Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

69 results about "Gateway address" patented technology

The gateway address (or default gateway) is a router interface connected to the local network that sends packets out of the local network. The gateway has a physical and a logical address.

Multi-cluster architecture, multi-cluster communication method and device, equipment and medium

The invention provides a multi-cluster architecture, a multi-cluster communication method and device, equipment and a medium, and the method comprises the steps: analyzing a cross-cluster call request when a first cluster gateway of a first cluster receives the cross-cluster call request, and determining a target service name corresponding to the cross-cluster call request; according to the target service name, querying a target cluster gateway address corresponding to a target service targeted by the cross-cluster call request; under the condition that the target cluster gateway address corresponding to the target service is not queried, acquiring the target cluster gateway address corresponding to the target service from the registration center, and sending an access request to a second cluster according to the target cluster gateway address; and a second cluster gateway of the second cluster determines a target address of a target node corresponding to the target service based on the access request, and forwards the access request to the target node. According to the invention, during cross-cluster request, the service address of the opposite-end business does not need to be known, and only the service name needs to be known; and a fault-tolerant mechanism is provided.
Owner:CHINA TELECOM CORP LTD

2.4 G-based RSSI (Received Signal Strength Indicator) positioning data relay transmission device and method

The invention discloses a 2.4 G-based RSSI (Received Signal Strength Indicator) positioning data relay transmission device and method, and belongs to the technical field of wireless communication. The device comprises a positioning label, a positioning gateway, a relay gateway and a public network gateway. The positioning tag broadcasts a 2.4 G signal containing the ID of the positioning tag; the positioning gateway scans the 2.4 G signal, and generates and broadcasts a data packet in which a positioning gateway address, a data packet number, a relay level and aggregated data are packaged; a relay gateway is switched to a low-power-consumption mode after initialization through a monitoring-learning-synchronization mechanism, wakes up and receives data in a broadcast time window of an upstream gateway of the relay gateway, updates a relay level and forwards the data to a downstream gateway, and therefore multi-hop relay transmission of the data is achieved. And the public network gateway finally uploads the data to a cloud platform or an upper computer. According to the invention, through data aggregation and time synchronization dormancy, the system power consumption is greatly reduced, and long-distance and long-endurance positioning data transmission of battery power supply in a complex environment is realized.
Owner:云筑信息科技(成都)有限公司 +1

Data transmission method of electronic equipment, electronic equipment and storage medium

The embodiment of the invention discloses a data transmission method of an electronic device, the electronic device and a storage medium, the data transmission method can be applied to a first system module, and by interrupting respective independent network configuration processes of two system modules during power-on, a virtual bridging network card in the first system module is used to transmit data to the first system module. Taking over a point-to-point group master network card enumerated by the first system module and a first connection network card connected with the second system module, and configuring a gateway address which is the same as the address of the second system module for the local area network of the assembly, after the wireless connection link is established between the wireless terminal equipment and the first system module, a user can directly select any one system module as a sending target, and the bridging network card processes or forwards the data according to the target address after receiving the data, so that the connection operation of data transmission in a multi-person communication process is simplified; the continuity of information transmission in the multi-person communication process is improved, and the convenience of using the wireless terminal equipment by the user in the interactive tablet environment is also improved.
Owner:GUANGZHOU SHIYUAN ELECTRONICS CO LTD +1

Heterogeneous Gateway Address Matching Method, Device, Computer Equipment and Storage Medium

The present application relates to a method and apparatus for heterogeneous address matching. The method includes: obtaining a first address set of a target geographical area, and constructing a first address graph data structure according to the first address set; obtaining a second address set of the target geographical area, and constructing a second address graph data structure according to the second address set; screening out a plurality of address matching pairs from the first address set and the second address set, labeling each address matching pair to obtain corresponding sample address matching pairs; iteratively training an address matching model using the first address graph data structure, the second address graph data structure, and the plurality of sample address matching pairs to obtain a trained address matching model; processing the first address graph data structure and the second address graph data structure through the trained address matching model, and identifying all address matching pairs in the first address set and the second address set according to the processing results. The present application can more accurately and quickly identify different-source addresses.
Owner:SHENZHEN YISHIHUOLALA TECH CO LTD

