IP Library Granted Patent US 8,320,372
Granted Patent B2
US 8,320,372 · App. 12/143,914 · Granted Nov 27, 2012

Processing of packet fragments

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,320,372
App. No.
12/143,914
Granted
Nov 27, 2012
Kind
B2
Abstract

In one embodiment, the present invention is a technique for processing fragments received at a node (e.g., a router) in a datagram-based communication system in order to provide a wide range of protection against potential fragment-based attacks. Received fragments are examined as they are received to verify that they do not overlap one another and that the fragment sequence does not exploit common weaknesses in IP packet-reassembly algorithms. Valid fragment sequences that represent potential threats to the receiver can be reordered and/or fully or partially re-assembled and re-fragmented into a fragment sequence that eliminates or reduces the threat to the receiver. Fragmented sequences that represent a likely attack are blocked, as are subsequent fragments of the associated packet.

Claims (84)

1. A method for processing fragments received at a node in a communication system, the method comprising:

(a) receiving a group of one or more fragments in a received sequence, wherein:

(i) the group of one or more fragments corresponds to a packet that was fragmented into a set of fragments having an offset order corresponding to increasing fragment offset values;

(ii) the set of fragments comprises an offset-0 fragment and one or more additional fragments;

(iii) the offset-0 fragment is the first fragment in the offset order of the set of fragments; and

(iv) the group comprises at least one additional fragment that is received before the offset-0 fragment;

(b) buffering the group of one or more fragments;

(c) analyzing a rule set to match a rule for the buffered group; and

(d) applying the matched rule to the buffered group to (i) determine whether the buffered group is to be re-transmitted and (ii) if the buffered group is to be re-transmitted, determine how to re-transmit the buffered group, wherein the rule set comprises:

(A) a first rule stipulating that received fragments corresponding to a single packet are re-transmitted in the received sequence in which the received fragments were received independent of whether at least one additional fragment is received before the offset-0 fragment, such that, when the first rule is applied to the buffered group, the offset-0 fragment is not the first fragment of the buffered group to be re-transmitted; and

(B) a second rule stipulating that received fragments corresponding to a single packet are re-transmitted in sequence by the offset order of the set of fragments, such that, when the second rule is applied to the buffered group, the offset-0 fragment is the first fragment of the buffered group to be re-transmitted.

2. The method of claim 1 , wherein the set of fragments comprises one or more fragments that are not part of the group of one or more fragments.

3. A method for processing fragments received at a node in a communication system, the method comprising:

(a) receiving a group of one or more fragments, wherein:

the group of one or more fragments corresponds to a packet that was fragmented into a set of fragments having an offset order corresponding to increasing fragment offset values; and

the group of one or more fragments corresponds to a subset of the set of fragments;

(b) buffering the group of one or more fragments;

(c) re-transmitting the buffered group;

(d) receiving a further fragment of the set that is not contiguous with the group;

(e) buffering the further fragment;

(f) receiving, after steps (a)-(e), one or more other fragments that form, with the group of one or more fragments and the buffered further fragment, a single contiguous subset of fragments; and

(g) re-transmitting, after steps (a)-(f), the one or more other fragments and the buffered further fragment.

4. The method of claim 3 , wherein step (c) occurs prior to step (d).

5. The method of claim 3 , wherein:

step (d) occurs prior to step (c); and

the further fragment is not re-transmitted when step (c) is performed.

6. The method of claim 3 , wherein:

the one or more fragments are received out of the offset order and

step (c) comprises retransmitting the buffered group in offset order.

7. The method of claim 3 , wherein:

the buffered further fragment and the one or more other fragments are received out of the offset order; and

step (g) comprises re-transmitting the one or more other fragments and the buffered further fragment in offset order.

8. A method for processing fragments received at a node in a communication system, the method comprising:

(a) receiving groups of fragments, wherein:

(i) each group of fragments corresponds to a different packet that was fragmented into a set of fragments having an offset order corresponding to increasing fragment offset values;

(ii) each set of fragments comprises an offset-0 fragment and one or more additional fragments; and

(iii) the offset-0 fragment is the first fragment in the offset order of the set of fragments;

(b) buffering the groups of fragments;

(c) analyzing a rule set to match a rule for each buffered group; and

(d) applying, to each buffered group, the corresponding matched rule to (i) determine whether the buffered group is to be re-transmitted and (ii) if the buffered group is to be re-transmitted, determine how to re-transmit the buffered group, wherein the rule set comprises:

(A) a first rule stipulating that received fragments corresponding to a single packet are to be at least partially reassembled prior to re-transmission; and

(B) a second rule stipulating that received fragments corresponding to a single packet are not to be reassembled prior to re-transmission.

