IP Library › Granted Patent US 12,294,594
Granted Patent B2
US 12,294,594 · App. 18/594,437 · Granted May 6, 2025

Intelligent quarantine on switch fabric for physical and virtualized infrastructure

Inventors: Balaji Sundararajan (Fremont, CA); Gaurang Rajeev Mokashi (Sunnyvale, CA); Preety Mordani (Fremont, CA); Vivek Agarwal (Campbell, CA)
Assignee: Cisco Technology, Inc.
H04L63/1416G06F9/45558H04L43/08H04L47/20H04L49/25H04L63/20G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,294,594
App. No.
18/594,437
Granted
May 6, 2025
Kind
B2
Abstract

Systems, methods, and computer-readable media for performing threat remediation through a switch fabric of a virtualized network environment. Data traffic passing into a virtualized network environment including a plurality of virtual machines running on a switch fabric is monitored. A network threat introduced through at a least a portion of the data traffic is identified at the switch fabric. One or more remedial measures are performed in the network environment based on the identification of the network threat in the virtualized network environment.

Claims (35)

1. A method comprising:

monitoring, at a first node in a switch fabric, data traffic passing into a network environment including a plurality of virtual machines;

detecting, at the first node, a traffic pattern indicative of a denial of service (DOS) attack within the monitored data traffic passing into the virtualized network environment;

generating threat information in response to detecting the traffic pattern indicative of a DOS attack; and

at the first node, using the threat information to block transmission of the DoS attack traffic at the switch fabric prior to the DOS attack traffic entering into either or both the virtual machines and one or more hypervisors hosting the virtual machines in the virtualized network environment.

2. The method of claim 1 , wherein the threat information identifies DOS attack traffic at a ternary content addressable memory (TCAM) level.

3. The method of claim 1 , further comprising: at a second node, using the threat information to block transmission of the DOS attack traffic from the switch fabric prior to the DOS attack traffic entering into either or both the virtual machines and one or more hypervisors hosting the virtual machines in the virtualized network environment.

4. The method of claim 1 , wherein the threat information is propagated to more than one node in the switching fabric.

5. The method of claim 1 , wherein the traffic pattern indicative of a DOS attack is based on monitoring for TCP/SYN packets in the data traffic monitored at the first node.

6. The method of claim 1 , wherein the traffic pattern indicative of a DOS attack is based on matching a signature of a known network threat at the first node.

7. The method of claim 1 , wherein the traffic pattern indicative of a DOS attack is based on matching an exclusion list at the first node.

8. A system comprising:

a switch fabric including a plurality of nodes, wherein each node in the plurality of nodes includes a physical network device, one or more processors, a memory; and wherein each node receives traffic to pass into a network environment including a plurality of virtual machines;

a switch fabric threat remediation agent, and

wherein the plurality of nodes and the switch fabric threat remediation agent include software instructions, which when executed by one or more processors within the switch fabric cause the system to perform operations including:

monitoring, at a first node in a switch fabric, data traffic passing into the network environment;

detecting, at the first node, a traffic pattern indicative of a denial of service (DOS) attack within the monitored data traffic passing into the virtualized network environment,

generating threat information in response to detecting the traffic pattern indicative of a DOS attack;

at the first node, using the threat information to block transmission of the DOS attack traffic at the physical network device prior to the DOS attack traffic entering into either or both the virtual machines and one or more hypervisors hosting the virtual machines in the virtualized network environment.

9. The system of claim 8 , wherein the switch fabric threat remediation agent is implemented, at least in part, in the virtualized network environment.

10. The system of claim 8 , wherein the switch fabric threat remediation agent is implemented, at least in part, in a container within the virtualized network environment.

11. The system of claim 8 , wherein the switch fabric threat remediation agent is implemented, at least in part, either physical or virtualized, in the switch fabric.

12. The system of claim 8 , wherein the threat information identifies DOS attack traffic at a ternary content addressable memory (TCAM) level.

13. The system of claim 8 , wherein the threat information is propagated to more than one node of the plurality of nodes.