A message forwarding method and device

This application provides a packet forwarding method and device. The method involves: determining whether to perform Layer 3 forwarding based on the destination MAC address of the Ethernet packet (which is the gateway MAC address); searching the link layer address mapping table based on the destination IP address of the inner IP packet of the Ethernet packet; obtaining a new destination MAC address from the matching link layer address mapping table entry when a matching entry for the destination IP address is found; searching the MAC address table based on the new destination MAC address; obtaining the outgoing port and outgoing VLAN from the matching entry when a matching entry for the new destination MAC address is found; modifying the destination MAC address, source MAC address, and incoming VLAN of the Ethernet packet to the new MAC address, gateway MAC address, and outgoing VLAN, respectively; and sending the modified Ethernet packet through the outgoing port.
Owner:NEW H3C TECH CO LTD

A networking method and system based on dynamic IPv6 address

The application discloses a networking method and system based on dynamic IPv6 addresses, wherein the system comprises terminal equipment and a VPN gateway, and the terminal equipment accesses a network through the VPN gateway. The dynamic change of the IPv6 address of the VPN gateway (if the public IPv4 address is sufficient, the method is also applicable) can effectively alleviate the network asset exposure surface and reduce the possibility of being attacked by taking advantage of the unlimited nature of the IPv6 address.
Owner:SHENYANG AEROSPACE ELECTRIC POWER EQUIP CO LTD

Method for accessing home intranet, edge access gateway, system, medium and product

The invention discloses a method for accessing a home intranet, an edge access gateway, a system, a medium and a product. The method comprises the following steps: acquiring information of a home terminal obtained by finishing Ethernet point-to-point protocol dialing; an access message sent by the cloud core network equipment is received, and when it is judged that the access message meets a preset condition according to an inner-layer message source IP address in the access message, an inner-layer destination MAC address and a destination IP address in the access message are analyzed to serve as a WAN MAC address and a terminal IP address of a corresponding broadband user; and querying a pre-stored uplink flow forwarding table according to the WAN MAC address and the terminal IP address to obtain a corresponding gateway MAC address and a corresponding terminal MAC address, respectively replacing the source and target MAC addresses of the access message with the gateway MAC address and the terminal MAC address, and then sending the access message to the home terminal. According to the embodiment of the invention, low-cost and high-speed private network accompanying communication can be realized.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Non-intrusive signature encryption video playing method based on secure decoding library

The embodiment of the invention discloses a non-intrusive signature encryption video playing method based on a secure decoding library. A specific embodiment of the method comprises the steps of configuring a decoding library supporting a security function in response to a situation that a target video monitoring platform does not support a preset protocol; initializing a decoding library, and transmitting the security gateway address and the target front-end equipment identifier to the decoding library; sending a video playing request to the target video monitoring platform through a transmission protocol of the target video monitoring platform, and receiving a signature encrypted video code stream from the target video monitoring platform; transmitting the signature encrypted video code stream to a decoding library; and based on the decoding library, carrying out adaptive security processing on the signature encrypted video code stream to obtain decoded video data, receiving the decoded video data from the decoding library, and playing the decoded video data. According to the embodiment, for a video monitoring platform of a non-GB35114 standard, the technical effects of reducing video playing delay and gateway load and meeting data security requirements are achieved.
Owner:北京中星天视科技有限公司 +1

Untrusted 3GPP access

A method for operating a user equipment operating in a visited cellular network for which no roaming agreement exists between a home cellular network of the user equipment and the visited cellular network. The user equipment transmits an access request to the visited cellular network requesting access to the visited cellular network. The access request includes an identifier indicating to originate from a user equipment for which no roaming agreement exists with the home cellular network of the user equipment. The user equipment transmits a session establishment request to the visited network to establish a data packet session in the visited cellular network. The UE determines an address of a gateway providing access to the home cellular network, and establishes a connection to the gateway based on the determined address via the visited cellular network.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Mirror flow control method and apparatus, electronic equipment and readable storage medium

This invention provides a mirroring traffic control method and apparatus. The method is applied to gateway devices in a gateway cluster, where the gateway cluster includes multiple gateway devices, each storing a mirroring configuration. The method includes: if the mirroring configuration contains the gateway address of a gateway device, then sending service traffic to a mirroring service node. The mirroring configuration is used to control some gateway devices in the gateway cluster to perform mirroring services. This allows service traffic to be mirrored to a test environment through mirroring configuration without changing the existing network architecture, thus achieving control over the traffic mirroring service.
Owner:BEIJING QIYI CENTURY SCI & TECH CO LTD

