Defense Method and System for Spoofing Source Attack under a Network Virtualization Technology
By exchanging and verifying trusted real source address prefixes between VXLAN gateways, the problem of forged source address attacks is solved, ensuring network security in network virtualization environment.
Patent Information
- Application Number
- CN202411587337.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-08
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-11-08
AI Technical Summary
In a network virtualization environment, forged source address attacks are difficult to be effectively defended, resulting in damage to network security.
Source address verification is performed by saving local trusted real source address prefix information in the VXLAN gateway and exchanging trusted real source address prefix between the VXLAN gateways to ensure that only traffic using the real source address can be forwarded.
It realizes effective defense against forged source address attacks and ensures network security in network virtualization environment.
Smart Images

Figure CN119402277B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a defense method and system for spoofing source attacks under network virtualization technology, and belongs to the technical field of network security research. Background Art
[0002] Network virtualization is to simulate multiple logical networks on a physical network. The content of network virtualization generally refers to a Virtual Private Network (VPN). The concept of a network connection is abstracted by the VPN, allowing remote users to access the internal network of an organization as if physically connected to the network. A Virtual eXtensible LAN (VXLAN) is a network virtualization technology that allows multiple organizations to use a single network without affecting security. With the rise of cloud technology, these data centers play a key role in running global critical applications and services.
[0003] VXLAN is a tunneling protocol established between a source network device and a destination network device. Its working principle is to segment a Layer 2 Ethernet frame and encapsulate it in a UDP packet (User Datagram Protocol). While network virtualization technology provides convenience for mutual access of multiple internal networks, it also exposes the internal network within the visible range of attackers to a certain extent, providing an opportunity for spoofing source address attacks.
[0004] Therefore, how to declare trusted true source address prefix information between VXLAN gateways in an extended virtual local area network in a network virtualization environment, and implement the function of verifying the true source address of VXLAN traffic on the VXLAN gateway to eliminate the harm of spoofing source address attacks to the current network is an urgent problem to be solved in the Internet routing system. Summary of the Invention
[0005] Aiming at the deficiencies of the prior art, the present invention provides a defense method for spoofing source attacks under network virtualization technology. In a virtual extensible local area network environment in network virtualization, the true source address is verified at both ends of the tunnel to achieve the goal of defending against spoofing source address traffic attacks.
[0006] Specifically, the VXLAN gateway stores the local trusted true source address prefix information, exchanges the trusted true source address prefix with other VXLAN gateways in the extensible virtual local area network. Each VXLAN gateway stores all the trusted true source address prefix information in the extensible virtual local area network. When communicating between VXLAN gateways, the VXLAN network performs source address verification on the traffic entering the device, and only the traffic using the true source address for communication is allowed to be forwarded, providing a guarantee for defending against spoofed source address attacks in the network virtualization environment.
[0007] The technical solution of the present invention is as follows:
[0008] A method for defending against spoofed source address attacks under network virtualization technology, the steps are as follows:
[0009] (1) The VXLAN gateway software system creates and initializes a trusted source address prefix table;
[0010] (2) The VXLAN gateway software system creates a VXLAN tunnel table;
[0011] (3) Assemble a trusted source address prefix advertisement message;
[0012] (4) Assemble a VXLAN data message for the traffic that needs to enter the VXLAN tunnel and forward it;
[0013] (5) The VXLAN gateway software system monitors network data and prepares to receive messages;
[0014] (6) If the received message is a trusted source address prefix advertisement message, scan the VXLAN tunnel table using the information related to the trusted source address prefix advertisement message;
[0015] (7) Traverse the trusted source address prefix table using the message information in step (6) and update the relevant information;
[0016] (8) If the received message is a VXLAN data message, scan the VXLAN tunnel table using the information related to the VXLAN data message;
[0017] (9) Scan the trusted source address prefix table using the scan result in step (8) and determine whether the data traffic is forwarded;
[0018] (10): Record the log information and return to step (5) to continue execution.
