Global Flow Tracking System for Spoofed Source Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network devices lack an effective method to trace and identify the source of packet flows, especially in cases of denial-of-service attacks, where spoofed source addresses complicate the tracking process.
Innovation Solution
A global flow tracking system that uses a flow signature to identify destination collectors, obtains a list of potential source collectors, and determines the path through which packets passed, allowing for the identification of verified source collectors and outputting information on the path and source collectors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional packet routing methods are used, then network devices can forward packets efficiently, but they cannot trace the source of flows especially when spoofed addresses are involved
Solution Approach 1:
The patent introduces flow collectors as intermediary devices deployed at strategic network points that capture and store flow information. These collectors act as mediators between the actual packet flow and the tracking system, enabling source identification without requiring modification of the packet forwarding path. The flow signature obtained from these intermediaries allows precise flow source identification even when spoofed addresses are present.
Solution Approach 2:
The tracking system is segmented into multiple independent components: flow collectors that capture traffic, a flow information manager that processes data, and a global routing map that provides network topology. This segmentation allows each component to perform its function independently, reducing overall system complexity while maintaining high measurement precision for flow source identification.
2Adaptability or versatility
If flow tracking is implemented across multiple networks, then source identification capability is improved, but the complexity of managing multiple collectors and routing information increases
Solution Approach 1:
The flow information manager is designed as a universal system that can handle flow information from multiple different networks and collector types. It provides a unified interface for managing flow data regardless of the source network, enabling multi-network tracking capability while abstracting away the complexity of individual collector management. The global routing map similarly provides universal topology information applicable across all connected networks.
3Loss of information
If detailed flow path information is collected, then security analysis capability is improved, but the amount of data to be processed and stored increases
Solution Approach 1:
The system extracts only the essential flow information needed for source identification and path tracing, such as flow signatures, collector identifiers, and routing map data. By taking out only the critical elements rather than collecting complete packet data, the system maintains information completeness for security analysis while significantly reducing the volume of data that needs to be processed and stored.
Data Source
AI summary
A device may obtain a flow signature, identify a destination collector to which packets bearing the flow signature are sent, obtain a list of potential source collectors that may have sent the packets bearing the flow signature to the destination collector, and identify a source collector, among the potential source collectors, that sent the packets to the destination collector. In addition, the device may output information related to a path from the source collector the destination collector.


