Network access method and device, electronic equipment and storage medium

By identifying and disconnecting untrusted terminals and calculating recovery time based on the number of alarms, the problem of persistent access by untrusted terminals is solved, realizing proactive network defense and intelligent recovery strategies, and improving network security and availability.

CN120979815APending Publication Date: 2025-11-18XINHUASAN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511399539.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

In security-sensitive network environments, untrusted terminals can continuously access the network by changing their MAC and IP addresses, posing a persistent security risk that is difficult to defend against effectively with existing technologies.

Method used

By receiving packets through the ports of network access devices, identifying untrusted terminals and disconnecting them, calculating recovery time based on the number of alarms, dynamically adjusting port recovery strategies, cutting off attack paths, and enhancing proactive defense capabilities.

Benefits of technology

It effectively blocks the attack paths of untrusted terminals, achieves an intelligent balance between security and availability, prevents untrusted terminals from successfully accessing the network, and dynamically adjusts recovery time to deal with frequent attacks or false alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979815A_ABST
    Figure CN120979815A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a network access method and device, electronic equipment and a storage medium. In the application, when it is identified that the address carried by the message received through the first port is not the trusted address of the first port, not only is the message discarded, but also the connection between the first port and the external device is disconnected, so that the attack path of the untrusted terminal is cut off from the source, and the security of the terminal is improved. The network cannot be successfully accessed even if the untrusted terminal continuously tries to access by changing the address, so that the active defense capability of the network is improved. Besides, the port recovery time is dynamically calculated according to the number of alarms, the interruption duration can be automatically prolonged during frequent attacks, attack behaviors can be effectively deterred and blocked, services can be recovered as soon as possible under the condition of false alarms or low risks, and intelligent balance of safety and availability is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and in particular to a network access method and device, an electronic device, and a storage medium. BACKGROUND

[0002] In a security-sensitive network environment, access by an untrusted terminal can lead to data leakage or network attacks. Therefore, preventing access by untrusted terminals is a key to ensuring data and network security.

[0003] Currently, related technologies match the source Media Access Control Address (MAC) and source Internet Protocol Address (IP) of a packet received by any port of a network access device with the MAC address and IP address pre-bound to the port, discard packets that do not match, and implement security protection. However, an attacker can continuously attempt access by changing the MAC address and IP address until a successful attack, which still poses a persistent security risk. SUMMARY

[0004] In view of this, the present application provides a network access method and device, an electronic device, and a storage medium.

[0005] The present application provides a network access method, which is applied to a network access device. The method comprises the following steps:

[0006] receiving a packet through a first port of the device; the first port is any port of the network access device;

[0007] receiving a packet through a first port of the device; the first port is any port of the network access device;

[0008] If it is identified that the address carried by the packet is not a trusted address of the first port, the packet is discarded, the connection between the first port and an external device is disconnected, and an illegal event alarm is output; the illegal event alarm is used to indicate that the terminal sending the packet is an untrusted terminal of the first port; wherein the number of alarms in the current time period is updated when the illegal event alarm is output;

[0009] In the case where the connection between the first port and the external device is disconnected, the recovery time of the connection between the first port and the external device is calculated according to a mapping relationship between a preset number of alarms and recovery time and the number of alarms in the current time period, and the connection between the first port and the external device is restored when the recovery time is reached, wherein the recovery time and the number of alarms have a positive correlation.

[0010] The embodiment of the present application further provides a network access device, which is applied to a network access equipment, and the device comprises:

[0011] a receiving module, configured to receive a message through a first port; the first port is any port of the network access equipment;

[0012] a port disabling module, configured to discard the message and disconnect the connection between the first port and an external equipment if it is identified that the address carried by the message is not a trusted address of the first port, and output an illegal event alarm; the illegal event alarm is used to indicate that a terminal sending the message is an untrusted terminal of the first port; wherein the number of alarms in a current time period is updated when the illegal event alarm is outputted;

[0013] a port recovery module, configured to calculate a recovery time of the connection between the first port and the external equipment according to a mapping relationship between a preset number of alarms and the recovery time and the number of alarms in the current time period if the connection between the first port and the external equipment is disconnected, and recover the connection between the first port and the external equipment when the recovery time is reached, wherein the recovery time is positively correlated with the number of alarms.