[0019] Preferably according to the present invention, in step (1), the trusted source address prefix table includes a source address prefix, a source address prefix mask, a VXLAN tunnel identifier, and an interface index number. Among them, the source address prefix is the trusted source address prefix value, the source address prefix mask is the mask value of the trusted source address prefix, the VXLAN tunnel identifier is the unique index value identifying the VXLAN tunnel, and the interface index number is the interface index value when the VXLAN traffic of the current source address prefix enters the VXLAN gateway. The trusted source address prefix table is initialized to be empty.
[0020] Preferably according to the present invention, in step (2), the VXLAN tunnel table includes a tunnel source address, a tunnel destination address, a VXLAN tunnel identifier, a tunnel peer network device number, and a data stream destination address. Among them, the tunnel source address is the source address used for tunnel communication between VXLAN gateways, the tunnel destination address is the destination address used for tunnel communication between VXLAN gateways, the VXLAN tunnel identifier is the unique index value currently identifying the VXLAN tunnel, the tunnel peer network device number is the number value of the VXLAN gateway device at the peer end of the current VXLAN tunnel, and the data stream destination address is the destination address of the data stream that needs to be encapsulated by the VXLAN tunnel. After the VXLAN gateway software system is started, it reads information from the local configuration file and initializes the VXLAN tunnel table.
[0021] Preferably according to the present invention, in step (3), the process of assembling the trusted source address prefix announcement message is as follows:
[0022] Take out the trusted source address prefix information from the local configuration file, fill the source address prefix, source address prefix mask, and network device number read from the trusted source address prefix information into the source address prefix, source address prefix mask, and network device number of the trusted source address prefix announcement message, and fill the destination address of the trusted source address prefix announcement message with the tunnel peer address read from the trusted source address prefix information.
[0023] Preferably according to the present invention, in step (4), the process of assembling the VXLAN data message is as follows:
[0024] The VXLAN gateway software system receives the data traffic, uses the destination address of the data traffic to scan the VXLAN tunnel table, takes out the tunnel source address, tunnel destination address, and VXLAN tunnel identifier from the matching items, assembles the VXLAN data message, uses the data stream as the payload of the VXLAN data message, fills the source address field of the message with the value of the tunnel source address, fills the destination address field of the message with the value of the tunnel destination address, fills the VNI field of the message with the value of the VXLAN tunnel identifier, and then sends the assembled VXLAN data message.
[0025] Preferably according to the present invention, in step (6), the specific operation steps are as follows:
[0026] If the received message is a trusted source address prefix advertisement message, record the VXLAN gateway interface index value when receiving the message and the source address of the message, extract the source address prefix, source address prefix mask, and network device number from the message, and traverse the tunnel peer network device number and tunnel source address of the VXLAN tunnel table according to the network device number and the source address of the message. If no record is found, perform step (6.1); if a record is found, perform step (6.2).
[0027] (6.1): Record that a trusted source address prefix advertisement message from an unknown source is received, and return to step (5) to continue execution.
[0028] (6.2): Use the matching item in step (6) to extract the VXLAN tunnel identifier from the matching item and record it.
[0029] According to the preference of the present invention, in step (7), the specific steps are as follows:
[0030] Use the source address prefix and source address prefix mask obtained from the message in step (6) and the VXLAN tunnel identifier obtained from the matching item to traverse the trusted source address prefix table. If a record is matched, perform step (7.1); if no record is matched, perform step (7.2).
[0031] (7.1): Use the VXLAN gateway interface index value recorded in step (6) to update the interface index number of the matching item, and return to step (5) to continue execution.
[0032] (7.2): Create a trusted source address prefix table entry, and fill in the interface index number, source address prefix, source address prefix mask, and VXLAN tunnel identifier of the table entry with the VXLAN gateway interface index value recorded in step (6), the source address prefix obtained from the message, the source address prefix mask, and the VXLAN tunnel identifier obtained from the matching item in step (6) respectively, and return to step (5) to continue execution.