Dynamic allocation methods, systems, devices and media for IoT gateways

This invention relates to the field of Internet of Things (IoT) communication technology, and more particularly to a dynamic allocation method, system, device, and medium for IoT gateways. The method includes: constructing a global state information database; when a sensor node needs to connect to an edge computer, the edge computer, based on the global state information database, filters all communication gateways according to a preset candidate set filtering strategy to obtain a set of candidate communication gateways; performing a weighted comprehensive calculation on each communication gateway in the candidate set to obtain an adaptation score for each communication gateway; obtaining a target communication gateway based on the adaptation score of each communication gateway combined with a preset switching mechanism; and the edge computer issuing an instruction containing the address code of the target communication gateway to the sensor node, thereby establishing a connection between the sensor node and the target communication gateway and transmitting data. This invention improves the system's concurrency limit, ensures the quality of data transmission, realizes the transformation from "local optimum" to "global optimum," and exhibits good adaptability.
Owner:FREQUENCY EXPLORATION INTELLIGENT TECH JIANGSU CO LTD +1

Multi-gateway scheduling processing method, device, system, server and storage medium

The application provides a multi-gateway scheduling processing method, device, system, server and storage medium, and relates to the technical field of communication. The method comprises the following steps: acquiring an access request of a client to a capability gateway cluster; if the access mode is a software development kit access, acquiring gateway subscription information of the client, determining a capability gateway address to be connected and permission information according to the application identifier, the capability identifier and the gateway subscription information, sending the capability gateway address to be connected and the permission information to the client, so that the client sends an authentication request to the capability gateway cluster corresponding to the capability gateway address to be connected, and completes the authentication according to the received authentication request response result. The method of the application avoids that all requests pass through a gateway access proxy server to distribute capability gateway addresses and permission information, thereby reducing the connection pressure of the gateway access proxy server and reducing the possibility of collapse of the gateway access proxy server in a high-concurrency scenario.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

A data transmission method and system

The application discloses a data transmission method and system, and relates to the technical field of computer networks. In the data transmission method, a server sets a default gateway address of a client when the client performs data transmission. When the client performs data transmission, the user does not need to manually configure the default gateway address, and only needs to configure an internet protocol address and a subnet mask, so that the efficiency of manually configuring network information is improved. The server determines a target default gateway address according to the default gateway address of a router and the data flow received by the default gateway address. Since the data flow received by the default gateway address is dynamically changed, the determined target default gateway address is dynamically changeable, the load is prevented from being concentrated on a static gateway address, the network information configuration is more reasonable, the problem of data transmission blockage is reduced, and the transmission efficiency of the network is improved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Privacy computing network authorization and state management and control method and system based on node contract

The invention discloses a privacy computing network authorization and state management and control method and system based on a node contract, relates to the field of privacy computing, and aims to solve the problems that a decentralized privacy computing collaborative network depends on centralized nodes, state synchronization is inconsistent and authorization management and control are extensive. Through point-to-point interaction of intercommunication gateways of an initiator node and a partner node, node cooperation application and data set authorization configuration are completed, and real-time synchronization and authorization full-life-cycle management of a data set and node information are realized; an initiator node and a partner node locally maintain a cooperative gateway address list based on an interworking gateway, automatic synchronization is achieved through cooperation application, a centralized registration center is not needed, network decentralization, state consistency and authorization refinement are ensured, and the method is suitable for a cross-mechanism privacy computing cooperation scene.
Owner:ZHEJIANG RURAL COMMERCIAL DIGITAL TECH CO LTD

Secure real-time updates for isolated security systems

Methods and systems provide secure, real-time software updates over a public network to an isolated security system. A method includes the steps of setting up a network address translation (NAT) data structure for allowing outbound connections only through a first firewall between the isolated security system and the public network, and configuring the isolated security system to identify an internet web gateway address to get a software update from a security system update manager over a predetermined protocol and port. A further step involves configuring a proxy setting in the isolated security system to identify an internet web gateway address of a proxy server in a NAT subnet.
Owner:SAUDI ARABIAN OIL CO

Admission method, network access method and related device, equipment, medium and product