[0014] The embodiment of the present application further provides an electronic device, comprising a processor and a computer readable storage medium for storing computer program instructions, the computer program instructions enable the processor to execute the steps of the above method when the computer program instructions are run by the computer readable storage medium.

[0015] The embodiment of the present application further provides a machine readable storage medium, which stores computer program instructions, and the computer program instructions can implement the steps of the above method when the computer program instructions are executed.

[0016] As can be seen from the above technical solution, in the embodiment, when it is identified that the address carried by the message received through the first port is not a trusted address of the first port (that is, it is identified that the terminal sending the message is an untrusted terminal of the first port), not only the message is discarded, but also the connection between the first port and the external equipment is disconnected, so that the attack path of the untrusted terminal is cut off from the root, and even if the untrusted terminal continuously attempts to access by changing the address, the untrusted terminal cannot successfully access the network, and the network active defense capability is improved.

[0017] Furthermore, when the connection between the first port and the external device is lost, the recovery time between the first port and the external device is calculated based on the preset mapping relationship between the number of alarms and the recovery time, as well as the number of alarms in the current time period. When the recovery time is reached, the connection between the first port and the external device is restored. In this way, the recovery time of the port is dynamically calculated based on the number of alarms. This can not only automatically extend the interruption time during frequent attacks, effectively deterring and blocking attack behavior, but also restore services as soon as possible in the case of false alarms or low risk, thus achieving an intelligent balance between security and availability. Attached Figure Description

[0018] Figure 1 A flowchart illustrating the method provided in the embodiments of this application;

[0019] Figure 2 A flowchart illustrating the process of identifying whether an address is a trusted address of the first port, as provided in an embodiment of this application.

[0020] Figure 3 This application provides a schematic diagram of the process for determining whether to permanently close the connection between the first port and the external device;

[0021] Figure 4 Another schematic flowchart illustrating the method provided in this application embodiment;

[0022] Figure 5 This is a schematic diagram of the device provided in the embodiments of this application;

[0023] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0024] To enable those skilled in the art to better understand the technical solutions provided in the embodiments of this application, and to make the above-mentioned objectives, features and advantages of the embodiments of this application more apparent and understandable, the technical solutions in the embodiments of this application will be further described in detail below with reference to the accompanying drawings.

[0025] See Figure 1 , Figure 1 This is a flowchart illustrating the method provided in an embodiment of this application. As one embodiment, the executing entity of this method can be a network access device, such as a switch, an optical network unit (ONU), etc.

[0026] like Figure 1 As shown, the process may include the following steps:

[0027] S101 receives messages through the first port.

[0028] In this embodiment, the first port is any port of the network access device.

[0029] S102, if it is identified that the address carried in the message is not a trusted address of the first port, the message is discarded, the connection between the first port and the external device is disconnected, and an illegal event alarm is output; the illegal event alarm is used to indicate that the terminal that sent the message is an untrusted terminal of the first port; wherein, when outputting the illegal event alarm, the alarm count in the current time period is updated.

[0030] In other words, if the address carried in the message is identified as a trusted address of the first port, it indicates that the terminal sending the message is a trusted terminal of the first port, and the message is forwarded. In this embodiment, when it is detected that the address carried in the message received by the first port is not a trusted address of the first port, not only is the message discarded, but the connection between the first port and the external device is also disconnected. Compared with the passive defense of simply discarding the message in the prior art, directly closing the port can 100% block the subsequent access of illegal terminals. This cuts off the attack path of untrusted terminals from the root. Even if untrusted terminals continuously attempt to access the network by changing their addresses, they will not be able to successfully access the network, effectively improving the network's active defense capability.

[0031] The step of identifying whether the address carried in the message is a trusted address of the first port will be described in detail later with specific embodiments, and will not be repeated here.

[0032] In this embodiment, disconnecting the connection between the first port and the external device means interrupting the physical connection of the first port at the hardware level, stopping the signal transmission of the physical layer (PHY), thereby putting the first port in an isolated and disabled state.

