Service Classifier Cloned Traffic Steering in SFC

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Service Function Chains (SFCs) lack a mechanism to steer and manage cloned or mirrored traffic, which is essential for security use-cases like DDoS behavioral detection, intrusion detection, and sandboxing, as they do not recognize or correlate such traffic, potentially affecting normal traffic by mis-resetting connections or modifying it.

Innovation Solution

The solution involves creating a cloned data packet with a mirror bit in the network service header (NSH) to identify it as cloned, setting a service index (SI) based on the service function path length, and transmitting it to corresponding service function forwarders, ensuring that cloned traffic is processed without affecting normal traffic and can be dropped or analyzed appropriately.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloned traffic is not identified and steered separately, then normal traffic processing is simplified, but security analysis functions cannot be performed and normal traffic may be incorrectly modified

Engineering Contradiction:
Improvesecurity analysis accuracyVSAvoidtraffic management mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a mirror bit in the Network Service Header (NSH) as an intermediary marker to identify cloned traffic packets. This intermediary mechanism allows the system to distinguish cloned traffic without fundamentally changing the traffic processing architecture, enabling security functions to operate on cloned packets while normal traffic flows unchanged through the service function chain.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments traffic handling into two distinct paths: normal traffic follows the standard service function chain processing, while cloned traffic (identified by the mirror bit) is steered to specific security analysis service functions. This segmentation allows different processing rules to apply to different traffic types simultaneously, resolving the contradiction between simplified processing and security analysis requirements.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If cloned traffic is processed by multiple service functions simultaneously, then security detection capability is improved, but traffic correlation and steering become complex

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidtraffic steering and correlation mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by setting the mirror bit in the NSH of cloned traffic packets before they enter the service function chain. This pre-marking allows downstream service functions to immediately identify and process cloned traffic appropriately without requiring complex real-time correlation mechanisms, as the cloned nature of each packet is self-evident from its header.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mirror bit mechanism provides universality by enabling a single identification approach to serve multiple security functions (DDoS detection, intrusion detection, sandboxing) simultaneously. The same NSH modification allows any service function in the chain to recognize and appropriately handle cloned traffic, eliminating the need for function-specific identification mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the mirror bit is set in cloned packets, then cloned traffic can be identified and processed separately, but additional header manipulation is required

Engineering Contradiction:
Improvecloned traffic identification accuracyVSAvoidpacket processing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent changes a single parameter in the existing NSH structure (the mirror bit) to enable cloned traffic identification. This minimal parameter change approach maintains compatibility with existing network service header formats and processing logic, requiring only simple bit manipulation rather than complex packet reconstruction or additional header fields.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10225270B2Steering of cloned traffic in a service function chain
Publication Date: 2019.03.05 CISCO TECHNOLOGY INC
  • US10225270B2 patent drawing
  • US10225270B2 patent drawing
  • US10225270B2 patent drawing

AI summary

Aspects of the embodiments are directed to a service classifier configured for steering cloned traffic through a service function chain. The service classifier is configured to create a cloned data packet by creating a copy of a data packet; activate a mirror bit in a network service header (NSH) of the cloned data packet, the mirror bit identifying the cloned packet to a service function forwarder network element as a cloned packet; and transmit the cloned packet to the service function forwarder network element.