IP Library Granted Patent US 11,509,684
Granted Patent B2
US 11,509,684 · App. 17/469,956 · Granted Nov 22, 2022

Method and apparatus for out of path border gateway protocol validation

Inventor: Jody Beck (Parker, CO)
Assignee: Charter Communications Operating, LLC
H04L63/1441H04L63/0263H04L63/105H04L63/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,509,684
App. No.
17/469,956
Granted
Nov 22, 2022
Kind
B2
Abstract

Methods and systems for service integrated domain name servers are described. A method for out of path border gateway protocol (BGP) validation includes receiving, at a network component, a prefix announcement. The network component denies acceptance of the prefix announcement. A BGP monitor at the network component sends the prefix announcement to an out of path validation controller. The out of path validation controller evaluates the prefix announcement against one or more validation tests, sends a validation notification based on the one or more validation tests, and programs the network component for a validated prefix announcement.

Claims (52)

1. A method for out of path border gateway protocol (BGP) validation, the method comprising:

receiving, at a first network component of a network from a second network component of a different network, a prefix announcement;

denying, by the first network component, acceptance of the prefix announcement;

sending, via a BGP monitor at the first network component, the prefix announcement to an out of path validation controller;

receiving, at the first network component from the out of path validation controller, the prefix announcement with a validation notification based on a validation score for one or more validation tests, where the prefix announcement is evaluated against the one or more validation tests at the out of path validation controller; and

updating, the first network component by the out of path validation controller with the prefix announcement, based on the validation notification being associated with positive validation.

2. The method of claim 1 , further comprising:

setting the first network component to deny all inbound prefix announcements.

3. The method of claim 1 , further comprising:

retrieving, by the BGP monitor at the first network component, the prefix announcement.

4. The method of claim 1 , wherein evaluation comprising at least one of:

determining a score for a prefix list validation test;

determining a score for an autonomous system (AS)-path filter validation test;

determining a score for a routing assets database (RADb) validation test;

determining a score for an Internet routing registry (IRR) filter validation test;

determining a score for a maximum prefix validation test;

determining a score for a resource public key infrastructure (RPKI) validation test;

determining a score for secure origin signing validation test;

determining a score for a path security tracking validation test;

determining a score for a topology tracking validation test;

determining a score for a path longevity validation test;

determining a score for a specific route overlap validation test; and

determining a score for a geographic boundary crossings validation test.

5. The method of claim 4 , wherein the evaluation further comprising:

computing the validation score by summing scores from the one or more validation tests.

6. The method of claim 5 , wherein the evaluation further comprising:

comparing the validation score against a security threshold.

7. The method of claim 1 , wherein the updating further comprising:

programming the first network component with the prefix announcement for a positive validation notification.

8. The method of claim 7 , wherein a local routing information base of the first network component is programmed by the out of path validation controller with the prefix announcement for a positive validation notification.

9. A system for out of path border gateway protocol (BGP) validation, the system comprising:

a non-route path server; and

a first physical router including a BGP monitor, wherein the first physical router is in a network and is configured to receive inbound prefix announcements from a second router in a different network and deny acceptance of the inbound prefix announcements, wherein the BGP monitor of the first physical router is configured to retrieve and send the inbound prefix announcements to the non-route path server, and wherein the non-route path server is configured to:

validate the inbound prefix announcements by comparing a validation score with a threshold, where the validation score is based on a plurality of route path tests applied to the inbound prefix announcements;

send to the first physical router an inbound prefix announcement of the inbound prefix announcements with a validation notification in response to the comparing; and

program the first physical router with the inbound prefix announcement based on the validation notification being associated with a positive validation.

10. The system of claim 9 , wherein the plurality of route path tests include at least a prefix list validation test, an autonomous system (AS)-path filter validation test, a routing assets database (RADb) validation test, an Internet routing registry (IRR) filter validation test, a maximum prefix validation test, a resource public key infrastructure (RPKI)validation test, a secure origin signing validation test, a path security tracking validation test, a topology tracking validation test, a path longevity validation test, a specific route overlap validation test, and a geographic boundary crossings validation test.

11. The system of claim 9 , wherein the threshold is configurable to provide multiple levels of security.

12. The system of claim 9 , wherein the first physical router includes a local routing information base which is programmed by the non-route path server.

13. The system of claim 9 , wherein the first physical router includes a pre-policy routing information base IN module which is set to deny acceptance of the inbound prefix announcements.

14. A method for out of path border gateway protocol (BGP) validation, the method comprising:

receiving, at an out of path server from a first network component of a network, a denied inbound prefix announcement sent via a BGP monitoring protocol, wherein the denied inbound prefix announcement is an inbound prefix announcement received from a second network component of a different network and denied by the first network component;

sending, by the out of path server to the first network component, the denied inbound prefix announcement with a validation notification based on comparing a validation score for the denied inbound prefix announcement against a security threshold, wherein the validation score is computed at the out of path server by applying a plurality of validation tests to the denied inbound prefix announcement; and

updating, by the out of path server, the first network component with the denied inbound prefix announcement based on a positive validation notification.

15. The method of claim 14 , further comprising:

setting the first network component to deny all inbound prefix announcements.

16. The method of claim 14 , wherein the plurality of validation tests include at least a prefix list validation test, an autonomous system (AS)-path filter validation test, a routing assets database (RADb) validation test, an Internet routing registry (IRR) filter validation test, a maximum prefix validation test, a resource public key infrastructure (RPKI)validation test, a secure origin signing validation test, a path security tracking validation test, a topology tracking validation test, a path longevity validation test, a specific route overlap validation test, and a geographic boundary crossings validation test.

17. The method of claim 16 , wherein the computing further comprising:

computing a score for each of the plurality of validation tests.

18. The method of claim 16 , wherein at least some of the plurality of validation tests have a scoring weight different than unity.

19. The method of claim 15 , wherein a local routing information base of the first network component is programmed by the out of path server with the denied inbound prefix announcement fora positive validation.

20. The method of claim 14 , wherein the security threshold is a configurable multi-level security setting.

Assignments (4)
SECURITY INTEREST Recorded Sep 22, 2022
From: CHARTER COMMUNICATIONS OPERATING, LLC; TIME WARNER CABLE ENTERPRISES, LLC
To: WELLS FARGO TRUST COMPANY, N.A.
Reel/Frame 061503/0937 →
SECURITY INTEREST Recorded Sep 22, 2022
From: CHARTER COMMUNICATIONS OPERATING, LLC; TIME WARNER CABLE ENTERPRISES, LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 061504/0307 →
SUPPLEMENTAL SECURITY AGREEMENT Recorded Aug 10, 2022
From: CHARTER COMMUNICATIONS OPERATING, LLC; TIME WARNER CABLE ENTERPRISES LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 061633/0069 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2021
From: BECK, JODY
To: CHARTER COMMUNICATIONS OPERATING, LLC
Reel/Frame 057422/0813 →
Continuity (2)
Continuation 16590664 · Oct 2, 2019
Related Publication 20210409443A1 · Dec 30, 2021