Link grouping for route optimization
    21.
    发明授权
    Link grouping for route optimization 有权
    路由优化的链路分组

    公开(公告)号:US09015299B1

    公开(公告)日:2015-04-21

    申请号:US11336734

    申请日:2006-01-20

    申请人: Pritam Shah

    发明人: Pritam Shah

    CPC分类号: H04L29/06 H04L69/14 Y02D50/30

    摘要: A technique manages route optimization for one or more groups of links in a computer network. According to the novel technique, each group or “subgroup” of links comprises one or more links, wherein the group may be configured based on various measures, such as, e.g., connectivity (physical or virtual), policies to be applied, per-prefix, per-application (e.g., Internet traffic or voice over IP, VoIP), geographic location, and/or quality-based (e.g., primary links and secondary/backup links). One or more policies may be defined for the groups of links (i.e., where these group policies are to be applied to the group as a whole), in addition to policies that may be defined for individual to links and/or prefixes. Once the link groups are established, traffic over the groups of links (e.g., routes to reachable address prefixes) may be managed and optimized according to the group policies, such as in accordance with Optimized Edge Routing (OER) techniques.

    摘要翻译: 一种技术管理计算机网络中一个或多个链路组的路由优化。 根据新颖技术,链路的每个组或“子组”包括一个或多个链路,其中可以基于各种措施来配置组,例如,连接(物理或虚拟),要应用的策略, 前缀,每个应用程序(例如,Internet流量或IP语音,VoIP),地理位置和/或基于质量(例如,主链接和辅助/备用链路)。 除了可以为个人链接和/或前缀定义的策略之外,可以为链路组定义一个或多个策略(即,将这些组策略应用于整个组)。 一旦建立了链路组,就可以根据组策略(例如,根据优化边缘路由(OER)技术)来管理和优化链路组上的流量(例如,到可到达地址前缀的路由)。

    Technique for using OER with an ECT solution for multi-homed sites
    22.
    发明授权
    Technique for using OER with an ECT solution for multi-homed sites 有权
    使用OER与多宿主站点的ECT解决方案的技术

    公开(公告)号:US08706883B2

    公开(公告)日:2014-04-22

    申请号:US13495845

    申请日:2012-06-13

    IPC分类号: G06F15/173

    摘要: In one embodiment, a plurality of spoke-to-hub virtual private network (VPN) tunnels are established from a spoke router located at an edge of a spoke network to a hub network. The spoke router is configured as an optimized edge routing (OER) node. The spoke router monitors a network statistic for each of a plurality of prefixes on each of the plurality of spoke-to-hub VPN tunnels. The monitored network statistic is analyzed to determine whether a distribution of traffic between the spoke network and the hub network can be optimized. In the event the distribution of traffic between the spoke network and the hub network can be optimized, traffic is redistributed on a per-prefix basis among the plurality of spoke-to-hub VPN tunnels based on the monitored network statistic, such that at least a portion of the traffic is routed over each of the plurality of spoke-to-hub VPN tunnels.

    摘要翻译: 在一个实施例中,从位于分支网络的边缘的分支路由器建立到集线器网络的多个辐射对集线器虚拟专用网络(VPN)隧道。 分支路由器配置为优化边缘路由(OER)节点。 所述分支路由器监视所述多个辐照到中心VPN隧道中的每一个上的多个前缀中的每一个的网络统计信息。 分析监控的网络统计信息,以确定辐射网络和集线器网络之间的流量分布是否可以优化。 在可以优化分布式网络和集线器网络之间的流量分配的情况下,基于所监视的网络统计信息,在多个辐射对中心VPN隧道之间的每个前缀基础上重新分配流量,使得至少 一部分业务被路由到多个辐对方VPN隧道中的每一个上。

    Dynamically right-sizing prefixes for network and application performance
    23.
    发明授权
    Dynamically right-sizing prefixes for network and application performance 有权
    用于网络和应用程序性能的动态正确的前缀

    公开(公告)号:US08687621B2

    公开(公告)日:2014-04-01

    申请号:US12478343

    申请日:2009-06-04

    IPC分类号: H04L12/28 G06F15/16

    摘要: In one embodiment, performance parameters may be determined for each of a plurality of network address prefixes in a computer network. Based on the respective performance parameters, the prefixes may be resized through at least one of consolidation of adjacent prefixes and splitting of prefixes, and traffic may then be routed in the computer network based on the resized prefixes.

