Source address verification method, device, controller and medium based on virtual network
By using virtual nodes and SAV verification tables in a dynamic network environment, the source address of the customer network is verified, and the problem of difficult to defend against source address forgery attacks in the existing technology is solved, and efficient and accurate source address verification and Internet security are achieved.
Patent Information
- Application Number
- CN202510101465.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-22
AI Technical Summary
The existing technology is difficult to verify the source address efficiently and accurately in a dynamic network environment, making it difficult to defend against source address forgery attacks, especially after the popularization of the IPv6 protocol.
When receiving the connection request from the client network, the closest virtual node is determined and the connection is established, the interface is bound and the source prefix is advertised, the original path is allocated to the client network based on the source prefix and the destination prefix, and the source address of the message is verified on multiple virtual nodes, ensuring that it exists in the preset SAV verification table and is marked as legal and trustworthy.
It realizes efficient and accurate source address verification in complex dynamic network environments, effectively defends against source address forgery attacks, and improves the security of the Internet.
Smart Images

Figure CN119561782B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a source address verification method, device, controller and medium based on a virtual network. Background Art
[0002] In the early stages of designing the layered architecture of the Internet, it was based on a basic assumption that network members are completely trustworthy, without fully considering the security threats that malicious behavior may bring, resulting in inherent security vulnerabilities in the design. In the current Internet architecture, network devices only forward messages based on the destination IP address of the message without verifying its source address, which provides an opportunity for attacks that forge source addresses, affecting Internet security. For example, in a distributed denial of service (DDoS) attack, attackers manipulate a large number of controlled computers or botnets to send a large number of requests to target servers (such as banks, payment gateways, and root domain name servers, etc.), resulting in a large amount of bandwidth resources being consumed on the target network, which not only seriously affects the normal operation of the target service, but may also further affect other devices in the same LAN, causing the entire network environment to deteriorate.
[0003] With the gradual popularization of IPv6 protocol, the problem of source address forgery has become more serious. IPv6 protocol provides a huge address space for the Internet, meeting the growing demand for the Internet. However, its decentralized address management method provides attackers with more opportunities to forge source addresses, which not only affects the accuracy of network billing and identity authentication based on real source addresses, but also poses a serious threat to the infrastructure and upper-layer applications of the Internet. Therefore, in order to solve the problem of source address forgery and improve the security of the Internet, the existing intra-domain source address validation (Source Address Validation, SAV), for example, the SAV mechanism based on the access control list (Access Control List, ACL) requires manual configuration of rules and frequent updates, which is time-consuming and error-prone. Once the ACL rules are not updated in time, legitimate traffic may be blocked by mistake or malicious traffic may be released by mistake. In addition, the inter-domain source address validation scheme attempts to generate SAV rules that automatically adapt to asymmetric routing and dynamic network changes by learning the real forwarding path of the source prefix. However, due to the dynamic nature of network topology, fault recovery, traffic engineering, and the complexity of Border Gateway Protocol (BGP), the implementation of the inter-domain SAV solution is difficult, which limits its practicality and deployment benefits. Summary of the invention
[0004] In order to overcome the shortcomings of the prior art, the present invention provides a source address verification method, device, controller and medium based on a virtual network, which can achieve efficient and accurate source address verification only through the source address of the message in a complex dynamic network environment, thereby effectively defending against source address forgery attacks.
[0005] A first aspect of the present application provides a source address verification method based on a virtual network, the method comprising:
[0006] When receiving a connection request from a customer network, determining a nearest virtual node to control the customer network to establish a connection with the nearest virtual node, bind an incoming interface, and notify a source prefix;
[0007] allocating an original path to the customer network based on the source prefix and the destination prefix;
[0008] When monitoring that the customer network sends a message from a source address to a destination address, obtaining all virtual nodes of the original path to verify the source address of the message based on all virtual nodes;
[0009] When it is determined that the source address exists in the preset SAV verification table and is marked as legal and credible, the message is allowed to be forwarded based on the original path, so that the message is forwarded to the destination address.
[0010] In an optional embodiment, the method further comprises:
[0011] Determine a path update problem according to a preset trigger condition, and determine an update path based on the path update problem;
[0012] The routing path of the SAV verification table is updated according to the update path.
[0013] In an optional implementation, determining the update path based on the path update problem includes:
[0014] Determining the attack success probability of the attacker, and modeling the path update problem as a multi-objective optimization problem based on the attack success probability;
[0015] Performing linear relaxation on the multi-objective optimization problem to obtain a continuous value solution;
[0016] Randomly rounding the continuous-valued solution to generate a set of binary decision variables;
[0017] Obtaining an approximate solution, and determining the approximate solution as the update path, wherein the approximate solution is output by adjusting the binary decision variables to meet preset constraint conditions;
[0018] The approximate solution is determined as the update path.
[0019] In an optional implementation, before determining the approximate solution as the update path, the method further includes:
[0020] Initializing a feasible solution by a local search heuristic algorithm, and recording the feasible solution and the objective function value corresponding to the feasible solution, wherein the feasible solution is any one of the approximate solutions;
[0021] Attempting to reroute each traffic demand through a different path, and updating the feasible solution when the objective function value improves, until a preset termination condition is met;
[0022] When the termination condition is met, the feasible solution output is used as the optimal solution, and the optimal solution is determined as the update path.
[0023] In an optional implementation, determining the attacker's attack success probability includes:
[0024] Determine a first probability that the attacker successfully connects to any virtual node in the NFV network;
[0025] Determine a second probability that the attacker's attack message successfully enters a correct interface;
[0026] Determining a third probability that the attacker successfully guesses the correct number of hops;
[0027] The attack success probability is determined based on the first probability, the second probability, and the third probability.
[0028] In an optional implementation, determining the attack success probability based on the first probability, the second probability, and the third probability includes:
[0029] The success probability of the attack is determined by the following formula:
[0030] ;
[0031] in, is the success probability of the attack, is the first probability, is the second probability, is the third probability, B is the maximum number of packets sent by each attacker per unit time, C The number of robots controlled by the attacker.
[0032] In an optional embodiment, the method further comprises:
[0033] determining the destination prefix of the customer network;
[0034] The control source virtual node initiates a detection operation through a destination prefix to establish a SAV verification table containing routing information, wherein the SAV verification table records a routing path from the source virtual node to the destination virtual node, and the routing path includes all virtual nodes from the source virtual node to the destination virtual node.