[0033] Disconnecting the first port from the external device includes at least one of the following operations:

[0034] Interrupt the transceiver circuit of the physical layer PHY chip at the first port;

[0035] Stop the optical transmission and / or optical reception of the optical module corresponding to the first port;

[0036] Disconnect or reset the clock connection corresponding to the first port;

[0037] Disconnect the PHY chip and MAC module.

[0038] In this embodiment, the illegal event alarm includes at least the detection time, the port number of the first port, and the MAC address and IP address carried in the message received by the first port.

[0039] As an example, after disconnecting the first port from the external device, the method also includes generating an illegal event log for subsequent staff to query.

[0040] S103, when the connection between the first port and the external device is disconnected, the recovery time between the first port and the external device is calculated based on the preset mapping relationship between the number of alarms and the recovery time, as well as the number of alarms in the current time period. When the recovery time is reached, the connection between the first port and the external device is restored. The recovery time and the number of alarms are positively correlated.

[0041] In this embodiment, the recovery time is determined differently depending on the number of alarms within the current time period. Thus, the recovery time is dynamically calculated based on the number of alarms to match the alarms. This can automatically extend the interruption time during frequent attacks, effectively deterring and blocking attack behavior, and can restore services as quickly as possible in the case of false alarms or low risk, achieving an intelligent balance between security and availability.

[0042] The specific implementation of step S103 will be described later with specific embodiments, and will not be repeated here.

[0043] This concludes the process. Figure 1 The process is shown below.

[0044] pass Figure 1 As can be seen from the process shown, in this embodiment, when it is identified that the address carried by the message received through the first port is not a trusted address of the first port (that is, the terminal that sent the message is identified as an untrusted terminal of the first port), not only is the message discarded, but the connection between the first port and the external device is also disconnected. In this way, the attack path of the untrusted terminal is cut off from the root. Even if the untrusted terminal changes its address and continues to try to access the network, it will not be able to successfully access the network, thus improving the network's proactive defense capability.

[0045] Furthermore, when the connection between the first port and the external device is lost, the recovery time between the first port and the external device is calculated based on the preset mapping relationship between the number of alarms and the recovery time, as well as the number of alarms in the current time period. When the recovery time is reached, the connection between the first port and the external device is restored. In this way, the recovery time of the port is dynamically calculated based on the number of alarms. This can not only automatically extend the interruption time during frequent attacks, effectively deterring and blocking attack behavior, but also restore services as soon as possible in the case of false alarms or low risk, thus achieving an intelligent balance between security and availability.

[0046] The following section elaborates on whether the address carried in the aforementioned identification message is a trusted address of the first port:

[0047] The specific implementation of identifying that the address carried in the message is not a trusted address of the first port can be as follows: if the source MAC address carried in the message is not a trusted MAC address of the first port, and / or the source IP address carried in the message is not a trusted IP address of the first port, then it is determined that the address carried in the message is not a trusted address of the first port.

[0048] See Figure 2 , Figure 2 This is a flowchart illustrating the process of identifying whether an address is a trusted address of the first port, as provided in an embodiment of this application.

[0049] like Figure 2 As shown, the process may include the following steps:

[0050] S201, determine whether the source MAC address and source IP address carried in the message match the trusted MAC address and trusted IP address of the first port, respectively.

[0051] If the result of step S201 is yes, then step S202 is executed; if the result of step S201 is no, then step S203 is executed.

[0052] S202, determine that the address carried in the message is a trusted address of the first port.

[0053] S203, determine that the address carried in the message is not a trusted address of the first port.

[0054] Specifically, a port binding table is pre-configured on each port of the network access device (as shown in Table 1 below). The port binding table includes the legal MAC address and legal IP address corresponding to each port. It should be noted that, depending on the network security level, in a high-security network, one port corresponds to one MAC address and one IP address, while in a relatively low-security network, one port can correspond to a range of MAC addresses and a range of IP addresses.

