navigation, communication, monitoring, etc.), and the power network is used for power system monitoring and management.
[0003] The ship network may have a network storm, which may be transmitted from the platform network to the power network, causing communication paralysis of the power network. Therefore, in order to ensure the communication safety of the power network, it is necessary to consider how to suppress the transmission of the network storm to the power network. SUMMARY
[0004] The present application provides a ship network storm suppression method and device, electronic equipment and storage medium to solve the technical problem of how to suppress the transmission of the network storm to the power network.
[0005] The present application provides a ship network storm suppression method, comprising: receiving a communication message transmitted from the ship platform network to the power network; In the case of a network storm on the ship, if the communication message is a first type of message, the communication message is discarded. The first type of message includes a target broadcast message.
[0006] According to the ship network storm suppression method provided by the present application, the target broadcast message includes an address resolution protocol broadcast message and a dynamic host configuration protocol broadcast message.
[0007] According to the ship network storm suppression method provided by the present application, the step of determining whether the communication message is the target broadcast message comprises: obtaining the target MAC address and the target IP address of the communication message; determining whether the communication message is the address resolution protocol broadcast message according to the target MAC address; determining whether the communication message is the dynamic host configuration protocol broadcast message according to the target IP address.
[0008] According to the ship network storm suppression method provided by the present application, the first type of message further includes a non-UDP / FTP message.
[0009] According to the ship network storm suppression method provided by the application, after receiving the communication message propagated from the ship platform network to the power network, the method further comprises: In the case of network storm of the ship, if the communication message is a second type of message, the communication message is sent to the power network. The second type of message comprises at least one of an automatic identification system broadcast message, a user datagram protocol message and a file transfer protocol message.
[0010] According to the ship network storm suppression method provided by the application, the step of judging whether the communication message is the automatic identification system broadcast message comprises: The UDP port of the communication message is acquired. The UDP port is used to judge whether the communication message is the automatic identification system broadcast message.
[0011] The application further provides a ship network storm suppression device, comprising: The receiving module is used to receive the communication message propagated from the ship platform network to the power network. The filtering module is used to discard the communication message in the case of network storm of the ship, if the communication message is a first type of message. The first type of message comprises a target broadcast message.
[0012] The application further provides an electronic device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the ship network storm suppression method according to any one of the above-mentioned methods when executing the program.
[0013] The application further provides a non-transitory computer readable storage medium, which stores a computer program, wherein the computer program is executed by a processor to implement the ship network storm suppression method according to any one of the above-mentioned methods.
[0014] The application further provides a computer program product comprising a computer program, wherein the computer program is executed by a processor to implement the ship network storm suppression method according to any one of the above-mentioned methods.
[0015] The ship network storm suppression method, device, electronic device and storage medium provided by the application can discard the target broadcast message propagated from the platform network to the power network in the case of network storm of the ship, so as to reduce the broadcast message flow and further suppress the network storm from propagating to the power network. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort based on these drawings.
[0017] Figure 1 is one of the flowcharts of the ship network storm suppression method provided by the present application.
[0018] Figure 2 is another flowchart of the ship network storm suppression method provided by the present application.
[0019] Figure 3 is a structural schematic diagram of the ship network storm suppression device provided by the present application.
[0020] Figure 4 is a structural schematic diagram of the electronic device provided by the present application. DETAILED DESCRIPTION
[0021] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions in the present application will be described clearly and completely in the following with reference to the drawings in the present application. Obviously, the described embodiments are some embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all the other embodiments obtained by those skilled in the art without any creative effort belong to the protection scope of the present application.
[0022] It should be noted that in the description of the present application, the terms "comprising", "containing" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such a process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article or device including the element. The terms "upper", "lower" and the like indicate the orientation or positional relationship shown in the drawings, and are only used to facilitate the description of the present application and simplify the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application. Unless otherwise specified and limited, the terms "mounting", "connection", "connection" should be broadly understood, for example, it can be fixedly connected, or it can be detachably connected, or integrally connected; it can be mechanically connected, or it can be electrically connected; it can be directly connected, or it can be indirectly connected through an intermediate medium, or it can be connected inside two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0023] The terms "first", "second" and the like in the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second" and the like are generally a class, and do not limit the number of objects, for example, the first object can be one or more. In addition, "and / or" means at least one of the connected objects, and the character " / ", generally means that the front and rear associated objects are in an "or" relationship.
[0024] The following will be described in conjunction with Figures 1-4 The ship network storm suppression method, device, electronic equipment and storage medium provided by the present application are described.
[0025] Broadcast messages in a ship network are sent to all devices in the network. When broadcast messages are excessively sent due to protocol design defects, network loops or malicious attacks, they will occupy all bandwidth and switch processing resources, causing network storms. That is, network storms are specifically manifested as excessive sending of broadcast messages. Based on the manifestation form of network storm, if the broadcast message can be intercepted, the network storm can be suppressed.