[0035] A second aspect of the present application provides a source address verification device based on a virtual network, the device comprising:
[0036] A connection establishment module, configured to determine the nearest virtual node when receiving a connection request from a client network, control the client network to establish a connection with the nearest virtual node, bind an input interface, and notify a source prefix;
[0037] A path allocation module, configured to allocate an original path to the customer network based on the source prefix and the destination prefix;
[0038] An address verification module, for obtaining all virtual nodes of the original path when monitoring the client network sending a message from a source address to a destination address, so as to verify the source address of the message based on all virtual nodes;
[0039] The message forwarding module is used to allow the message to be forwarded based on the original path when it is determined that the source address exists in a preset SAV verification table and is marked as legal and credible, so that the message is forwarded to the destination address.
[0040] A third aspect of the present application provides a controller, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the virtual network-based source address verification method when executing the computer program.
[0041] A fourth aspect of the present application provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps of the above-mentioned virtual network-based source address verification method are implemented.
[0042] In summary, the virtual network-based source address verification method, device, controller and medium provided by the present application, when receiving a connection request from a customer network, first determine the nearest virtual node, and control the customer network to establish a connection with the nearest virtual node, and introduce a virtual network layer to provide a controlled connection entry for the customer network, bind the input interface and notify the source prefix, thereby ensuring that the source address information of the customer network is correctly recorded and can be used for subsequent verification processes. The original path is allocated to the customer network based on the source prefix and the destination prefix, providing a predefined and traceable path for message forwarding, which helps to check whether the message is transmitted along the correct path in the subsequent verification process. When monitoring the client network sending a message from the source address to the destination address, all virtual nodes of the original path are obtained, and the source address of the message is verified based on these nodes. The authenticity and credibility of the source address of the message are ensured by verifying multiple virtual nodes on the message transmission path. The verification process relies on the preset SAV verification table, which records the legal and credible source address information. Only when the source address of the message exists in the verification table and is marked as legal and credible, the message is allowed to continue to be forwarded based on the original path. If the source address verification passes, the message will be allowed to be forwarded to the destination address based on the original path, ensuring that only legal messages that have been strictly verified can reach the target network, thereby effectively preventing source address forgery attacks. By building a virtual network, dynamically allocating paths, and adopting a multi-node verification mechanism, the existing source address forgery problem is effectively solved, and the security of the Internet is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 It is a framework diagram of a source address verification system based on a virtual network shown in an embodiment of the present application;
[0044] Figure 2 It is a schematic diagram of the system working principle of a source address verification system based on a virtual network shown in an embodiment of the present application;
[0045] Figure 3 It is a flow chart of a source address verification method based on a virtual network shown in an embodiment of the present application;
[0046] Figure 4 It is another flow chart of a source address verification method based on a virtual network shown in an embodiment of the present application;
[0047] Figure 5 is a schematic diagram of a method for dynamically updating a transmission path shown in an embodiment of the present application;
[0048] Figure 6 It is a functional module diagram of a source address verification device based on a virtual network shown in an embodiment of the present application;
[0049] Figure 7 It is a schematic diagram of the structure of a controller shown in an embodiment of the present application. DETAILED DESCRIPTION
[0050] The present invention is further described below in conjunction with the accompanying drawings and embodiments.
[0051] The following will clearly and completely describe the concept, specific structure and technical effects of the present invention in combination with the embodiments and drawings, so as to fully understand the purpose, characteristics and effects of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, other embodiments obtained by technicians in this field without creative work are all within the scope of protection of the present invention. In addition, all the connection / connection relationships involved in the patent do not refer to the direct connection of components, but refer to the formation of a better connection structure by adding or reducing connection accessories according to the specific implementation situation. The various technical features in the invention can be combined interchangeably without conflicting with each other.
[0052] Reference Figure 1As shown, it is an architecture diagram of a source address verification system based on a virtual network shown in an embodiment of the present application. The source address verification system based on the virtual network is constructed based on the intra-domain and inter-domain source address verification architecture protocol (SourceAddress Validation Architecture, SAVNET). SAVNET provides source address verification services by building a network function virtualization (NFV) trust network on a traditional network (e.g., Underlay network). The core of the SAVNET architecture is to dynamically manage and control the path through the control center of the NFV network (referred to as the central controller) to ensure the authenticity of the source address in network communication. SAVNET can be divided into two main layers, namely the NFV layer and the Underlay layer. The NFV layer is mainly responsible for source address verification and path control, while the Underlay layer continues to perform the physical transmission task of data. Through the layered design of the NFV layer and the Underlay layer, SAVNFV can improve the accuracy and security of source address verification without changing the existing network infrastructure. Specifically, the top-level architecture of the SAVNET architecture is based on virtual nodes (hereinafter referred to as PoP nodes) to build an NFV trust network (hereinafter referred to as NFV network). For example, multiple PoP nodes (virtual node 1, virtual node 2, virtual node 3, virtual node 4, virtual node 5, etc.) based on the NFV network are interconnected through a virtual private network (VPN) to form a virtual network. Each virtual node is assigned one or more IP addresses for communication in the NFV network. That is, the virtualized source address verification function is deployed using the PoP node as an access point, and the path and verification rules are managed by the central controller. The inbound interface is bound and the source prefix is announced in the PoP node, and a SAV verification table is established to record the legal path. The NFV network is built on the existing Internet infrastructure to provide additional security and credibility to ensure that the source address of the NFV network for communication is authentic and reliable. Any autonomous system (AS) has the opportunity to join the NFV network, thereby ensuring the authenticity of the communication source address between the ASs joining the network, and providing a guarantee for secure communication between different trusted ASs. That is, all ASs willing to participate become part of the trust network by accessing the PoP node. After joining, the AS can enjoy the source address verification service to ensure the authenticity of the communication source address, while sharing the security benefits of the trust network. The open design enhances the scalability and compatibility of the network, promoting more AS collaboration to jointly improve overall security.The underlying architecture of the SAVNET architecture is based on the traditional Underlay network, so there is no need to make large-scale modifications or reconstruction of the existing infrastructure. As the underlying infrastructure, the Underlay network maintains its original stability and scalability, which makes the deployment and integration of the system more efficient. SAVNFV is based on the NFV network and the central controller, aiming to provide enhanced network security and credibility, while encouraging the participation of AS to gain more benefits. Through the inbound interface inspection and path control, it helps to ensure that the source address of the communication is authentic and reliable, thereby improving the security of the network. The Underlay network is still responsible for the actual data transmission and routing functions, while the NFV network provides additional security verification services. The hierarchical structure of the NFV layer and the Underlay layer helps to maintain the performance and stability of the network, while enhancing the security of the network and providing a more reliable communication environment.
