Securing Virtualized Networks Against Spoofing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtualized network models, such as VXLAN, lack secure mechanisms to prevent source address spoofing and rogue node access, allowing unauthorized nodes to join tenant networks and bypass security measures.

Innovation Solution

A network automation engine learns the current network policy and generates a security policy to secure dynamic virtualized networks by constructing multicast join filters, access control lists, and ingress ACLs to authorize VTEP ports and drop unauthorized traffic, thereby preventing rogue node access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conversational learning models are used to maintain compatibility with traditional Ethernet networks, then ease of operation is improved, but network security deteriorates due to lack of spoofing prevention

Engineering Contradiction:
Improvecompatibility with traditional Ethernet networksVSAvoidsource address spoofing
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by implementing security policies before rogue nodes can join the network. The system proactively learns the network topology and configures multicast join filters, access control lists, and ingress ACLs in advance to prevent unauthorized access. This is evident in the automated policy generation that occurs as nodes are discovered, creating security measures before potential attacks can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security policy mechanism that sits between the conversational learning model and the network traffic. The automated policy generation system acts as a mediator that translates learned network topology into security configurations, including multicast join filters and access control lists, without disrupting the underlying Ethernet compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If automated policy generation is implemented to secure virtualized networks, then network security is improved, but device complexity increases

Engineering Contradiction:
Improverogue node accessVSAvoidsecurity policy implementation
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies self-service through automated policy generation that learns network topology autonomously and configures security policies without manual intervention. The system automatically discovers nodes, determines their roles, and generates appropriate security configurations including multicast join filters and access control lists. This eliminates the need for complex manual security policy implementation while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes parameters from static manual configuration to dynamic automated generation. Security policies are no longer fixed but adapt based on learned network conditions. The system continuously monitors and adjusts security parameters such as multicast group memberships, access control list entries, and ingress/egress filtering rules based on the current network state, simplifying implementation while maintaining security.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multicast join filters and access control lists are constructed to authorize VTEP ports, then reliability is improved, but ease of operation deteriorates due to manual configuration requirements

Engineering Contradiction:
Improveauthorized traffic controlVSAvoidsecurity policy configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements feedback through automated policy generation that continuously learns network topology and adjusts security configurations accordingly. The system monitors network traffic and node behavior, using this feedback to dynamically update multicast join filters, access control lists, and ingress ACLs. This closed-loop approach ensures reliable traffic control while eliminating manual configuration, as the system self-adjusts based on observed network conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2915090B1System and method for securing virtualized networks
Publication Date: 2020.12.16 LUMINUS NETWORKS INC
  • EP2915090B1 patent drawingFigure 1
  • EP2915090B1 patent drawingFigure 2
  • EP2915090B1 patent drawingFigure 3

AI summary

A method and apparatus that secures a dynamic virtualized network is described. In an exemplary embodiment, a device learns a current network policy of the dynamic virtualized network, where the dynamic virtualized network is a virtualized layer 2 network that is overlaid on a layer 3 physical network. In addition, the current network policy includes multiple network policy elements, where each of the multiple network policy elements identifies an authorized endpoint in the dynamic virtualized network. Furthermore, the layer 3 physical network includes multiple network access devices. The device further determines a network security policy for the dynamic virtualized network from the current network policy. The network security policy includes one or more second network policy elements that are a different network policy element than one of the multiple network policy elements of the current network policy. In addition, each of the one or more second network policy network elements adds an additional policy on how network traffic is processed in the dynamic virtualized network by a port of one of the plurality of network access devices. The device further applies the network security policy to each network access device that is affected by the network security policy.