[0026] As Figure 1 shown, the ship network storm suppression method provided by the present application includes steps S1-S2.
[0027] Step S1, receiving a communication message propagated from the ship platform network to the power network.
[0028] The ship platform network can propagate various communication messages to the power network, including broadcast messages, UDP (User Datagram Protocol) messages, FTP (File Transfer Protocol) messages, non-UDP / FTP messages, etc. Among them, the broadcast message includes Address Resolution Protocol (ARP) broadcast message, Dynamic Host Configuration Protocol (DHCP) broadcast message, Automatic Identification System (AIS) broadcast message, etc. The UDP message can transmit temperature sensor data, pressure sensor data, GPS data stream, camera video stream, etc. The FTP message can transmit upgrade firmware, log file, configuration file, etc. The non-UDP / FTP message is a communication message that is neither a UDP message nor an FTP message, including industrial protocol Modbus TCP message, device remote maintenance and security operation SSH message, etc.
[0029] Step S2, in the case of network storm on the ship, if the communication message is a first type of message, the communication message is discarded; wherein the first type of message includes a target broadcast message.
[0030] Before step S2, it is necessary to determine whether a network storm occurs on the ship. The determination method can be to set a flow threshold (such as 10%), if the broadcast message flow in the communication message accounts for more than the flow threshold, it can be considered that a network storm has occurred.
[0031] Among them, the target broadcast message can be any broadcast message, that is, all broadcast messages are discarded, which is the best way to suppress network storm, but some broadcast messages that must be propagated (such as safety-related messages) will also be filtered out, which may affect the safety of the ship.
[0032] From the above, in the case of network storm on the ship, the target broadcast message propagated from the platform network to the power network is discarded, so as to reduce the broadcast message flow, and further suppress the network storm from propagating to the power network.
[0033] In some embodiments, the target broadcast message of the present application can include address resolution protocol broadcast messages and dynamic host configuration protocol broadcast messages.
[0034] The ARP broadcast message is used to analyze the MAC address corresponding to the IP address (such as platform network host communication with power network controller), and the message type is two-layer broadcast. The DHCP broadcast message is used to dynamically allocate IP address for the device (such as user terminal access to the network), and the message type is UDP broadcast.
[0035] In this way, the address resolution protocol broadcast message and the dynamic host configuration protocol broadcast message propagated from the platform network to the power network can be filtered, and the ARP broadcast message flow and the DHCP broadcast message flow are reduced.
[0036] Of course, before filtering the ARP broadcast message and the DHCP broadcast message, it is necessary to determine whether the communication message is the ARP broadcast message and the DHCP broadcast message. The step of determining whether the communication message is the target broadcast message of the application can include: Obtaining the target MAC address and the target IP address of the communication message; Determining whether the communication message is the address resolution protocol broadcast message according to the target MAC address; Determining whether the communication message is the dynamic host configuration protocol broadcast message according to the target IP address.
[0037] Considering that the target MAC address of the ARP broadcast message is usually FF: FF: FF: FF: FF: FF, the step of determining whether the communication message is the address resolution protocol broadcast message according to the target MAC address can further include: if the target MAC address of the communication message is FF: FF: FF: FF: FF: FF, it is determined that the communication message is the ARP broadcast message.
[0038] Considering that the target IP address of the DHCP broadcast message is usually 255.255.255.255, and the source port is 68 or the target port is 67, the step of determining whether the communication message is the dynamic host configuration protocol broadcast message according to the target IP address can further include: if the target IP address of the communication message is 255.255.255.255 and the source port is 68, it is determined that the communication message is the DHCP broadcast message; if the target IP address of the communication message is 255.255.255.255 and the target port is 67, it is determined that the communication message is the DHCP broadcast message.
[0039] In this way, the purpose of determining whether the communication message is the ARP broadcast message or the DHCP broadcast message can be achieved.
[0040] For the non-UDP / FTP message propagated from the platform network to the power network, since the non-UDP / FTP message is not a broadcast message, it does not directly cause a network storm, and the non-UDP / FTP message can be allowed to propagate to the power network. However, the non-UDP / FTP message is not a mandatory message, and transmitting the non-UDP / FTP message will occupy the network communication bandwidth and aggravate the adverse effects of the network storm on the power network.
[0041] In order to avoid the adverse effects of the non-UDP / FTP message propagation on the power network, in some embodiments, the first type of message of the present application can also include a non-UDP / FTP message.
[0042] For the communication message that does not belong to the first type of message, in order to ensure normal communication between the platform network and the power network, it is necessary to allow such a message to propagate to the power network.
