Application level admission overload control
Generally described, the present disclosure relates to communications. More specifically, this disclosure relates to application level admission overload control. In one illustrative embodiment, intelligence can be embedded into a communication system so that it can detect and prevent network attacks without the need of costly network and firewall appliances. The communication system can control the in-flow of network packets to help prevent system overload situations through a packet oriented admission policy, connected oriented admission policy or both. By doing so, it not only makes the communication system more robust, secure and cost effective, but also can prevent service interruptions. This can reduce support calls and prove cost-effective to the customer as well as a solution provider. The communication system can protect network applications from internal network traffic and/or attacks.
1 . A method to provide packet-admission control comprising:
calculating an overload factor for an application; and
accepting a threshold of packets for said application adjusted by said overload factor.
2 . The method of claim 1 , comprising dropping packets above said threshold.
3 . The method of claim 1 , comprising dropping packets from a source when a number of said packets exceed a defined value within a time interval.
4 . The method of claim 3 , comprising accepting said packets from said source when an expiration period elapses.
5 . The method of claim 1 , wherein accepting a threshold of packets for said application adjusted by said overload factor comprises defining a threshold value, multiplying said threshold value with said overload factor and rounding up said multiplied threshold value to define said threshold of packets.
6 . The method of claim 5 , wherein multiplying said threshold value with said overload factor comprises aggregating said threshold value with an overload factor ranging from 0 representing overloaded to 1 representing idle.
7 . The method of claim 1 , comprising accepting a higher threshold of packets adjusted by said overload factor when receiving preferred packets.
8 . The method of claim 7 , comprising dropping packets when a number of said preferred packets are above said higher threshold.
9 . A communication system comprising:
at least one processor; and
a memory operatively coupled to said processor, said memory storing program instructions that when executed by said processor, causes said processor to:
control admission of connection requests;
frame messages for said connection requests;
accept a threshold of packets for said messages.
10 . The communication system of claim 9 , wherein controlling admission of connection requests comprises denying requests when a number of said requests exceed a predefined threshold.
11 . The communication system of claim 9 , wherein controlling admission of connection requests comprises dropping requests from a source when a number of said requests from said source exceeds a defined value within a time interval and accepting said requests from said source when an expiration period elapses.
12 . The communication system of claim 9 , wherein controlling admission of connection requests comprises accepting a threshold of connection requests adjusted by an overload factor for an application.
13 . The communication system of claim 9 , wherein controlling admission of connection requests comprises denying subsequent connection requests when said connection requests reach a lower threshold limit.
14 . The communication system of claim 13 , wherein controlling admission of connection requests comprises disregarding said connection requests for a defined period when said connection requests reaches a higher threshold limit.
15 . The communication system of claim 13 , wherein controlling a number of connection requests comprises adjusting said lower threshold limit and higher threshold limit with an overload factor.
16 . A system comprising:
an admission controller providing control services to at least one application, wherein said at least one application provides feedback to said admission controller to remove lagging messages by modifying control parameters within said admission controller.
17 . The system of claim 16 , wherein said lagging messages define an overload situation.
18 . The system of claim 16 , wherein modifying control parameters lowers an influx of network packets.
19 . The system of claim 16 , wherein a monitor of said admission controller provides said feedback.
20 . The system of claim 16 , wherein said admission controller removes lagging messages by providing a packet oriented admission policy, connected oriented admission policy or both.