Method of Preventing Node Hijacking from the Rogue DHCP Server in Campus Network Using Link Layer Discovery Protocol
摘要
Dynamic Host Configuration Protocol (DHCP) is extensively implemented on campus networks to establish a link between the client device and user. The primary function of DHCP is to allocate an Internet Protocol (Internet Protocol) address to a host or node in order to identify and monitor the perimeter condition. In this article, we will look at how an intruder could merely set up an illegal DHCP server on a layer 2 network, to attempt to acquire a local connected host with an early responding server. DHCP is vulnerable to a variety of attacks, including malicious DHCP servers that carry out attacks that use incorrect IP addresses to compete with real servers on the campus network, and attacks such as malicious URLs that lead to phishing attacks and intercepting and listening in on communications as a middleman attack and so on. The objective of this article is to detect untrustworthy DHCP servers and use Link Layer Discovery Protocol (LLDP) to create a topology information database based on the Type-Length-Value parameter of the local device for port identification and node status. In this recursive process, the system parses device identification information and compares locally connected hosts with neighboring devices to prepare a topology map and identify suspiciously addressed hosts on the network.