The embodiment of the invention provides an access method, a network access method, a related device, equipment, a medium and a product. The access method is applied to a gateway, and comprises the following steps: writing a preset authentication passing identifier into a gateway MAC address based on a preset rewriting rule under the condition that terminal identity authentication passes, and obtaining a rewritten gateway MAC address; the rewritten gateway MAC address is sent to the terminal, so that the terminal sends an access request to a target network by taking the rewritten gateway MAC address as a target MAC address; and in response to an access request of the terminal to the target network, analyzing the target MAC address carried by the access request according to a preset rewriting rule, and accessing the terminal to the target network under the condition that the preset authentication passing identifier is obtained through analysis. According to the admission method, admission control is carried out based on the target MAC address, only whether the target MAC address contains the preset authentication passing identifier or not needs to be identified, searching and matching of the source MAC address do not need to be carried out, memory is saved, the admission control efficiency is improved, and management and maintenance are simplified.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Address allocation method of gateway, core network, user terminal, medium and product

The embodiment of the application provides a gateway address allocation method, a core network, a user terminal, a medium and a product. The method comprises the following steps: when a protocol data unit session is established by the user terminal, the core network acquires the information of a network segment of a hanging device associated with the user terminal and an Internet protocol address of the user terminal, encapsulates the information of the network segment of the hanging device into a protocol configuration option field, and constructs a protocol data unit session establishment response message according to the protocol configuration option field and the Internet protocol address of the user terminal, wherein the protocol data unit session establishment response message comprises the protocol configuration option field and the Internet protocol address of the user terminal. Then, the protocol data unit session establishment response message is sent to the user terminal, and the user terminal is used for allocating the Internet protocol address of the gateway used by the hanging device according to the protocol data unit session establishment response message. The application does not need a user to manually configure the network segment information to the user terminal, and the intelligent degree and the accuracy of address allocation are improved.
Owner:CHENGDU TD TECH LTD

A data resource positioning method and system based on identification resolution

The application discloses a data resource positioning method and system based on identification analysis, relates to the technical field of data communication and resource management, and comprises the following steps: receiving a data resource positioning request, separating a global unique identification in the data resource positioning request into a prefix part and a suffix part; performing main domain analysis according to the prefix part; performing resource analysis according to the suffix part; the resource analysis sends the suffix part to a digital object warehouse gateway address; a gateway corresponding to the digital object warehouse gateway address searches and returns a target data resource from a corresponding digital object warehouse according to the suffix part, and verifies access authority at the same time. Through the hierarchical processing mechanism of the main domain analysis and the resource analysis, the application solves the technical problem of accurate positioning of massive heterogeneous data resources, adopts the technical means of prefix hierarchical query and suffix accurate matching, realizes unified management and efficient access of data resources, improves data sharing and exchange efficiency, and guarantees the safety of data access.
Owner:GUANGZHOU ZHONGDE INFORMATION TECHNOLOGY CO LTD

Deployment method of gateway system and related equipment

The invention relates to a deployment method of a gateway system and related equipment. The method comprises the following steps: in response to starting of a server based on a PXE mode, acquiring an authorization token, a gateway address and a filling control center IP address from an approval center according to server equipment information; wherein the authorization token is generated when the approval center approves the downloading authority of the server according to the server equipment information and the approval is passed; when the approval is passed, the approval center is also used for generating an equipment key and synchronizing the equipment key to the filling control center; establishing a cross-network segment route according to the gateway address, and obtaining an equipment key and a system mirror image file from a filling control center through the cross-network segment route according to the authorization token; and decrypting the verification information ciphertext according to the device key, verifying the boot mirror image according to a verification strategy and a verification value obtained by decryption, and installing the boot mirror image under the condition that the verification is passed. According to the embodiment of the method, automatic deployment of the gateway system is realized, and the security of the gateway system is improved.
Owner:BEIJING EETRUST TECH CO LTD

Method and system for privacy computing network authorization and state management based on node contract

The application discloses a kind of based on node contract's privacy computing network authorization and state management method and system, it is related to privacy computing field, it aims at solving the problem of relying on centralization node, state synchronization inconsistency and extensive authorization management in the decentralized privacy computing collaborative network. Through the point-to-point interaction of the intercommunication gateway of initiator node and partner node, node cooperation application, data set authorization configuration are completed, and the real-time synchronization of data set and node information and the authorization full life cycle management are realized;Initiator node and partner node maintain the cooperation gateway address list based on intercommunication gateway locally, automatically synchronized through cooperation application, without centralized registration center, ensure network decentralization, state consistency and authorization refinement, suitable for cross-institution privacy computing collaborative scene.
Owner:ZHEJIANG RURAL COMMERCIAL DIGITAL TECH CO LTD