    摘要翻译: 在一个实施例中,可以为计算机网络中的多个网络地址前缀中的每一个确定性能参数。 基于相应的性能参数,可以通过相邻前缀的合并和前缀的分割中的至少一个来调整前缀,并且然后可以基于调整大小的前缀在计算机网络中路由业务。

    Method and apparatus for automatically optimizing routing operations at the edge of a network
    24.
    发明授权
    Method and apparatus for automatically optimizing routing operations at the edge of a network 有权
    用于自动优化网络边缘的路由操作的方法和装置

    公开(公告)号:US08073968B1

    公开(公告)日:2011-12-06

    申请号:US10980550

    申请日:2004-11-03

    IPC分类号: G06F15/173 G06F15/16

    摘要: An Optimized Edge Routing (OER) technique provides efficiently data routing at the edge of a network or subnetwork. The technique employs a Master node that manages a set of border nodes located at the edge of the network or subnetwork. The Master node may be a stand-alone network management node or may be incorporated into a network node, such as a border node. Unlike prior implementations, the Master node instructs the border nodes to dynamically acquire (“learn”) prefixes of incoming and outgoing data flows and to selectively filter a set of learned address prefixes whose corresponding data flows match a predetermined set of criteria. The criteria may be based on routing metrics other than, or in addition to, conventional cost-based or distance-based metrics. Further, the criteria may include a set of filtering parameters that may be reconfigured, e.g., by the Master node, from time to time. Using the learned prefixes filtered by the border nodes, the Master node can distribute network traffic and utilize network bandwidth more efficiently than conventionally done.

    摘要翻译: 优化的边缘路由(OER)技术可在网络或子网的边缘高效地提供数据路由。 该技术采用主节点来管理位于网络或子网边缘的一组边界节点。 主节点可以是独立的网络管理节点,或者可以并入到诸如边界节点的网络节点中。 与先前的实现不同,主节点指示边界节点动态地获取(“学习”)入局和出站数据流的前缀,并且选择性地过滤一组学习的地址前缀,其相应的数据流与预定标准集匹配。 该标准可以基于除了常规的基于成本或基于距离的度量之外的除了或附加的路由度量。 此外,标准可以包括可以例如由主节点不时地重新配置的一组过滤参数。 使用由边界节点过滤的学习前缀,主节点可以比传统方式更高效地分配网络流量并利用网络带宽。

    Detecting network denial of service attacks
    25.
    发明授权
    Detecting network denial of service attacks 有权
    检测网络拒绝服务攻击

    公开(公告)号:US07266754B2

    公开(公告)日:2007-09-04

    申请号:US10641494

    申请日:2003-08-14

    IPC分类号: H03M13/00

    摘要: A method for detecting a suspicious packet flow in a packet-switched network comprises the computer-implemented step of receiving a first packet in which the SYN bit but not the ACK or RST bit of the packet's TCP header is set. If a specified first time has elapsed, a packet counter associated with the destination address of the flow is incremented. A determination as to whether the packet counter is greater than a specified threshold values is made. If the packet counter is greater than the threshold value, a notification message is generated. In one embodiment, information identifying a packet flow is aggregated to an aggregation cache based on the destination address of the flow.