14. The system of claim 13 , wherein each node that receives the propagated threat information uses the threat information to prevent transmission of the DOS attack traffic from the switch fabric into either or both the virtual machines and one or more hypervisors hosting the virtual machines in the virtualized network environment.

15. The system of claim 8 , wherein the traffic pattern indicative of a DoS attack is based on monitoring for TCP/SYN packets in the data traffic monitored at the first node.

16. A non-transitory media storing program instructions, which when executed by one or more processors in a system comprising a plurality of nodes organized in a switch fabric, which when executed by one or more processors within the switch fabric cause the system to perform operations including:

monitoring, at a first node in the switch fabric, data traffic passing into a virtualized network environment;

detecting, at the first node, a traffic pattern indicative of a denial of service (DOS) attack within the monitored data traffic passing into the virtualized network environment;

generating threat information in response to detecting the traffic pattern indicative of a DOS attack; and

at the first node, using the threat information to block transmission of the DoS attack traffic at the switch fabric prior to the DOS attack traffic entering into at least one hypervisor or virtual machine in the virtualized network environment.

17. The non-transitory media of claim 16 , wherein the operations further include configuring the first node to identify DOS attack traffic at a ternary content addressable memory (TCAM) level.

18. The non-transitory media of claim 16 , wherein the operations further include propagating the threat information to more than one node of the plurality of nodes.

19. The non-transitory media of claim 18 , wherein the operations further include using the threat information to block transmission of DOS attack traffic at each node that receives the propagated threat information prior to the DOS attack traffic entering into at least one hypervisor or virtual machine in the virtualized network environment.

20. The non-transitory media of claim 16 , wherein the traffic pattern indicative of a denial of service (DOS) attack is based on monitoring for TCP/SYN packets in the data traffic monitored at the first node.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2024
From: SUNDARARAJAN, BALAJI; MOKASHI, GAURANG RAJEEV; MORDANI, PREETY; AGARWAL, VIVEK
To: CISCO TECHNOLOGY, INC.
Reel/Frame 066636/0109 →
Continuity (4)
Continuation 18415423 · Jan 17, 2024
Continuation 18171322 · Feb 17, 2023
Continuation 16826082 · Mar 20, 2020
Related Publication 20240250966A1 · Jul 25, 2024
References Cited (23)
US 9197664B1 · Aziz et al. · 2015 [cited by applicant]
US 9591020B1 · Aziz · 2017 [cited by applicant]
US 11159389B1 · Miriyala et al. · 2021 [cited by applicant]
US 11245721B2 · Konda et al. · 2022 [cited by applicant]
US 11750622B1 · Kim et al. · 2023 [cited by applicant]
US 20100202466A1 · Eswaran · 2010 [cited by examiner]
US 20100212005A1 · Eswaran · 2010 [cited by examiner]
US 20130219497A1 · Lukas et al. · 2013 [cited by applicant]
US 20130219500A1 · Lukas et al. · 2013 [cited by applicant]
US 20160164894A1 · Zeitlin · 2016 [cited by examiner]
US 20160171215A1 · Bank et al. · 2016 [cited by applicant]
US 20170118041A1 · Bhattacharya · 2017 [cited by examiner]
US 20170163685A1 · Schwartz · 2017 [cited by examiner]
US 20170366575A1 · Polepalli et al. · 2017 [cited by applicant]
US 20180006921A1 · Mozes · 2018 [cited by examiner]
US 20180091547A1 · St. Pierre · 2018 [cited by applicant]
US 20180139221A1 · Chen · 2018 [cited by applicant]
US 20180189489A1 · Zhang et al. · 2018 [cited by applicant]
US 20190028505A1 · Shpiner · 2019 [cited by examiner]
US 20190199746A1 · Doron et al. · 2019 [cited by applicant]
US 20200106742A1 · Moore et al. · 2020 [cited by applicant]
US 20200278892A1 · Nainar et al. · 2020 [cited by applicant]
EP 3486775A1 · 2019 [cited by examiner]