Securing Virtualized Networks Against Spoofing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virtualized network models, such as VXLAN, lack secure mechanisms to prevent source address spoofing and rogue node access, allowing unauthorized nodes to join tenant networks and bypass security measures.
Innovation Solution
A network automation engine learns the current network policy and generates a security policy to secure dynamic virtualized networks by constructing multicast join filters, access control lists, and ingress ACLs to authorize VTEP ports and drop unauthorized traffic, thereby preventing rogue node access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conversational learning models are used to maintain compatibility with traditional Ethernet networks, then ease of operation is improved, but network security deteriorates due to lack of spoofing prevention
Solution Approach 1:
The patent applies preliminary action by implementing security policies before rogue nodes can join the network. The system proactively learns the network topology and configures multicast join filters, access control lists, and ingress ACLs in advance to prevent unauthorized access. This is evident in the automated policy generation that occurs as nodes are discovered, creating security measures before potential attacks can occur.
Solution Approach 2:
The patent introduces an intermediary security policy mechanism that sits between the conversational learning model and the network traffic. The automated policy generation system acts as a mediator that translates learned network topology into security configurations, including multicast join filters and access control lists, without disrupting the underlying Ethernet compatibility.
2Object-affected harmful factors
If automated policy generation is implemented to secure virtualized networks, then network security is improved, but device complexity increases
Solution Approach 1:
The patent applies self-service through automated policy generation that learns network topology autonomously and configures security policies without manual intervention. The system automatically discovers nodes, determines their roles, and generates appropriate security configurations including multicast join filters and access control lists. This eliminates the need for complex manual security policy implementation while maintaining high security standards.
Solution Approach 2:
The patent changes parameters from static manual configuration to dynamic automated generation. Security policies are no longer fixed but adapt based on learned network conditions. The system continuously monitors and adjusts security parameters such as multicast group memberships, access control list entries, and ingress/egress filtering rules based on the current network state, simplifying implementation while maintaining security.
3Reliability
If multicast join filters and access control lists are constructed to authorize VTEP ports, then reliability is improved, but ease of operation deteriorates due to manual configuration requirements
Solution Approach 1:
The patent implements feedback through automated policy generation that continuously learns network topology and adjusts security configurations accordingly. The system monitors network traffic and node behavior, using this feedback to dynamically update multicast join filters, access control lists, and ingress ACLs. This closed-loop approach ensures reliable traffic control while eliminating manual configuration, as the system self-adjusts based on observed network conditions.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and apparatus that secures a dynamic virtualized network is described. In an exemplary embodiment, a device learns a current network policy of the dynamic virtualized network, where the dynamic virtualized network is a virtualized layer 2 network that is overlaid on a layer 3 physical network. In addition, the current network policy includes multiple network policy elements, where each of the multiple network policy elements identifies an authorized endpoint in the dynamic virtualized network. Furthermore, the layer 3 physical network includes multiple network access devices. The device further determines a network security policy for the dynamic virtualized network from the current network policy. The network security policy includes one or more second network policy elements that are a different network policy element than one of the multiple network policy elements of the current network policy. In addition, each of the one or more second network policy network elements adds an additional policy on how network traffic is processed in the dynamic virtualized network by a port of one of the plurality of network access devices. The device further applies the network security policy to each network access device that is affected by the network security policy.