DHCP Snooping Database Distribution for Mobile Host Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face challenges in defending against man-in-the-middle attacks due to host device mobility, as they struggle to verify IP to MAC pairings across different leaf node devices, leading to potential packet drops and compromised network security.
Innovation Solution
Implementing a method where a leaf node device receives an indication of a secure route to a host device from another leaf node device, allowing it to create or update DHCP snoop database entries for validated IP-to-MAC pairings, enabling secure traffic validation even when host devices move across the network, using mechanisms like EVPN routing and BGP Extended Community Attributes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DHCP snooping is implemented to verify IP to MAC pairings for network security, then network security against man-in-the-middle attacks is improved, but host device mobility is restricted because leaf node devices cannot validate traffic from moved host devices
Solution Approach 1:
The DHCP snooping database is segmented and distributed across multiple leaf node devices. Each leaf node maintains a local DHCP snooping database that can be populated with IP to MAC pairing information from other leaf nodes, enabling local validation of mobile host devices without requiring centralized database access.
Solution Approach 2:
A route advertisement mechanism acts as an intermediary between leaf node devices. When a host device moves to a new leaf node, the previous leaf node advertises the host's IP to MAC pairing information through route advertisements, enabling the new leaf node to validate traffic from the mobile host device.
2Speed
If DHCP snoop database entries are maintained locally at each leaf node device, then traffic validation speed is improved, but network complexity increases due to distributed database management
Solution Approach 1:
The route advertisement mechanism serves multiple functions: it propagates routing information, distributes DHCP snooping database entries across leaf nodes, and enables traffic validation at the new leaf node. This multi-functionality reduces the need for separate database synchronization mechanisms, simplifying the overall system despite the distributed architecture.
3Reliability
If IP to MAC pairing verification is performed at each leaf node device, then network security is improved, but packet delivery is disrupted when host devices move between leaf nodes
Solution Approach 1:
DHCP snooping database entries and IP to MAC pairing information are propagated to potential new leaf nodes before host devices actually move there. Route advertisements carry this information in advance, so when a host device connects to a new leaf node, the validation can proceed immediately without packet loss or security violations.
Data Source
AI summary
This disclosure describes methods of operating a leaf node device, such as a switch device, connected to a switch fabric of a network. The leaf node device receives, from another leaf node device via the switch fabric, an indication of a secure route to a host device. In response to receiving the indication of the secure route, the leaf node device creates or updates a routing entry for the host device in a routing information base of the leaf node device and creates or updates an entry for the host device in a Dynamic Host Configuration Protocol (DHCP) snoop database of the leaf node device. The leaf node may thereby communicate with the host device that is attached to the leaf node device as a result of moving from the other leaf node device.


