IP Library Granted Patent US 8,537,672
Granted Patent B2
US 8,537,672 · App. 13/041,618 · Granted Sep 17, 2013

Early traffic regulation techniques to protect against network flooding

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,537,672
App. No.
13/041,618
Granted
Sep 17, 2013
Kind
B2
Abstract

Methods and apparatus for providing an Anti-Flooding Flow-Control (AFFC) mechanism suitable for use in defending against flooding network Denial-of-Service (N-DoS) attacks is described. Features of the AFFC mechanism include (1) traffic baseline generation, (2) dynamic buffer management, (3) packet scheduling, and (4) optional early traffic regulation. Baseline statistics on the flow rates for flows of data corresponding to different classes of packets are generated. When a router senses congestion, it activates the AFFC mechanism of the present invention. Traffic flows are classified. Elastic traffic is examined to determine if it is responsive to flow control signals. Flows of non-responsive elastic traffic is dropped. The remaining flows are compared to corresponding class baseline flow rates. Flows exceeding the baseline flow rates are subject to forced flow rate reductions, e.g., dropping of packets.

Claims (20)

1. A method comprising:

detecting potential congestion at a given node in a network;

sending a request message from the given node to a destination node to which the given node is sending one or more packets associated with the destination node, wherein said one or more packets are causing the potential congestion at the given node;

conducting a back tracing operation at the destination node to determine a data flow path causing potential congestion at the given node, wherein the destination node reconstructs the data flow path based on previously retrieved data; and

sending data, from the destination node to the given node, the data comprising the reconstructed flow path information associated with packets causing potential congestion at the given node, wherein the data is sent in response to the request message from the given node.

2. The method of claim 1 further comprising sending a control message, from the given network node to an upstream network node, the control message including information for initiating flow control of the packets causing potential congestion at the given node.

3. The method of claim 2 wherein the network node is one of a router, switch and end host.

4. The method of claim 2 further comprising implementing, at the upstream network node, flow rate control of packets directed to the destination node.

5. The method of claim 4 wherein the flow rate control comprises one of blocking packets, limiting packets, and dropping packets directed to the destination node.

6. The method of claim 4 further comprising sending another message, to the upstream node from the given node, in response to the given node no longer detecting potential congestion at the given node.

7. A system comprising:

a first network node configured to:

detect congestion at the first network node;

send a request message to a destination network node communicatively coupled to the first network node, the request message causing the destination network node to determine the path of at least one packet flow causing congestion at the first network node; and

transmit a traffic regulation signal from the first network node to a second network node communicatively coupled to the first network node in response to receiving, from the destination network node, path information associated with the packet flow causing congestion at the first network node, wherein the second network node is upstream to the first network node and the traffic regulation signal causes the second network node to regulate traffic directed to the destination node, wherein the destination node is configured to reconstruct packet flow paths based on previously retrieved data and transmit, to the first network node, information associated with the reconstructed packet flow paths in response to receiving the request message.

8. The system of claim 7 wherein the traffic regulation signal comprises a destination address associated with at least one packet flow causing congestion at the first network node.

9. The system of claim 7 wherein the second network node is configured to control the flow rate of packets directed to the destination node by one of blocking packets, limiting packets, and dropping packets directed to the destination node.

10. The system of clam 7 wherein the first network node detects congestion by comparing incoming traffic with a baseline.

11. The system of claim 10 wherein the first network node is further configured to generate the baseline by analyzing the traffic flowing through the first network node over a period of time.

12. The system of claim 10 wherein the first network node is further configured to receive the baseline from an external source.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2014
From: HOME RUN PATENTS LLC
To: PALO ALTO NETWORKS, INC.
Reel/Frame 033556/0655 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2013
From: VERIZON PATENT AND LICENSING INC.
To: HOME RUN PATENTS LLC
Reel/Frame 030507/0961 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2013
From: VERIZON SERVICES CORP.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 030121/0051 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2013
From: YE, BAOQING
To: VERIZON SERVICES CORP.
Reel/Frame 030125/0165 →