IP Library Granted Patent US 12,199,999
Granted Patent B2
US 12,199,999 · App. 17/712,407 · Granted Jan 14, 2025

Flowspec message processing apparatus and method

Inventors: Scott Cameron (Chicago, IL); Danielle Fritz (Canton, MI); Mitchell Hoffmeyer (Ann Arbor, MI); Scott Iekel-Johnson (Ann Arbor, MI); Andrew Inman (Ann Arbor, MI); Grant Levene (Chicago, IL); Jiasi Li (Bethesda, MD); William Martin Northway, Jr. (Ypsilanti, MI); Ryan O'Rielly (Ann Arbor, MI); Michael Ratanatharathorn (Whitmore Lake, MI); Lori Sulik (Taylor, MI); Chris Thiele (Livonia, MI); James Edward Winquist (Ypsilanti, MI)
Assignee: ARBOR NETWORKS, INC.
H04L63/1425H04L41/0816H04L41/0846H04L63/1416H04L63/1458H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,199,999
App. No.
17/712,407
Granted
Jan 14, 2025
Kind
B2
Abstract

A method and apparatus for processing flow specification (Flowspec) messages to one or more of a plurality of customer networks by a controller device coupled to the plurality of customer networks. Preferably a network controller monitors network traffic flowing through each of the customer networks for detecting a network attack in one of the plurality of customer networks, via monitoring of the network traffic. Upon detection of a network attack, a Flowspec message is generated for the customer network detected to be under network attack wherein the Flowspec message is configured specifically for that customer network. The generated Flowspec message is transmitted to the customer network detected to be under network attack for implementation by the customer network for mitigation of the detected network attack.

Claims (34)

1. A method for processing flow specification (FlowSpec) messages to one or more customer networks of a plurality of customer networks by a controller device coupled to the plurality of customer networks, comprising:

monitoring, by the controller device, a plurality of Internet Protocol (IP) packets flowing through the one or more customer networks of the plurality of customer networks;

detecting, by the controller device, based on one or more first attributes of an IP packet of the plurality of IP packets, a network attack in a first customer network of the plurality of customer networks;

retrieving, by the controller device, responsive to detecting the network attack, from a database comprising a stack of pre-existing Flowspec messages, a first Flowspec message associated with the one or more first attributes of the IP packet;

generating, by the controller device, responsive to retrieving the first Flowspec message, a second Flowspec message for the first customer network by adjusting one or more aspects of the first Flowspec message, the second Flowspec message generated based on a match between one or more characteristics of the first customer network and one or more second attributes of the first Flowspec message, the one or more characteristics of the first customer network determined by a network service provider connected to the one or more customer networks and the controller device;

transmitting, by the controller device, the second Flowspec message to cause the first customer network to implement one or more actions specific to the first customer network to mitigate the network attack in the first customer network; and

storing, by the controller device, the second Flowspec message in the stack of pre-existing Flowspec messages, wherein the second Flowspec message is adaptable to be selected for use by the controller device for a second customer network of the plurality of customer networks, contingent upon the second Flowspec message being reconfigured in view of specific criteria for the second customer network.

2. The method as recited in claim 1 , wherein the controller device is provided in the network service provider, and wherein the network service provider provides Internet service to the plurality of customer networks.

3. The method as recited in claim 2 , comprising:

transmitting, by the controller device, the second Flowspec message to one or more router devices in the network service provider such that the one or more router devices in the network service provider are also enabled to perform mitigation of the network attack upon first network traffic flowing through the first customer network while not affecting second network traffic flowing through one or more second customer networks of the plurality of customer networks.

4. The method as recited in claim 3 , wherein retrieving the first Flowspec message includes:

selecting, by the controller device, the first Flowspec message from the stack of pre-existing Flowspec messages.

5. The method as recited in claim 3 , wherein generating the second Flowspec message includes:

generating, by the controller device, a BGP Flowspec for port 53/UDP for an edge router device in the first customer network and the one or more router devices in the network service provider.

