IP Library Granted Patent US 9,398,045
Granted Patent B2
US 9,398,045 · App. 14/481,637 · Granted Jul 19, 2016

Network device and method for avoiding address resolution protocol attack

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,398,045
App. No.
14/481,637
Granted
Jul 19, 2016
Kind
B2
Abstract

A network device records IP addresses and MAC addresses of a plurality of CPEs to form an address mapping table, sends first ARP request packets to the plurality of CPEs according to the IP addresses in the address mapping table, and receives first ARP response packets. The network device compares the MAC addresses in the first ARP response packets with the corresponding MAC addresses in the address mapping table to identify an unusual MAC address. The network device generates a plurality of IP addresses randomly, sends second ARP request packets according to the plurality of IP addresses, and receives second ARP response packets. In response to a MAC address in the second ARP response packets being same with the unusual MAC address, the network device blocks packets transmission corresponding to the unusual MAC address.

Claims (27)

1. A network device, connecting with a plurality of customer premise equipments (CPEs), the network device comprising:

at least one processor;

a storage system; and

one or more programs that are stored in the storage system and executed by the at least one processor, the one or more programs comprising instructions for:

recording internet protocol (IP) addresses and media access control (MAC) addresses of the plurality of CPEs to form an address mapping table;

sending first address resolution protocol (ARP) request packets to the plurality of CPEs according to the IP addresses in the address mapping table and receiving first ARP response packets;

comparing the MAC addresses in the first ARP response packets with the corresponding MAC addresses in the address mapping table to identify an unusual MAC address;

generating a plurality of IP addresses randomly that are different from the IP addresses in the address mapping table upon condition that the unusual MAC address exists;

sending second ARP request packets according to the plurality of IP addresses, and receiving second ARP response packets; and

in response to a MAC address in the second ARP response packets being same with the unusual MAC address, blocking packets transmission corresponding to the unusual MAC address.

2. The network device as claimed in claim 1 , wherein the MAC address is unusual upon condition that the MAC addresses in the first ARP response packets are not the same with the corresponding MAC addresses in the address mapping table.

3. The network device as claimed in claim 1 , wherein the network device and the plurality of CPEs are in a same local area network (LAN) and the plurality of IP addresses generated randomly is a plurality of IP addresses not belonging to the LAN.

4. The network device as claimed in claim 1 , wherein the network device and the plurality of CPEs are in a same local area network (LAN) and the plurality of IP addresses generated randomly is a plurality of IP addresses not used in the LAN.

5. The network device as claimed in claim 1 , wherein when one MAC address in the second ARP response packets is the same with the unusual MAC address, the CPE with the unusual MAC address is identified to be a hacker.

6. The network device as claimed in claim 1 , wherein the one or more programs further comprising instructions for deleting the IP address and the MAC address of the hacker in the address mapping table.

7. A method for avoiding address resolution protocol (ARP) attack, applied in a network device, the network device connecting with a plurality of customer premise equipments (CPEs), the method comprising:

recording internet protocol (IP) addresses and media access control (MAC) addresses of the plurality of CPEs to form an address mapping table;

sending first ARP request packets to the plurality of CPEs according to the IP addresses in the address mapping table and receiving first ARP response packets;

comparing the MAC addresses in the first ARP response packets with the corresponding MAC addresses in the address mapping table to identify an unusual MAC address;

generating a plurality of IP addresses randomly that are different from the IP addresses in the address mapping table upon condition that the unusual MAC address exists;

sending second ARP request packets according to the plurality of IP addresses, and receiving second ARP response packets; and

in response to a MAC address in the second ARP response packets being same with the unusual MAC address, blocking packets transmission corresponding to the unusual MAC address.

8. The method as claimed in claim 7 , wherein the MAC address is unusual upon condition that the MAC addresses in the first ARP response packets are not the same with the corresponding MAC addresses in the address mapping table.

9. The method as claimed in claim 7 , wherein the network device and the plurality of CPEs are in a same local area network (LAN), and the plurality of IP addresses generated randomly is a plurality of IP addresses not belonging to the LAN.

10. The method as claimed in claim 7 , wherein the network device and the plurality of CPEs are in a same local area network (LAN), and the plurality of IP addresses generated randomly is a plurality of IP addresses not used in the LAN.

11. The method as claimed in claim 7 , wherein when one MAC address in the second ARP response packets is the same with the unusual MAC address, the CPE with the unusual MAC address is identified to be a hacker.

12. The method as claimed in claim 7 , further comprising: deleting the IP address and the MAC address of the hacker in the address mapping table.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2018
From: HON HAI PRECISION INDUSTRY CO., LTD.
To: CLOUD NETWORK TECHNOLOGY SINGAPORE PTE. LTD.
Reel/Frame 045171/0306 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2014
From: LEE, DA-JHENG
To: HON HAI PRECISION INDUSTRY CO., LTD.
Reel/Frame 033703/0387 →