Network Terminal Management Using ARP Probe Theft Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication networks, theft terminals that duplicate and use IP/MAC addresses of normal terminals cause IP conflicts and security issues like hacking and wiretapping, as existing systems lack effective methods to identify and block such malicious activity.
Innovation Solution
An apparatus and method that analyzes network packets to collect and store address data, uses ARP probe packets to identify theft terminals by comparing IP/MAC addresses, and applies automatic private IP addressing (APIPA) to reset the theft terminal's IP address, blocking network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IP/MAC addresses are used for terminal identification without verification procedures, then communication simplicity is improved, but network security deteriorates due to easy address duplication by malicious users
Solution Approach 1:
The system performs preliminary actions by collecting and storing address data of normal terminals before theft terminals can duplicate them. When an ARP probe packet is received, the system checks against pre-stored address data to identify theft terminals, preventing security breaches before they can cause harm.
Solution Approach 2:
The system implements feedback mechanisms by monitoring ARP probe packets and comparing them against stored address data. When a theft terminal is detected, the system provides feedback by transmitting reply packets that trigger APIPA function to reset the theft terminal's IP address, creating a closed-loop security response system.
2Adaptability or versatility
If theft terminals are allowed to duplicate IP/MAC addresses, then device compatibility is improved, but network reliability deteriorates due to IP conflicts and security breaches
Solution Approach 1:
The system applies preliminary anti-action by proactively detecting theft terminals through ARP probe packet analysis and comparing them against pre-stored address data. Before theft terminals can cause IP conflicts or security breaches, the system transmits reply packets that trigger IP address resetting, preventing harmful effects in advance.
Solution Approach 2:
The system converts the harmful behavior of theft terminals into a beneficial detection mechanism. By analyzing ARP probe packets that theft terminals must send to obtain IP addresses, the system identifies and blocks these malicious devices, transforming their necessary communication protocol into a security detection opportunity.
3Reliability
If ARP probe packets are analyzed to identify theft terminals, then network security is improved, but system complexity increases due to additional packet analysis and address data management
Solution Approach 1:
The system applies self-service by utilizing existing network infrastructure and protocols to perform security functions. It uses standard ARP probe packets already present in network communication, leverages the APIPA function already built into terminal devices for IP address resetting, and employs existing packet analysis capabilities, thereby achieving enhanced security without requiring completely new complex systems.
Data Source
AI summary
A method for managing a terminal, according to one embodiment, may comprise the steps of: collecting, from packets received from a plurality of terminals connected to a network, address data of the plurality of terminals and state information indicating a network connection state of each of the plurality of terminals; obtaining, from a received ARP probe packet, a first IP address and a first MAC address of a first terminal that has transmitted the ARP probe packet; and, when address data including the same IP address and MAC address as the first IP address and the first MAC address is retrieved from among pre-stored address data, determining whether the first terminal is a stolen terminal that has copied address data of another terminal, according to the state information of a terminal having the same address data as the first IP address and the first MAC address from among the plurality of terminals.


