IP Library Patent Application 14505119
Patent Application
App. No. 14/505,119

METHOD FOR DEFENDING AGAINST DENIAL-OF-SERVICE ATTACK ON THE IPV6 NEIGHBOR CACHE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/505,119
Abstract

A method of defending against a denial-of-service (DoS) attack on an IPv6 neighbor cache includes steps of determining a number of neighbor cache entries currently stored in the neighbor cache and then determining whether the number of entries exceeds a neighbor cache threshold that is less than a neighbor cache limit defining a maximum capacity of the neighbor cache. When the number of entries in the neighbor cache exceeds the neighbor cache threshold, stateless neighbor resolution is triggered. Stateless neighbor resolution entails sending a neighbor solicitation to resolve an address for an incoming packet without logging a corresponding entry in the neighbor cache. Additional techniques that complement the above method involve purging of neighbor cache entries designated as incomplete, prioritization of the entries based on trustworthiness, shortening the incomplete-status timer to less than 3 seconds, and curtailing the number of retransmissions of the neighbor solicitations.

Claims (31)

1 . A method of mitigating a denial-of-service attack against an IPv6 network node, the method comprising effecting a control procedure to prioritize Neighbor Discovery Protocol (NDP) activities.

2 . The method of claim 1 , further comprising:

monitoring a number of entries in a Neighbor Cache;

comparing the number of entries in the Neighbor Cache to a threshold; and

effecting the control procedure when the number of entries in the Neighbor Cache exceeds the threshold.

3 . The method of claim 1 , wherein effecting a control procedure to control NDP activities comprises prioritizing entries in a Neighbor Cache.

4 . The method of claim 3 , wherein prioritizing entries in the Neighbor Cache comprises preferentially prioritizing Neighbor Cache entries associated with trusted sources of packets.

5 . The method of claim 4 , further comprising deeming Neighbor Cache entries associated with router advertisements using Secure Neighbor Discovery (SEND).

6 . The method of claim 3 , wherein prioritizing entries in the Neighbor Cache comprises assigning a low priority to Neighbor Cache entries designated as incomplete.

7 . The method of claim 3 , further comprising replacing lower priority entries in the Neighbor Cache with newly generated higher priority entries.

8 . The method of claim 7 , further comprising replacing lower priority entries in the Neighbor Cache with newly generated higher priority entries only when the Neighbor Cache is full.

9 . The method of claim 3 , further comprising assigning priorities to Neighbor Cache entries based on Quality of Service (QoS) parameters associated with the Neighbor Cache entries.

10 . The method of claim 9 , wherein the QoS parameters are Differentiated Services Code Points (DSCPs).

11 . The method of claim 3 , wherein prioritizing entries in the Neighbor Cache comprises assigning a low priority to Neighbor Cache entries associated with addresses on a blacklist.

12 . The method of claim 3 , wherein prioritizing entries in the Neighbor Cache comprises assigning a low priority to Neighbor Cache entries associated with an address suspected of denial-of-service activity.

13 . The method of claim 3 , wherein prioritizing entries in the Neighbor Cache comprises assigning priorities to Neighbor Cache entries based on respective ages of the Neighbor Cache entries.

14 . The method of claim 3 , wherein prioritizing entries in the Neighbor Cache comprises preferentially prioritizing entries that can be verified by Upper Layer Protocol (ULP).

15 . The method of claim 3 , wherein prioritizing entries in the Neighbor Cache comprises preferentially prioritizing entries associated with a route's next hop addresses.

16 . The method of claim 3 , wherein prioritizing entries in the Neighbor Cache comprises preferentially prioritizing router flagged entries.

17 . The method of claim 3 , wherein prioritizing entries in the Neighbor Cache comprises assigning a low priority to Neighbor Cache entries designated as stale.

18 . The method of claim 3 , wherein prioritizing entries in the Neighbor Cache comprises assigning a low priority to Neighbor Cache entries designated as delay or probe entries.

19 . The method of claim 3 , wherein prioritizing entries in the Neighbor Cache comprises assigning a low priority to Neighbor Cache entries associated with unsolicited advertisements.

20 . The method of claim 3 , wherein prioritizing entries in the Neighbor Cache comprises assigning a low priority to Neighbor Cache entries for which an over-ride flag was set.

21 . A method of mitigating a denial-of-service attack against an IPv6 network node, the method comprising:

detecting an indication of heavy Neighbor Discover Protocol (NDP) activity;

and responsive to detection of heavy NDP activity, modifying neighbor solicitation activity to reduce an impact of the heavy NDP activity on NDP operations.

22 . The method of claim 21 , wherein detecting an indication of heavy NDP activity comprises:

monitoring a number of entries in a Neighbor Cache;

comparing the number of entries in the Neighbor Cache to a threshold; and

determining that heavy NDP activity has been detected when the number of entries in the Neighbor Cache exceeds the threshold.

23 . The method of claim 21 , wherein modifying neighbor solicitation activity to reduce the impact of the heavy NDP activity on NDP operations comprises transmitting neighbor solicitation messages without making corresponding entries in a Neighbor Cache.

Assignments (3)
RELEASE (REEL 038041 / FRAME 0001) Recorded Jan 2, 2018
From: JPMORGAN CHASE BANK, N.A.
To: RPX CORPORATION; RPX CLEARINGHOUSE LLC
Reel/Frame 044970/0030 →
SECURITY AGREEMENT Recorded Mar 9, 2016
From: RPX CORPORATION; RPX CLEARINGHOUSE LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 038041/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2015
From: ROCKSTAR CONSORTIUM US LP; ROCKSTAR CONSORTIUM LLC; BOCKSTAR TECHNOLOGIES LLC; CONSTELLATION TECHNOLOGIES LLC; MOBILESTAR TECHNOLOGIES LLC; NETSTAR TECHNOLOGIES LLC
To: RPX CLEARINGHOUSE LLC
Reel/Frame 034924/0779 →