6. The method as recited in claim 5 , wherein the second Flowspec message is an n-tuple consisting of several matching criteria to be applied to IP traffic in the edge router device of the first customer network and the one or more router devices in the network service provider.

7. The method as recited in claim 6 , wherein the second Flowspec message is distributed as a BGP NLRI in a BGP announcement message.

8. The method as recited in claim 7 , wherein the second Flowspec message implements a filter for mitigation of a DDOS network attack in the edge router device in the first customer network and one or more edge router devices in the network service provider.

9. A network controller device coupled to a plurality of customer networks for processing flow specification (Flowspec) messages to one or more customer networks of the plurality of customer networks, comprising:

one or more databases having memory configured to store instructions; and

a processor disposed in communication with the memory, wherein the processor upon execution of the instructions is configured to:

monitor a plurality of Internet Protocol (IP) packets flowing through the one or more customer networks of the plurality of customer networks;

detect, based on one or more first attributes of an IP packet of the plurality of IP packets, a network attack in a first customer network of the plurality of customer networks;

retrieve, responsive to detection of the network attack, from a database comprising a stack of pre-existing Flowspec messages, a first Flowspec message associated with the one or more first attributes of the IP packet;

generate, responsive to retrieval of the first Flowspec message, a second Flowspec message for the first customer network by adjusting one or more aspects of the first Flowspec message, the second Flowspec message generated based on a match between one or more characteristics of the first customer network and one or more second attributes of the first Flowspec message, the one or more characteristics of the first customer network determined by a network service provider connected to the one or more customer networks and the network controller device;

transmit the second FlowSpec message to cause the first customer network to implement one or more actions specific to the first customer network to mitigate the network attack in the first customer network; and

store the second Flowspec message in the stack of pre-existing Flowspec messages, wherein the second Flowspec message is adaptable to be selected for use by the network controller device for a second customer network of the plurality of customer networks, contingent upon the second Flowspec message being reconfigured in view of specific criteria for the second customer network.

10. The network controller device as recited in claim 9 , wherein the network controller device is provided in the network service provider, and wherein the network service provider provides Internet service to the plurality of customer networks.

11. The network controller device as recited in claim 10 , wherein the processor is configured to:

transmit the second Flowspec message to one or more router devices in the network service provider such that the one or more router devices in the network service provider are also enabled to perform mitigation of the network attack upon first network traffic flowing through the first customer network while not affecting second network traffic flowing through one or more second customer networks of the plurality of customer networks.

12. The network controller device as recited in claim 11 , the processor configured to retrieve the first Flowspec message for the first customer network by:

selecting the first Flowspec message from the stack of pre-existing Flowspec messages.

13. The network controller device as recited in claim 11 , the processor configured to generate the second Flowspec message by:

generating a BGP Flowspec for port 53/UDP for an edge router device in the first customer network and the one or more router devices in the network service provider and wherein the second Flowspec message is distributed as a BGP NLRI in a BGP announcement message.

14. The network controller device as recited in claim 13 , wherein the second Flowspec message is an n-tuple consisting of several matching criteria to be applied to IP traffic in the edge router device of the first customer network and one or more edge router devices in the network service provider and wherein the second Flowspec message implements a filter for mitigation of a DDOS network attack in the edge router device of the first customer network and the one or more edge router devices in the network service provider.