[0055] Table 1: Port Binding Table

[0056] Port number Legal MAC address Legal IP address Port 1 00:1B:63:A1:B2:C3 192.168.1.10 Port 1 00:3C:63:A1:B2:24 192.168.1.11

[0057] After configuring the port binding table, when a packet is received through the first port of this device, the source MAC address and source IP address of the packet are parsed. If the source MAC address carried by the packet matches the valid MAC address configured for the first port, and the source IP address carried by the packet matches the valid MAC address configured for the first port, then the terminal that sent the packet is determined to be a trusted terminal of the first port, and the packet is forwarded.

[0058] If the source MAC address carried by the message does not match the valid MAC address configured on the first port, and / or the source IP address carried by the message matches the valid IP address configured on the first port, then the terminal that sent the message is determined to be an untrusted terminal of the first port, the message is discarded, and the connection between the first port and the external device is disconnected.

[0059] Optionally, the identification of whether the address carried in the message is a trusted address of the first port can be achieved by a detection unit configured on the first port, which monitors the traffic messages of the first port in real time.

[0060] In this way, it can be accurately identified whether the address carried in the message received by the first port is a trusted address of the first port, providing a basis for whether to disconnect the connection between the first port and the external device.

[0061] The above provides a detailed explanation of whether the address carried in the identification message is a trusted address of the first port.

[0062] The following section elaborates on the calculation of the recovery time of the connection between the first port and the external device:

[0063] It should be noted that the above-mentioned update of the number of alarms in the current time period can be achieved through a counter. Specifically, with a fixed duration as the period, such as 24 hours as the period, if an illegal event alarm occurs in the current period (that is, the current time period), the counter will be incremented by one based on the original count.

[0064] As an example, the specific implementation process of calculating the recovery time of the connection between the first port and the external device can be reflected by a formula based on the preset mapping relationship between the number of alarms and the recovery time, as well as the number of alarms in the current time period. After the formula is preset, the number of alarms in the current time period is substituted into the formula for calculation, and the calculation result is the recovery time of the connection between the first port and the external device.

[0065] For example, based on the preset mapping relationship between the number of alarms and the recovery time, and the number of alarms in the current time period, the recovery time of the connection between the first port and the external device is calculated using the following formula:

[0066] T h =T d +L b *2 n (Formula 1)

[0067] Among them, T h The recovery time for the connection between the first port and the external device;

[0068] T dL is the disconnection time between the first port and the external device. b The set experience value;

[0069] n represents the number of alarms within the current time period.

[0070] For example, if a packet is found to carry an address that is not a trusted address of the first port, the packet is discarded, and the connection between the first port and the external device is disconnected (disconnection time is 9:00). At this time, the counter is updated from 1 to 2. Simultaneously, based on an empirical value of 30 minutes, the counter is updated to 2, and the recovery time is calculated as 9:00 + 30 × 2. 2 =11:00. Start the timer corresponding to the configured first port. When 11:00 is reached, restore the connection between the first port and the external device. In this way, the connection between the first port and the external device is restored automatically, reducing the workload of manual restoration.

[0071] It should be noted that the formula used to determine the recovery time is not limited to the above formula (1), but can also be other formulas. This application does not specifically limit the formula.

[0072] As an example, the above calculation of the recovery time between the first port and the external device based on the number of alarms in the current time period and the preset mapping relationship between the number of alarms and the recovery time is performed on the premise that the total number of times the connection between the first port and the external device is disconnected in the current time period is less than a set threshold.

[0073] In other words, when it is determined that the address carried in a message is not a trusted address of the first port, the message is discarded, and the connection between the first port and the external device is disconnected, the following steps are required: Figure 3 The process shown is as follows:

[0074] See Figure 3 , Figure 3 This application provides a schematic diagram of the process for determining whether to permanently close the connection between the first port and the external device.

[0075] like Figure 3 As shown, the process may include the following steps:

[0076] S301: First, obtain the total number of times the connection between the first port and the external device is disconnected within the current time period, and then determine whether the total number of times the connection between the first port and the external device is disconnected within the current time period is greater than or equal to the set threshold.

[0077] If the result of step S301 is yes, then step S302 is executed; if the result of step S301 is no, then step S303 is executed.

[0078] S302, permanently close the connection between the first port and the external device to prevent the connection between the first port and the external device from being restored based on the recovery time.