[0053] Among them, the central server is the core component of the NFV network, responsible for global path calculation and allocation, source address verification rule generation and distribution, and network security policy management. Based on the network-wide topology information and real-time traffic status, the central server dynamically plans the optimal communication path from the source prefix to the destination prefix, and supports multiple strategies such as the shortest path, load balancing, or high-security path. When network topology changes or attack traffic anomalies are detected, the central controller can adjust the path and verification rules in real time to ensure the efficiency and security of the network. In addition, the central server can also uniformly manage the security policies of the NFV network, including the path update frequency of virtual functions and the optimization of verification rules to adapt to dynamic network environments and reduce management complexity. For large networks, the central controller supports distributed deployment, and through sub-controller sharding computing tasks, it can achieve effective control of multi-regional networks.
[0054] Among them, the NFV network is the infrastructure of the SAVNFV architecture, carrying virtualization functions and control signaling, and supporting dynamic deployment and real-time adjustment. The NFV network decouples the source address verification function from traditional hardware devices through virtualization, realizing the rapid deployment and flexible expansion of functional modules. In the NFV network, the central controller and PoP nodes work together through control signaling to build a dynamically adjustable verification framework. The architecture of the NFV network enables the verification logic to be flexibly migrated and expanded in the form of services to meet the needs of different network scales. At the same time, the elastic architecture of the NFV network can dynamically allocate resources according to traffic fluctuations, thereby ensuring verification efficiency while reducing operating costs, providing strong support for source address verification in complex network environments.
[0055] For example, when virtual node 1 wants to send a data packet to virtual node 2, virtual node 1 first sends the data packet to the central controller in the form of a message. After receiving the message, the central controller can check whether the source address of the data packet in the message (i.e., the IP address of virtual node 1) is legal. If the source address is legal, the central controller forwards the data packet to virtual node 2; if the source address is illegal, the central controller can directly discard the data packet.
[0056] In some embodiments, the central controller can dynamically allocate and update paths according to network policies, and achieve efficient source address verification and flexible attack defense through virtualization and dynamic management. Among them, the path control of the NFV network is managed and controlled by a central controller, that is, the central controller is responsible for determining the routing path of the data packet to ensure the credibility and security of the communication. The central controller can adjust the path according to network policies and requirements to adapt to different communication scenarios. In addition, in order to prevent the routing path from being guessed and causing the SAV verification to fail, the central controller can also update the route regularly.
[0057] In some embodiments, an intrusion detection system (IDS) can be added to the source address verification system based on the virtual network to monitor the attack during network transmission. In real scenarios, DDoS attacks are not random and all the time, but have certain regularity. When an attack occurs, the IDS analyzes the degree of network impact and promptly records detailed information about the event, such as the real source address of the attack message, the forged address, the victim address, etc. The IDS sends the attack information to the central controller, which is then centrally processed.
[0058] The central controller is equipped with a SAV verification table for each PoP node, which records the source prefix, destination prefix, next hop, and interface of the message entering the PoP node. The following Table 1 shows the source address verification information table of virtual node 1 (hereinafter referred to as PoP1) in the central controller, that is, the SAV verification table of PoP1:
[0059] Table 1
[0060]
[0061] Among them, the source address refers to the IP address of the data sender, and the destination address refers to the IP address of the data receiver. In network communication, each device or node has a unique IP address to identify its identity and location. When data is transmitted in the network, it is routed to the correct recipient according to the destination address. The next hop refers to the IP address of the next node to which the data should be sent after the current node. In the network, data usually passes through multiple nodes to reach the destination address, and each node determines the location of the next node based on the routing table (for example, the SAV verification table). The inbound interface refers to the network interface through which data enters the current node. The network interface is a communication channel on a physical device or virtual device that is used to connect different networks or devices. It can be seen that the data needs to be transmitted from autonomous system A (hereinafter referred to as AS A) to autonomous system B (hereinafter referred to as ASB), and virtual node 2 (PoP2) is specified as the next hop, and the inbound interface i1 is specified as the physical or logical interface through which the data enters the current network node or device.
[0062] Refer to Figure 2 , the legitimate local inbound interface for the service message with source prefix AS A entering PoP1 is interface i1, and the service message sent to AS B can smoothly enter the NFV network through interface i1 of PoP1 through VPN and be routed to the subsequent PoP2. At this time, if autonomous system C (hereinafter referred to as AS C) wants to communicate with AS B by forging the source address of AS A, because AS C cannot establish VPN communication with interface i1 of PoP1, AS C can choose to send messages by connecting to other nodes or other interfaces of PoP1. When the forged message enters the NFV network through interface i3 of PoP1, the central controller can check the SAV verification table of PoP1 and find that the message does not match the inbound interface in the SAV verification table, so the service message will be discarded at the central controller; similarly, the message cannot be propagated to AS B in the NFV network through an interface of PoP2.
[0063] Compared with the existing technology, this application designs an efficient and dynamic source address verification mechanism based on SAVNFV technology through NFV architecture. By utilizing the scalability and flexibility of NFV, the source address verification function is deployed in the network virtual device. At the same time, the central controller dynamically manages the verification rules and path allocation, thereby realizing accurate source address verification in a dynamic network environment.
[0064] Reference Figure 3 As shown, it is a flow chart of a source address verification method based on a virtual network shown in an embodiment of the present application, and the source address verification method based on a virtual network includes the following steps.
[0065] S31, when receiving a connection request from a customer network, determining a nearest virtual node, controlling the customer network to establish a connection with the nearest virtual node, binding an input interface, and notifying a source prefix.
[0066] Among them, the customer network refers to a network that needs to access the SAVNFV architecture (i.e., the NFV network) for source address verification. In some embodiments, before a customer network needs to be accessed, the customer network needs to clarify its own source prefix, i.e., the network address segment, which is used to identify important information about the network identity and scope. The customer network needs to find the PoP node that is closest to its geographical location or has the lowest network latency in order to establish an efficient and stable network connection. The central server can select the PoP node with the shortest physical distance or the lowest latency to the customer network based on the information of the network topology and routing protocol. Specifically, dynamic path calculation, Border Gateway Protocol (BGP) or other routing selection algorithms can be used to determine which PoP node can provide the best connection quality or the lowest latency, so as to serve as the entry node of the customer network, i.e., the nearest virtual node (referred to as the nearest PoP node). After receiving the source prefix notification of the customer network, the PoP node will allocate an ingress interface to the customer network, which is the only channel for the customer network traffic to enter the PoP node. The correct routing and verification of traffic is ensured by associating the source prefix of the customer network with the specific ingress interface of the PoP node. The customer network selects the nearest PoP node to access the NFV network to optimize network performance and reduce latency. When the customer network establishes a connection with the nearest PoP node, it will advertise its source prefix to the nearest PoP node and bind the nearest PoP node as the inbound interface so that the nearest PoP node can identify and process traffic from the customer network.