Assignments (2)
SECURITY INTEREST Recorded Oct 22, 2024
From: NETSCOUT SYSTEMS, INC.; ARBOR NETWORKS LLC; NETSCOUT SYSTEMS TEXAS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069216/0007 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2022
From: CAMERON, SCOTT, MR.; FRITZ, DANIELLE; HOFFMEYER, MITCHELL; IEKEL-JOHNSON, SCOTT; INMAN, ANDREW; LEVENE, GRANT; LI, JIASI; NORTHWAY, WILLIAM MARTIN, JR., MR.; O'RIELLY, RYAN; RATANATHARATHORN, MICHAEL, MR.; SULIK, LORI; THIELE, CHRIS; WINQUIST, JAMES EDWARD
To: ARBOR NETWORKS, INC.
Reel/Frame 059521/0828 →
Continuity (1)
Related Publication 20230319082A1 · Oct 5, 2023
References Cited (40)
US 7100084B2 · Unkle et al. · 2006 [cited by applicant]
US 7610173B2 · Gross et al. · 2009 [cited by applicant]
US 10033696B1 · Burns · 2018 [cited by examiner]
US 11870642B2 · Miriyala · 2024 [cited by examiner]
US 20050260996A1 · Groenendaal · 2005 [cited by examiner]
US 20090106592A1 · Gross et al. · 2009 [cited by applicant]
US 20090300748A1 · Diehl · 2009 [cited by examiner]
US 20110280150A1 · Turk · 2011 [cited by examiner]
US 20130007257A1 · Ramaraj · 2013 [cited by examiner]
US 20130031037A1 · Brandt · 2013 [cited by examiner]
US 20130044758A1 · Nguyen · 2013 [cited by examiner]
US 20150350229A1 · Mitchell · 2015 [cited by examiner]
US 20160020969A1 · Vasseur · 2016 [cited by examiner]
US 20160182300A1 · Mopuri · 2016 [cited by examiner]
US 20160261628A1 · Doron · 2016 [cited by examiner]
US 20170063920A1 · Thomas · 2017 [cited by examiner]
US 20170214713A1 · Doron · 2017 [cited by examiner]
US 20190028381A1 · Li · 2019 [cited by examiner]
US 20190140960A1 · Liang · 2019 [cited by examiner]
US 20190199746A1 · Doron · 2019 [cited by examiner]
US 20200021613A1 · Tong · 2020 [cited by examiner]
US 20200106863A1 · Jain · 2020 [cited by examiner]
US 20200137118A1 · Lyon · 2020 [cited by examiner]
US 20200177626A1 · Wichtlhuber · 2020 [cited by examiner]
US 20200213358A1 · Helfinstine · 2020 [cited by examiner]
US 20210112091A1 · Compton · 2021 [cited by examiner]
US 20210181694A1 · Lillestolen et al. · 2021 [cited by applicant]
US 20210182737A1 · Lillestolen et al. · 2021 [cited by applicant]
US 20210258251A1 · Eastlake, III · 2021 [cited by examiner]
US 20220021646A1 · Joshi · 2022 [cited by examiner]
US 20220116417A1 · Compton · 2022 [cited by examiner]
US 20220263803A1 · Zhuang · 2022 [cited by examiner]
US 20230011397A1 · Panse · 2023 [cited by examiner]
US 20230156523A1 · Xiong · 2023 [cited by examiner]
EP 3839838A1 · 2021 [cited by applicant]
Bakker, D. R. “Impact-based optimisation of BGP Flowspec rules for DDOS attack mitigation.” Bachelor's thesis, University of Twente, 2019. (Year: 2019). [cited by examiner]
Chouk, Wissem. “The use of BGP Flowspec in the protection against DDOS attacks.” (2019). (Year: 2019). [cited by examiner]
Van Gijtenbeek, Lennart, and Tim Dijkhuizen. “DDOS Defense Mechanisms for IXP Infrastructures.” (2018). (Year: 2018). [cited by examiner]
Noction. “DDOS Mitigation and BPG Flowspec”, <https://www.noction.com/blog/ddos-mitigation>. Aug. 2019. (Year: 2019). [cited by examiner]
Kock, Joeri. A signature-based Approach to DDOS Attack Mitigation Using BGP Flowspec Rules. MS thesis. University of Twente, 2019. (Year: 2019). [cited by examiner]