IP Library Granted Patent US 10,129,125
Granted Patent B2
US 10,129,125 · App. 14/974,756 · Granted Nov 13, 2018

Identifying a source device in a software-defined network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,129,125
App. No.
14/974,756
Granted
Nov 13, 2018
Kind
B2
Abstract

In an example, there is disclosed a computing apparatus, having: a network interface to communicatively couple to a software-defined network (SDN); first one or more logic elements providing an SDN controller engine to provide a control function for the SDN; and second one or more logic elements providing a route tracing engine to: receive a tunneling notification from a network device agent, the tunneling notification associated with a network flow; and perform a backtracking traceroute operation to deterministically identify a source device for the flow. There is also disclosed a method of providing the foregoing, and one or more tangible, non-transitory computer-readable storage mediums for providing the foregoing.

Claims (57)

1. A computing apparatus, comprising:

a network interface to communicatively couple to an overlay network of a software-defined network (SDN);

first one or more logic elements comprising an SDN controller engine to provide a control function for the SDN; and

second one or more logic elements comprising a route tracing engine to:

receive a tunneling notification from a network device agent, the tunneling notification associated with a network flow; and

perform a backtracking traceroute operation to deterministically identify a source device for the network flow, wherein performing a backtracking traceroute comprises iteratively backtracking through a plurality of source virtual tunneling endpoints (VTEPs), comprising:

querying a first virtual tunneling endpoint (VTEP);

determining that the first VTEP is a security function container (SFC);

querying the SFC for its source VTEP for the network flow;

querying a second VTEP;

determining that the second VTEP is a network device (ND); and

designating the ND as a source device for the network flow.

2. The computing apparatus of claim 1 , wherein the backtracking traceroute operation is further to deterministically determine a path for the network flow.

3. The computing apparatus of claim 1 , wherein the SDN controller engine is further to identify a malicious or potentially malicious packet within the network flow, and to block the network flow at the source network device.

4. The computing apparatus of claim 1 , wherein the SDN controller engine is further to receive a route tracing request from a device via the network interface, and to provide via the network interface information regarding at least one security device that the network flow is to pass through.

5. The computing apparatus of claim 1 , wherein the route tracing engine is further configured to provide flow tags to enable tracking of source/destination and intermediate switches of the network flow.

6. The computing apparatus of claim 5 , wherein the SDN controller engine is to provide a reactive SDN network.

7. The computing apparatus of claim 1 , wherein the SDN controller engine is configured to provide an overlay network lacking explicit per-flow entries.

8. The computing apparatus of claim 7 , wherein the route tracing engine is further configured to insert an NFV service header (NSH) between a tunnel header and an original packet of the network flow.

9. The computing apparatus of claim 8 , wherein the NSH comprises information on a sequence of NFVs that the network flow is to traverse.

10. The computing apparatus of claim 8 , wherein the NSH comprises information sufficient to enable an NFV to determine a next-hop NVF for a packet of the network flow.

11. One or more tangible, non-transitory computer-readable storage mediums having stored thereon executable instructions to:

communicatively couple to an overlay network of a software-defined network (SDN) via a network interface;

provide an SDN controller engine to provide a control function for the SDN; and

provide a route tracing engine to:

receive a tunneling notification from a network device agent, the tunneling notification associated with a network flow; and

perform a backtracking traceroute operation to deterministically identify a source device for the network flow, wherein performing a backtracking traceroute comprises iteratively backtracking through a plurality of source virtual tunneling endpoints (VTEPs), comprising:

querying a first virtual tunneling endpoint (VTEP);

determining that the first VTEP is a security function container (SFC); and

querying the SFC for its source VTEP for the network flow;

querying a second VTEP;

determining that the second VTEP is a network device (ND); and

designating the ND as a source device for the network flow.

12. The one or more tangible, non-transitory computer-readable mediums of claim 11 , wherein the backtracking traceroute operation is further to deterministically determine a path for the network flow.

13. The one or more tangible, non-transitory computer-readable mediums of claim 11 , wherein the SDN controller engine is further to identify a malicious or potentially malicious packet within the network flow, and to block the network flow at the source network device.

14. The one or more tangible, non-transitory computer-readable mediums of claim 11 , wherein the SDN controller engine is further to receive a route tracing request from a device via the network interface, and to provide via the network interface information regarding at least one security device that the network flow is to pass through.

15. The one or more tangible, non-transitory computer-readable mediums of claim 11 , wherein the route tracing engine is further configured to provide flow tags to enable tracking of source/destination and intermediate switches of the network flow.

16. The one or more tangible, non-transitory computer-readable mediums of claim 15 , wherein the SDN controller engine is to provide a reactive SDN network.

17. The one or more tangible, non-transitory computer-readable mediums of claim 11 , wherein the SDN controller engine is configured to provide an overlay network lacking explicit per-flow entries.

18. The one or more tangible, non-transitory computer-readable mediums of claim 17 , wherein the route tracing engine is further configured to insert an NFV service header (NSH) between a tunnel header and an original packet of the network flow.

19. The one or more tangible, non-transitory computer-readable mediums of claim 18 , wherein the NSH comprises information on a sequence of NFVs that the network flow is to traverse.

20. The one or more tangible, non-transitory computer-readable mediums of claim 18 , wherein the NSH comprises information sufficient to enable an NFV to determine a next-hop NVF for a packet of the network flow.

21. A computer-implemented method, comprising:

communicatively coupling to an overlay network of a software-defined network (SDN) via a network interface;

providing an SDN controller engine to provide a control function for the SDN; and

providing a route tracing engine to:

receive a tunneling notification from a network device agent, the tunneling notification associated with a network flow; and

perform a backtracking traceroute operation to deterministically identify a source device for the network flow, wherein performing a backtracking traceroute comprises iteratively backtracking through a plurality of source virtual tunneling endpoints (VTEPs), comprising:

querying a first virtual tunneling endpoint (VTEP);

determining that the first VTEP is a security function container (SFC); and

querying the SFC for its source VTEP for the network flow;

querying a second VTEP;

determining that the second VTEP is a network device (ND); and

designating the ND as a source device for the network flow.

22. The method of claim 21 , wherein the backtracking traceroute operation is further to deterministically determine a path for the network flow.

23. The method of claim 21 , wherein the SDN controller engine is further to identify a malicious or potentially malicious packet within the network flow, and to block the network flow at the source network device.

24. The method of claim 21 , wherein the SDN controller engine is further to receive a route tracing request from a device via the network interface, and to provide via the network interface information regarding at least one security device that the network flow is to pass through.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2016
From: AGRAWAL, GOPAL; MULKA, SHIVAKRISHNA ANANDAM
To: MCAFEE, INC.
Reel/Frame 038092/0977 →