IP Library Granted Patent US 7,804,774
Granted Patent B2
US 7,804,774 · App. 11/565,942 · Granted Sep 28, 2010

Scalable filtering and policing mechanism for protecting user traffic in a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,804,774
App. No.
11/565,942
Granted
Sep 28, 2010
Kind
B2
Abstract

Described are computer-based methods and apparatuses, including computer program products, for scalable filtering and policing mechanism for protecting user traffic in a network. A data packet is filtered by a multi-tiered filtering and transmission system. Data packets matching the first tier filter are discarded. Data packets matching the second tier filter are transmitted to an output module based on a criterion. Data packets in the third tier filter are hashed into bins and data packets matching an entry in the bin are transmitted to the output module based on a criterion for the bin. Data packets in the fourth tier transmission system are transmitted to the output module based on a criterion. Data packets that do not meet the criterion for transmission to the output module are transmitted to an attack identification module which analyzes the data packets to identify attacks.

Claims (67)

1. A method of policing data on a network, the method comprising:

receiving a data packet at an index module of a computing device;

hashing, by the index module, the data packet using one or more fields in the data packet to generate a bin identification and a user signature;

processing, by the index module, the bin identification to associate the user signature with a first bin included in a plurality of bins;

comparing, at a bin module of the computing device, the user signature to zero or more stored user signatures associated with the first bin;

transmitting, by the bin module, the data packet to a transmission module of the computing device based on the comparing;

transmitting, by the transmission module, the data packet to an output module of the computing device based on a criterion, and

wherein, if a capacity of the first bin is exceeded, then the data packet is transmitted to the transmission module without comparing the user signature to the zero or more stored user signatures.

2. The method of claim 1 , wherein the one or more fields in the data packet is a port number, an Ethernet virtual local area network (VLAN) tag, meta-data about the data packet, a receiver interface, a source internet protocol (IP) address, an incoming logical IP address, a destination IP address, a source media access control (MAC) address, a destination MAC address, or combinations thereof.

3. The method of claim 1 , wherein the stored user signatures are modified by an admission control module.

4. The method of claim 3 , wherein the modification is an addition, a subtraction, an edit, or combinations thereof of the stored user signatures.

5. The method of claim 3 , wherein the admission control module processes a request for service from the input module.

6. The method of claim 3 , wherein the modification of the stored user signatures is predicated upon a successful authentication.

7. The method of claim 1 , wherein the criterion is rate control.

8. The method of claim 7 , wherein the rate control is a rate limit.

9. The method of claim 8 , wherein the rate limit dynamically adapts based on a number of stored user signatures in the first bin.

10. The method of claim 8 , wherein the rate limit is an amount of data over a set time.

11. The method of claim 8 , wherein the rate limit is a packet rate limit, a byte rate limit, a steady state rate limit, a burst limit, or combinations thereof.

12. The method of claim 1 wherein:

if the capacity of the first bin is not exceeded and the data packet is not associated with a user of a system, the probability of transmitting the data packet to the transmission module is low.

13. The method of claim 12 , wherein the one or more fields in the data packet is a port number, an Ethernet virtual local area network (VLAN) tag, meta-data about the data packet, a receiver interface, a source internet protocol (IP) address, an incoming logical IP address, a destination IP address, a source media access control (MAC) address, a destination MAC address, or combinations thereof.

14. The method of claim 12 , wherein the stored user signatures are modified by an admission control module.

15. The method of claim 14 , wherein the modification is an addition, a subtraction, an edit, or combinations thereof of the stored user signatures.

16. The method of claim 14 , wherein the admission control module processes a request for service from the input module.

17. The method of claim 14 , wherein the modification of the stored user signatures is predicated upon a successful authentication.

18. The method of claim 12 , wherein the criterion is rate control.

19. The method of claim 18 , wherein the rate control is a rate limit.

20. The method of claim 19 , wherein the rate limit dynamically adapts based on a number of stored user signatures in the first bin.

21. The method of claim 19 , wherein the rate limit is an amount of data over a set time.

22. The method of claim 19 , wherein the rate limit is a packet rate limit, a byte rate limit, a steady state rate limit, a burst limit, or combinations thereof.

23. A method of policing data on a network, the method comprising:

receiving a data packet from a first user at an index module of a computing device;

hashing, by the index module, the data packet using one or more fields in the data packet to generate a bin identification and a user signature, wherein the user signature for the first user is the same as the user signature for a second user;

processing, by the index module, the bin identification to associate the user signature with a first bin included in a plurality of bins;

comparing, at a bin module of the computing device, the user signature of the first user to zero or more stored user signatures associated with the first bin;

transmitting, by the bin module, the data packet to a transmission module of the computing device based on the comparing;

transmitting, by the transmission module, the data packet to an output module of the computing device based on a criterion;

wherein the criterion is rate control;

wherein the rate control is a rate limit; and

wherein the rate limit dynamically adapts based on a number of stored user signatures in the first bin.

24. The method of claim 23 , wherein the rate limit is an amount of data over a set of time.

25. The method of claim 23 , wherein the rate limit is a packet rate limit, a byte rate limit, a steady rate limit, a burst limit, or a combination thereof.

