Anti-spoofing Check via Interface-Source ID Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unicast reverse path forwarding (uRPF) checks in strict mode often lead to mistaken discarding of packets, resulting in inaccurate identification of packet security, as they do not accurately differentiate between spoofing and non-spoofing attack packets.

Innovation Solution

An anti-spoofing attack check method that determines the security of packets by correlating a source IP address with a first identifier corresponding to its outbound interface or network domain and a second identifier corresponding to the receiving interface or network domain, allowing for accurate identification of spoofing attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If uRPF strict mode check is used to prevent source address spoofing attacks, then packet security identification is improved, but packet accuracy deteriorates due to mistaken discard of legitimate packets

Engineering Contradiction:
Improvepacket security identificationVSAvoidpacket identification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the single uRPF strict mode check into multiple verification dimensions: (1) source address verification against routing table, (2) interface verification to determine if incoming interface matches outbound interface of reverse route, and (3) additional verification mechanisms. This segmentation allows the system to maintain security requirements while reducing false positives by examining multiple aspects of packet validity independently

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary verification mechanisms between the source address check and the final packet acceptance/rejection decision. These intermediaries include additional validation steps that examine packet characteristics, routing consistency, and interface properties to distinguish legitimate packets from spoofed packets more accurately, preventing mistaken discards

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If uRPF strict mode check is used to filter spoofing packets, then network security is improved, but packet loss increases due to mistaken discards

Engineering Contradiction:
Improvespoofing attack preventionVSAvoidlegitimate packet loss
Core Design Contradiction:
Object-affected harmful factorsVSLoss of substance

Solution Approach 1:

The patent applies partial verification actions rather than a single all-or-nothing check. Instead of relying solely on the strict interface match requirement, the system performs multiple partial verification steps including source address validation, routing consistency checks, and additional packet characteristic analysis. This allows the system to achieve comprehensive security validation while maintaining higher packet acceptance rates for legitimate traffic

Inventive Principle:
Principle #16Partial or excessive action

3Device complexity

If simple source address routing check is used, then device complexity is reduced, but security effectiveness deteriorates due to spoofing attack vulnerability

Engineering Contradiction:
Improvecheck mechanism simplicityVSAvoidspoofing attack prevention
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent merges multiple verification functions into a unified anti-spoofing check mechanism. It combines source address verification, interface validation, routing table lookup, and packet characteristic analysis into an integrated security check system. This merging approach maintains operational simplicity for network devices while achieving comprehensive spoofing attack prevention through the coordinated execution of multiple verification functions

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12177250B2Anti-spoofing attack check method, device, and system
Publication Date: 2024.12.24 HUAWEI TECH CO LTD
  • US12177250B2 patent drawing
  • US12177250B2 patent drawing
  • US12177250B2 patent drawing

AI summary

An anti-spoofing attack check method, including: receiving, by a first network device, a packet via a first interface; determining, by the first network device based on a source IP address of the packet, a first identifier corresponding to the source IP address; determining, by the first network device based on the first interface, a second identifier corresponding to the first interface; and determining, by the first network device, security of the packet based on the first identifier and the second identifier. The method helps prevent misjudgment of the anti-spoofing attack check.