[0067] Through the above optional implementation, when the customer network needs to access the SAVNFV architecture for source address verification, it will first determine its own source prefix and initiate a connection request to the nearest PoP node. Based on the network topology and routing protocol information, the central server will select the PoP node that is geographically closest to the customer network or has the lowest network latency as the entry node of the customer network. The customer network will establish an efficient and stable network connection through this entry node. When the customer network establishes a connection with the nearest PoP node, it will announce its source prefix and bind the PoP node as the inbound interface, so that the nearest PoP node can identify and process traffic from the customer network, thereby optimizing network performance and reducing latency.
[0068] In an optional embodiment, the method further comprises:
[0069] determining the destination prefix of the customer network;
[0070] The control source virtual node initiates a detection operation through a destination prefix to establish a SAV verification table containing routing information, wherein the SAV verification table records a routing path from the source virtual node to the destination virtual node, and the routing path includes all virtual nodes from the source virtual node to the destination virtual node.
[0071] In some embodiments, when the customer network successfully connects to the nearest PoP node, the customer network can simultaneously announce its destination prefix while announcing its source prefix. According to the determined destination prefix, the PoP node corresponding to the source prefix, that is, the source PoP node can initiate a detection operation according to the destination information corresponding to the destination prefix, and gradually establish a verification table containing routing information, called a SAV verification table. Specifically, the source PoP node initiates a network detection based on the target address (destination), confirms whether the path from the source to the destination is legal, and collects the corresponding routing information. In the process of detecting transmission, each router passing through will record the routing information of the detection in its routing table, and the routing information may include the source address, destination address, address of the router passed through, and related routing metrics, etc. Therefore, the central server can establish a SAV verification table based on the routing information, and the SAV verification table may include, but is not limited to: source prefix, destination prefix, next hop PoP node, input interface and other information. After the SAV verification table is established, the SAV verification table is used to record the information of each legal path, and each PoP node maintains a SAV verification table (also called a SAV information table) to record the verification information of the source address, recording the legitimacy and credibility of the source address to ensure the accessibility of the communication path.
[0072] Through the above optional implementation method, by determining the destination prefix of the customer network and initiating a detection operation through the destination prefix, a SAV verification table containing routing information is established, and the routing path from the source virtual node to the destination virtual node is recorded, thereby ensuring the reachability and security of the communication path, so that the source address of the message can be subsequently verified based on the SAV verification table to see if it matches the record in the SAV verification table, thereby determining whether the message is legal.
[0073] S32: Allocate an original path to the customer network based on the source prefix and the destination prefix.
[0074] Among them, there are multiple PoP nodes between the source PoP node of the source prefix and the destination PoP node of the destination prefix. The path from the source PoP node to the destination PoP node is formed based on the source PoP node, the destination PoP node and the PoP nodes between the two, which is called the original path, so that the customer network can communicate based on the original path. In some embodiments, the central controller can allocate one or more paths for each pair of <source prefix, destination prefix>, and continuously update the path information to ensure the flexibility and real-time nature of the communication path and adapt to the dynamic changes of the NFV network. Specifically, the central server can obtain the current network status, topology information and traffic demand of the NFV network, and dynamically calculate the original path based on the current network status, topology information and traffic demand.
[0075] For example, suppose there is an enterprise network consisting of multiple routers and switches, and each PoP node is connected through different links, and the links have certain bandwidth, delay and current load status, then the appropriate transmission path is dynamically calculated for a set of traffic requirements according to the current network status. Specifically, the central controller can monitor and collect node information, link information and topology in real time, where the node information can include the location information of switches, routers and servers in the NFV network, and the link information can include the capacity (bandwidth limit), current traffic load, delay and packet loss rate of each link, etc. The topology refers to the connection relationship between PoP nodes and which devices are connected through which links. For example, there is a link between router A and router B with a bandwidth of 100 Mbps, and currently 50Mbps is used; there are two links between router B and router C, which are 50Mbps and 30Mbps, respectively, and the current utilization rates are 40% and 60%, respectively. When the network administrator or application proposes a set of traffic requirements, and specifies which source nodes need to be reached from which target nodes, and the required bandwidth. For example, traffic demand 1 needs to go from PoP node A to PoP node C, and requires 10Mbps, and traffic demand 2 needs to go from PoP node A to PoP node D, and requires 20Mbps. The central controller can calculate a feasible path that meets the conditions for each traffic demand based on the topology information and traffic demand. Specifically, it can use a path calculation algorithm, such as a shortest path algorithm (such as the Dijkstra algorithm), and select a path that meets the requirements in combination with the current state of the link. For traffic demand 1, from PoP node A to PoP node C, the central controller checks whether the link loads from PoP node A to PoP node B and from PoP node B to PoP node C are sufficient, that is, path 1 is PoP node A→PoP node B→PoP node C (can be described as A→B→C), with a total delay of 10ms and an available bandwidth of 30Mbps, while path 2 is PoP node A→PoP node D→PoP node C (can be described as A→D→C), with a total delay of 15ms and an available bandwidth of 20Mbps), so path 1 with lower delay is selected. For traffic demand 2, from PoP node A to PoP node D, the central controller checks the link loads from PoP node A to PoP node B and from PoP node B to PoP node D, that is, path 1 is PoP node A→PoP node B→PoP node D (which can be described as A→B→D), with a total delay of 12ms and an available bandwidth of 25Mbps. Because the bandwidth requirement is met and the path delay is low, path 1 is selected. If the link load changes suddenly, for example, the link utilization rate from PoP node A to PoP node B increases to 90%, the central controller will recalculate the path and switch to the backup path. For example, switch traffic demand 1 from path A→B→C to A→D→C. After the calculation is completed, the central controller can send the path rules to each router and switch.For example, for router A, the traffic to destination address C is sent to PoP node B through interface eth1. For router B, the traffic to destination address C is sent to PoP node C through interface eth2. Therefore, the central controller dynamically selects and allocates paths according to the current state and demand of the network. For traffic demand 1, the path is allocated from A→B→C, and for traffic demand 2, the path is allocated from A→B→D. In addition, when the network state changes, the central controller can also automatically adjust the path to ensure network performance and reliability.
[0076] In other embodiments, the central controller may also consider other factors, such as path security, load balancing requirements, and latency, and select the optimal path for each pair of <source prefix, destination prefix> through an optimization algorithm. When the network environment changes (such as topology updates or traffic fluctuations), the central controller may recalculate and adjust the path in real time to adapt to dynamic needs and ensure the flexibility and reliability of communication.
