IP Library › Granted Patent US 11,277,441
Granted Patent B2
US 11,277,441 · App. 16/839,666 · Granted Mar 15, 2022

Infrastructure distributed denial of service protection

Inventors: Dvir Shapira (Sunnyvale, CA); Ehud Cohen (Kfar Saba, IL); Tomer Bronshtein (Ashdod, IL); Eyal Leshem (Jerusalem, IL); Alon Ludmer (Kfar Saba, IL)
Assignee: IMPERVA, INC.
H04L63/1458H04L63/029H04L63/0236H04L63/10H04L63/1408H04L45/12H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,277,441
App. No.
16/839,666
Granted
Mar 15, 2022
Kind
B2
Abstract

A method of providing infrastructure protection for a server of a network organization, the method including announcing an IP address range associated with the network organization using a border gateway protocol on an edge router of a scrubbing center associated with the network organization. The method further including receiving an incoming network packet intended for a server of the network organization identified using a public IP address within the IP address range, the public IP address serving as a first anycast address for a plurality of scrubbing centers in a distributed network of scrubbing servers, the plurality of scrubbing centers including the scrubbing center. The method further including determining, by the scrubbing center, whether the incoming network packet is legitimate. The method further including, responsive to determining that the incoming network packet is legitimate, routing, by a processor, the incoming network packet to the server at a private IP address.

Claims (53)

1. A method of providing infrastructure protection for a server of a network organization comprising a plurality of servers, the method comprising:

announcing as an internet protocol (IP) address associated with the server, a public IP address allocated to the server by a scrubbing center network that maintains a plurality of public IP addresses, the public IP address serving as a first anycast address for the scrubbing center network and dedicated to the server, wherein the public IP address is announced using a border gateway protocol (BGP) on an edge router of the scrubbing center network, and wherein each of the plurality of public IP addresses is dedicated to a respective server of the plurality of servers;

receiving, at a scrubbing center of the scrubbing center network, an incoming network packet intended for the server of the network organization identified using the public IP address;

determining, by the scrubbing center, whether the incoming network packet is legitimate; and

responsive to determining that the incoming network packet is legitimate:

modifying a header of the incoming network packet to indicate a spoofed IP address as a source IP address of the network packet the spoofed IP address dedicated to the server; and

routing, by a processor, the incoming network packet to the server at a private IP address, wherein the spoofed IP address serves as a second anycast address for the scrubbing center network.

2. The method of claim 1 , wherein a mapping of the public IP address to the private IP address is maintained between the scrubbing center network and the server.

3. The method of claim 2 , further comprising:

receiving an encapsulated outgoing network packet from the server, wherein the encapsulated outgoing network packet is an outgoing network packet which has been encapsulated by the server with header information comprising the spoofed IP address as a destination address;

decapsulating the outgoing network packet to generate a decapuslated outgoing network packet by removing the encapsulation added by the server that includes the header information; and

transmitting the decapsulated outgoing network packet to the end user.

4. The method of claim 3 , wherein the decapsulating is performed by the processor at a scrubbing center nearest the server.

5. The method of claim 3 , wherein the received encapsulated outgoing network packet is received at a network organization and routed external to the server.

6. The method of claim 1 , wherein the IP address is announced by a scrubbing center of the scrubbing center network that is nearest to an end user.

7. The method of claim 6 , wherein the scrubbing center nearest the end user comprises one selected from the group consisting of geographically closest, lowest cost, healthiest, with the least congested route, and another distance measure.

8. The method of claim 1 , wherein the routing is executed using generic routing encapsulation.

9. An apparatus, comprising:

a memory to store an incoming network packet directed to a server of a network organization comprising a plurality of servers; and

a processor, operatively coupled to the memory, to:

announce as an Internet protocol (IP) address associated with the server, a public IP address allocated to the server by a scrubbing center network that maintains a plurality of IP addresses, the public IP address serving as a first anycast address for the scrubbing center network and dedicated to the server, wherein the public IP address is announced using a border gateway protocol (BGP) on an edge router of the scrubbing center network, and wherein each of the plurality of public IP addresses is dedicated to a respective server of the plurality of servers;

receive, at a scrubbing center of the scrubbing center network, the incoming network packet intended for the server of the network organization identified using the public IP address;

determine, by the scrubbing center, whether the incoming network packet is legitimate; and

responsive to determining that the incoming network packet is legitimate:

modifying a header of the incoming network packet to indicate a spoofed IP address as a source IP address of the network packet the spoofed IP address dedicated to the server; and

route the incoming network packet to the server at a private IP address, wherein the spoofed IP address serves as a second anycast address for the scrubbing center network.

