ARP Packet Priority Determination for Routing Protocol Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current routing protocols are vulnerable to ARP attacks, which can disrupt communication links and cause fatal impacts on core node routers, as they fail to effectively distinguish between legitimate and attack ARP packets, leading to broken protocol links and communication interruptions.
Innovation Solution
A method and device that generate a white list protection entry based on dynamic routing protocol subscription information to determine the priority of ARP packets, allowing for the differentiation between attack and legal ARP packets, ensuring normal interaction of the routing protocol by prioritizing legal ARP packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ARP packets are processed without priority differentiation, then all ARP packets are treated equally, but attack ARP packets can disrupt routing protocol interactions and cause communication interruptions
Solution Approach 1:
The patent applies local quality by assigning different priority levels to different ARP packets based on their destination addresses. Specifically, ARP packets destined for routing protocol interactions (e.g., OSPF, BGP, ISIS protocols) are assigned high priority, while other ARP packets receive normal or low priority. This selective differentiation ensures that critical routing protocol communications are protected from disruption by attack packets, while maintaining normal processing for non-critical ARP traffic.
Solution Approach 2:
The patent implements feedback mechanisms through ARP inspection and validation processes. The system monitors incoming ARP packets, validates their legitimacy against configured policies and routing protocol requirements, and adjusts packet handling accordingly. This feedback loop enables the system to identify and prioritize legitimate routing protocol ARP packets while filtering or deprioritizing attack packets, thereby maintaining reliable protocol interactions.
2Ease of operation
If all ARP packets are processed with equal priority, then processing is simple, but legal ARP packets for routing protocol interaction may be delayed or disrupted by attack packets
Solution Approach 1:
The patent maintains processing simplicity through automated priority assignment based on packet characteristics. Rather than requiring complex manual configuration, the system automatically identifies routing protocol ARP packets through destination address matching and assigns appropriate priorities. This automated approach preserves ease of operation while ensuring that critical keep-alive and information packets are processed before attack packets.
Solution Approach 2:
The patent applies preliminary action by pre-configuring priority rules and ARP inspection policies before attack occurs. The system establishes beforehand which destination addresses correspond to routing protocol interactions and assigns high priority to packets destined for those addresses. This preliminary configuration ensures that when attack packets arrive, the system can immediately differentiate and prioritize legitimate traffic without requiring real-time complex decision-making.
3Device complexity
If ARP entries are refreshed periodically without priority differentiation, then ARP maintenance is straightforward, but attack packets can age out legitimate ARP entries causing fatal impacts on core node routers
Solution Approach 1:
The patent applies local quality to ARP entry maintenance by assigning different aging behaviors to different ARP entries based on their importance. ARP entries associated with routing protocol interactions are marked as high priority and configured with extended or indefinite aging times, ensuring they remain in the ARP table even during extended periods. Regular ARP entries use standard aging mechanisms. This differentiated approach protects core node router stability while maintaining manageable ARP table operations.
Solution Approach 2:
The patent implements feedback in ARP maintenance through continuous monitoring of ARP packet flows and entry validity. The system tracks which ARP entries are actively used for routing protocol interactions and adjusts their aging behavior accordingly. This feedback mechanism ensures that legitimate routing protocol ARP entries are preserved while allowing outdated or potentially malicious entries to be removed, maintaining both reliability and operational simplicity.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
Provided are a method and a device for determining and sending a priority of a packet, and a routing system. The method comprises: receiving an ARP packet; determining the white list protection entry of the ARP packet according to the dynamic routing protocol subscription information. By means of the present invention, the technical problem in the related art that the ARP packet cannot be interacted normally due to an ARP attack is solved.