[0077] Refer to Figure 4 ,At the control layer, the central controller can generate an optimal path from the source to the destination, called the original path, based on the source address corresponding to the source prefix of the message of the customer network and the destination address corresponding to the destination prefix, and store the original path in the path information corresponding to the SAV verification table of the data layer.
[0078] S33, when it is monitored that the client network sends a message from the source address to the destination address, all virtual nodes of the original path are obtained to verify the source address of the message based on all virtual nodes.
[0079] The source address is the IP address corresponding to the source prefix, and the destination address is the IP address corresponding to the destination prefix, which marks where the message of the customer network is transmitted from and to.
[0080] Refer to Figure 4 In some embodiments, during the communication process, when the central server receives a message from the client network, the message includes a source address and a destination address, etc. That is, when the central server monitors that the source address sends a message to the destination address, it first queries the SAV verification table to check whether the message meets the requirements of the current inbound interface. If the message does not meet the inbound interface requirements, the "discard message" operation is performed to end the process. If the message meets the inbound interface requirements, the next step is continued to further verify the message.
[0081] For each PoP node, it will receive a message from a PoP node above it, and check whether the message is sent from the expected source PoP node (i.e., the previous PoP node in the original path). Specifically, the PoP node will parse the received message and extract key information such as the source address, destination address, next hop, and message content. The PoP node verifies the source address of the message according to its corresponding SAV verification table. First, it verifies whether the source address exists in the SAV verification table. When it is determined that the source address of the message exists in the SAV verification table, it further determines whether the source address of the message is legal and credible, thereby avoiding potential source address forgery attacks. If the source address of the message does not exist in the SAV information table or is marked as illegal, the "discard message" operation is performed.
[0082] In some embodiments, during the transmission process, the message may be damaged or tampered with, and the central controller can verify the integrity of the message, for example, by calculating the checksum or hash value of the message and comparing it with the checksum provided by the sender.
[0083] S34, when it is determined that the source address exists in the preset SAV verification table and is marked as legal and credible, the message is allowed to be forwarded based on the original path, so that the message is forwarded to the destination address.
[0084] The message will follow the original path in the SAV verification table, through a series of routers or switches, and finally reach the destination address. By verifying the message at each PoP node that the message needs to pass through, at each PoP node, the message will be further processed or forwarded to the final destination address through a series of forwarding, and then output to the target network or device by the destination PoP node. When the message is successfully transmitted to the destination address, the entire communication process from source to destination is completed. Through the SAV information verification table, each PoP node can verify whether the source address of the data packet is legal, thereby preventing source address spoofing attacks.
[0085] In some embodiments, for all discarded messages or discovered abnormal situations, the central server should record logs and provide alarm information, which can be used for subsequent security analysis and troubleshooting.
[0086] Through the above optional implementation, the security and reliability of network communication are guaranteed through a verification mechanism based on the original path. During the communication process, the central server first verifies the incoming interface of the message to ensure that the message meets the current network requirements; for each PoP node, the source address of the received message will be verified to confirm whether the message comes from the expected source PoP node, and determine whether the source address is legal and credible, so as to avoid source address forgery attacks; at the same time, the central controller also verifies the integrity of the message through checksums or hash values to ensure that the message has not been damaged or tampered with. If the message passes all verification links, it will be forwarded along the original path specified by the SAV verification table, and finally reach the destination address through a series of routers or switches, ensuring that the data is safely and reliably transmitted to the destination.
[0087] In addition, during the message communication process, in order to avoid malicious attacks, this application also proposes a set of algorithms for dynamically optimizing network paths. By comprehensively considering the security risks and traffic characteristics of the path, the update frequency is dynamically adjusted to achieve a balance between security and performance. At the same time, the security improvement and performance overhead brought by the update are evaluated. It is particularly suitable for dealing with increasingly complex source address spoofing attacks (such as DDoS) in the current network, and effectively solves the shortcomings of existing solutions in terms of dynamics, verification efficiency and verification accuracy.
[0088] In an optional embodiment, the method further comprises:
[0089] Determine a path update problem according to a preset trigger condition, and determine an update path based on the path update problem;
[0090] The routing path of the SAV verification table is updated according to the update path.
[0091] In order to deal with the problem that attackers guessing the forwarding path may cause verification failure, a dynamic path update mechanism can be introduced, and the central controller is responsible for regularly updating the communication path from the source PoP to the destination PoP. By frequently and irregularly changing the communication path, it is difficult for attackers to accurately guess the correct forwarding path, thereby enhancing the security of source address verification. In some embodiments, the central controller can trigger the path update problem according to a preset trigger condition, for example, setting the trigger condition to a time trigger (such as updating the path every certain time), an event trigger (such as a link failure, a sudden change in traffic, etc.), etc., then the central controller can decide when to perform a dynamic path update according to the preset trigger condition.
[0092] In some embodiments, the central controller first models the attack cost problem, and the network is represented as a graph. ,in V Represents the set of nodes in the NFV network, Erepresents the link set between PoP nodes. At the same time, the central controller determines the traffic demand set D, where the traffic demand D consists of several traffic demands. , each flow demand , including the source PoP node , Destination PoP node and flow rate In order to evaluate the probability that an attacker can successfully connect to a PoP node in the NFV network and send a packet to the victim through the correct interface and number of hops, the central controller first determines the number of PoP nodes N in the NFV network, the number of PoP nodes in the global network, and the number of , the number of interfaces M of each PoP node, the default time to live (TTL) value H, the number of robots controlled by the attacker C, and the maximum number of packets sent by each attacker per unit time B. The robots controlled by the attacker refer to devices remotely controlled by the attacker in cyberspace, which can be personal computers, servers, smart phones, IoT devices, etc.
[0093] The attacker's attack success probability is determined by the following formula: :
[0094] ;
[0095] in, is the probability that the attacker connects to any PoP node in the NFV network (called the first probability), is the probability that the attack packet enters the correct interface (called the second probability), is the probability that the attacker guesses the correct number of hops (called the third probability).
[0096] Furthermore, the central server can model the path update problem as a multi-objective optimization problem, where the objectives may include maximizing the attack cost and minimizing the performance overhead. Specifically, a binary decision variable is predefined: , indicating the flow demand Whether to pass the path Routing and pre-define a binary decision variable , indicating the path Whether to update. For each pair of traffic requests and path , the output solution will give a decision variable , indicating the flow demand Whether to pass the path Routing is performed. When Select the path through ,when When No path selected For example, assuming the traffic demand is Selected the path and path , then the output solution will exist and , while other paths If the flow demand Selected the path , then the output solution will exist , while other paths .
