IP Library › Granted Patent US 9,813,314
Granted Patent B2
US 9,813,314 · App. 14/336,106 · Granted Nov 7, 2017

Mitigating reflection-based network attacks

Inventors: Jean-Philippe Vasseur (Saint Martin d'Uriage, FR); Sukrit Dasgupta (Norwood, MA)
Assignee: Cisco Technology, Inc.
H04L43/062H04L12/2854H04L63/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,813,314
App. No.
14/336,106
Granted
Nov 7, 2017
Kind
B2
Abstract

In one embodiment, a network device routes traffic along a network path and receives a performance threshold crossing alert regarding performance of the network path. The network device detects that the performance threshold crossing alert is part of a potential network attack by analyzing, by the device, the performance threshold crossing alert. The network device also provides a notification of the detected network attack.

Claims (70)

1. A method, comprising:

routing, by a network device, traffic along a network path;

receiving, at the network device, a performance threshold crossing alert regarding performance of the network path;

detecting that the performance threshold crossing alert is part of a potential network attack by analyzing, by the network device, the performance threshold crossing alert, wherein the detection distinguishes performance threshold crossing alerts from legitimate entities from performance threshold crossing alerts from malicious entities;

providing, by the network device, a notification of the detected network attack;

generating, by the network device, one or more keys and one or more seed values;

performing, by the network device, handshaking with a second network device located along the network path by exchanging keys and seed values;

receiving, at the network device, a performance threshold crossing alert from the second network device, wherein the alert from the second network device is digitally signed using a particular key generated using the exchanged seed values; and validating, by the network device, the alert from the second network device received from the second network device using one of the exchanged keys.

2. The method as in claim 1 , wherein detecting that the performance threshold crossing alert is part of a potential network attack comprises:

predicting, by the network device, a probability of receiving the performance threshold crossing alert, wherein the potential network attack is detected based on the predicted probability of receiving the performance threshold crossing alert.

3. The method as in claim 1 , wherein the performance threshold crossing alert correspond to an amount of jitter or delays along the network path.

4. The method as in claim 1 , wherein detecting that the performance threshold crossing alert is part of a potential network attack comprises:

sending, by the network device, one or more measurement probe packets along the network path;

receiving, at the network device, path characteristics identified from the sent one or more probe packets; and

comparing, by the network device, the path characteristics to the alert.

5. The method as in claim 1 , wherein detecting that the performance threshold crossing alert is part of a potential network attack comprises:

sending, by the network device, a packet that identifies the traffic and does not have a payload to a second device located along the network path; and

receiving, from the second device, a notification that confirms that the alert is part of an attempted attack.

6. The method as in claim 1 , wherein detecting that the performance threshold crossing alert is part of a potential network attack comprises:

querying, by the network device, whether the performance threshold crossing alert was also received by a second network device, wherein the second network device routes traffic along a second network path; and

receiving, from the second device, a notification that confirms that the alert is part of an attempted attack.

7. The method as in claim 1 , wherein detecting that the performance threshold crossing alert is part of a potential network attack comprises:

providing the threshold crossing alert to a user interface device; and

receiving, from the user interface device, a notification that confirms that the alert is part of an attempted attack.

8. An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the network interfaces and configured to execute one or more processes; and

a memory configured to store a process executable by the processor, the process when executed operable to:

route traffic along a network path;

receive a performance threshold crossing alert regarding performance of the network path;

detect that the performance threshold crossing alert is part of a potential network attack by analyzing the performance threshold crossing alert, wherein the detection distinguishes performance threshold crossing alerts from legitimate entities from performance threshold crossing alerts from malicious entities;

provide a notification of the detected network attack;

generate one or more keys and one or more seed values;

perform handshaking with a second network device located along the network path by exchanging keys and seed values;

receive a performance threshold crossing alert from the second network device, wherein the alert from the second network device is digitally signed using a particular key generated using the exchanged seed values; and

validate the alert from the second network device received from the second network device using one of the exchanged keys.

9. The apparatus as in claim 8 , wherein the potential network attack is detected by:

predicting a probability of receiving the performance threshold crossing alert, wherein the potential network attack is detected based on the predicted probability of receiving the performance threshold crossing alert.

10. The apparatus as in claim 8 , wherein the performance threshold crossing alert corresponds to an amount of jitter or delays along the network path.

11. The apparatus as in claim 8 , wherein the potential network attack is detected by:

sending one or more measurement probe packets along the network path;

receiving path characteristics identified from the sent one or more probe packets; and

comparing the path characteristics to the performance threshold crossing alert.

12. The apparatus as in claim 8 , wherein the potential network attack is detected by:

sending a packet that identifies the traffic and does not have a payload to a second device located along the network path; and

receiving, from the second device, a notification that confirms that the performance threshold crossing alert is part of an attempted attack.

13. The apparatus as in claim 8 , wherein the potential network attack is detected by:

querying whether the performance threshold crossing alert was also received by a second network device, wherein the second network device routes traffic along a second network path; and

receiving, from the second device, a notification that confirms that the alert is part of an attempted attack.

14. The apparatus as in claim 8 , wherein the potential network attack is detected by:

providing the threshold crossing alert to a user interface device; and

receiving, from the user interface device, a notification that confirms that the alert is part of an attempted attack.

15. A tangible, non-transitory, computer-readable media having software encoded thereon, the software when executed by a processor operable to:

route traffic along a network path;

receive a performance threshold crossing alert regarding performance of the network path;

detect that the performance threshold crossing alert is part of a potential network attack by analyzing the performance threshold crossing alert, wherein the detection distinguishes performance threshold crossing alerts from legitimate entities from performance threshold crossing alerts from malicious entities;

provide a notification of the detected network attack;

generate one or more keys and one or more seed values;

perform handshaking with a second network device located along the network path by exchanging keys and seed values;

receive a performance threshold crossing alert from the second network device, wherein the alert from the second network device is digitally signed using a particular key generated using the exchanged seed values; and

validate the alert from the second network device received from the second network device using one of the exchanged keys.

16. The computer-readable media as in claim 15 , wherein the software when executed is further operable to:

predict a probability of receiving the performance threshold crossing alert, wherein the potential network attack is detected based on the predicted probability of receiving the performance threshold crossing alert.

17. The computer-readable media as in claim 15 , wherein the performance threshold crossing alert corresponds to an amount of jitter or delays along the network path.

18. The computer-readable media as in claim 15 , wherein the software when executed is further operable to:

send a packet that identifies the traffic and does not have a payload to a second device located along the network path; and

receive, from the second device, a notification that confirms that the performance threshold crossing alert is part of an attempted attack.

19. The computer-readable media as in claim 15 , wherein the software when executed is further operable to:

query whether the performance threshold crossing alert was also received by a second network device, wherein the second network device routes traffic along a second network path; and

receive, from the second device, a notification that confirms that the alert is part of an attempted attack.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2014
From: VASSEUR, JEAN-PHILIPPE; DASGUPTA, SUKRIT
To: CISCO TECHNOLOGY, INC.
Reel/Frame 033350/0472 →
Continuity (1)
Related Publication 20160020969A1 · Jan 21, 2016