[0033] According to the preference of the present invention, in step (8), the specific steps are as follows:
[0034] If the received message is a VXLAN data message, record the ingress interface index value when the message enters the VXLAN gateway, and scan the VXLAN tunnel table using the source address, destination address, and VNI extracted from the message. If no match is found, perform step (8.1); if a match is found, perform step (8.2).
[0035] (8.1): Discard the VXLAN data message, and return to step (5) to continue execution.
[0036] (8.2): Extract the data traffic of the VXLAN data packet payload, extract the source address from the data traffic, and record it.
[0037] Preferably according to the present invention, in step (9), the specific steps are as follows:
[0038] Using the source address obtained in step (8.2) and the ingress interface index value obtained in step (8), scan the trusted source address prefix table, combine the source address prefix mask of each table entry with the packet source address to obtain the packet source address prefix, compare it with the source address prefix of the table entry, and compare the ingress interface index value with the interface index number of the table entry. If a match is found, execute step (9.1); if no match is found, execute step (9.2);
[0039] Step (9.1): Forward the data traffic from the VXLAN gateway.
[0040] Step (9.2): Discard the data traffic.
[0041] A defense system against spoofing source attacks under network virtualization technology, comprising:
[0042] A table entry creation module for creating and initializing a trusted source address prefix table and a VXLAN tunnel table;
[0043] A trusted source address prefix advertisement packet assembly module: for assembling a trusted source address prefix advertisement packet;
[0044] A VXLAN data packet assembly module: for assembling a VXLAN data packet for the traffic that needs to enter the VXLAN tunnel and forwarding it;
[0045] A network data monitoring module: for monitoring network data and preparing to receive packets;
[0046] A packet judgment module: for judging the received packet type and performing corresponding operations. If the received packet is a trusted source address prefix advertisement packet, scan the VXLAN tunnel table using the relevant information of the trusted source address prefix advertisement packet, and traverse the trusted source address prefix table using the scanned packet information to update the relevant information;
[0047] If the received packet is a VXLAN data packet, scan the VXLAN tunnel table using the relevant information of the VXLAN data packet, and scan the trusted source address prefix table using the scan result to determine whether to forward the data traffic;
[0048] A recording module: for recording log information.
[0049] The beneficial effects of the present invention are as follows:
[0050] The VXLAN gateway of the present invention stores local trusted true source address prefix information and exchanges trusted true source address prefixes with other VXLAN gateways in the extensible virtual local area network. Each VXLAN gateway stores all the trusted true source address prefix information in the extensible virtual local area network. When VXLAN gateways communicate with each other, the VXLAN network verifies the source address of the traffic entering the device, and only the traffic using the true source address for communication is allowed to be forwarded, providing a guarantee for defending against spoofed source address attacks in the network virtualization environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 It is a schematic diagram of the topological structure of the present invention;
[0052] Figure 2 It is a schematic diagram of the trusted source address prefix of the present invention;
[0053] Figure 3 It is a schematic diagram of the VXLAN tunnel of the present invention;
[0054] Figure 4 It is a schematic diagram of the trusted source address prefix advertisement message of the present invention;
[0055] Figure 5 It is a schematic diagram of the VXLAN data packet of the present invention;
[0056] Figure 6 It is a schematic diagram of the process of the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0057] The present invention will be further described below by way of embodiments in conjunction with the drawings, but is not limited thereto.
