Suspicious Control Flow Detection¶
Juniper enhanced the initial DDoS protection feature with Suspicious Control Flow Detection (SCFD). It provides deeper analysis within a given protocol or packet-type: a solution that addresses the need for more granular flow policing, supported from Junos OS 17.1R1
Introduction¶
Another potent feature integrated into the MX series platform and the MX Trio silicon is the DDoS protection. MX ddos-protection is enabled by default, and the feature is co-operated with the RE filter. A policer configured in the lo0 input filter will be downloaded to the Trio PFE (Packet Forwarding Engine) where it is executed before any DDoS (Distributed Denial of Service) policer functionality. The default mode of ddos-protection feature is supported on all MX platforms. It is also available on the PTX10000 series, and certain ACX7000 models.
The ddos-protection feature is configurable from the CLI and is designed to protect both the control and forwarding plane.
A substantial enhancement has been developed to get more of the MX Trio: the Suspicious Control Flow Detection (SCFD). With this granular flow policing, Juniper has elevated the initial DDoS protection feature to enable more comprehensive analysis within specific protocols or packet types.
Unlike basic DDoS, SCFD remains deactivated by default. Once enabled, flow protection monitors the specific contributors to the various aggregate flows. It dynamically tries to determine those that are "hostile" by virtue of their accounting for the majority of the aggregate packet rate. Suspicious flows are monitored within a specified time frame to record both the moments when they are flagged as suspicious and when these flows revert back to acceptable levels. A suspect flow in violation of its configured rate can be dropped, policed, or forwarded based on configuration. The latter case does not provide any inherent protection over basic DDoS, but the identification and logging of flows that were found to be in violation can be useful for later analysis and possible subsequent DDoS tuning.
Trio offers massive subscriber scale in terms of logical interfaces, IPv4 and IPv6 routes, and hierarchical queuing.
The design of MX Trio PFE that has ASIC performance and flexibility of FPGA allows it. In Trio chipset, multiple instructions can be executed to a packet before it leaves the forwarding engine; run-to-completion.


Exception traffic will traverse through several protection mechanism before it punts to RE.
In Figure 3 below, the depicted scenario involves incoming traffic from FPC0 destined for an interface on FPC1, with the path traversing through the fabric:

Problem Examples¶
Scenario 1¶
VRF attack to a protocol that is uncovered in lo0.0, associated to VRF-A

Scenario 2¶
A new loopback interface Lo0.101 has been assigned to VRF-A lacks appropriate filter protection. Within this context, a VRF attack targets an exception traffic towards either Lo0.101 or a customer facing interface.

Solution Description¶
RE and VRF Filter¶
While this subject lies beyond the purview of this blog, its significance as a fundamental practice prompted its inclusion in this discussion. RE protection is important and required on every loopback interface which can be added separately or by using apply-groups feature.
Furthermore, other methods, including apply-path, are elaborated in the Day One book, accessible as a PDF: https://supportportal.juniper.net/s/article/Securing-the-Routing-Engine-on-M-MX-and-T-Series?language=en_US
Another method would be VRF filter:
With the focus of this article being MX DDoS protection, let's turn our attention back to:
SCFD¶
MX ddos-protection in SCFD (Suspicious Control Flow Detection) mode
Configure:
Example of a BFD attack:
Now, what happens with the same attack coming from multiple sources:
And this is where the brilliance of the MX router shines. When facing a massive attack from thousands of sources, it initiates mitigation on a per-flow basis:
The MX platform intelligently condenses the attack into a single flow, automatically assigning it one Flow ID. This resource-saving approach is enabled due to the attack's consistent signature:
Most deployments don't require any specific tweaking of the feature.
Telemetry models are also available as described in https://www.juniper.net/documentation/us/en/software/junos/open-config/interfaces-telemetry/topics/concept/junos-telemetry-interface-grpc-sensors.html
Quoting the config guide: /junos/system/linecard/ddos/
Distributed denial of service (DDoS) sensor. This sensor supports the Openconfig data model junos/ui/openconfig/yang/ and junos-ddos.yang.
You can stream information using Juniper proprietary gRPC or UDP (native) export. There are 45 packet types for DDoS. To maintain a reasonably sized data stream, data is exported for all protocols that have seen traffic using the zero-suppression model.
You can also add the following leaves to the end of the path to stream specific statistics:
- group_name
- group_id
- protocol_name
- protocol_id
- location
- received
- arrive-policer
- dropped-individual_policer
- dropped_aggregate_policer
- total_dropped
- final_passed
- arrival_rate
- max_arrival_rate
- pass_rate
- policer_state
- policer_violation_count
- policer_violation_start_time
- policer_violation_end_time
- policer_violation_duration
The following packet types are supported:
Useful links¶
- Control Plane DDoS Protection Flow Detection Overview: https://www.juniper.net/documentation/us/en/software/junos/security-services/topics/concept/subscriber-management-scfd-overview.html
- MX Series, 2nd Edition Chapter 4: https://www.oreilly.com/library/view/juniper-mx-series/9781491932711/ch04.html
- Telemetry config guide: https://www.juniper.net/documentation/us/en/software/junos/open-config/interfaces-telemetry/topics/concept/junos-telemetry-interface-grpc-sensors.html
Glossary¶
- AS: Autonomous System
- BFD: Bidirectional Forwarding Detection
- DDOS: Distributed Denial-of-Service
- FPGA: Field Programmable Gate Array
- IP: Internet Protocol
- Junos: Operating System used in Juniper Networks routing, switching and security devices.
- MPLS: Multiprotocol Label Switching
- MX: Multi-Service router with programmable silicon
- PE: Provider Edge router
- PFE: Packet Forwarding Engine
- PIC: Physical Interface Cards
- RE: Routing Engine
- SCFD: Suspicious Control Flow Detection
- Trio: Juniper silicon. multi-threaded programmable packet processing engine and a hierarchy of high-capacity memory systems
- VPN: Virtual Private Network