First Hop Security Endpoint Cache for VM Migration IP Theft Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized datacenters, detecting IP address theft is challenging due to the migration of virtual machines (VMs) which does not trigger ARP or ND communications, making it difficult to distinguish between legitimate VM movements and rogue device activities.

Innovation Solution

The First Hop Security (FHS) solution intercepts DHCP, ARP, and ND protocol messages to build a distributed secure endpoint cache, using credentials like Source IP address, Source MAC Address, Endpoint Group, and Layer 2 Bridge Domain for identity, and performs theft validation by probing the old location of endpoints to ensure their legitimacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If VM migration is enabled to accommodate variable cloud data services demand, then adaptability and resource efficiency are improved, but the ability to detect IP address theft deteriorates because VM migration does not trigger ARP or ND communications

Engineering Contradiction:
ImproveVM migration capabilityVSAvoidIP address theft detection
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a First Hop Security (FHS) mechanism as an intermediary that intercepts DHCP, ARP, and ND protocol messages to build a distributed secure endpoint cache. This intermediary monitors endpoint credentials (Source IP address, Source MAC Address, Endpoint Group, Layer 2 Bridge Domain) and performs theft validation by probing old locations, enabling detection of IP theft while allowing legitimate VM migration without ARP/ND communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If traditional ARP/ND monitoring is used to detect IP theft, then detection capability is improved, but VM migration capability deteriorates because these protocols are not triggered during migration

Engineering Contradiction:
ImproveIP theft detection capabilityVSAvoidVM migration capability
Core Design Contradiction:
Difficulty of detecting and measuringVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary actions by building a distributed secure endpoint cache before migration occurs. The FHS mechanism pre-monitors endpoint credentials and maintains records of endpoint locations. When migration happens without ARP/ND communications, the pre-established cache and probing mechanism enable detection of legitimate migration versus IP theft, allowing VM migration capability to function without traditional protocol triggers.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If IP theft validation probing is performed to ensure endpoint legitimacy, then security against IP theft is improved, but network traffic and processing overhead increase

Engineering Contradiction:
ImproveIP address theft preventionVSAvoidnetwork traffic and processing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements feedback mechanisms where the FHS mechanism probes old endpoint locations to validate migration legitimacy. The probing process receives feedback responses that indicate whether an endpoint has legitimately migrated or if IP theft is occurring. This feedback-driven approach enables reliable IP theft prevention by continuously monitoring endpoint locations and adjusting security decisions based on probe responses, while the distributed cache reduces redundant probing overhead.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11757935B2Endpoint security mechanism to detect IP theft on a virtual machine mobility in switch fabric
Publication Date: 2023.09.12 CISCO TECHNOLOGY INC
  • US11757935B2 patent drawing
  • US11757935B2 patent drawing
  • US11757935B2 patent drawing

AI summary

Methods to secure against IP address thefts by rogue devices in a virtualized datacenter are provided. Rogue devices are detected and distinguished from a migration of an endpoint in a virtualized datacenter. A first hop network element in a one or more network fabrics intercepts a request that includes an identity of an endpoint and performs a local lookup for the endpoint entity identifier. Based on the lookup not finding the endpoint entity identifier, the first hop network element broadcasts a message such as a remote media access address (MAC) query to other network elements in the one or more network fabrics. Based on the received response, which may include an IP address associated with the MAC address, the first hop network element performs a theft validation process to determine whether the request originated from a migrated endpoint or a rogue device.