    摘要翻译: 用于检测分组交换网络中的可疑分组流的方法包括计算机实现的步骤,用于接收其中设置了该分组的TCP报头的SYN位而不是ACK或RST位的第一分组。 如果指定的第一次已经过去,则与流的目的地地址相关联的分组计数器递增。 确定分组计数器是否大于指定的阈值。 如果分组计数器大于阈值,则生成通知消息。 在一个实施例中,基于流的目的地地址将标识分组流的信息聚合到聚合高速缓存。

    Route optimization of services provided by one or more service providers for combined links
    26.
    发明申请
    Route optimization of services provided by one or more service providers for combined links 有权
    由一个或多个服务提供商为组合链路提供的服务的路由优化

    公开(公告)号:US20070100776A1

    公开(公告)日:2007-05-03

    申请号:US11336584

    申请日:2006-01-20

    IPC分类号: G06F17/00

    摘要: A technique performs route optimization of services provided by one or more service providers (SPs) for communication links that are combined in a computer network. According to the novel technique, performance characteristics and statistics (“link data”) for two or more combined links are merged to form link data for a single “virtual combined link.” Route optimization techniques (e.g., priority-based route optimization) may then be applied to one or more virtual combined links based on the combined link data, in addition to link data for zero or more conventional single links (physical or virtual). Illustratively, a route optimization technique may be used in accordance with the present invention to efficiently and accurately minimize costs associated with services provided by a plurality of SPs, wherein each SP charges for utilization of its service based on a tiered pricing structure. The tiered pricing structure comprises one or more tiers, wherein each tier correlates to an amount of service provided by the SP and an associated cost.

    摘要翻译: 一种技术对由一个或多个服务提供商(SP)提供的用于组合在计算机网络中的通信链路的服务的路由优化。 根据新技术,将两个或多个组合链路的性能特征和统计(“链路数据”)合并形成单个“虚拟组合链路”的链路数据。 除了零个或多个传统单链路(物理或虚拟)的链路数据之外,路由优化技术(例如,基于优先级的路由优化)可以基于组合的链路数据被应用于一个或多个虚拟组合链路。 说明性地,根据本发明可以使用路由优化技术来有效和准确地最小化与由多个SP提供的服务相关联的成本,其中每个SP基于分层定价结构收费以利用其服务。 分层定价结构包括一个或多个层,其中每个层与由SP提供的服务量和相关联的成本相关。

    Method and apparatus for updating best path based on real-time congestion feedback
    27.
    发明申请
    Method and apparatus for updating best path based on real-time congestion feedback 有权
    基于实时拥塞反馈更新最佳路径的方法和装置

    公开(公告)号:US20070047446A1

    公开(公告)日:2007-03-01

    申请号:US11216589

    申请日:2005-08-30

    IPC分类号: H04L12/26 H04L12/56

    摘要: Techniques are provided for updating best path based on real-time congestion feedback. A method comprises monitoring packets received from an internetworked system, wherein the packets are received on one of a plurality of external interfaces of a networking device; detecting that a received packet includes real-time information that signals a present or pending congestion condition on a path from the external interfaces of the networking device to the internetworked system; notifying a control logic of the real-time information; receiving from the control logic control information defining a change in one or more paths from the external interfaces to the internetworked system; and changing the one or more paths from the external interfaces to the internetworked system. Examining ingress traffic on external interfaces of an internetworked system can cause changes to routes, routing policies and PBRs in routers of the first internetworked system in response to real-time congestion.

    摘要翻译: 提供了基于实时拥塞反馈来更新最佳路径的技术。 一种方法包括监视从互联网络系统接收的分组,其中分组在网络设备的多个外部接口之一上被接收; 检测所接收的分组包括实时信息,所述实时信息表示从所述网络设备的外部接口到所述互联网络系统的路径上的当前或未完成拥塞状况; 通知实时信息的控制逻辑; 从控制逻辑控制信息接收定义从外部接口到互联网系统的一个或多个路径的变化; 并将一个或多个路径从外部接口改变为互联网络系统。 检查互联网络系统的外部接口上的入口流量可能会导致第一个互联网络系统的路由器中的路由,路由策略和PBR的更改,以响应实时拥塞。

    Identifying the best service provider link for performance routing
    28.
    发明授权
    Identifying the best service provider link for performance routing 有权
    确定性能路由的最佳服务提供商链接

    公开(公告)号:US09154403B2

    公开(公告)日:2015-10-06

    申请号:US13525586

    申请日:2012-06-18

    CPC分类号: H04L45/04

    摘要: In one embodiment, a method includes obtaining a first packet included in a flow to be forwarded to a border router, and replicating the first packet to create a duplicate. The first packet is forwarded onto a first set of links, and the duplicate is forwarded onto a second set of links, to the border router. First information relating to the first packet and the first set of links, and second information relating to the duplicate and the second set of links, is obtained. The first information and the second information are used to determine whether to forward the flow on the first set of links. The first set of links is used to forward the flow if it is determined that the first set of links is to be used to forward the flow, otherwise the second set of links is used to forward the flow.