[0058] Embodiment 1:
[0059] As Figure 6 shown, this embodiment provides a method for defending against spoofed source address attacks under network virtualization technology. The topological schematic diagram is shown in Figure 1 . The left side shows the position of the VXLAN gateway in the network, which is used to mark the position of the function of defending against spoofed source address attacks in the architecture under network virtualization technology in this embodiment; the right side shows the actual process of defending against spoofed source address attacks in this embodiment. After the trusted source address announcement between VXLAN gateways, the VXLAN gateway will create a correspondence between the trusted source prefix information and the gateway interface. When the VXLAN gateway communicates, the source address of the traffic entering the VXLAN gateway is taken out, and the interface index information of the traffic entering the VXLAN gateway is recorded and compared with the correspondence between the local trusted source prefix information and the gateway interface. Only when the match is completely successful can the data traffic pass, achieving the goal of defending against spoofed source address attacks under network virtualization technology.
[0060] The defense method steps are as follows:
[0061] S100: Start the VXLAN gateway software system, establish a trusted source address prefix table and configure the initial value. The trusted source address prefix table is as Figure 2 shown, including a 32-bit source address prefix field, a 16-bit source address prefix mask field, an 8-bit VXLAN tunnel identifier field, and a 32-bit interface index number field.
[0062] S200: Establish a VXLAN tunnel table and configure the initial value. The VXLAN tunnel table is as Figure 3 shown, including a 32-bit tunnel source address field, a 32-bit tunnel destination address field, an 8-bit VXLAN tunnel identifier field, a 16-bit tunnel peer network device number field, and a 32-bit data flow destination address field.
[0063] S300: The VXLAN gateways start to send trusted source address prefix announcement messages to each other. The trusted source address prefix announcement message is as Figure 4 shown, including a 32-bit source address prefix field, a 16-bit source address prefix mask field, a 16-bit network device number field, and a 32-bit destination address field;
[0064] S400: Assemble VXLAN packets for the traffic that needs to enter the VXLAN tunnel and forward them. The VXLAN data packet is as Figure 5 shown, including a 32-bit source address field, a 32-bit destination address field, and a 16-bit VNI field;
[0065] S500: The VXLAN gateway software system monitors network data and prepares to receive packets;
[0066] S600: The VXLAN gateway software system receives the trusted source address prefix announcement message sent by S300, records the system information, extracts the relevant information of the message, scans the VXLAN tunnel table. If there is no record, execute S601; if there is a record, execute S602;
[0067] S601: Record the log information and return to S500 to continue execution;
[0068] S602: According to the matching item obtained in S600, extract the VXLAN tunnel identifier from the matching item and record it.
[0069] S700: According to the information obtained in S600, scan the trusted source address prefix table. If there is a record, execute S701; if there is no record, execute S702;
[0070] S701: Update the interface index number field of the matching entry according to the VXLAN gateway interface index value recorded in S600, and return to S500 to continue execution;
[0071] S702: Create a trusted source address prefix table entry, fill in the corresponding table entry fields according to the information obtained in S600, and return to S500 to continue execution;
[0072] S800: The VXLAN gateway software system receives a VXLAN data packet, records the ingress interface index value, extracts the relevant information in the packet, scans the VXLAN tunnel table. If there is no record, execute S801; if there is a record, execute S802;
[0073] S801: Discard the data packet and return to S500 to continue execution.
[0074] S802: Extract the data traffic from the payload of the VXLAN data packet, extract the source address of the packet from the data traffic, and record it.
[0075] S900: According to the information obtained in S800, scan the trusted source address prefix table. If there is a match, execute S901; if there is no match, execute S902;
[0076] S901: Forward the data traffic out of the VXLAN gateway;
[0077] S902: Discard the data traffic.
[0078] S1000: Record the log information and return to S500 to continue execution.
