IP Library Granted Patent US 9,954,876
Granted Patent B2
US 9,954,876 · App. 14/965,859 · Granted Apr 24, 2018

Automatic tunnels routing loop attack defense

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,954,876
App. No.
14/965,859
Granted
Apr 24, 2018
Kind
B2
Abstract

The present disclosure relates to systems, methods, and non-transitory computer readable storage medium for detecting a tunnel routing loop attack on a computer network. A method of the presently claimed invention receives a packet of data over an automatic tunnel. When the received packet includes an Internet protocol version 6 (IPv6) packet headers in the received packet may be extracted from the received packet. When an extracted header is a tunnel routing loop attack (TRLA) header, address information included in the TRLA header may be matched to a destination address that the IPv6 packet is about to be tunneled through. When the address information included in the TRLA header matches the destination address that the IPv6 packet is about to be tunneled through the IPv6 packet is dropped because the match indicates that that a loop is about to be formed.

Claims (46)

1. A method for detecting a tunnel routing loop attack on a computer network, the method comprising:

receiving an internet protocol version 6 (IPv6) packet at a first network device over a network interface;

adding address information to the IPv6 packet that identifies a second network device in a tunnel routing attack (TRLA) header;

encapsulating the IPv6 packet in an IPv4 packet;

forwarding the IPv4 packet to a second network device through an automatic tunnel to the second network device;

receiving a second version of the IPv6 packet at the first network device;

identifying that the IPv6 packet includes the TRLA header;

identifying that the first network device that has previously forwarded the IPv6 packet from the address information in the TRLA header, wherein the identification that the first network device has previously forwarded the IPv6 packet indicates that the IPv6 packet is associated with the tunnel routing loop attack; and

dropping the second version of the IPv6 packet after identifying that the first network device previously forwarded the IPv6 packet to the second network device based on the indication that the previously forwarded IPv6 packet is associated with the tunnel routing loop attack.

2. The method of claim 1 , wherein the first network device added the TRLA header after initially receiving the IPv6 packet.

3. The method of claim 1 , wherein the IPv6 packet is passed through one or more other network devices, and the one or more other network devices modifies the TRLA header to identify addresses of the one or more other network devices.

4. The method of claim 1 , wherein the TRLA header is added after a hop-by-hop header in the IPv6 packet.

5. The method of claim 1 , wherein the second network device receives the IPv4 packet, extracts the IPv6 packet from the IPv4 packet, and sends the IPv6 packet to another network device.

6. The method of claim 1 , wherein the IPv6 packet and the second version of the IPv6 packet include different information in at least one header of the IPv6 packet.

7. The method of claim 6 , wherein the IPv6 packet and the second version of the IPv6 packet include the same payload data.

8. A non-transitory computer-readable storage medium embodied thereon a program executable by a processor for performing a method of detecting a tunnel routing loop attack on a computer network, the method comprising:

receiving an internet protocol version 6 (IPv6) packet at a first network device over a network interface;

adding address information to the IPv6 packet that identifies a second network device in a tunnel routing attack (TRLA) header;

encapsulating the IPv6 packet in an IPv4 packet;

forwarding the IPv4 packet to a second network device through an automatic tunnel to the second network device;

receiving a second version of the IPv6 packet at the first network device;

identifying that the IPv6 packet includes the TRLA header;

identifying that the first network device that has previously forwarded the IPv6 packet from the address information in the TRLA header, wherein the identification that the first network device has previously forwarded the IPv6 packet indicates that the IPv6 packet is associated with the tunnel routing loop attack; and

dropping the second version of the IPv6 packet after identifying that the first network device previously forwarded the IPv6 packet to the second network device based on the indication that the previously forwarded IPv6 packet is associated with the tunnel routing loop attack.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the first network device added the TRLA header after initially receiving the IPv6 packet.

10. The non-transitory computer-readable storage medium of claim 8 , wherein the IPv6 packet is passed through one or more other network devices, and the one or more other network devices modifies the TRLA header to identify addresses of the one or more other network devices.

11. The non-transitory computer-readable storage medium of claim 8 , wherein the TRLA header is added after a hop-by-hop header in the IPv6 packet.

12. The non-transitory computer-readable storage medium of claim 8 , wherein the second network device receives the IPv4 packet, extracts the IPv6 packet from the IPv4 packet, and sends the IPv6 packet to another network device.

13. The non-transitory computer-readable storage medium of claim 8 , wherein the IPv6 packet and the second version of the IPv6 packet include different information in at least one header of the IPv6 packet.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the IPV6 packet and the second version of the IPv6 packet include the same payload data.

15. A system for detecting a tunnel routing loop attack on a computer network, the system comprising:

a first network device; and

a second network device, wherein the first network device of the one or more other network devices:

receives an internet protocol version 6 (IPv6) packet at a first network device over a network interface;

adds address information to the IPv6 packet that identifies the second network device in a tunnel routing attack (TRLA) header;

encapsulates the IPv6 packet in an IPv4 packet;

forwards the IPv4 packet to the second network device through an automatic tunnel to the second network device;

receives a second version of the IPv6 packet at the first network device;

identifies that the IPv6 packet includes the TRLA header;

identifies that the first network device that has previously forwarded the IPv6 packet from the address information in the TRLA header, wherein the identification that the first network device has previously forwarded the IPv6 packet indicates that the IPv6 packet is associated with the tunnel routing loop attack; and

drops the second version of the IPv6 packet after identifying that the first network device previously forwarded the IPv6 packet based on the indication that the previously forwarded IPv6 packet is associated with the tunnel routing loop attack.

16. The system of claim 15 , wherein the first network device added the TRLA header after initially receiving the IPv6 packet.

17. The system of claim 15 , wherein the IPv6 packet is passed through one or more other network devices, and the one or more other network devices modifies the TRLA header to identify addresses of the one or more other network devices.

18. The system of claim 15 , wherein the TRLA header is added after a hop-by-hop header in the IPv6 packet.

19. The system of claim 15 , wherein the second network device receives the IPv4 packet, extracts the IPv6 packet from the IPv4 packet, and sends the IPv6 packet to another network device.

20. The system of claim 15 , wherein the IPv6 packet and the second version of the IPv6 packet include different information in at least one header of the IPv6 packet.

Assignments (17)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 059912/0097 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
CHANGE OF NAME Recorded Jun 19, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046393/0009 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037848/0001 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037847/0843 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 037848/0210 →