Service Classifier Cloned Traffic Steering in SFC
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Service Function Chains (SFCs) lack a mechanism to steer and manage cloned or mirrored traffic, which is essential for security use-cases like DDoS behavioral detection, intrusion detection, and sandboxing, as they do not recognize or correlate such traffic, potentially affecting normal traffic by mis-resetting connections or modifying it.
Innovation Solution
The solution involves creating a cloned data packet with a mirror bit in the network service header (NSH) to identify it as cloned, setting a service index (SI) based on the service function path length, and transmitting it to corresponding service function forwarders, ensuring that cloned traffic is processed without affecting normal traffic and can be dropped or analyzed appropriately.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloned traffic is not identified and steered separately, then normal traffic processing is simplified, but security analysis functions cannot be performed and normal traffic may be incorrectly modified
Solution Approach 1:
The patent introduces a mirror bit in the Network Service Header (NSH) as an intermediary marker to identify cloned traffic packets. This intermediary mechanism allows the system to distinguish cloned traffic without fundamentally changing the traffic processing architecture, enabling security functions to operate on cloned packets while normal traffic flows unchanged through the service function chain.
Solution Approach 2:
The patent segments traffic handling into two distinct paths: normal traffic follows the standard service function chain processing, while cloned traffic (identified by the mirror bit) is steered to specific security analysis service functions. This segmentation allows different processing rules to apply to different traffic types simultaneously, resolving the contradiction between simplified processing and security analysis requirements.
2Adaptability or versatility
If cloned traffic is processed by multiple service functions simultaneously, then security detection capability is improved, but traffic correlation and steering become complex
Solution Approach 1:
The patent applies preliminary action by setting the mirror bit in the NSH of cloned traffic packets before they enter the service function chain. This pre-marking allows downstream service functions to immediately identify and process cloned traffic appropriately without requiring complex real-time correlation mechanisms, as the cloned nature of each packet is self-evident from its header.
Solution Approach 2:
The mirror bit mechanism provides universality by enabling a single identification approach to serve multiple security functions (DDoS detection, intrusion detection, sandboxing) simultaneously. The same NSH modification allows any service function in the chain to recognize and appropriately handle cloned traffic, eliminating the need for function-specific identification mechanisms.
3Reliability
If the mirror bit is set in cloned packets, then cloned traffic can be identified and processed separately, but additional header manipulation is required
Solution Approach 1:
The patent changes a single parameter in the existing NSH structure (the mirror bit) to enable cloned traffic identification. This minimal parameter change approach maintains compatibility with existing network service header formats and processing logic, requiring only simple bit manipulation rather than complex packet reconstruction or additional header fields.
Data Source
AI summary
Aspects of the embodiments are directed to a service classifier configured for steering cloned traffic through a service function chain. The service classifier is configured to create a cloned data packet by creating a copy of a data packet; activate a mirror bit in a network service header (NSH) of the cloned data packet, the mirror bit identifying the cloned packet to a service function forwarder network element as a cloned packet; and transmit the cloned packet to the service function forwarder network element.


