vHSFC: Generic and Agile Verification of Service Function Chain with parallel VNFs

Sheng Chen, Jinxi Li, Baochao Chen, Deke Guo, Keqiu Li · 2023

With the advent of network function virtualization (NFV) and mobile edge computing (MEC), outsourcing network functions (NFs, i.e., firewall) to the MEC is becoming popular among network service providers. Notably, NF outsourcing raises an essential security concern about whether these outsourced NFs and associated service function chains (SFCs) are correctly implemented according to enterprises’ specifications. In particular, SFC with parallel VNFs, which take advantage of parallelism, have been conducted to reduce the traffic delay of traditional sequential SFC, called the hybrid SFC in this paper. Nevertheless, how to ensure correct behaviors and discover runtime mistakes for hybrid SFC remains an open problem.In this paper, we propose vHSFC, a verification scheme for hybrid SFC, enabling enterprises to verify the correctness of SFC enforcement in real-time. vHSFC achieves its goal with a lightweight verified routing protocol, which detects various hybrid SFC violations and attacks, i.e., packet modification, incompliant forwarding path, etc. To demonstrate the feasibility and performance of vHSFC, we have implemented the prototype on top of several containers and conducted extensive experiments with real traffic. The experimental results show that our vHSFC can continuously ensure proper enforcement and discover unexpected violations while incurring sensible overhead.

Read the paper · More papers on PaperTik