A stateless lightweight cross-range network control method and system

The present invention discloses a stateless lightweight cross-range network control method and system. The present invention realizes the configuration of cross-range network connection by adding a range gateway element in the topology, wherein a range gateway element is configured for each cross-range network connection in each sub-range scenario; when the cross-range scenario is started, each sub-range network is constructed and the unique ID of each element of the local topology is reported to the joint management center; the joint management center sends a triple data record containing the local and opposite cross-range port unique IDs and the opposite border gateway IP address to the border gateway of the sub-range; the border gateway generates a corresponding record locally based on the received triple data, and starts to listen at the designated port, encapsulating the intercepted message content and the opposite cross-range port unique ID together and sending it; the opposite range border gateway decapsulates and forwards it. The present invention can reduce the difficulty of implementing cross-range traffic intercommunication and improve the convenience of maintaining cross-range scenarios.
Owner:SAINING WANGAN

Access authentication method, device, system, electronic device and storage medium

The present invention proposes an access authentication method, device, system, electronic device and storage medium, which relate to the field of communication technology. Two address pools with the same IP address range and gateway address are configured on the SDN controller, and the two address pools are associated with different VRF information. The SDN controller receives a DHCP relay request message sent by a DHCP relay device. When the address pool associated with the VRF information in the DHCP relay request message is the address pool corresponding to the default VLAN, an IP address is allocated to the terminal from the address pool and the terminal is authenticated; the access port VLAN of the terminal after successful authentication is configured as an authorized VLAN, and the IP address is synchronized to the allocation list of the address pool corresponding to the authorized VLAN. In this way, after the terminal is successfully authenticated, it can directly use the IP address obtained before authentication to communicate, without waiting for the terminal to renew its lease or manually triggering the terminal to re-acquire the IP address in the authorized VLAN before communication.
Owner:MAIPU COMM TECH CO LTD

ARP table item synchronization method and MLAGE-Lite test system

The invention discloses an ARP (Address Resolution Protocol) table item synchronization method and an MLAP-Lite test system. The method applied to auxiliary test equipment of the MLAP-Lite test system comprises the following steps: receiving an ARP message notified by the test equipment in a VLAN (Virtual Local Area Network); the gateway address of the ARP message is an IP (Internet Protocol) address of the same VLAN (Virtual Local Area Network) interface configured by the two MLAP-Lite gateways; packaging an LLDP message according to the ARP message; and the LLDP message is sent to the two MLAP-Lite gateways through a link aggregation port in the VLAN. According to the method, the ARP table item is not stored on the auxiliary testing equipment, so that the overall configuration complexity is reduced, and the performance requirement on the auxiliary testing equipment is reduced; and the two MLAGE-Lite gateways can synchronously receive the latest ARP table item information in real time, so that the problem of traffic abnormality caused by inconsistency of table items on two sides after the ARP changes in a waiting period in the prior art is solved.
Owner:MAIPU COMM TECH CO LTD

Full-link gray release method with front end and rear end separated

The invention discloses a full-link gray release method with separated front and rear ends, which is applied to the technical field of electronic information and aims to solve the problems that the traditional software release is high in full risk, the experience is influenced by shutdown and the gray capacity is insufficient. According to the method, a three-layer collaborative architecture of'front-end gray level + back-end service gray level + elegant shutdown 'is adopted, the front-end gray level layer configures IP dimension gray level users based on Nginx, and front-end resources and gateway addresses are dynamically switched; the back-end service gray level layer realizes gray level request routing through a self-defined load balancer in combination with a registration center; and the elegant shutdown layer ensures safe offline of the old version. External users may participate in grayscale by invitation or traffic segmentation. During implementation, version preparation and user traffic planning are firstly completed, and front-end gray level control, rear-end service gray level routing and elegant shutdown and traffic switching are sequentially executed. Compared with the prior art, the method has the advantages of controllable risk, non-stop upgrading, full-link collaboration, flexible expansion and the like, and the security of software release and the user experience are improved.
Owner:BEIJING TIANWEI CHENGXIN ELECTRONIC COMMERCE CO LTD

Privacy disclosure prevention traceable code scanning method and system based on trusted execution environment

