Attack Source Tracing in SFC Overlay Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security appliances, such as firewalls and Intrusion Prevention Systems, are ineffective in tracing the source of Denial of Service (DoS) attacks in service function chain (SFC) overlay networks, as attackers often remain hidden by not receiving packets from the attacked target.

Innovation Solution

A method and device for tracing attack sources in SFC overlay networks, where an attack tracer sends a request with flow characteristics to SFC domains, and classifiers and service function forwarders perform flow matching to identify the attack source by recording and comparing hash values, reducing the number of hops needed for tracing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security appliances (firewalls, IPS) are used to detect attacks, then attack detection capability is provided, but attack source identification capability is lost

Engineering Contradiction:
Improveattack source identificationVSAvoidattack detection effectiveness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system segments the attack detection and source identification functions into separate components: security appliances detect attacks while the attack tracer system identifies sources by tracing packets through SFC domains using flow matching at classifiers

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The attack tracer acts as an intermediary system that receives detected attack information from security appliances and performs flow matching through SFC domains to identify the attack source, bridging the gap between detection and identification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If attackers do not receive packets from the attacked target, then they remain hidden, but attack source tracing becomes difficult

Engineering Contradiction:
Improveattack source tracing difficultyVSAvoidattack source identification accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The system performs preliminary flow matching at classifiers before packets reach the target, recording flow characteristics and matching them against stored patterns to identify attack sources proactively rather than reactively

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces traditional packet-based tracing mechanisms with a flow-based matching system that compares flow characteristics (5-tuples, SFC headers) against stored flow patterns to identify attack sources without requiring packet round-trips

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Loss of time

If flow matching is performed sequentially through multiple SFC domains, then comprehensive attack source identification is achieved, but tracing time increases

Engineering Contradiction:
Improveattack source tracing timeVSAvoidattack source identification accuracy
Core Design Contradiction:
Loss of timeVSMeasurement precision

Solution Approach 1:

The system implements parallel flow matching across multiple SFC domains simultaneously, with each domain performing independent flow matching operations that converge to identify the attack source, reducing overall tracing time while maintaining accuracy

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11991186B2Attack source tracing in SFC overlay network
Publication Date: 2024.05.21 NOKIA TECHNOLOGIES OY
  • US11991186B2 patent drawing
  • US11991186B2 patent drawing
  • US11991186B2 patent drawing

AI summary

Embodiments of the present disclosure relate to methods, devices and computer readable storage medium for tracing an attack source in a service function chain overlay network. In example embodiments, a request for tracing an attack source of an attacking data is sent at the attack tracer to a first service function chain domain of a plurality of service function chain domains through which the attacking data flow passes subsequently. The request includes flow characteristics of the attacking data flow. Then, the attack tracer receives a first set of results of flow matching based on the flow characteristics from the first service function chain domain. The attack tracer identifies the attack source in the plurality of service function chain domains at least in part based on the first set of results. In this way, the attack source may be traced efficiently in the service function chain overlay network.