[0043] Therefore, in some embodiments, as shown in Figure 2 After step S1, the ship network storm suppression method of the present application can further include: Step S3, in the case of a network storm on the ship, if the communication message is a second type of message, the communication message is sent to the power network. Among them, the second type of message includes at least one of the automatic identification system broadcast message, the user datagram protocol message and the file transfer protocol message.
[0044] As mentioned above, if the target broadcast message is an arbitrary broadcast message, it is equivalent to discarding all broadcast messages propagated to the power network, which may affect the safety of the ship. For example, the AIS broadcast message is used to broadcast the position, speed and other safety information of the ship. If the AIS broadcast message is discarded, the power system will lose the position, speed and other information of the ship, affecting the function of the power system. The second type of message includes the AIS broadcast message, and the AIS broadcast message is allowed to be sent to the power network, which is beneficial to ensure the normal function of the power system.
[0045] For the UDP message, since the UDP message is mainly used to transmit temperature sensor data, pressure sensor data, GPS data stream, camera video stream and other sensor data, the sensor data has an important influence on the safety of the ship, and the second type of message includes the UDP message, which allows the UDP message to be sent to the power network, which can avoid the power system unable to collect sensor data, and is beneficial to ensure the normal function of the power system.
[0046] For the FTP message, since the FTP message is mainly used for transmitting the upgrade firmware, log file, configuration file and the like, the upgrade firmware is used for upgrading the power system, the log file can provide the navigation data for the power system, and the configuration file is used for correctly configuring the power system, the FTP message also needs to be transmitted to the power network. The second type of message includes the FTP message, and the FTP message is allowed to be sent to the power network, which is beneficial to ensuring the normal function of the power system.
[0047] Of course, before sending the second type of message to the power network, it is also needed to judge whether the communication message is the second type of message, i.e., whether it is the AIS broadcast message, the UDP message or the FTP message.
[0048] In some embodiments, the step of judging whether the communication message is the AIS broadcast message can include: acquiring the UDP port of the communication message; judging whether the communication message is the automatic identification system broadcast message according to the UDP port.
[0049] Specifically, since the AIS broadcast message is the message based on the UDP protocol, and the default UDP port is 10110, the step of judging whether the communication message is the automatic identification system broadcast message according to the UDP port can further include: if the UDP port of the communication message is 10110, it is judged that the communication message is the AIS broadcast message.
[0050] In this way, the purpose of judging whether the communication message is the AIS broadcast message can be achieved.
[0051] In some embodiments, the step of judging whether the communication message is the UDP message can include: acquiring the transport layer protocol number of the communication message; judging whether the communication message is the UDP message according to the transport layer protocol number.
[0052] Specifically, since the transport layer protocol number (Protocol field of the IP header) of the UDP message is 17 by default, the step of judging whether the communication message is the UDP message according to the transport layer protocol number can further include: if the transport layer protocol number of the communication message is 17, it is judged that the communication message is the UDP message.
[0053] In this way, the purpose of judging whether the communication message is the UDP message can be achieved.
[0054] In some embodiments, the step of judging whether the communication message is the FTP message can include: acquiring the TCP port of the communication message; judging whether the communication message is the FTP message according to the TCP port of the communication message.
[0055] Specifically, since the FTP message is a TCP protocol-based message, the TCP port of the FTP message is 20 or 21 by default, and therefore, the judgment of whether the communication message is an FTP message according to the TCP port of the communication message can further include: If the TCP port of the communication message is 20 or 21, the communication message is judged to be an FTP message.
[0056] In this way, the purpose of judging whether the communication message is an FTP message can be achieved.
[0057] As shown in Figure 3 The application also provides a ship network storm suppression device, which comprises: A receiving module configured to receive a communication message propagated from a ship platform network to a power network; A filtering module configured to, in the case of a network storm occurring on the ship, discard the communication message if the communication message is a first type of message; The first type of message comprises a target broadcast message.
[0058] It should be noted that the ship network storm suppression device provided by the application can execute the ship network storm suppression method of any of the above embodiments, and therefore, the present embodiment will not be described in detail.
[0059] The target broadcast message of the application can further comprise an address resolution protocol broadcast message and a dynamic host configuration protocol broadcast message.
[0060] The ship network storm suppression device of the application can further comprise a judgment module configured to: Obtain a target MAC address and a target IP address of the communication message; Judge whether the communication message is an address resolution protocol broadcast message according to the target MAC address; Judge whether the communication message is a dynamic host configuration protocol broadcast message according to the target IP address.
[0061] The first type of message of the application can further comprise a non-UDP / FTP message.
[0062] The filtering module of the application can be further configured to: In the case of a network storm occurring on the ship, send the communication message to the power network if the communication message is a second type of message; The second type of message comprises at least one of an automatic identification system broadcast message, a user datagram protocol message, and a file transfer protocol message.
