IP Library Patent Application 14161391
Patent Application
App. No. 14/161,391

NETWORK CONTROL SOFTWARE NOTIFICATION WITH DENIAL OF SERVICE PROTECTION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/161,391
Abstract

Techniques are disclosed for notifying network control software of new and moved source MAC addresses. In one embodiment, a switch may redirect a packet sent by a new or migrated virtual machine to the network control software as a notification. The switch does not forward the packet, thereby protecting against denial of service attacks. The switch further adds to a forwarding database a temporary entry which includes a “No_Redirect” flag for a new source MAC address, or updates an existing entry for a source MAC address that hits in the forwarding database by setting the “No_Redirect” flag. The “No_Redirect” flag indicates whether a notification has already been sent to the network control software for this source MAC address. The switch may periodically retry the notification to the network control software, until the network control software validates the source MAC address, depending on whether the “No_Redirect” is set.

Claims (26)

1 - 8 . (canceled)

9 . One or more non-transitory computer-readable storage media storing instructions, which when executed by a client device and a server system, performs operations for notifying network control software of new and moved source media access control (MAC) addresses, comprising:

receiving, by a switch device, a first packet;

if the first packet includes a new source MAC address, inserting into a forwarding database a temporary entry which includes the source MAC address and a flag which is set to indicate that the network control software has been notified;

if the first packet includes a moved source MAC address, updating an existing entry in the forwarding database which includes the source MAC address by setting the flag for the entry; and

forwarding the first packet towards the network control software.

10 . The non-transitory computer-readable storage media of claim 9 , wherein the first packet is not forwarded towards a port associated with the target MAC address included in the first packet.

11 . The non-transitory computer-readable storage media of claim 9 , wherein the temporary entry includes a field indicating the temporary status of the entry and wherein the temporary entry does not include routing information.

12 . The non-transitory computer-readable storage media of claim 9 , wherein the flag is periodically reset by an aging function which walks the forwarding database.

13 . The non-transitory computer-readable storage media of claim 9 , the operations further comprising:

determining that a second packet has a source MAC address that matches the temporary entry or the existing entry; and

redirecting the received second packet to the network control software if the flag is reset for the temporary entry or the existing entry.

14 . The non-transitory computer-readable storage media of claim 9 , the operations further comprising, adding, by the network control software, an access control list (ACL) rule to block or discard packets received from the source MAC address of the first packet if the network control software does not validate the source MAC address.

15 . The non-transitory computer-readable storage media of claim 9 , the operations further comprising, inserting into the forwarding database, by the network control software, an entry which includes routing information for the first packet and resetting the flag if the network control software validates the source MAC address.

16 . The non-transitory computer-readable storage media of claim 9 , wherein the first packet was transmitted by a new virtual machine or a moved virtual machine.

17 . A system, comprising:

a client device, having a processor and memory, configured to execute a program for notifying network control software of new and moved source media access control (MAC) addresses, by performing operations comprising:

receiving a first packet,

if the first packet includes a new source MAC address, inserting into a forwarding database a temporary entry which includes the source MAC address and a flag which is set to indicate that the network control software has been notified,

if the first packet includes a moved source MAC address, updating an existing entry in the forwarding database which includes the source MAC address by setting the flag for the entry, and

forwarding the first packet towards the network control software.

18 . The system of claim 17 , wherein the temporary entry includes a field indicating the temporary status of the entry and wherein the temporary entry does not include routing information.

19 . The system of claim 17 , wherein the flag is periodically reset by an aging function which walks the forwarding database.

20 . The system of claim 17 , the operations further comprising:

determining that a second packet has a source MAC address that matches the temporary entry or the existing entry; and

redirecting the received second packet to the network control software if the flag is reset for the temporary entry or the existing entry.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2014
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE. LTD.
Reel/Frame 034194/0353 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2014
From: BASSO, CLAUDE; CORS, JOSEP; JANAKIRAMAN, VENKATESH K.; LAO, SZE-WA; SHAH, SAMEER M.; SHEDIVY, DAVID A.; SPIEGEL, ETHAN M.; VAIDHYANATHAN, NATARAJAN; VERRILLI, COLIN B.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 032022/0470 →