[0097] For each path , the output solution will give a decision variable , indicating the path Whether it needs to be updated. , indicating the path Need to update when , indicating the path No update is required. For example, if the path and path Selected for flow requirements , and the path is selected for update, the output will contain If the path No update is required, then the output will contain .
[0098] The maximum attack cost is determined by the following formula:
[0099] ;
[0100] The minimum performance cost is determined by the following formula:
[0101] ;
[0102] in, The control overhead introduced for updating the path, The delay introduced by the update path, To control expenses The corresponding weight coefficient is used to measure the importance of controlling the overhead in the optimization goal. For delay The corresponding weight coefficient is used to measure the importance of delay in the optimization goal. The control overhead may include the computational cost of path update (e.g., the time and resources required by the central controller to recalculate the path), the distribution cost of control information (e.g., the communication overhead required by the central controller to distribute the updated path information to each node in the network), the complexity of device configuration (e.g., network devices (such as routers or switches) need to receive and apply new path rules, which requires additional processing time and resources), etc. The larger the value, the more sensitive the optimization objective is to the control overhead, that is, the more inclined to choose a path update scheme with a smaller control overhead. The delay includes the interruption time of path switching (for example, the network device may need a short switching time when applying a new path, resulting in the introduction of communication delay), the propagation delay of the new path (for example, the new path may be longer than the old path (more hops), resulting in an increase in the transmission time of the data packet), the impact on network stability (for example, frequent path updates may cause instantaneous congestion or jitter of the link, thereby increasing the network delay), etc. The larger the value of , the more sensitive the optimization objective is to delay, that is, it is more inclined to choose a path update scheme with lower delay.
[0103] It should be noted that and The value of depends on the actual application scenario. For example, in scenarios that are sensitive to network update costs (such as large-scale networks or devices with limited resources), It is usually set higher. In scenarios with high network real-time requirements (such as video conferencing and real-time games), is usually set higher. In practice, and The value can be adjusted through experiments or the experience of the network administrator to achieve a balance between performance and cost.
[0104] At the same time, the central server can also predetermine the path set P and the capacity of each path And the number of paths that the controller allows to update is limited to X. Then, based on this, the constraints are pre-defined, including flow distribution constraints, path capacity constraints, and path update constraints. The flow distribution constraint refers to the flow demand of each A path must be chosen for routing, i.e. ; The path capacity constraint refers to each path The total traffic on the network cannot exceed its capacity , that is ; The path update constraint means that the central controller can only update a limited number of paths X, that is, .
[0105] Next, the central controller solves the multi-objective optimization problem of the path update problem. Specifically, the multi-objective optimization problem is first linearly relaxed by LP linear relaxation to obtain a continuous value solution , then Perform random rounding to generate a set of binary decision variables , that is, for each flow demand ,according to Select the path by value , and set , similarly Indicates flow demand Whether to pass the path (0 or 1); for each path ,according to The value of determines whether to update the path and sets , similarly Indicates the path Whether it is updated (0 or 1). And by adjusting and To meet the preset constraints. When the constraints are met, the adjusted binary variable As the final decision output, the adjusted Determined as an approximate solution , and the approximate solution Determine the update path so that the central controller can update the path in the SAV verification table according to the update path. Through the LP linear relaxation method, the binary decision variables (0 or 1) in the path update problem are relaxed to continuous values (usually between 0 and 1), so that the approximate solution of the multi-objective optimization problem can be solved. Once the continuous value solution is obtained, the central controller can convert it to 0 or 1 through rounding operations. For example, if a continuous value is 0.8, it can be rounded to 1; if a continuous value is 0.2, it can be rounded to 0. The rounded variable is the final decision variable, which usually indicates whether to select a certain path or whether to update a certain path.
[0106] Through the above optional implementation method, by introducing a dynamic path update mechanism, the problem of verification failure caused by attackers guessing the forwarding path is effectively addressed. The central controller is used to dynamically update the communication path according to preset trigger conditions, and the path update decision is optimized by modeling the attack cost problem and the multi-objective optimization problem. The approximate solution of the multi-objective optimization problem is solved by linear relaxation and random rounding methods, the update path is determined, and the routing path in the SAV verification table is updated accordingly. This not only enhances the security of source address verification, but also ensures the optimization of network performance, effectively improving the security protection capability in the virtual network environment.
[0107] In an optional implementation, when a solution is obtained using LP relaxation, the central controller can also try to improve the quality of the solution through a local search heuristic algorithm. The local search attempts to find a better combination of path selection and update decisions without violating constraints. Specifically, a feasible solution is randomly generated. , or the approximate solution output from the LP linear relaxation Get an initial solution as a feasible solution , that is, select a path from all feasible paths and calculate the flow demand The objective function value after transferring from the current path to the new path Change, if the new objective function value If it is better than the current solution (i.e. smaller, if it is a minimization problem), then update the current solution Assign new traffic flow to the new traffic flow and update the objective function value accordingly. That is, try to improve the solution through local search, that is, for each flow demand , try different paths Reroute and update the solution when the objective function value improves ; For each path , trying to update or restore the path and updating the solution when the objective function value improves , until the preset termination condition is met, and finally the updated As the optimal solution and its corresponding objective function value. For example, the central controller can set a maximum number of iterations N (for example, set N=10) as the termination condition, and stop when the local search heuristic algorithm executes N iterations; or set a maximum execution time T (for example, set T=10 minutes) as the termination condition, and stop when the algorithm runs for more than T; or if the objective function in multiple consecutive iterations improves to less than a preset threshold, it is considered that the algorithm has converged to a local optimal solution, and the search is stopped; or other termination conditions can be set.
[0108] Through the above optional implementation, by introducing the heuristic algorithm of local search, the quality of the solution is significantly improved in the source address verification method based on the virtual network. On the basis of the approximate solution obtained by LP relaxation, the objective function (such as maximizing the attack cost and / or minimizing the performance overhead) is optimized by continuously adjusting x and y through local search, and the traffic demand is rerouted by trying different paths to find a better traffic distribution solution. It can also flexibly respond to various termination conditions, such as the maximum number of iterations, the maximum execution time, or the threshold for improving the objective function value, so as to ensure that the optimal solution is obtained with reasonable time and resource consumption. By combining the LP relaxation and local search methods, not only the accuracy of path selection and update decisions is improved, but also the efficiency and reliability of the entire source address verification system are enhanced.
[0109] Refer to Figure 5 , assuming that AS A is used as the source address and AS B is used as the destination address, and two paths are allocated from AS A to AS, namely 1-3-4 and 1-2-3-5-4. When the central controller selects the 1-3-4 path, the next hop of the SAV verification table in PoP1 is PoP3, and the inbound interface of the entry from AS A to AS B in the SAV verification table in PoP4 is i1. If the second path is selected, the two SAV verification tables will also be updated accordingly.