[0063] The ship network storm suppression device of the application can further comprise a judgment module configured to: Obtain a UDP port of the communication message; According to the UDP port, it is judged whether the communication message is an automatic identification system broadcast message.
[0064] The ship network storm suppression device of the present application can further comprise a judgment module for: acquiring the transport layer protocol number of the communication message; judging whether the communication message is a UDP message according to the transport layer protocol number.
[0065] The ship network storm suppression device of the present application can further comprise a judgment module for: acquiring the TCP port of the communication message; judging whether the communication message is an FTP message according to the TCP port of the communication message.
[0066] Figure 4 is a structural schematic diagram of an electronic device provided by the present application, as Figure 4 shown, the electronic device can include a processor, a communications interface, a memory and a communications bus, wherein the processor, the communications interface and the memory complete mutual communication through the communications bus. The processor can invoke the logical instructions in the memory to execute a ship network storm suppression method, which comprises: receiving a communication message propagated from a ship platform network to a power network; in the case of a network storm occurring on the ship, if the communication message is a first type of message, discarding the communication message; wherein the first type of message includes a target broadcast message.
[0067] In addition, the logical instructions in the memory described above can be realized in the form of a software functional unit and sold or used as an independent product, and can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk and various program code storage media.
[0068] In another aspect, the present application also provides a computer program product, which comprises a computer program stored on a non-transitory computer-readable storage medium, and the computer program comprises program instructions, when the program instructions are executed by a computer, the computer can execute the ship network storm suppression method provided by the above-mentioned embodiments, and the method comprises: receiving a communication message propagated from a ship platform network to a power network; in the case of a network storm occurring on the ship, if the communication message is a first type of message, discarding the communication message; wherein the first type of message comprises a target broadcast message.
[0069] In another aspect, the present application also provides a non-transitory computer-readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the ship network storm suppression method provided by the above-mentioned embodiments, and the method comprises: receiving a communication message propagated from a ship platform network to a power network; in the case of a network storm occurring on the ship, if the communication message is a first type of message, discarding the communication message; wherein the first type of message comprises a target broadcast message.
[0070] The device embodiments described above are only schematic, wherein the units illustrated as separate components may or may not be physically separate, and the components illustrated as units may or may not be physical units, i.e., may be located in one place or distributed on a plurality of network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment. Those skilled in the art can understand and implement without creative labor.
[0071] From the above description of the embodiments, those skilled in the art can clearly understand that the embodiments can be realized by means of software plus necessary general hardware platforms, and of course can also be realized by hardware. Based on such understanding, the above technical solutions, essentially or in the sense of contribution to the prior art, can be embodied in the form of a software product, which can be stored in a computer-readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in each embodiment or some parts of the embodiments.
[0072] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement to some technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method of ship network storm mitigation, characterized by, The method comprises: receiving a communication message propagated from a ship platform network to a power network; in the case of a network storm occurring on the ship, if the communication message is a first type of message, discarding the communication message; wherein the first type of message comprises a target broadcast message.
2. The ship network storm suppression method of claim 1, wherein, The target broadcast message comprises an address resolution protocol broadcast message and a dynamic host configuration protocol broadcast message.
3. The ship network storm suppression method of claim 2, wherein, The step of determining whether the communication message is the target broadcast message comprises: obtaining a target MAC address and a target IP address of the communication message; determining whether the communication message is the address resolution protocol broadcast message according to the target MAC address; determining whether the communication message is the dynamic host configuration protocol broadcast message according to the target IP address.
4. The shipboard network storm suppression method of claim 1, wherein, The first type of message further comprises a non-UDP / FTP message.
5. The shipboard network storm suppression method of claim 1, wherein, After receiving the communication message propagated from the ship platform network to the power network, the method further comprises: in the case of a network storm occurring on the ship, if the communication message is a second type of message, sending the communication message to the power network; wherein the second type of message comprises at least one of an automatic identification system broadcast message, a user datagram protocol message, and a file transfer protocol message.
6. The ship network storm suppression method of claim 5, wherein, The step of determining whether the communication message is the automatic identification system broadcast message comprises: obtaining a UDP port of the communication message; determining whether the communication message is the automatic identification system broadcast message according to the UDP port.
7. A ship network storm suppression apparatus, characterized by, The method comprises: a receiving module configured to receive a communication message propagated from a ship platform network to a power network; a filtering module configured to, in the case of a network storm occurring on the ship, if the communication message is a first type of message, discard the communication message; wherein the first type of message comprises a target broadcast message.
8. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the computer program to implement the ship network storm suppression method according to any one of claims 1 to 6. 9.A non-transitory computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the ship network storm suppression method according to any one of claims 1 to 6.
10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the ship network storm suppression method according to any one of claims 1 to 6.