IP Library Granted Patent US 10,320,839
Granted Patent B2
US 10,320,839 · App. 15/708,504 · Granted Jun 11, 2019

Automatic anti-spoof for multicast routing

Inventors: Ville Mattila (Helsinki, FI); Tomi Salminen (Helsinki, FI); Tuomo Syvänne (Helsinki, FI)
Assignee: Forcepoint, LLC
H04L63/1466H04L47/20H04L61/2007H04L63/0227H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,320,839
App. No.
15/708,504
Granted
Jun 11, 2019
Kind
B2
Abstract

A method, system and computer-usable medium are disclosed for performing an automated anti-spoofing configuration operation, comprising: determining whether a source address of an internet protocol (IP) packet is allowed by a receiving interface of a firewall; determining whether the IP packet comprises a multicast packet when the IP packet is allowed by the receiving interface of the firewall; replacing the source address with a rendezvous point address; using the rendezvous point address to determine whether routing path information associated with the multicast packet matches information stored within a multicast routing information base for the receiving interface of the firewall; and, identifying the multicast packet as spoofed when the routing path information associated with multicast packet does not have corresponding information stored within the multicast routing information base.

Claims (58)

1. A computer-implementable method for performing an automated anti-spoofing configuration operation, comprising:

determining whether a source address of an internet protocol (IP) packet is allowed by a receiving interface of a firewall;

determining whether the IP packet comprises a multicast packet when the IP packet is allowed by the receiving interface of the firewall;

replacing the source address with a rendezvous point address;

using the rendezvous point address to determine whether routing path information associated with the multicast packet matches information stored within a multicast routing information base for the receiving interface of the firewall; and,

identifying the multicast packet as spoofed when the routing path information associated with the multicast packet does not have corresponding information stored within the multicast routing information base;

comparing the rendezvous point address of the multicast packet with a rendezvous point address for any active multicast joins to determine whether the rendezvous point address of the multicast packet has an associated active multi cast join; and,

identifying the multicast packet as spoofed when the rendezvous point address does not have an associated active multicast join.

2. The method of claim 1 , wherein:

the receiving interface of the firewall comprises a network interface.

3. The method of claim 1 , wherein:

the active multicast join comprises a recipient network address associated with a rendezvous address designated as a destination of a group of multicast packets associated with a particular multicast session.

4. The method of claim 1 , further comprising:

determining whether logging of the multicast packet is required; and,

logging information relating to the multicast packet when logging of the multicast packet is required.

5. The method of claim 1 , further comprising:

determining whether the multicast packet is received by a Protocol independent Multicast (PIM) enabled interface of a firewall when the IP packet comprises the multicast packet.

6. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

determining whether a source address of an internet protocol (IP) packet is allowed by a receiving interface of a firewall;

determining whether the IP packet comprises a multicast packet when the IP packet is allowed by the receiving interface of the firewall;

replacing the source address with a rendezvous point address;

using the rendezvous point address to determine whether routing path information associated with the multicast packet matches information stored within a multicast routing information base for the receiving interface of the firewall; and,

identifying the multicast packet as spoofed when the routing path information associated with the multicast packet does not have corresponding information stored within the multicast routing information base;

comparing the rendezvous point address of the multicast packet with a rendezvous point address for any active multicast joins to determine whether the rendezvous point address of the multicast packet has an associated active multicast join; and,

identifying the multicast packet as spoofed when the rendezvous point address does not have an associated active multicast join.

7. The system of claim 6 , wherein:

the receiving interface of the firewall comprises a network interface.

8. The system of claim 6 , wherein:

the active multicast join comprises a recipient network address associated with a rendezvous address designated as a destination of a group of multicast packets associated with a particular multicast session.

9. The system of claim 6 , wherein the instructions executable by the processor are further configured for:

determining whether logging of the multicast packet is required; and,

logging information relating to the multicast packet when logging of the multicast packet is required.

10. The system of claim 6 , wherein the instructions executable by the processor are further configured for:

determining whether the multicast packet is received by a Protocol independent Multicast (PIM) enabled interface of a firewall when the IP packet comprises the multicast packet.

11. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

determining whether a source address of an internet protocol (IP) packet is allowed by a receiving interface of a firewall;

determining whether the IP packet comprises a multicast packet when the IP packet is allowed by the receiving interface of the firewall;

replacing the source address with a rendezvous point address;

using the rendezvous point address to determine whether routing path information associated with the multicast packet matches information stored within a multicast routing information base for the receiving interface of the firewall; and,

identifying the multicast packet as spoofed when the routing path information associated with the multicast packet does not have corresponding information stored within the multicast routing information base;

comparing the rendezvous point address of the multicast packet with a rendezvous point address for any active multicast joins to determine whether the rendezvous point address of the multicast packet has an associated active multicast join; and,

identifying the multicast packet as spoofed when the rendezvous point address does not have an associated active multicast join.

12. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the receiving interface of the firewall comprises a network interface.

13. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the active multicast join comprises a recipient network address associated with a rendezvous address designated as a destination of a group of multicast packets associated with a particular multicast session.

14. The non-transitory, computer-readable storage medium of claim 11 , wherein the computer executable instructions are further configured for:

determining whether logging of the multicast packet is required; and,

logging information relating to the multicast packet when logging of the multicast packet is required.

15. The non-transitory, computer-readable storage medium of claim 11 , wherein the computer executable instructions are further configured for:

determining whether the multicast packet is received by a Protocol Independent Multicast (PIM) enabled interface of a firewall when the IP packet comprises the multicast packet.

16. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

17. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055492/0266 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Jul 6, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 046495/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2017
From: MATTILA, VILLE; SALMINEN, TOMI; SYVÄNNE, TUOMO
To: FORCEPOINT, LLC
Reel/Frame 043623/0465 →
Continuity (1)
Related Publication 20190089735A1 · Mar 21, 2019