[0110] In order to facilitate understanding of the inventive concept of the embodiment of the present application, the present application provides a forwarding path information table in a central controller as shown in Table 2 below:
[0111] Table 2
[0112]
[0113] At the same time, the present application also provides a SAV verification table of virtual node 1 in a central controller as shown in Table 3 below:
[0114] Table 3
[0115]
[0116] At the same time, the present application also provides a SAV verification table of a virtual node 4 in a central controller as shown in Table 4 below:
[0117] Table 4
[0118]
[0119] In some embodiments, the central controller can also send a test data packet from AS A to AS B to verify whether the update path is correctly configured. The test data packet will be transmitted along the selected update path and SAV verification will be performed on each PoP node included in the update path. In addition, if a PoP node fails or the network is interrupted, the central controller can detect it and reselect an available update path. Further, the central controller will send an update instruction to the affected PoP node to update its SAV verification table and routing information. Through the path selection and SAV verification table update mechanism of the central controller, the dynamic update of the network transmission path and the synchronous update of the SAV information can be achieved, which improves the flexibility and security of the network and provides a strong guarantee for the efficient transmission of network traffic.
[0120] In some embodiments, the central controller can dynamically adjust the path selection strategy according to changes in network conditions to optimize network performance. For example, when the traffic load on a certain path is too high, the central controller can select another path with a lower load to transmit data.
[0121] Compared with the source address verification technology in the prior art, for example, 1) the scheme based on access control list requires manual configuration of rules, which is not only inefficient, but also prone to errors due to frequent manual updates; 2) the strict unicast reverse path forwarding (uRPF) technology shows poor adaptability when dealing with asymmetric routing, and it is difficult to effectively cope with dynamic network environments; 3) for high-traffic DDoS attacks, the verification capability of the existing scheme is limited and cannot fundamentally improve the security of the network; 4) when deployed in large-scale networks, the above-mentioned technologies also face the problems of performance degradation and high management complexity, which restricts their practical application. The SAVNFV architecture proposed in this application establishes an NFV network and uses a central controller to implement dynamic path control to ensure the authenticity and reliability of the source address in network communication. Any autonomous system can join the NFV network to improve the security of the communication source address. SAVNFV enables AS to enjoy incremental benefits while maintaining the traditional network structure at the bottom layer, without large-scale modifications to the infrastructure, and improves the defense capabilities against security threats such as source address forgery and DDoS attacks without affecting network performance. Specifically, in terms of flexible deployment, virtualization technology is used to achieve on-demand deployment of the source address verification function, so that it can adapt to large-scale networks; in terms of dynamic adaptability, the verification rules and path updates are dynamically adjusted through a centralized controller to improve the applicability of the solution in complex network environments; in terms of security, the overall protection capability of the network is significantly enhanced by accurately identifying and filtering forged source address traffic, thereby providing a more efficient solution for dealing with source address spoofing and other network security threats.
[0122] Reference Figure 6 , which is a functional module diagram of a source address verification device based on a virtual network according to an embodiment of the present application.
[0123] In some embodiments, the virtual network-based source address verification device 60 may include a plurality of functional modules composed of computer program segments. The computer programs of the various program segments of the virtual network-based source address verification device 60 may be stored in the memory of the controller and executed by at least one processor to perform (see Figure 3 Description) The function of source address verification based on a virtual network. According to the functions performed, it can be divided into multiple functional modules. The functional modules may include: a connection establishment module 601, a path allocation module 602, an address verification module 603, a message forwarding module 604, a path update module 605 and a verification table establishment module 606. The module referred to in this application refers to a series of computer program segments that can be executed by at least one processor and can perform fixed functions, which are stored in a memory. In this embodiment, the functions of each module will be described in detail in subsequent embodiments.
[0124] The connection establishment module 601 is used to determine the nearest virtual node when receiving a connection request from a customer network, so as to control the customer network to establish a connection with the nearest virtual node, bind an input interface, and notify a source prefix.
[0125] The path allocation module 602 is a path allocation module, configured to allocate an original path to the customer network based on the source prefix and the destination prefix.
[0126] The address verification module 603 is used to obtain all virtual nodes of the original path when monitoring the client network sending a message from the source address to the destination address, so as to verify the source address of the message based on all virtual nodes.
[0127] The message forwarding module 604 is used to allow the message to be forwarded based on the original path when it is determined that the source address exists in the preset SAV verification table and is marked as legal and credible, so that the message is forwarded to the destination address.
[0128] The path updating module 605 is used to: determine the path updating problem according to a preset trigger condition, and determine the updated path based on the path updating problem; and update the routing path of the SAV verification table according to the updated path.
[0129] The path update module 605 is also specifically used to: determine the attacker's attack success probability, and model the path update problem as a multi-objective optimization problem based on the attack success probability; perform linear relaxation on the multi-objective optimization problem to obtain a continuous value solution; perform random rounding on the continuous value solution to generate a set of binary decision variables; obtain an approximate solution, and determine the approximate solution as the update path, the approximate solution is output by adjusting the binary decision variables to meet preset constraints; determine the approximate solution as the update path.
[0130] The path updating module 605 is also specifically used to: initialize a feasible solution through a local search heuristic algorithm, and record the feasible solution and the objective function value corresponding to the feasible solution, wherein the feasible solution is any one of the approximate solutions; attempt to reroute each traffic demand through a different path, and update the feasible solution when the objective function value improves until a preset termination condition is met; when the termination condition is met, the feasible solution output is used as the optimal solution, and the optimal solution is determined as the updated path.
[0131] The path update module 605 is also specifically used to: determine a first probability that the attacker successfully connects to any virtual node in the NFV network; determine a second probability that the attacker's attack message successfully enters the correct interface; determine a third probability that the attacker successfully guesses the correct number of hops; and determine the probability of attack success based on the first probability, the second probability and the third probability.
[0132] The verification table establishment module 606 is used to: determine the destination prefix of the customer network; control the source virtual node to initiate a detection operation through the destination prefix to establish a SAV verification table containing routing information, wherein the SAV verification table records the routing path from the source virtual node to the destination virtual node, and the routing path includes all virtual nodes from the source virtual node to the destination virtual node.
[0133] It should be understood that the various variations and specific embodiments of the virtual network-based source address verification method provided in the above-mentioned embodiments are also applicable to the virtual network-based source address verification device of the present embodiment. Through the above-mentioned detailed description of the virtual network-based source address verification method, those skilled in the art can clearly know the implementation method of the virtual network-based source address verification device in the present embodiment. For the sake of brevity of the specification, it will not be described in detail here.