26. The method of claim 23 , wherein the one or more fields in the data packet is a port number, an Ethernet virtual local area network (VLAN) tag, meta-data about the data packet, a receiver interface, a source interne protocol (IP) address, an incoming logical IP address, a destination IP address, a source media access control (MAC) address, a destination MAC address, or combinations thereof.

27. The method of claim 23 , wherein the stored user signatures are modified by an admission control module.

28. The method of claim 27 , wherein the modification is an addition, a subtraction, an edit, or combinations thereof of the stored user signatures.

29. The method of claim 27 , wherein the admission control module processes a request for service from the input module.

30. The method of claim 27 , wherein the modification of the stored user signatures is predicated upon a successful authentication.

31. The method of claim 23 , wherein the first user is not a user of the system.

32. A system for policing data on a network, the system comprising a computing device comprising:

an index module configured and adapted to receive a data packet, hash the data packet to generate a bin identification and a user signature, and associate the bin identification of the data packet to a first bin included in a plurality of bins;

a bin module configured and adapted to compare the user signature to zero or more stored user signatures associated with the first bin;

a transmission module configured and adapted to transmit a matched data packet to an output module based on a criterion;

wherein, if a capacity of the first bin is exceeded, then the data packet is transmitted to the transmission module without comparing the user signature to the zero or more stored user signatures.

33. The system of claim 32 , wherein the one or more fields in the data packet is a port number, an Ethernet virtual local area network (VLAN) tag, meta-data about the data packet, a receiver interface, a source internet protocol (IP) address, an incoming logical IP address, a destination IP address, a source media access control (MAC) address, a destination MAC address, or combinations thereof.

34. The system of claim 32 , wherein the stored user signatures are modified by an admission control module.

35. The system of claim 32 , wherein the index module hashes part or all of the data packet.

36. The system of claim 32 wherein if the capacity of the first bin is not exceeded and the data packet is not associated with a user of the system, the probability of transmitting the data packet to the transmission module is low.

37. A system for policing data on a network, the system comprising a computing device comprising:

an index module configured and adapted to receive a data packet from a first user, hash the data packet to generate a bin identification and a user signature, wherein the user signature for the first user is the same as the user signature for a second user, and associate the bin identification of the data packet to a first bin included in a plurality of bins;

a bin module configured and adapted to compare the user signature of the first user to zero or more stored user signatures associated with the first bin;

a transmission module configured and adapted to transmit a matched data packet to an output module based on a criterion;

wherein the criterion is rate control;

wherein the rate control is a rate limit; and

wherein the rate limit dynamically adapts based on a number of stored user signatures in the first bin.

38. The system of claim 37 , wherein the rate limit is an amount of data over a set time.

39. The system of claim 37 , wherein the rate limit is a packet rate limit, a byte rate limit, a steady-state rate limit, a burst limit, or combinations thereof.

40. The system of claim 37 , wherein the first user is not a user of the system.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Jun 24, 2024
From: CITIZENS BANK, N.A.
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 067822/0433 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT R/F 044978/0801 Recorded Dec 6, 2021
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 058949/0497 →
SECURITY INTEREST Recorded Mar 3, 2020
From: RIBBON COMMUNICATIONS OPERATING COMPANY, INC.
To: CITIZENS BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 052076/0905 →
CHANGE OF NAME Recorded Jan 16, 2019
From: SONUS NETWORKS, INC.
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC.
Reel/Frame 048078/0036 →
SECURITY INTEREST Recorded Jan 2, 2018
From: GENBAND US LLC; SONUS NETWORKS, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 044978/0801 →
CHANGE OF NAME Recorded Dec 24, 2017
From: SONUS, INC.
To: SONUS NETWORKS, INC.
Reel/Frame 044957/0213 →
MERGER AND CHANGE OF NAME Recorded Dec 24, 2017
From: SOLSTICE SAPPHIRE, INC.; SONUS NETWORKS, INC.; SONUS NETWORKS, INC.
To: SONUS, INC.
Reel/Frame 044957/0243 →
RELEASE OF SECURITY INTEREST Recorded Oct 24, 2017
From: BANK OF AMERICA, N.A.
To: SONUS NETWORKS, INC.; SONUS FEDERAL, INC.; NETWORK EQUIPMENT TECHNOLOGIES, INC.; PERFORMANCE TECHNOLOGIES, INCORPORATED; SONUS INTERNATIONAL, INC.; TAQUA, INC.
Reel/Frame 044283/0361 →
SECURITY INTEREST Recorded Sep 12, 2014
From: SONUS NETWORKS, INC.; SONUS FEDERAL, INC.; NETWORK EQUIPMENT TECHNOLOGIES, INC.; PERFORMANCE TECHNOLOGIES, INCORPORATED; SONUS INTERNATIONAL, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033728/0409 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2007
From: YANG, JIAN; LI, SHIPING; DUFFY, MARK; BHARRAT, SHAUN JAIKARRAN
To: SONUS NETWORKS, INC.
Reel/Frame 018853/0384 →