[0079] S303, the step of calculating the recovery time of the connection between the first port and the external device based on the number of alarms in the current time period and the preset mapping relationship between the number of alarms and the recovery time.

[0080] If the execution result of step S301 is yes, then the connection between the first port and the external device is permanently closed to suppress the restoration of the connection between the first port and the external device based on the recovery time (optionally, the method for closing the connection between the first port and the external device can be: terminating the timing function of the timer of the first port). If the total number of times the connection between the first port and the external device is disconnected within the current time period is greater than or equal to the set threshold, it means that the number of times the first port is disconnected and then restored to normal use within the current time period is too frequent. For example, if the first port has been disconnected 5 times in 4 hours, it means that the first port has been restored 4 times. In this case, the first port is permanently closed and will no longer be automatically restored. A permanent port closure alarm is generated and sent out to wait for manual intervention by the administrator.

[0081] If the execution result of step S301 is negative, then continue to execute the step of determining the recovery time for the connection between the first port and the external device to be restored from disconnection to normal use based on the number of alarms in the current time period and the preset base time.

[0082] The recovery time of the connection between the first port and the external device is explained in detail below.

[0083] To illustrate the method provided in this application in more detail, the following will be combined with... Figure 4 The solution provided in this application will be described in more detail by way of specific embodiments.

[0084] S401 receives messages through the first port.

[0085] S402, determine whether the source MAC address and source IP address carried in the message match the trusted MAC address and trusted IP address of the first port, respectively.

[0086] If the result of step S402 is yes, then step S403 is executed; if the result of step S402 is no, then step S404 is executed.

[0087] S403, forward the message.

[0088] S404: Discard the message, disconnect the connection between the first port and the external device, output an illegal event alarm, and increment the current counter by one.

[0089] It should be noted that the counter will be reset to zero at each time period.

[0090] S405, obtain the total number of times the connection between the first port and the external device is disconnected within the current time period, and determine whether the total number of times the connection between the first port and the external device is disconnected within the current time period is greater than or equal to a set threshold.

[0091] If the result of step S405 is yes, then step S406 is executed; if the result of step S405 is no, then step S407 is executed.

[0092] S406, terminate the timing function of the timer on the first port to permanently close the connection between the first port and the external device, thereby preventing the connection between the first port and the external device from being restored based on the recovery time.

[0093] S407: Based on the preset mapping relationship between the number of alarms and the waiting recovery time, and the number of alarms in the current time period, calculate the recovery time of the connection between the first port and the external device, and start the timer of the first port.

[0094] S408 restores the connection between the first port and the external device when the timer reaches the recovery time.

[0095] The methods provided in the embodiments of this application have been described above. The apparatus provided in the embodiments of this application is described below:

[0096] See Figure 5 , Figure 5 This is a structural diagram of the device provided in an embodiment of this application. Figure 5 As shown, the device is applied to a network access device, and the device includes: a conversion module 501 and a calling module 502.

[0097] The receiving module 501 is used to receive messages through the first port; the first port can be any port of the network access device.

[0098] The port disabling module 502 is used to discard the packet and disconnect the connection between the first port and the external device if it is identified that the address carried in the packet is not a trusted address of the first port, and to output an illegal event alarm; the illegal event alarm is used to indicate that the terminal that sent the packet is an untrusted terminal of the first port; wherein, when outputting the illegal event alarm, the alarm count in the current time period is updated.

[0099] The port recovery module 503 is used to calculate the recovery time of the connection between the first port and the external device when the connection between the first port and the external device is disconnected, based on the preset mapping relationship between the number of alarms and the recovery time, and the number of alarms in the current time period. When the recovery time is reached, the connection between the first port and the external device is restored. The recovery time and the number of alarms are positively correlated.

[0100] As an example, identifying a trusted address whose address carried in a message is not the first port includes:

[0101] If the source MAC address carried by the message is not a trusted MAC address of the first port, and / or the source IP address carried by the message is not a trusted IP address of the first port, then it is determined that the address carried by the message is not a trusted address of the first port.

[0102] As an example, the recovery time of the connection between the first port and the external device is calculated based on the number of alarms in the current time period and the preset mapping relationship between the number of alarms and the recovery time. This is performed on the premise that the total number of times the connection between the first port and the external device is disconnected in the current time period is less than a set threshold.

