Attack Source Tracing in SFC Overlay Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security appliances, such as firewalls and Intrusion Prevention Systems, are ineffective in tracing the source of Denial of Service (DoS) attacks in service function chain (SFC) overlay networks, as attackers often remain hidden by not receiving packets from the attacked target.
Innovation Solution
A method and device for tracing attack sources in SFC overlay networks, where an attack tracer sends a request with flow characteristics to SFC domains, and classifiers and service function forwarders perform flow matching to identify the attack source by recording and comparing hash values, reducing the number of hops needed for tracing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional security appliances (firewalls, IPS) are used to detect attacks, then attack detection capability is provided, but attack source identification capability is lost
Solution Approach 1:
The system segments the attack detection and source identification functions into separate components: security appliances detect attacks while the attack tracer system identifies sources by tracing packets through SFC domains using flow matching at classifiers
Solution Approach 2:
The attack tracer acts as an intermediary system that receives detected attack information from security appliances and performs flow matching through SFC domains to identify the attack source, bridging the gap between detection and identification
2Difficulty of detecting and measuring
If attackers do not receive packets from the attacked target, then they remain hidden, but attack source tracing becomes difficult
Solution Approach 1:
The system performs preliminary flow matching at classifiers before packets reach the target, recording flow characteristics and matching them against stored patterns to identify attack sources proactively rather than reactively
Solution Approach 2:
The system replaces traditional packet-based tracing mechanisms with a flow-based matching system that compares flow characteristics (5-tuples, SFC headers) against stored flow patterns to identify attack sources without requiring packet round-trips
3Loss of time
If flow matching is performed sequentially through multiple SFC domains, then comprehensive attack source identification is achieved, but tracing time increases
Solution Approach 1:
The system implements parallel flow matching across multiple SFC domains simultaneously, with each domain performing independent flow matching operations that converge to identify the attack source, reducing overall tracing time while maintaining accuracy
Data Source
AI summary
Embodiments of the present disclosure relate to methods, devices and computer readable storage medium for tracing an attack source in a service function chain overlay network. In example embodiments, a request for tracing an attack source of an attacking data is sent at the attack tracer to a first service function chain domain of a plurality of service function chain domains through which the attacking data flow passes subsequently. The request includes flow characteristics of the attacking data flow. Then, the attack tracer receives a first set of results of flow matching based on the flow characteristics from the first service function chain domain. The attack tracer identifies the attack source in the plurality of service function chain domains at least in part based on the first set of results. In this way, the attack source may be traced efficiently in the service function chain overlay network.