[0079] Embodiment 2:
[0080] This embodiment provides a defense system against forged source attacks under network virtualization technology, including:
[0081] A table entry creation module, used to create and initialize a trusted source address prefix table and a VXLAN tunnel table;
[0082] A trusted source address prefix advertisement message assembly module: used to assemble a trusted source address prefix advertisement message;
[0083] A VXLAN data packet assembly module: used to assemble a VXLAN data packet for the traffic that needs to enter the VXLAN tunnel and forward it;
[0084] A network data monitoring module: used to monitor network data and prepare to receive packets;
[0085] Message judgment module: used to judge the received message type and perform corresponding operations. If the received message is a trusted source address prefix announcement message, scan the VXLAN tunnel table using the information related to the trusted source address prefix announcement message, and traverse the trusted source address prefix table using the message information obtained from the scan to update the relevant information;
[0086] If the received message is a VXLAN data message, scan the VXLAN tunnel table using the information related to the VXLAN data message, and scan the trusted source address prefix table using the scan result to determine whether the data traffic is forwarded;
[0087] Recording module: used to record log information.
Claims
1. A defense method against spoofing attacks under network virtualization technology, characterized in that, The steps are as follows: (1) Create and initialize the trusted source address prefix table; (2) Create the VXLAN tunnel table; (3) Assemble the trusted source address prefix announcement message; (4) Assemble the VXLAN data message for the traffic that needs to enter the VXLAN tunnel and forward it; (5) Monitor network data and prepare to receive messages; (6) If the received message is a trusted source address prefix announcement message, scan the VXLAN tunnel table using the information related to the trusted source address prefix announcement message; (7) Use the source address prefix, source address prefix mask obtained from the message in step (6), and the VXLAN tunnel identifier obtained from the matching entry to traverse the trusted source address prefix table. If a record is matched, execute step (7.1); if no record is matched, execute step (7.2); (7.1): Use the ingress VXLAN gateway interface index value recorded in step (6) to update the interface index number of the matching entry, and return to step (5) to continue execution; (7.2): Create an entry in the trusted source address prefix table, and fill in the interface index number, source address prefix, source address prefix mask, and VXLAN tunnel identifier of the entry with the ingress VXLAN gateway interface index value recorded in step (6), the source address prefix obtained from the message, the source address prefix mask, and the VXLAN tunnel identifier obtained from the matching entry in step (6) respectively, and return to step (5) to continue execution; (8) If the received message is a VXLAN data message, scan the VXLAN tunnel table using the information related to the VXLAN data message; (9) Scan the trusted source address prefix table using the scan result of step (8) and determine whether to forward the data traffic; (10): Record the log information and return to step (5) to continue execution.
2. The defense method against spoofing attacks under network virtualization technology according to claim 1, characterized in that, In step (1), the trusted source address prefix table includes the source address prefix, source address prefix mask, VXLAN tunnel identifier, and interface index number. Among them, the source address prefix is the trusted source address prefix value, the source address prefix mask is the mask value of the trusted source address prefix, the VXLAN tunnel identifier is the unique index value identifying the VXLAN tunnel, and the interface index number is the interface index value when the VXLAN traffic of the current source address prefix enters the VXLAN gateway. The trusted source address prefix table is initialized to be empty.
3. The defense method against spoofing source attacks under network virtualization technology according to claim 2, characterized in that, In step (2), the VXLAN tunnel table includes the tunnel source address, tunnel destination address, VXLAN tunnel identifier, tunnel peer network device number, and data stream destination address. Among them, the tunnel source address is the source address used for tunnel communication between VXLAN gateways, the tunnel destination address is the destination address used for tunnel communication between VXLAN gateways, the VXLAN tunnel identifier is the unique index value currently identifying the VXLAN tunnel, the tunnel peer network device number is the number value of the VXLAN gateway device at the other end of the current VXLAN tunnel, and the data stream destination address is the destination address of the data stream that needs to be encapsulated by the VXLAN tunnel.
4. The defense method against spoofing source attacks under network virtualization technology according to claim 3, characterized in that, In step (3), the process of assembling the trusted source address prefix announcement message is as follows: Retrieve the trusted source address prefix information from the local configuration file, and fill the source address prefix, source address prefix mask, and network device number read from the trusted source address prefix information into the source address prefix, source address prefix mask, and network device number of the trusted source address prefix advertisement message. Fill the destination address of the trusted source address prefix advertisement message with the tunnel peer address read from the trusted source address prefix information.
