IP Library Granted Patent US 12,192,231
Granted Patent B2
US 12,192,231 · App. 18/392,537 · Granted Jan 7, 2025

Managing traffic control in a network mitigating DDOS

Inventors: Robert Smith (Irvine, CA); Shawn Marck (San Francisco, CA)
Assignee: Level 3 Communications, LLC
H04L63/1458H04L41/0813H04L41/0816H04L41/0823H04L41/0866H04L41/0889H04L45/02H04L45/021H04L45/04H04L45/42H04L45/745H04L47/80H04L63/20H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,231
App. No.
18/392,537
Granted
Jan 7, 2025
Kind
B2
Abstract

Embodiments are provided for managing routes of data traffic within a network. The management may be performed via a graphical user interface that interacts with a Web server to update a configuration file. The configuration file can be converted to router management commands by a network management device (e.g., a BGP speaker). The commands can then be sent to border routers for controlling network traffic. Embodiments are also provided for capturing and logging routing updates made in a network.

Claims (53)

1. A method of managing routes of data traffic within a network, the method comprising performing, by a computer system:

receiving an address and a first routing action;

updating a configuration file to specify the first routing action to be performed by a border router associated with the address;

converting the configuration file into router management commands to be performed by the border router associated with the address based on the first routing action; and

sending the router management commands to the border router.

2. The method as recited in claim 1 , wherein the address is a source address.

3. The method as recited in claim 1 , wherein the address is a destination address.

4. The method as recited in claim 1 , wherein updating the configuration file includes adding the address to the configuration file.

5. The method as recited in claim 1 , wherein the computer system is a server.

6. The method as recited in claim 5 , wherein the router management commands are Border Gateway Protocol (BGP) commands, and wherein the server acts as BGP speaker.

7. The method as recited in claim 1 , wherein the computer system includes a server in a transmitting device, wherein the transmitting device converts the configuration file and sends the router management command.

8. The method as recited in claim 1 , wherein the address and the first routing action are received via a user interface that provides a plurality of routing actions from which to select.

9. The method as recited in claim 8 , wherein the plurality of routing actions includes a null routing action.

10. The method as recited in claim 8 , wherein the plurality of routing actions includes a diversion routing action that specifies a computing device within the network that is not a destination address.

11. The method as recited in claim 8 , wherein the plurality of routing actions includes a discard routing action, where the discard routing action occurs at the plurality of border routers.

12. The method as recited in claim 10 , wherein a computing device filters network traffic based on rules.

13. The method as recited in claim 12 , wherein the filtering mitigates denial of service attacks on the destination address.

14. The method as recited in claim 1 , further comprising:

forwarding one or more router management commands from a plurality of border routers including the border router to one or more other routers based on the first routing action.

15. The method as recited in claim 1 , wherein the address specifies a range of addresses.

16. The method as recited in claim 8 , wherein the user interface displays a list of destination addresses and an associated routing action.

17. The method as recited in claim 16 , wherein the user interface provides selection objects for editing or deleting the destination address from the list.

18. The method as recited in claim 16 , wherein the user interface provides selection object to add a border router to which the router management commands are sent.

19. The method as recited in claim 16 , wherein the user interface displays a time associated with each destination address on the list.

20. The method as recited in claim 19 , with the time corresponds to how long the associated routing action has been performed for each destination address on the list.

21. The method as recited in claim 1 , further comprising:

sending a message to each of a plurality of border routers; and

updating a status on the user interface based on responses from the plurality of border routers.

22. The method as recited in claim 21 , further comprising:

sending an alert message to a system operator if no response is received from the border router.

23. The method as recited in claim 1 , further comprising:

querying a routing log file for routing changes; and

adding any new route changes to a database of routing changes.

24. The method as recited in claim 1 , wherein the address is a destination address, the method further comprising:

accessing a plurality of routing tables from a plurality of routers of the network to determine possible routes to the address, the plurality of routers including a plurality of border routers; and

displaying information about the possible routes to the address.

25. The method as recited in claim 24 , wherein the information about the possible routes includes where the possible routes will exit the network.

26. The method as recited in claim 1 , further comprising:

receiving credentials from the user; and

determining a type of account of the user from a plurality of account types based on the credentials, wherein one account type is a limited account that has allowed routing actions that are a subset of all routing actions allowed.

27. The method as recited in claim 26 , further comprising:

displaying only allowed routing actions to a particular user that has the limited account.

28. A method of configuring routers, the method comprising performing, by a computer system:

receiving specification of a customer network and a routing action to route traffic to the customer network via a mitigation network, the customer network including a plurality of customer router addresses;

initiating one or more connections between the mitigation network and the customer network using a plurality of routing variables; and

sending, to a border router, router management commands to route the traffic destined for the customer network to the mitigation network, the border router being external to the mitigation network.