[0103] If the total number of times the connection between the first port and the external device is disconnected within the current time period is greater than or equal to a set threshold, the port recovery module is further used for:

[0104] Permanently shut down the connection between the first port and the external device to prevent the connection between the first port and the external device from being restored based on the recovery time.

[0105] As an example,

[0106] Based on the preset mapping relationship between the number of alarms and the recovery waiting time, and the number of alarms in the current time period, the recovery time of the connection between the first port and the external device is calculated using the following formula:

[0107] T h =T d +L b *2 n

[0108] Among them, T h The recovery time for the connection between the first port and the external device;

[0109] T d L is the disconnection time between the first port and the external device. b The set experience value;

[0110] n represents the number of alarms within the current time period.

[0111] As one embodiment, disconnecting the first port from the external device includes at least one of the following operations:

[0112] Interrupt the transceiver circuit of the physical layer PHY chip at the first port;

[0113] Stop the optical transmission and / or optical reception of the optical module corresponding to the first port;

[0114] Disconnect or reset the clock connection corresponding to the first port;

[0115] Disconnect the PHY chip and MAC module.

[0116] As an example,

[0117] Restoring the connection between the first port and the external device upon reaching the recovery time includes:

[0118] When the configured timer reaches its recovery time, the connection between the first port and the external device is restored; when the connection between the first port and the external device is disconnected, the timer's timing function is activated.

[0119] Permanently shutting down the connection between the first port and external devices includes:

[0120] Terminate the timer's timing function to permanently shut down the connection between the first port and external devices.

[0121] This concludes the process. Figure 5 Structural description of the device shown.

[0122] See Figure 6 , Figure 6 This is a structural diagram of an electronic device provided in an embodiment of this application. Figure 6 As shown, the hardware structure may include: a processor and a machine-readable storage medium, the machine-readable storage medium storing machine-executable instructions that can be executed by the processor; the processor is used to execute the machine-executable instructions to implement the method disclosed in the above example of this application.

[0123] Based on the same application concept as the above method, this application embodiment also provides a machine-readable storage medium storing a plurality of computer instructions, which, when executed by a processor, can implement the method disclosed in the above examples of this application.

[0124] For example, the aforementioned machine-readable storage medium can be any electronic, magnetic, optical, or other physical storage device that can contain or store information such as executable instructions, data, etc. For instance, machine-readable storage media can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), solid-state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or combinations thereof.

[0125] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A network access method, characterized in that, This method is applied to network access devices, and the method includes: Messages are received through a first port; the first port can be any port of the network access device. If it is identified that the address carried in the message is not a trusted address of the first port, the message is discarded, the connection between the first port and the external device is disconnected, and an illegal event alarm is output; the illegal event alarm is used to indicate that the terminal that sent the message is an untrusted terminal of the first port; wherein, when outputting the illegal event alarm, the number of alarms in the current time period is updated; When the connection between the first port and the external device is lost, the recovery time between the first port and the external device is calculated based on the preset mapping relationship between the number of alarms and the recovery time, as well as the number of alarms in the current time period. When the recovery time is reached, the connection between the first port and the external device is restored. The recovery time is positively correlated with the number of alarms.

2. The method according to claim 1, characterized in that, The identified trusted addresses whose addresses are not the first port include: If the source Media Access Control (MAC) address carried by the message is not a trusted MAC address of the first port, and / or the source Internet Protocol (IP) address carried by the message is not a trusted IP address of the first port, then it is determined that the address carried by the message is not a trusted address of the first port.

3. The method according to claim 1, characterized in that, The step of calculating the recovery time of the connection between the first port and the external device based on the number of alarms in the current time period and the preset mapping relationship between the number of alarms and the recovery time is performed on the premise that the total number of times the connection between the first port and the external device is disconnected in the current time period is less than a set threshold. If the total number of times the connection between the first port and the external device is disconnected within the current time period is greater than or equal to a set threshold, the method further includes: The connection between the first port and the external device is permanently closed to prevent the restoration of the connection between the first port and the external device based on the recovery time.

