AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (5 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Open Access

SAVNFV: Towards a Scalable and Accurate Inter-Domain Source Address Validation Platform with Network Functions Virtualization

College of Computer Science and Software Engineering, Shenzhen University, Shenzhen 518060, China
Show Author Information

Abstract

Nowadays, Source Address Validation (SAV) is increasingly important for defending Distributed Denial of Service (DDoS) attacks and other malicious activities. Existing ingress/edge filtering-based solutions, such as SAVI, filter spoofed source addresses using Access Control Lists (ACL) or unicast Reverse Path Forwarding (uRPF), but they only provide coarse-grained filtering. Source Address Validation in intra-domain and inter-domain NETworks (SAVNET) has recently attracted much attention in both industry and the Internet Engineering Task Force (IETF), deploying SAV inside Internet Service Provider (ISP) networks and generating SAV tables by binding source address prefixes with incoming interfaces. However, SAVNET requires upgrading almost all routers across networks, which is impractical—especially in inter-domain scenarios. Moreover, due to policy routing and load balancing, determining the exact incoming interface for each source prefix is challenging. In this paper, we propose SAVNFV, a Network Functions Virtualization (NFV) based platform that provides SAV capabilities by building a “clean” virtual overlay network. SAVNFV randomly generates paths for each flow through a centralized controller, making the SAV table easy to obtain. The paths are periodically refreshed, and packets are transmitted through multiple routes, making it nearly impossible for attackers to identify the correct incoming interface. We formulate the multi-path transmission as an optimization problem and prove it to be NP-Complete, then design approximation algorithms with theoretical guarantees. Comprehensive simulations show that SAVNFV blocks 94.6% more malicious traffic than traditional solutions while maintaining acceptable path stretch. We also implement the system using open-source routing software and build a real-world experimental platform to further validate our design.

References

【1】
【1】
 
 
Big Data Mining and Analytics
Pages 536-553

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Yang S, Zhang Z, Cui L. SAVNFV: Towards a Scalable and Accurate Inter-Domain Source Address Validation Platform with Network Functions Virtualization. Big Data Mining and Analytics, 2026, 9(2): 536-553. https://doi.org/10.26599/BDMA.2025.9020117

1176

Views

104

Downloads

0

Crossref

0

Web of Science

0

Scopus

0

CSCD

Received: 14 October 2025
Revised: 08 November 2025
Accepted: 24 November 2025
Published: 09 February 2026
© The author(s) 2026.

The articles published in this open access journal are distributed under the terms of the Creative Commons Attribution 4.0 International License (http://creativecommons.org/licenses/by/4.0/).