9. The method of claim 8 , wherein:

the groups of fragments comprise a first group and a second group; and

step (c) matches (i) the first rule to the buffered first group and (ii) the second rule to the buffered second group, such that:

the buffered first group is at least partially reassembled prior to being re-transmitted; and

the buffered second group is not reassembled prior to being re-transmitted.

10. The method of claim 8 , wherein step (c) comprises determining the corresponding matched rule for each buffered group based on information in the offset-0 fragment.

11. The method of claim 8 , wherein the first rule comprises:

a first sub-rule stipulating that the reassembled fragments corresponding to the single packet are to be re-fragmented prior to re-transmission; and

a second sub-rule stipulating that the reassembled fragments corresponding to the single packet are not to be re-fragmented prior to re-transmission.

12. The method of claim 11 , wherein:

the groups of fragments comprise a first group and a third group; and

step (c) matches (i) the first rule and the first sub-rule to the buffered first group and (ii) the first rule and the second sub-rule to the buffered third group, such that:

the buffered first group is at least partially reassembled and then re-fragmented prior to being re-transmitted; and

the buffered third group is at least partially reassembled, but not then re-fragmented prior to being re-transmitted.

13. The method of claim 8 , wherein applying the first rule to a buffered group comprises reassembling at least two of the received fragments of the buffered group to produce at least a portion of the single packet in its intact, pre-fragmented form.

14. A method for processing fragments received at a node in a communication system, the method comprising:

(a) receiving a set of fragments in a received sequence, wherein:

(i) the set of fragments corresponds to a packet that was fragmented into the set of fragments having an offset order corresponding to increasing fragment offset values;

(ii) the set of fragments comprises an offset-0 fragment and one or more additional fragments;

(iii) the offset-0 fragment is the first fragment in the offset order of the set of fragments;

(iv) the set of fragments is received out of the offset order; and

(v) at least one of the additional fragments is received after the offset-0 fragment;

(b) buffering the set of fragments; and

(c) then re-transmitting the set of fragments as fragments in the offset order such that none of the fragments are re-transmitted until after all of the fragments in the set have been received and buffered.

15. A method for processing fragments received at a node in a communication system, the method comprising:

(a) receiving a first fragment, wherein:

(i) the first fragment corresponds to a packet that was fragmented into a set of fragments having an offset order corresponding to increasing fragment offset values;

(ii) the set of fragments comprises an offset-0 fragment and one or more additional fragments; and

(iii) the offset-0 fragment is the first fragment in the offset order of the set of fragments;

(b) analyzing a rule set to match a rule for the first fragment;

(c) applying the matched rule to process the first fragment;

(d) receiving a second fragment corresponding to the packet; and

(e) applying the matched rule to process the second fragment, wherein the processing of the second fragment is different from the processing of the first fragment.

16. The method of claim 15 , wherein the first fragment corresponding to the packet is re-transmitted and the second fragment corresponding to the packet is not re-transmitted.

17. The method of claim 15 , wherein the first fragment is re-transmitted in a first manner and the second fragment is re-transmitted in a second manner different from the first manner.

18. A method for processing fragments received at a node in a communication system, the method comprising:

(a) receiving a first group of one or more fragments, wherein the first group corresponds to a first packet that was fragmented into a first set of fragments;

(b) analyzing a rule set to match a first rule for the first group;

(c) applying the matched first rule to process the first group;

(d) receiving a second group of one or more fragments, wherein the second group corresponds to a second packet that is different from the first packet and was fragmented into a second set of fragments;

(e) analyzing the rule set to match a second rule for the second group; and

(f) applying the matched second rule to process the second group, wherein the first group is re-transmitted and the second group is not re-transmitted.

Assignments (15)
PATENT SECURITY AGREEMENT Recorded Aug 6, 2024
From: RPX CORPORATION; RPX CLEARINGHOUSE LLC
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 068328/0674 →
RELEASE OF LIEN ON PATENTS Recorded Aug 5, 2024
From: BARINGS FINANCE LLC
To: RPX CORPORATION
Reel/Frame 068328/0278 →
PATENT SECURITY AGREEMENT Recorded Apr 22, 2023
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 063429/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 9, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA INC.
Reel/Frame 033950/0261 →
SECURITY INTEREST Recorded Mar 7, 2013
From: ALCATEL-LUCENT USA INC.
To: CREDIT SUISSE AG
Reel/Frame 030510/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2012
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 028969/0703 →
MERGER Recorded Sep 11, 2012
From: LUCENT TECHNOLOGIES INC.
To: ALCATEL-LUCENT USA INC.
Reel/Frame 028935/0868 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2008
From: MENTEN, LAWRENCE E.
To: LUCENT TECHNOLOGIES INC.
Reel/Frame 021134/0304 →