10. The apparatus of claim 9 , wherein a mapping of the public IP address to the private IP address is maintained between the scrubbing center network and the server.

11. The apparatus of claim 10 , the processor further to:

receive an encapsulated outgoing network packet from the server, wherein the encapsulated outgoing network packet is an outgoing network packet which has been encapsulated by the server with header information comprising the spoofed IP address as a destination address;

decapsulate the outgoing network packet to generate a decapuslated outgoing network packet by removing the encapsulation added by the server that includes the header information; and

transmit the decapsulated outgoing network packet to the end user.

12. The apparatus of claim 11 , wherein the decapsulating is performed by the processor at a scrubbing center nearest the server.

13. The apparatus of claim 11 , the processor further to receive the encapsulated outgoing network packet at a network organization and route the encapsulate outgoing network packet external to the server.

14. The apparatus of claim 9 , wherein the IP address is announced by a scrubbing center of the scrubbing center network that is nearest to an end user.

15. The apparatus of claim 14 , wherein the scrubbing center nearest the end user comprises one selected from the group consisting of geographically closest, lowest cost, healthiest, with the least congested route, and another distance measure.

16. The apparatus of claim 9 , wherein the processor is further to route the incoming network packet using generic routing encapsulation.

17. A non-transitory computer readable storage medium having instructions encoded thereon that, when executed by a processor, cause the processor to:

announce as an internet protocol (IP) address associated with the server, a public IP address allocated to the server by a scrubbing center network that maintains a plurality of IP addresses, the public IP address serving as a first anycast address for the scrubbing center network and dedicated to the server, wherein the public IP address is announced using a border gateway protocol (BGP) on an edge router of the scrubbing center network, and wherein the server is one of a plurality of servers in a network organization and each of the plurality of public IP addresses is dedicated to a respective server of the plurality of servers;

receive, at a scrubbing center of the scrubbing center network, an incoming network packet intended for the server of the network organization identified using the public IP address;

determine, by the scrubbing center, whether the incoming network packet is legitimate; and

responsive to determining that the incoming network packet is legitimate:

modifying a header of the incoming network packet to indicate a spoofed IP address as a source IP address of the network packet the spoofed IP address dedicated to the server; and

route, by the processor, the incoming network packet to the server at a private IP address, wherein the spoofed IP address serves as a second anycast address for the scrubbing center network.

18. The non-transitory computer readable storage medium of claim 17 , wherein a mapping of the public IP address to the private IP address is maintained between the scrubbing center network and the server.

19. The non-transitory computer readable storage medium of claim 18 , the processor further to:

receive an encapsulated outgoing network packet from the server, wherein the encapsulated outgoing network packet is an outgoing network packet which has been encapsulated by the server with header information comprising the spoofed IP address as a destination address;

decapsulate the outgoing network packet to generate a decapuslated outgoing network packet by removing the encapsulation added by the server that includes the header information; and

transmit the decapsulated outgoing network packet to the end user.

20. The non-transitory computer readable storage medium of claim 19 , wherein the decapsulating is performed by the processor at a scrubbing center nearest the server.

21. The non-transitory computer readable storage medium of claim 19 , the processor further to receive the encapsulated outgoing network packet at a network organization and route the encapsulate outgoing network packet external to the server.

22. The non-transitory computer readable storage medium of claim 17 , wherein the IP address is announced by a scrubbing center of the scrubbing center network that is nearest to an end user.

23. The non-transitory computer readable storage medium of claim 22 , wherein the scrubbing center nearest the end user comprises one selected from the group consisting of geographically closest, lowest cost, healthiest, with the least congested route, and another distance measure.

24. The non-transitory computer readable storage medium of claim 17 , wherein the processor is further to route the incoming network packet using generic routing encapsulation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2020
From: SHAPIRA, DVIR; COHEN, EHUD; BRONSHTEIN, TOMER; LESHEM, EYAL; LUDMER, ALON
To: IMPERVA, INC.
Reel/Frame 052352/0497 →
Continuity (4)
Continuation 16749883 · Jan 22, 2020
Continuation 15628620 · Jun 20, 2017
Provisional Application 62353021 · Jun 21, 2016
Related Publication 20200236136A1 · Jul 23, 2020