Method and apparatus for updating best path based on real-time congestion feedback
    1.
    发明授权
    Method and apparatus for updating best path based on real-time congestion feedback 有权
    基于实时拥塞反馈更新最佳路径的方法和装置

    公开(公告)号:US07606159B2

    公开(公告)日:2009-10-20

    申请号:US11216589

    申请日:2005-08-30

    IPC分类号: H04L12/28

    摘要: Techniques are provided for updating best path based on real-time congestion feedback. A method comprises monitoring packets received from an internetworked system, wherein the packets are received on one of a plurality of external interfaces of a networking device; detecting that a received packet includes real-time information that signals a present or pending congestion condition on a path from the external interfaces of the networking device to the internetworked system; notifying a control logic of the real-time information; receiving from the control logic control information defining a change in one or more paths from the external interfaces to the internetworked system; and changing the one or more paths from the external interfaces to the internetworked system. Examining ingress traffic on external interfaces of an internetworked system can cause changes to routes, routing policies and PBRs in routers of the first internetworked system in response to real-time congestion.

    摘要翻译: 提供了基于实时拥塞反馈来更新最佳路径的技术。 一种方法包括监视从互联网络系统接收的分组,其中分组在网络设备的多个外部接口之一上被接收; 检测所接收的分组包括实时信息,所述实时信息表示从所述网络设备的外部接口到所述互联网络系统的路径上的当前或未完成拥塞状况; 通知实时信息的控制逻辑; 从控制逻辑控制信息接收定义从外部接口到互联网系统的一个或多个路径的变化; 并将一个或多个路径从外部接口改变为互联网络系统。 检查互联网络系统的外部接口上的入口流量可能会导致第一个互联网络系统的路由器中的路由,路由策略和PBR的更改,以响应实时拥塞。

    Method and apparatus for updating best path based on real-time congestion feedback
    2.
    发明申请
    Method and apparatus for updating best path based on real-time congestion feedback 有权
    基于实时拥塞反馈更新最佳路径的方法和装置

    公开(公告)号:US20070047446A1

    公开(公告)日:2007-03-01

    申请号:US11216589

    申请日:2005-08-30

    IPC分类号: H04L12/26 H04L12/56

    摘要: Techniques are provided for updating best path based on real-time congestion feedback. A method comprises monitoring packets received from an internetworked system, wherein the packets are received on one of a plurality of external interfaces of a networking device; detecting that a received packet includes real-time information that signals a present or pending congestion condition on a path from the external interfaces of the networking device to the internetworked system; notifying a control logic of the real-time information; receiving from the control logic control information defining a change in one or more paths from the external interfaces to the internetworked system; and changing the one or more paths from the external interfaces to the internetworked system. Examining ingress traffic on external interfaces of an internetworked system can cause changes to routes, routing policies and PBRs in routers of the first internetworked system in response to real-time congestion.

    摘要翻译: 提供了基于实时拥塞反馈来更新最佳路径的技术。 一种方法包括监视从互联网络系统接收的分组,其中分组在网络设备的多个外部接口之一上被接收; 检测所接收的分组包括实时信息,所述实时信息表示从所述网络设备的外部接口到所述互联网络系统的路径上的当前或未完成拥塞状况; 通知实时信息的控制逻辑; 从控制逻辑控制信息接收定义从外部接口到互联网系统的一个或多个路径的变化; 并将一个或多个路径从外部接口改变为互联网络系统。 检查互联网络系统的外部接口上的入口流量可能会导致第一个互联网络系统的路由器中的路由,路由策略和PBR的更改,以响应实时拥塞。

    Method and apparatus for automatically optimizing routing operations at the edge of a network
    3.
    发明授权
    Method and apparatus for automatically optimizing routing operations at the edge of a network 有权
    用于自动优化网络边缘的路由操作的方法和装置

    公开(公告)号:US08073968B1

    公开(公告)日:2011-12-06

    申请号:US10980550

    申请日:2004-11-03

    IPC分类号: G06F15/173 G06F15/16

    摘要: An Optimized Edge Routing (OER) technique provides efficiently data routing at the edge of a network or subnetwork. The technique employs a Master node that manages a set of border nodes located at the edge of the network or subnetwork. The Master node may be a stand-alone network management node or may be incorporated into a network node, such as a border node. Unlike prior implementations, the Master node instructs the border nodes to dynamically acquire (“learn”) prefixes of incoming and outgoing data flows and to selectively filter a set of learned address prefixes whose corresponding data flows match a predetermined set of criteria. The criteria may be based on routing metrics other than, or in addition to, conventional cost-based or distance-based metrics. Further, the criteria may include a set of filtering parameters that may be reconfigured, e.g., by the Master node, from time to time. Using the learned prefixes filtered by the border nodes, the Master node can distribute network traffic and utilize network bandwidth more efficiently than conventionally done.