[0134] See also Figure 7 FIG. 1 is a schematic diagram of the structure of a controller according to an embodiment of the present application. In a preferred embodiment of the present application, the controller 7 includes a memory 71 , at least one processor 72 and at least one communication bus 73 .
[0135] Those skilled in the art should understand that Figure 7 The structure of the controller shown does not constitute a limitation of the embodiments of the present application, and can be either a bus structure or a star structure. The controller 7 can also include more or less other hardware or software than shown in the figure, or a different component arrangement.
[0136] In some embodiments, the controller 7 is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application-specific integrated circuits, programmable gate arrays, digital processors, and embedded devices. The controller 7 may also include user equipment, which includes but is not limited to any electronic product that can interact with a user through a keyboard, mouse, remote control, touchpad, or voice control device, such as a personal computer, tablet computer, smart phone, digital camera, etc.
[0137] In the above embodiments provided in the present application, it should be understood that the disclosed methods, devices, computer-readable storage media, and controllers can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation, such as multiple components or modules can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or components or modules, which can be electrical, mechanical or other forms.
[0138] The components described as separate components may or may not be physically separated, and the components shown as components may or may not be physical modules, that is, they may be located in one place or distributed on multiple network modules. Some or all of the components may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0139] In addition, each functional module in each embodiment of the present invention may be integrated into one processing module, or each component may exist physically separately, or two or more modules may be integrated into one module. The above integrated modules may be implemented in the form of hardware or in the form of software functional modules.
[0140] If the integrated module is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.
[0141] It should be noted that, for the convenience of description, the aforementioned method embodiments are all described as a series of action combinations, but those skilled in the art should be aware that the present invention is not limited by the described action sequence, because according to the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present invention.
[0142] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0143] The above is a specific description of the preferred implementation of the present invention, but the invention is not limited to the embodiments. Those skilled in the art can make various equivalent modifications or substitutions without violating the spirit of the present invention. These equivalent modifications or substitutions are all included in the scope defined by the claims of this application.
Claims
1. A source address verification method based on a virtual network, characterized in that: The method comprises: When receiving a connection request from a customer network, determining a nearest virtual node to control the customer network to establish a connection with the nearest virtual node, bind an incoming interface, and notify a source prefix; allocating an original path to the customer network based on the source prefix and the destination prefix; When monitoring that the customer network sends a message from a source address to a destination address, obtaining all virtual nodes of the original path to verify the source address of the message based on all virtual nodes; When it is determined that the source address exists in a preset SAV verification table and is marked as legal and credible, the message is allowed to be forwarded based on the original path so that the message is forwarded to the destination address, and the SAV verification table records the routing path from the source virtual node to the destination virtual node, and the routing path includes all virtual nodes from the source virtual node to the destination virtual node; Determine a path update problem according to a preset trigger condition, and determine an update path based on the path update problem; determine the attacker's attack success probability, and model the path update problem as a multi-objective optimization problem based on the attack success probability, wherein the attack success probability is determined by the probability of the attacker connecting to any virtual node in the NFV network, the probability of the attack message entering the correct interface, and the probability of the attacker guessing the correct number of hops; perform linear relaxation on the multi-objective optimization problem to obtain a continuous value solution; perform random rounding on the continuous value solution to generate a set of binary decision variables; obtain an approximate solution, and determine the approximate solution as the update path, wherein the approximate solution is output by adjusting the binary decision variables to meet the preset constraints; determine the approximate solution as the update path.
2. The source address verification method based on a virtual network according to claim 1, characterized in that: Before determining the approximate solution as the update path, the method further includes: Initializing a feasible solution by a local search heuristic algorithm, and recording the feasible solution and the objective function value corresponding to the feasible solution, wherein the feasible solution is any one of the approximate solutions; Attempting to reroute each traffic demand through a different path, and updating the feasible solution when the objective function value improves, until a preset termination condition is met; When the termination condition is met, the feasible solution output is used as the optimal solution, and the optimal solution is determined as the update path.
3. The source address verification method based on a virtual network according to claim 1, characterized in that: Determining the attacker's attack success probability includes: Determine a first probability that the attacker successfully connects to any virtual node in the NFV network; Determine a second probability that the attacker's attack message successfully enters a correct interface; Determining a third probability that the attacker successfully guesses the correct number of hops; The attack success probability is determined based on the first probability, the second probability, and the third probability.
4. The source address verification method based on a virtual network according to claim 3, characterized in that: Determining the attack success probability based on the first probability, the second probability and the third probability includes: The success probability of the attack is determined by the following formula: ; in, is the success probability of the attack, is the first probability, is the second probability, is the third probability, B is the maximum number of packets sent by each attacker per unit time, C The number of robots controlled by the attacker.
5. The method for verifying a source address based on a virtual network according to any one of claims 1 to 4, characterized in that: The method further comprises: determining the destination prefix of the customer network; The control source virtual node initiates a detection operation through the destination prefix to establish a SAV verification table containing routing information.
6. A source address verification device based on a virtual network, characterized in that: The device comprises: A connection establishment module, configured to determine the nearest virtual node when receiving a connection request from a client network, control the client network to establish a connection with the nearest virtual node, bind an input interface, and notify a source prefix; A path allocation module, configured to allocate an original path to the customer network based on the source prefix and the destination prefix; An address verification module, for obtaining all virtual nodes of the original path when monitoring the client network sending a message from a source address to a destination address, so as to verify the source address of the message based on all virtual nodes; A message forwarding module, used for allowing the message to be forwarded based on the original path when it is determined that the source address exists in a preset SAV verification table and is marked as legal and credible, so that the message is forwarded to the destination address, the SAV verification table records the routing path from the source virtual node to the destination virtual node, and the routing path includes all virtual nodes from the source virtual node to the destination virtual node; A path update module is used to determine a path update problem according to a preset trigger condition, and determine an update path based on the path update problem; determine the attack success probability of an attacker, and model the path update problem as a multi-objective optimization problem based on the attack success probability, wherein the attack success probability is determined by the probability of the attacker connecting to any virtual node in the NFV network, the probability of the attack message entering the correct interface, and the probability of the attacker guessing the correct number of hops; linearly relax the multi-objective optimization problem to obtain a continuous value solution; randomly round the continuous value solution to generate a set of binary decision variables; obtain an approximate solution, and determine the approximate solution as the update path, wherein the approximate solution is output by adjusting the binary decision variables to meet the preset constraints; and determine the approximate solution as the update path.
7. A central controller, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the source address verification method based on a virtual network as described in any one of claims 1 to 5 when executing the computer program.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the source address verification method based on a virtual network described in any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Route configuration method and device, equipment, storage medium and product
CN119109866A