The invention discloses a privacy disclosure prevention traceable code scanning method and system based on a trusted execution environment, and belongs to the technical field of mobile internet security. The method comprises the steps that a special two-dimensional code is generated and published, a security gateway address and a scene identifier are encoded in the two-dimensional code, after user equipment scans the code, encryption feature information is extracted in a local trusted execution environment through a client security module, an encryption channel is established, the encryption feature information and the scene identifier are sent to a security gateway through the encryption channel, and the security gateway address and the scene identifier are encrypted. The cloud trusted execution environment service module receives the information, performs decryption and business processing in a secure enclave, generates a traceability evidence, automatically triggers an intelligent contract, writes the traceability evidence and a data use event into a block chain, and returns a business processing result to a merchant system, and a user performs traceability query through user equipment. According to the invention, based on TEE and block chain technologies, privacy zero leakage in a code scanning process is realized, data is credibly traced by using a full link, and security compliance is improved.
Owner:JIANG SU RUN HAI KE XING WU LIAN WANG KE JI YOU XIAN GONG SI

Data processing method, device and equipment

The invention provides a data processing method, device and equipment, which can be applied to the technical field of networks. The data processing method comprises the steps that port detection messages are sent to a plurality of to-be-detected servers according to a preset time interval, the port detection messages are used for detecting the communication states of ports in the to-be-detected servers, and the source addresses of the port detection messages are gateway addresses; under the condition that a plurality of reply messages from the to-be-detected server are received within a first preset time period, a message queue of the reply messages is determined, the message queue comprises a key value, and the key value indicates an identifier of the to-be-detected server and a port number of the to-be-detected server used for sending the reply messages; and determining a port detection result of the to-be-detected server according to the message queue.
Owner:DAWNING CLOUD COMPUTING TECH CO LTD +1

Communication method and device, electronic equipment and storage medium

The invention relates to a communication method and device, electronic equipment and a storage medium. The method comprises the following steps: in response to a communication request based on a first communication card, establishing a target data channel through a second communication card; the first communication card is a non-data card, the second communication card is a data card, and the target data channel is used for enabling the electronic equipment to be connected with the Internet; acquiring a target gateway address of the first communication card based on the target data channel; and based on the target gateway address, connecting a target server corresponding to the first communication card, so that the electronic equipment performs a call based on the first communication card. According to the method, the target number of channels are established through the second call card to assist the first call card in call, voice call and short message service can be realized without being in a WiFi coverage range, the limitation of needing to be in the WiFi coverage range is avoided, and the communication flexibility is improved.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Bare metal server onboarding system, method, and apparatus

Embodiments of the present application provide a bare metal server online system, method and device, in which the system comprises: a cloud platform management device, configured to perform network configuration of a physical switch accessed by a bare metal server in a business network when detecting that the bare metal server is switched from a provision network to the business network; acquire a gateway address of a gateway device corresponding to the business network; create a first DHCP port of the business network by multiplexing the gateway address; a DHCP server, configured to create a first DHCP service and run the first DHCP service through the gateway address; and respond to a first DHCP request through the first DHCP service to allocate an IP address in the business network to the bare metal server. The first DHCP port is created and the first DHCP service is run by multiplexing the gateway address of the gateway device of the business network, so that the bare metal server is successfully online.
Owner:RUIJIE NETWORKS CO LTD

Method and system for detecting and blocking direct connection behavior of terminal

The invention relates to the field of direct connection detection, and provides a terminal direct connection behavior detection and blocking method and system. The method comprises the following steps: when a network card insertion action is detected, starting ARP scanning, sending an RTMGETADDR message to a kernel by utilizing Netlink, extracting an IP address bound with a network card, a subnet mask and a gateway address so as to calculate an IP address range and a host number in the same local area network, circularly sending ARP message detection to all IP addresses, and recording an ARP cache table; the MAC addresses in the ARP cache table are read, and invalid MAC addresses are filtered out; if there is only one valid MAC in the ARP table of the network card after filtering and multiple times of ARP scanning, it is determined that the network cable is directly connected; after detecting that the network cable is directly connected, checking an MAC address manufacturer prefix according to an MAC database and an equipment fingerprint database which are input in advance, and excluding disguise attacks of intermediate equipment; and judging the risk level of the equipment directly connected with the network cable, and blocking, alarming or releasing according to different risk levels.
Owner:中孚安全技术有限公司