5. The defense method against spoofing source attacks under the network virtualization technology according to claim 4, characterized in that In step (4), the VXLAN data packet assembly process is as follows: Receive data traffic, use the destination address of the data traffic to scan the VXLAN tunnel table, extract the tunnel source address, tunnel destination address, and VXLAN tunnel identifier from the matching entries, assemble the VXLAN data packet, use the data stream as the payload of the VXLAN data packet, fill the source address field of the packet with the value of the tunnel source address, fill the destination address field of the packet with the value of the tunnel destination address, fill the VNI field of the packet with the value of the VXLAN tunnel identifier, and then send the assembled VXLAN data packet.
6. The defense method against spoofing source attacks under network virtualization technology according to claim 5, characterized in that, In step (6), the specific operation steps are as follows: If the received packet is a trusted source address prefix advertisement message, record the VXLAN gateway interface index value when receiving the packet and the source address of the packet. Extract the source address prefix, source address prefix mask, and network device number from the packet. Traverse the tunnel peer network device number and tunnel source address of the VXLAN tunnel table according to the network device number and the source address of the packet. If no record is found, execute step (6.1); if a record is found, execute step (6.2). (6.1): Record that a trusted source address prefix advertisement message from an unknown source is received, and return to step (5) to continue execution. (6.2): Use the matching entry in step (6) to extract the VXLAN tunnel identifier from the matching entry and record it.
7. The defense method against spoofing attacks under network virtualization technology according to claim 6, characterized in that, In step (8), the specific steps are as follows: If the received packet is a VXLAN data packet, record the ingress interface index value when the packet enters the VXLAN gateway. Scan the VXLAN tunnel table using the source address, destination address, and VNI extracted from the packet. If no match is found, execute step (8.1); if a match is found, execute step (8.2). (8.1): Discard the VXLAN data packet and return to step (5) to continue execution. (8.2): Extract the data traffic of the VXLAN data packet payload, extract the source address from the data traffic, and record it.
8. The defense method against spoofing attacks under network virtualization technology according to claim 7, characterized in that, In step (9), the specific steps are as follows: Use the source address obtained in step (8.2) and the ingress interface index value obtained in step (8) to scan the trusted source address prefix table. Combine the source address prefix mask of each table entry with the source address of the packet to obtain the source address prefix of the packet, and compare it with the source address prefix of the table entry. Compare the ingress interface index value with the interface index number of the table entry. If a match is found, execute step (9.1); if no match is found, execute step (9.2). Step (9.1): Forward the data traffic out of the VXLAN gateway. Step (9.2): Discard the data traffic.
9. A defense system against spoofing attacks under network virtualization technology, for the defense method against spoofing attacks under network virtualization technology described in claim 1, characterized in that, Include: The entry creation module is used to create and initialize the trusted source address prefix table and the VXLAN tunnel table; The trusted source address prefix announcement message assembly module: used to assemble the trusted source address prefix announcement message; The VXLAN data message assembly module: used to assemble VXLAN data messages for the traffic that needs to enter the VXLAN tunnel and forward them; The network data monitoring module: used to monitor network data and prepare to receive messages; The message judgment module: used to judge the received message type and perform corresponding operations. If the received message is a trusted source address prefix announcement message, scan the VXLAN tunnel table using the relevant information of the trusted source address prefix announcement message, and traverse the trusted source address prefix table using the scanned message information to update the relevant information; If the received message is a VXLAN data message, scan the VXLAN tunnel table using the relevant information of the VXLAN data message, and scan the trusted source address prefix table using the scan result to determine whether the data traffic is forwarded; The recording module: used to record log information.
Citation Information
Patent Citations
Method and device for verifying intra-domain source addresses
CN101931628A
IPv6 real source address prefix verification method based on reverse error correction
CN118487857A