    摘要翻译: 优化的边缘路由(OER)技术可在网络或子网的边缘高效地提供数据路由。 该技术采用主节点来管理位于网络或子网边缘的一组边界节点。 主节点可以是独立的网络管理节点,或者可以并入到诸如边界节点的网络节点中。 与先前的实现不同,主节点指示边界节点动态地获取(“学习”)入局和出站数据流的前缀,并且选择性地过滤一组学习的地址前缀,其相应的数据流与预定标准集匹配。 该标准可以基于除了常规的基于成本或基于距离的度量之外的除了或附加的路由度量。 此外,标准可以包括可以例如由主节点不时地重新配置的一组过滤参数。 使用由边界节点过滤的学习前缀,主节点可以比传统方式更高效地分配网络流量并利用网络带宽。

    Detecting network denial of service attacks
    4.
    发明授权
    Detecting network denial of service attacks 有权
    检测网络拒绝服务攻击

    公开(公告)号:US07266754B2

    公开(公告)日:2007-09-04

    申请号:US10641494

    申请日:2003-08-14

    IPC分类号: H03M13/00

    摘要: A method for detecting a suspicious packet flow in a packet-switched network comprises the computer-implemented step of receiving a first packet in which the SYN bit but not the ACK or RST bit of the packet's TCP header is set. If a specified first time has elapsed, a packet counter associated with the destination address of the flow is incremented. A determination as to whether the packet counter is greater than a specified threshold values is made. If the packet counter is greater than the threshold value, a notification message is generated. In one embodiment, information identifying a packet flow is aggregated to an aggregation cache based on the destination address of the flow.

    摘要翻译: 用于检测分组交换网络中的可疑分组流的方法包括计算机实现的步骤,用于接收其中设置了该分组的TCP报头的SYN位而不是ACK或RST位的第一分组。 如果指定的第一次已经过去,则与流的目的地地址相关联的分组计数器递增。 确定分组计数器是否大于指定的阈值。 如果分组计数器大于阈值,则生成通知消息。 在一个实施例中,基于流的目的地地址将标识分组流的信息聚合到聚合高速缓存。

    Detecting network denial of service attacks
    5.
    发明申请
    Detecting network denial of service attacks 有权
    检测网络拒绝服务攻击

    公开(公告)号:US20050039104A1

    公开(公告)日:2005-02-17

    申请号:US10641494

    申请日:2003-08-14

    IPC分类号: H03M13/00 H04L29/06

    摘要: A method for detecting a suspicious packet flow in a packet-switched network comprises the computer-implemented step of receiving a first packet in which the SYN bit but not the ACK or RST bit of the packet's TCP header is set. If a specified first time has elapsed, a packet counter associated with the destination address of the flow is incremented. A determination as to whether the packet counter is greater than a specified threshold values is made. If the packet counter is greater than the threshold value, a notification message is generated. In one embodiment, information identifying a packet flow is aggregated to an aggregation cache based on the destination address of the flow.

    摘要翻译: 用于检测分组交换网络中的可疑分组流的方法包括计算机实现的步骤,用于接收其中设置了该分组的TCP报头的SYN位而不是ACK或RST位的第一分组。 如果指定的第一次已经过去,则与流的目的地地址相关联的分组计数器递增。 确定分组计数器是否大于指定的阈值。 如果分组计数器大于阈值,则生成通知消息。 在一个实施例中,基于流的目的地地址将标识分组流的信息聚合到聚合高速缓存。

    ROUTE OPTIMIZATION OF SERVICES PROVIDED BY ONE OR MORE SERVICE PROVIDERS FOR COMBINED LINKS
    6.
    发明申请
    ROUTE OPTIMIZATION OF SERVICES PROVIDED BY ONE OR MORE SERVICE PROVIDERS FOR COMBINED LINKS 有权
    由一个或多个服务提供商为组合链接提供的服务的路由优化

    公开(公告)号:US20120166360A1

    公开(公告)日:2012-06-28

    申请号:US13409883

    申请日:2012-03-01

    IPC分类号: G06Q50/32

    摘要: In one embodiment, two or more links, coupled to a first service provider (SP) that charges a price for utilization of services according to a first pricing structure, are combined to form a single virtual combined link. Each of the two or more links of the virtual combined link and one or more other links, coupled to a second SP that charges a price for utilization of services according to a second pricing structure, are monitored to obtain link data. The link data for the two of more links of the virtual combined link is merged to form link data for the virtual combined link. Data distribution among the virtual combined link and the one or more other links is optimized to distribute data among the virtual combined link and the one or more other links in a manner that minimizes cost.