    摘要翻译: 在一个实施例中,一种方法包括获得包含在要转发到边界路由器的流中的第一分组,以及复制第一分组以创建副本。 第一个分组被转发到第一组链路上,并且将该副本转发到第二组链路到边界路由器。 获得与第一分组和第一组链接有关的第一信息,以及与重复和第二组链接有关的第二信息。 第一信息和第二信息用于确定是否转发第一组链路上的流。 如果确定第一组链接用于转发流,则第一组链接用于转发流,否则第二组链接用于转发流。

    Event triggered traceroute for optimized routing in a computer network
    29.
    发明授权
    Event triggered traceroute for optimized routing in a computer network 有权
    事件触发traceroute在计算机网络中优化路由

    公开(公告)号:US08880724B2

    公开(公告)日:2014-11-04

    申请号:US12023099

    申请日:2008-01-31

    摘要: In one embodiment, a network device (e.g., a master controller) may detect an event on a current path in a computer network from a local network domain to a destination address prefix of a remote domain. In response, the device may dynamically (e.g., intelligently) determine a trace target destination address within the destination address prefix, and may perform (or request performance of) a Traceroute of the current path and a selection of alternate paths in the network from the local network domain to the trace target, where the Traceroute is adapted to obtain per-hop measurements along the respective traced path. The measurements may then be stored, for example, to be used for optimal path selection, fault identification reporting, etc.

    摘要翻译: 在一个实施例中,网络设备(例如,主控制器)可以检测计算机网络中的当前路径上的从本地网络域到远程域的目的地地址前缀的事件。 作为响应,设备可以动态地(例如,智能地)确定目的地地址前缀内的跟踪目的地目的地地址,并且可以执行(或请求执行)当前路径的Traceroute和网络中的备选路径的选择 本地网络域到跟踪目标,其中Traceroute适用于沿着相应的跟踪路径获取每跳测量。 然后可以存储测量结果,例如用于最佳路径选择,故障识别报告等。

    Route optimization of services provided by one or more service providers for combined links
    30.
    发明授权
    Route optimization of services provided by one or more service providers for combined links 有权
    由一个或多个服务提供商为组合链路提供的服务的路由优化

    公开(公告)号:US08874490B2

    公开(公告)日:2014-10-28

    申请号:US13409883

    申请日:2012-03-01

    IPC分类号: G06Q99/00 H04L12/14 G06Q30/02

    摘要: In one embodiment, two or more links, coupled to a first service provider (SP) that charges a price for utilization of services according to a first pricing structure, are combined to form a single virtual combined link. Each of the two or more links of the virtual combined link and one or more other links, coupled to a second SP that charges a price for utilization of services according to a second pricing structure, are monitored to obtain link data. The link data for the two of more links of the virtual combined link is merged to form link data for the virtual combined link. Data distribution among the virtual combined link and the one or more other links is optimized to distribute data among the virtual combined link and the one or more other links in a manner that minimizes cost.

    摘要翻译: 在一个实施例中,耦合到根据第一定价结构为服务的价格收费的第一服务提供商(SP)的两个或多个链路被组合以形成单个虚拟组合链路。 监视虚拟组合链路和一个或多个其他链路的两个或更多个链路中的每一个,耦合到根据第二定价结构为服务的价格收费的第二SP,以获得链路数据。 虚拟组合链接的两个链接的链接数据被合并以形成用于虚拟组合链接的链接数据。 优化虚拟组合链路和一个或多个其他链路之间的数据分布,以便以最小化成本的方式在虚拟组合链路和一个或多个其他链路之间分发数据。