IP Library Granted Patent US 7,733,788
Granted Patent B1
US 7,733,788 · App. 11/053,737 · Granted Jun 8, 2010

Computer network control plane tampering monitor

Assignee: Sandia Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,733,788
App. No.
11/053,737
Granted
Jun 8, 2010
Kind
B1
Abstract

A computer network control plane tampering monitor that detects unauthorized alteration of a label-switched path setup for an information packet intended for transmission through a computer network.

Claims (30)

1. A method practiced on a computer for monitoring a path through a computer network comprising:

generating a first message unit, the first message unit including a path identifier and at least one information field;

generating a second message unit within a node along the path through the computer network, the second message unit comprising the path identifier, and a path summary comprising the at least one information field; and

generating a notification, responsive to determining whether the first message unit and the second message unit produce an expected pair of values of the at least one information field.

2. The method of claim 1 , further comprising determining by a comparator whether the first message unit and the second message unit produce the expected pair of values of the at least one information field.

3. The method of claim 1 , wherein the node along the path through the computer network wherein the step of generating the second message unit is carried out is a node within which the first message unit was generated or a next-hop node.

4. The method of claim 1 , wherein the first message unit further comprises an identifier of a next-hop node of the computer network.

5. The method of claim 1 , wherein the second message unit further comprises an identifier of a next-hop node of the computer network and a path summary.

6. A method practiced on a computer for monitoring a path through a computer network comprising:

generating a first message unit, the first message unit including a path identifier and at least one information field;

generating a second message unit within a node along the path through the computer network, the second message unit comprising the path identifier, and a path summary comprising the at least one information field; and

generating a notification, responsive to determining whether the first message unit and the second message unit produce an expected pair of values of the at least one information field, wherein the path through the computer network comprises a label-switched path.

7. The method of claim 6 , wherein the first message unit comprises a first path message and the second message unit comprises a second path message.

8. The method of claim 7 , wherein the at least one information field includes one of a label-switched path ID field, a label request object, an explicit route object, a record route object, a sender template object, a session attribute object, a filter spec object, a flow spec object, and a class-of-service object.

9. The method of claim 6 , wherein the first message unit comprises a first reservation message and the second message unit comprises a second reservation message.

10. The method of claim 9 , wherein the at least one information field includes one of a label-switched path ID object, a label object, a record route object, a session object, and a style object.

11. A method practiced on a computer for monitoring a path through a computer network comprising:

detecting a generation of a tear-down message unit by a network node;

determining whether the network node is an authorized node to generate the tear-down message unit; and

generating a notification if the network node is not the authorized node.

12. The method of claim 11 , wherein the tear-down message unit comprises a path tear-down message

and the step of determining comprises determining whether the path tear-down message corresponds to a path tear-down message generated by the authorized node.

13. The method of claim 12 , wherein the path tear-down message comprises a label-switched path session ID field object and a sender template object and the step of determining comprises determining whether the label-switched path session ID field object and the sender template object of the path tear-down message correspond to a label-switched path session ID field object and a sender template object of the path tear-down message generated by the authorized node.

14. The method of claim 11 , wherein the tear-down message unit comprises a reservation tear-down message and the step of determining comprises determining whether the reservation tear-down message corresponds to a reservation tear-down message generated by the authorized node.

15. The method of claim 14 , wherein the reservation tear-down message comprises a label-switched reservation session ID field object and a next-hop object and the step of determining comprises determining whether the label-switched reservation session ID field object and the next-hop object of the tear-down message correspond to label-switched path reservation session ID field object and a next-hop object of the reservation tear-down message generated by the authorized node.

16. A method practiced on a computer for monitoring a path through a computer network comprising:

generating a message unit comprising a path identifier and a path summary comprising at least one information field;

determining by a comparator whether the message unit complies with an allowed policy in a network policy database; and

generating a notification if the message unit fails to comply with the allowed policy in the network policy database.

17. The method of claim 16 , wherein the network policy database defines an allowable condition including one of a path route and a class of service request.

Assignments (3)
CHANGE OF NAME Recorded Sep 27, 2018
From: SANDIA CORPORATION
To: NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA, LLC
Reel/Frame 047631/0102 →
CONFIRMATORY LICENSE Recorded Mar 21, 2005
From: SANDIA CORPORATION
To: ENERGY, U.S. DEPARTMENT OF
Reel/Frame 015930/0040 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2005
From: MICHALSKI, JOHN T.; TORGERSON, MARK D.; TARMAN, THOMAS D.; BLACK, STEPHEN P.
To: SANDIA CORPORATION, OPERATOR OF SANDIA NATIONAL LABORATORIES
Reel/Frame 015852/0018 →
Continuity (1)
Provisional Application 6060564400 · Aug 30, 2004