29. The method as recited in claim 28 , wherein the customer network is specified as a plurality of network addresses.

30. The method as recited in claim 28 , wherein the routing variables include a plurality of internal addresses.

31. The method as recited in claim 28 , wherein the routing variables include a plurality of external addresses.

32. The method as recited in claim 28 , wherein the connections are IP tunnels.

33. The method as recited in claim 32 , wherein the customer network and the routing action are received via a user interface that further includes a mechanism for inputting a plurality of routing variables and wherein the routing variables are used to initiate the IP tunnels.

34. The method as recited in claim 32 , wherein the user interface further includes a mechanism for inputting the number of IP tunnels to be initiated.

35. The method as recited in claim 32 , wherein the IP tunnels are GRE tunnels.

Assignments (4)
ASSIGNMENT OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 069295/0858 Recorded Jun 12, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS RETIRING COLLATERAL AGENT
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 075738/0427 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (SECOND LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0749 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (FIRST LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0858 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 24, 2023
From: SMITH, ROBERT; MARCK, SHAWN
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 065948/0693 →
Continuity (6)
Continuation 17881925 · Aug 5, 2022
Continuation 16861269 · Apr 29, 2020
Continuation 16189580 · Nov 13, 2018
Continuation 14991024 · Jan 8, 2016
Provisional Application 62119751 · Feb 23, 2015
Related Publication 20240163310A1 · May 16, 2024
References Cited (32)
US 7340519B1 · Golan et al. · 2008 [cited by applicant]
US 20060256788A1 · Donahue · 2006 [cited by applicant]
US 20060272018A1 · Fouant · 2006 [cited by applicant]
US 20080062891A1 · Van der Merwe · 2008 [cited by applicant]
US 20080209334A1 · Pirbhai et al. · 2008 [cited by applicant]
US 20090323544A1 · Gaddis et al. · 2009 [cited by applicant]
US 20100142543A1 · Shaikh et al. · 2010 [cited by applicant]
US 20110261812A1 · Kini · 2011 [cited by applicant]
US 20110264822A1 · Ferguson · 2011 [cited by examiner]
US 20110296005A1 · Labovitz et al. · 2011 [cited by applicant]
US 20110296053A1 · Medved · 2011 [cited by applicant]
US 20120110195A1 · Schemitsch · 2012 [cited by applicant]
US 20120131211A1 · Schemitsch · 2012 [cited by examiner]
US 20120290716A1 · Ogielski · 2012 [cited by examiner]
US 20120324216A1 · Sun · 2012 [cited by applicant]
US 20130182710A1 · Scholl · 2013 [cited by examiner]
US 20130263256A1 · Dickinson · 2013 [cited by examiner]
US 20140029410A1 · Kannan · 2014 [cited by applicant]
US 20140372577A1 · Hui · 2014 [cited by applicant]
US 20140379929A1 · Cicic · 2014 [cited by applicant]
US 20150263888A1 · Hallivuori · 2015 [cited by applicant]
US 20160248806A1 · Smith et al. · 2016 [cited by applicant]
US 20190081978A1 · Smith et al. · 2019 [cited by applicant]
US 20200267177A1 · Smith · 2020 [cited by applicant]
US 20220385533A1 · Smith · 2022 [cited by applicant]
Extended European Search Report, dated Nov. 12, 2018, Application No. 16756170.3, filed Feb. 23, 2016; 18 pgs. [cited by applicant]
International Preliminary Report on Patentability dated Aug. 29, 2017, Int'l Appl. No. PCT/US16/019094, Int'l Filing Date Feb. 23, 2016; 12 pgs. [cited by applicant]
International Search Report dated Jun. 23, 2016, Int'l Appl. No. PCT/US16/019094, Int'l Filing Date Feb. 23, 2016; 4 pgs. [cited by applicant]
Partial Supplementary European Search Report, dated Aug. 3, 2018, Application No. 16756170.3, filed Feb. 23, 2016; 19 pgs. [cited by applicant]
Singapore Notice of Intention to Refuse, dated Jan. 17, 2019, Application No. 11201706628T, filed Feb. 23, 2016; 1 pg. [cited by applicant]
Singapore Search Report and Written Opinion, dated Aug. 2, 2018, Application No. 11201706628T, filed Feb. 23, 2016; 6 pgs. [cited by applicant]
Written Opinion of the International Searching Authority dated Jun. 23, 2016, Int'l Appl. No. PCT/US16/019094, Int'l Filing Date Feb. 23, 2016; 10 pgs. [cited by applicant]