IP Library Granted Patent US 7,774,833
Granted Patent B1
US 7,774,833 · App. 10/668,455 · Granted Aug 10, 2010

System and method for protecting CPU against remote access attacks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,774,833
App. No.
10/668,455
Granted
Aug 10, 2010
Kind
B1
Abstract

A system and method that provides for protection of a CPU of a router, by establishing a management port on a router. Hosts which are connected to a non-management ports of the router are denied access to management functions of a CPU of the router. The system and method can utilize an application specific integrated circuit, in conjunction with a CAM-ACL, which analyzes data packets received on the ports of router, and the ASIC operates to drop data packets which are directed to the CPU of the router. This system and method operates to filter data packets which may be generated in attempts to hack in to control functions of a network device, and the operation does not require that the CPU analyze all received data packets in connection with determining access to the control functions of the router.

Claims (29)

1. A method comprising:

identifying, by a network device, a first port of the network device as a management port, the first port having a gateway address;

identifying, by the network device, a second port of the network device as a non-management port; and

filtering, by the network device, a data packet received on the second port if a destination IP address of the data packet corresponds to the gateway address of the first port and if the data packet utilizes a management protocol.

2. The method of claim 1 , wherein the filtering comprises dropping the data packet.

3. The method of claim 1 , further comprising passing the data packet received on the second port if the data packet originated from a virtual local area network that includes the first port.

4. The method of claim 3 , wherein another network device is connected to the second port, wherein a port of the another network device is defined to be part of the virtual local area network and is assigned a source IP address corresponding to the gateway address of the first port, and wherein management data packets for managing the another network device are sent to the source IP address.

5. The method of claim 4 , wherein the management data packets have higher priority than other data packets routed through the network device.

6. The method of claim 1 , wherein the network device includes an application specific integrated circuit operable to perform the filtering.

7. The method of claim 6 , wherein the application specific integrated circuit is configured to determine if the destination IP address for the data packet received on the second port corresponds to the gateway address of the first port.

8. A network device comprising:

a first port defined as a management port;

a second port defined as a non-management port;

an application specific integrated circuit operable to filter a data packet received on the second port if a destination IP address of the data packet corresponds to a gateway address of the first port and if the data packet utilizes a management protocol.

9. The network device of claim 8 wherein the filtering comprises dropping the data packet.

10. The network device of claim 8 , wherein the application specific integrated circuit is further operable to pass the data packet received on the second port if the data packet originated from a virtual local area network that includes the first port.

11. A network device comprising:

a plurality of ports including a management port; and

a control component configured to:

determine if a destination IP address included in a received data packet corresponds to a gateway IP address of the management port;

if the destination IP address corresponds to the gateway IP address of the management port, determine if the data packet originated from a management virtual local area network (VLAN), wherein the management VLAN includes the management port;

if the data packet did not originate from the management VLAN, determine if the data packet uses a management protocol; and

if the data packet uses a management protocol, drop the packet.

12. The network device of claim 11 wherein if the destination IP address does not correspond to the gateway IP address of the management port, the control component is configured to pass the data packet.

13. The network device of claim 11 wherein if the data packet did originate from the management VLAN, the control component is configured to pass the data packet.

14. The network device of claim 11 wherein if the data packet does not use a management protocol, the control component is configured to pass the data packet.

15. The network device of claim 11 wherein the network device is a router.

16. The method of claim 1 wherein filtering the data packet received on the second port comprises storing the data packet in a memory area separate from other types of received data packets.

17. The network device of claim 8 wherein filtering the data packet received on the second port comprises storing the data packet in a memory area separate from other types of received data packets.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2018
From: BROCADE COMMUNICATIONS SYSTEMS LLC
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047270/0247 →
CHANGE OF NAME Recorded Dec 13, 2017
From: BROCADE COMMUNICATIONS SYSTEMS, INC.
To: BROCADE COMMUNICATIONS SYSTEMS LLC
Reel/Frame 044891/0536 →
RELEASE OF SECURITY INTEREST Recorded Jan 22, 2015
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: BROCADE COMMUNICATIONS SYSTEMS, INC.; FOUNDRY NETWORKS, LLC
Reel/Frame 034804/0793 →
RELEASE OF SECURITY INTEREST Recorded Jan 21, 2015
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: BROCADE COMMUNICATIONS SYSTEMS, INC.; INRANGE TECHNOLOGIES CORPORATION; FOUNDRY NETWORKS, LLC
Reel/Frame 034792/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2010
From: FOUNDRY NETWORKS, LLC
To: BROCADE COMMUNICATIONS SYSTEMS, INC.
Reel/Frame 024864/0700 →
CHANGE OF NAME Recorded Jul 21, 2010
From: FOUNDRY NETWORKS, INC.
To: FOUNDRY NETWORKS, LLC
Reel/Frame 024733/0739 →
SECURITY AGREEMENT Recorded Jan 20, 2010
From: BROCADE COMMUNICATIONS SYSTEMS, INC.; FOUNDRY NETWORKS, LLC; INRANGE TECHNOLOGIES CORPORATION; MCDATA CORPORATION; MCDATA SERVICES CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 023814/0587 →
SECURITY AGREEMENT Recorded Dec 22, 2008
From: BROCADE COMMUNICATIONS SYSTEMS, INC.; FOUNDRY NETWORKS, INC.; INRANGE TECHNOLOGIES CORPORATION; MCDATA CORPORATION
To: BANK OF AMERICA, N.A. AS ADMINISTRATIVE AGENT
Reel/Frame 022012/0204 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2003
From: SZETO, RONALD W.; KWAN, PHILIP; WAI-KIT KWONG, RAYMOND
To: FOUNDRY NETWORKS, INC.
Reel/Frame 014565/0086 →