4. The method according to claim 1, characterized in that, The recovery time of the connection between the first port and the external device is calculated based on the preset mapping relationship between the number of alarms and the recovery waiting time, as well as the number of alarms in the current time period, using the following formula: T h =T d +L b *2 n Among them, T h The recovery time for the connection between the first port and the external device; T d L is the disconnection time between the first port and the external device. b The set experience value; n represents the number of alarms within the current time period.

5. The method according to claim 1, characterized in that, Disconnecting the first port from the external device includes at least one of the following operations: Interrupt the transceiver circuit of the physical layer PHY chip at the first port; Stop the optical transmission and / or optical reception of the optical module corresponding to the first port; Disconnect or reset the clock connection corresponding to the first port; Disconnect the PHY chip and the MAC module.

6. The method according to claim 3, characterized in that, Restoring the connection between the first port and the external device upon reaching the recovery time includes: When the configured timer reaches the recovery time, the connection between the first port and the external device is restored; the timer starts its timing function when the connection between the first port and the external device is disconnected. The permanent closure of the connection between the first port and the external device includes: Terminate the timer's timing function to permanently shut down the connection between the first port and the external device.

7. A network access device, characterized in that, This device is used in network access equipment, and the device includes: A receiving module is used to receive messages through a first port; the first port is any port of the network access device. The port disabling module is used to discard the packet and disconnect the connection between the first port and the external device if it is identified that the address carried by the packet is not a trusted address of the first port, and to output an illegal event alarm; the illegal event alarm is used to indicate that the terminal that sent the packet is an untrusted terminal of the first port; wherein, when outputting the illegal event alarm, the alarm count in the current time period is updated; The port recovery module is used to calculate the recovery time between the first port and the external device when the connection between the first port and the external device is disconnected, based on a preset mapping relationship between the number of alarms and the recovery time, and the number of alarms in the current time period. When the recovery time is reached, the connection between the first port and the external device is restored. The recovery time is positively correlated with the number of alarms.

8. The apparatus according to claim 7, characterized in that, The identified trusted addresses whose addresses are not the first port include: If the source MAC address carried by the message is not a trusted MAC address of the first port, and / or the source IP address carried by the message is not a trusted IP address of the first port, then it is determined that the address carried by the message is not a trusted address of the first port. And / or, The step of calculating the recovery time of the connection between the first port and the external device based on the number of alarms in the current time period and the preset mapping relationship between the number of alarms and the recovery time is performed on the premise that the total number of times the connection between the first port and the external device is disconnected in the current time period is less than a set threshold. If the total number of times the connection between the first port and the external device is disconnected within the current time period is greater than or equal to a set threshold, the port recovery module is further configured to: Permanently shut down the connection between the first port and the external device to prevent the restoration of the connection between the first port and the external device based on the recovery time; And / or, The recovery time of the connection between the first port and the external device is calculated based on the preset mapping relationship between the number of alarms and the recovery waiting time, as well as the number of alarms in the current time period, using the following formula: T h =T d +L b *2 n Among them, T h The recovery time for the connection between the first port and the external device; T d L is the disconnection time between the first port and the external device. b The set experience value; n represents the number of alarms within the current time period; And / or, Disconnecting the first port from the external device includes at least one of the following operations: Interrupt the transceiver circuit of the physical layer PHY chip at the first port; Stop the optical transmission and / or optical reception of the optical module corresponding to the first port; Disconnect or reset the clock connection corresponding to the first port; Disconnect the PHY chip and the MAC module; And / or, Restoring the connection between the first port and the external device upon reaching the recovery time includes: When the configured timer reaches the recovery time, the connection between the first port and the external device is restored; the timer starts its timing function when the connection between the first port and the external device is disconnected. The permanent closure of the connection between the first port and the external device includes: Terminate the timer's timing function to permanently shut down the connection between the first port and the external device.

9. An electronic device, characterized in that, The electronic device includes: Processor; and A computer-readable storage medium storing computer program instructions that, when executed by the processor, cause the processor to perform the steps of the method as described in any one of claims 1 to 6.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that, when executed by a processor, cause the processor to perform the steps of the method as described in any one of claims 1 to 6.