IP Library Patent Application 12762366
Patent Application
App. No. 12/762,366

METHOD AND APPARATUS FOR TRACING PACKETS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/762,366
Abstract

A system and method for performing source path isolation in a network. The system comprises an intrusion detection system (IDS), a source path isolation server (SS 1 ) and at least one router configured to operate as a source path isolation router (SR 1 ) operating within an autonomous system. When IDS detects a malicious packet, a message is sent to SS 1. SS 1 in turn generates a query message (QM) containing at least a portion of the malicious packet. Then, QM is sent to participating routers located one hop away. SR 1 uses the query message to determine if it has observed the malicious packet by comparing it with locally stored information about packets having passed through SR 1. SR 1 sends a reply to SS 1, and SS 1 uses the reply to identify the ingress point into the network of the malicious packet.

Claims (33)

1 . A system for determining a point of entry of a malicious packet into a network using a representation of the malicious packet, the system comprising:

an intrusion detection system for detecting the malicious packet in the network; and

an isolation server responsive to operation of the intrusion detection system, for isolating the malicious packet;

wherein the system is operable such that the point of entry of the malicious packet is determined.

2 . The system of claim 1 and wherein the isolation server further comprises: computer code for generating a message containing identification information about the malicious packet.

3 . The system of claim 2 and wherein the isolation server further comprises: computer code for forwarding the message to certain of a plurality of routers displaced one hop away from the server.

4 . The system of claim 3 and wherein the certain of the plurality of routers comprises:

computer code for generating a hash value of the identification information;

computer code for establishing a bit map of hash values representative of those of packets which are transmitted through the certain of the plurality of routers; and

computer code for comparing the hash value against the hash values.

5 . A computer program product embodied on a computer readable medium for determining whether a target packet has been encountered in a network, comprising:

computer code for sending a message identifying the target packet to at least one network component;

computer code for receiving a reply containing information associated with the target packet from the at least one network component; and

computer code for processing the reply to extract the information; and

computer code for using the information, wherein the computer program product is operable such that it is determined whether the target packet has been encountered in the network.

6 . The computer program product of claim 5 and wherein a detection device is incorporated into a server including at least a portion of the computer code.

7 . The computer program product of claim 5 and wherein the network further includes a host, the host including capability for placing packets onto the network.

8 . The computer program product of claim 5 and wherein the computer code for sending operates to include the target packet into the message.

9 . The computer program product of claim 5 and wherein the message comprises a representation of the target packet.

10 . The computer program product of claim 9 and wherein the representation is a hash of at least a portion of the target packet.

11 . The computer program product of claim 5 and wherein the at least one network component is located one hop away from a server.

12 . The computer program product of claim 5 and wherein the at least one network component is located more than one hop away from a server.

13 . The computer program product of claim 5 and wherein a first component of the at least one network component forwards the reply to another of the at least one network component.

14 . The computer program product of claim 13 and wherein the first component is a router.

15 . The computer program product of claim 5 and wherein the information is hash information derived from hashing at least a portion of the message to obtain a query hash value.

16 . The computer program product of claim 5 and wherein the computer code for determining is accomplished using a source path isolation technique.

17 . The computer program product of claim 16 and wherein the source path isolation technique includes a breadth-first search.

18 . The computer program product of claim 16 and wherein the source path isolation technique includes a depth-first search.

19 . A method for determining whether a target packet has been encountered in a network, comprising:

sending a message identifying the target packet to at least one network component;

receiving a reply containing information associated with the target packet from the at least one network component; and

processing the reply to extract the information; and

using the information, wherein it is determined whether the target packet has been encountered in the network.