Automated Multicast Anti-Spoofing via Rendezvous Point Address Replacement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multicast anti-spoofing solutions require manual configuration and are not enabled by default, making them inefficient and prone to security vulnerabilities in network environments, especially in distributed denial of service (DDoS) attacks where source addresses are easily spoofed.

Innovation Solution

An automated method and system for configuring a firewall's multicast anti-spoofing settings by determining the source address of IP packets, replacing it with a rendezvous point address, and matching routing path information to identify and log or discard spoofed multicast packets, thereby enhancing network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of multicast anti-spoofing is implemented, then network security is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically performs anti-spoofing configuration without requiring manual intervention. The firewall independently determines source addresses, replaces them with rendezvous point addresses, checks routing path information, and identifies spoofed packets autonomously, eliminating the need for complex manual configuration while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures anti-spoofing parameters and routing information before actual multicast traffic arrives. By establishing the multicast routing information base and rendezvous point addresses in advance, the system prepares the security framework proactively, reducing operational complexity during live operations

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual configuration of multicast anti-spoofing is implemented, then network security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidoperational ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The automated system performs all anti-spoofing operations independently without requiring operator intervention. The firewall automatically processes source addresses, performs routing lookups, and identifies spoofed packets, making the system as easy to operate as enabling a simple feature while maintaining high security standards

Inventive Principle:
Principle #25Self-service

3Productivity

If automated anti-spoofing configuration is implemented, then processor efficiency is improved, but device complexity increases

Engineering Contradiction:
Improveprocessor efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system pre-computes and stores routing path information and rendezvous point addresses in the multicast routing information base before traffic arrives. This preliminary preparation allows the firewall to perform rapid automated anti-spoofing checks without complex real-time computations, improving processor efficiency while managing complexity through advance preparation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10320839B2Automatic anti-spoof for multicast routing
Publication Date: 2019.06.11 FORCEPOINT LLC
  • US10320839B2 patent drawing
  • US10320839B2 patent drawing
  • US10320839B2 patent drawing

AI summary

A method, system and computer-usable medium are disclosed for performing an automated anti-spoofing configuration operation, comprising: determining whether a source address of an internet protocol (IP) packet is allowed by a receiving interface of a firewall; determining whether the IP packet comprises a multicast packet when the IP packet is allowed by the receiving interface of the firewall; replacing the source address with a rendezvous point address; using the rendezvous point address to determine whether routing path information associated with the multicast packet matches information stored within a multicast routing information base for the receiving interface of the firewall; and, identifying the multicast packet as spoofed when the routing path information associated with multicast packet does not have corresponding information stored within the multicast routing information base.