IP Library Granted Patent US 7,487,541
Granted Patent B2
US 7,487,541 · App. 10/730,926 · Granted Feb 3, 2009

Flow-based method for tracking back single packets

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,487,541
App. No.
10/730,926
Granted
Feb 3, 2009
Kind
B2
Abstract

A method and system for tracing-back single packets based on storing only one record per flow, ‘FlowId’, observed by a router on a given interface and in a given time window ‘Time Period’. This record can be seen as a canonical representation for all packets seen during this window. A malicious packet may be traced back to its origin by identifying the port of arrival based on that packet time of arrival X and the FlowId.

Claims (36)

1. A method of tracking-back a single malicious data packet in a connection-oriented communication network including a network node comprising a plurality of router interfaces, the method comprising the steps of:

a) for a given time window of a predetermined length, computing a flow identifier that uniquely identifies a given flow seen by a respective router interface at said network node;

b) inserting said flow identifier into a data structure storing flow identifiers computed at said respective router interface during said time window;

c) storing said data structure in a searchable repository at said network node;

d) repeating steps a) to c) for a plurality of successive time windows, wherein each router interface stores a separate data structure for each time window;

e) determining an arrival time window including a time of arrival of said single malicious packet at said network node, and computing a flow identifier for said single malicious packet; and

f) identifying said router interface for said single malicious packet by searching for the flow identifier of said single malicious packet in all data structures stored at said network node that contain data for said arrival time window.

2. The method of claim 1 , further comprising tracing-back hop by hop the source of said single packet from said router, by performing steps e) and f) for each network node along the path of said single malicious packet.

3. The method of claim 1 , wherein step a) is based on a flow definition adopted for said network.

4. The method of claim 1 , wherein step a) comprises applying a specified function to one or more header fields of each packet received in said flow.

5. The method of claim 1 , wherein step a) comprises applying a specified function to one or more header fields of each packet received in said flow and an incoming interface identification parameter.

6. The method of claim 1 , wherein step a) comprises applying a specified function to one or more characteristics of each packet.

7. The method of claim 1 , wherein step a) comprises applying a specified function to one or more characteristics of each packet received in said flow and an incoming interface identification parameter.

8. The method of claim 1 , wherein said data structure is a hash table based on a Bloom filter.

9. The method of claim 1 , wherein said searchable repository is maintained for each router interface at said network node.

10. The method of claim 9 , wherein said searchable repository stores all said data structures for all router interfaces at said network node.

11. The method of claim 1 , wherein said searchable database is a centralized searchable repository maintained for said network.

12. A method of tracking-back a single malicious data packet in a connection-oriented communication network including a network node comprising a plurality of router interfaces, the method comprising the steps of:

a) for a given time window of a predetermined length, computing a flow identifier that uniquely identifies a given flow seen by a respective router interface at said network node based on a flow characterization parameter obtained from a flow management system;

b) inserting said flow identifier into a data structure storing flow identifiers computed at said respective router interface during said time window;

c) storing said data structure in a database that is a centralized searchable repository;

d) repeating steps a) to c) for a plurality of successive time windows, wherein each router interface stores a separate data structure for each time window; and

e) finding, in said searchable repository, the router interface for said single malicious packet by searching for a corresponding flow identifier in all data structures containing data for an arrival time window, wherein the arrival time window includes a time of arrival of said single malicious packet.

13. A system for tracking-back a single malicious data packet in a connection-oriented communication, comprising:

means for computing a flow identifier that uniquely identifies a given flow seen by a router interface at a network node during a given time window of a predetermined length;

means for inserting said flow identifier into a data structure storing flow identifiers computed at said router interface during said time window;

a database that is a centralized searchable repository for storing said data structure; and

a search engine for finding, in said searchable repository, the router interface for said single malicious packet by searching for a corresponding flow identifier in all data structures containing data for an arrival time window wherein die arrival time window includes a time of arrival of said since malicious packet.

14. The system of claim 13 further comprising a flow-based monitoring system for tracking back hop-by-hop the source of said single malicious packet.

15. The system of claim 13 , wherein a searchable repository is maintained for each interface at said network node.

16. The system of claim 13 , wherein a searchable repository is maintained for said network node.

17. The system of claim 13 , wherein said searchable repository is a centralized database maintained for said network.

18. The system of claim 13 , further comprising a flow based monitoring system for providing a flow characterization parameter to said means for calculating.

19. The system of claim 13 further comprising a flow management system for generating a flow characterization parameter.

20. The system of claim 19 , wherein said means for computing is a flow identifier calculator for computing said flow identifier from at least one of packet header fields, packet characterization parameters, and interface identification information.

21. The system of claim 19 , wherein said means for computing is a flow identifier calculator for computing said flow identifier from packet header information.

Assignments (14)
PATENT SECURITY AGREEMENT Recorded Aug 6, 2024
From: RPX CORPORATION; RPX CLEARINGHOUSE LLC
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 068328/0674 →
RELEASE OF LIEN ON PATENTS Recorded Aug 5, 2024
From: BARINGS FINANCE LLC
To: RPX CORPORATION
Reel/Frame 068328/0278 →
PATENT SECURITY AGREEMENT Recorded Apr 22, 2023
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 063429/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2014
From: CREDIT SUISSE AG
To: ALCATEL LUCENT
Reel/Frame 033868/0001 →
SECURITY AGREEMENT Recorded Jan 30, 2013
From: ALCATEL LUCENT
To: CREDIT SUISSE AG
Reel/Frame 029821/0001 →
CHANGE OF NAME Recorded Dec 17, 2008
From: ALCATEL
To: ALCATEL LUCENT
Reel/Frame 021990/0751 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 10, 2003
From: ROBERT, JEAN-MARC
To: ALCATEL
Reel/Frame 014791/0942 →