    摘要翻译: 在一个实施例中,耦合到根据第一定价结构为服务的价格收费的第一服务提供商(SP)的两个或多个链路被组合以形成单个虚拟组合链路。 监视虚拟组合链路和一个或多个其他链路的两个或更多个链路中的每一个,耦合到根据第二定价结构为服务的价格收费的第二SP,以获得链路数据。 虚拟组合链接的两个链接的链接数据被合并以形成用于虚拟组合链接的链接数据。 优化虚拟组合链路和一个或多个其他链路之间的数据分布,以便以最小化成本的方式在虚拟组合链路和一个或多个其他链路之间分发数据。

    System and method for increasing granularity of prefix control in a computer network
    7.
    发明授权
    System and method for increasing granularity of prefix control in a computer network 有权
    在计算机网络中增加前缀控制的粒度的系统和方法

    公开(公告)号:US08098578B1

    公开(公告)日:2012-01-17

    申请号:US11337195

    申请日:2006-01-20

    IPC分类号: H04L12/26

    摘要: A technique dynamically increases the granularity of prefix control in a computer network. According to the novel technique, a routing table is populated with one or more reachable prefixes, e.g., learned or configured prefixes, and performance characteristics (e.g., bandwidth, cost, delay, etc.) of the prefixes are monitored. Upon determining that a need exists for more granular prefix control (i.e., smaller prefixes), one or more boundaries may be determined upon which to divide one or more of the prefixes based on the monitored characteristics and/or need. Once the one or more boundaries are determined, the one or more prefixes may be “split” accordingly, e.g., by injecting more specific prefixes into the routing table, thus providing more granular prefix control (i.e., by controlling the split prefixes).

    摘要翻译: 一种技术动态地增加了计算机网络中前缀控制的粒度。 根据新颖技术,路由表被填充有一个或多个可达到的前缀,例如学习或配置的前缀,并且监视前缀的性能特征(例如,带宽,成本,延迟等)。 在确定需要存在更多的粒度前缀控制(即,较小的前缀)时,可以根据所监视的特性和/或需要确定一个或多个前缀来划分一个或多个前缀的一个或多个边界。 一旦确定了一个或多个边界,则一个或多个前缀可以相应地“分割”,例如通过将更多的特定前缀注入到路由表中,从而提供更细粒度的前缀控制(即,通过控制分割前缀)。

    INTEGRATING SECURITY SERVER POLICIES WITH OPTIMIZED ROUTING CONTROL
    8.
    发明申请
    INTEGRATING SECURITY SERVER POLICIES WITH OPTIMIZED ROUTING CONTROL 有权
    整合安全性服务器政策与优化路由控制

    公开(公告)号:US20100054241A1

    公开(公告)日:2010-03-04

    申请号:US12199496

    申请日:2008-08-27

    IPC分类号: H04L12/28

    摘要: In one embodiment, a first set of one or more control policies at a control server of a network domain may be transmitted to a routing master controller of the network domain, which uses a second set of one or more traffic policies to determine optimal paths for directing traffic through the domain. The routing master controller may then generate a third set of one or more integrated policies based on the first and second sets of policies, e.g., based on the knowledge and policies of both the control server and the routing master controller.

    摘要翻译: 在一个实施例中,在网络域的控制服务器处的第一组一个或多个控制策略可以被发送到网络域的路由主控制器,网络域的路由主控制器使用第二组一个或多个流量策略来确定用于 引导流量通过域。 然后,例如基于控制服务器和路由主控制器的知识和策略,路由主控制器可以基于第一组策略和第二组策略生成第一组一个或多个集成策略。

    EVENT TRIGGERED TRACEROUTE FOR OPTIMIZED ROUTING IN A COMPUTER NETWORK
    9.
    发明申请
    EVENT TRIGGERED TRACEROUTE FOR OPTIMIZED ROUTING IN A COMPUTER NETWORK 有权
    在计算机网络中优化路由的事件触发跟踪

    公开(公告)号:US20090198832A1

    公开(公告)日:2009-08-06

    申请号:US12023099

    申请日:2008-01-31

    IPC分类号: G06F15/173

    摘要: In one embodiment, a network device (e.g., a master controller) may detect an event on a current path in a computer network from a local network domain to a destination address prefix of a remote domain. In response, the device may dynamically (e.g., intelligently) determine a trace target destination address within the destination address prefix, and may perform (or request performance of) a Traceroute of the current path and a selection of alternate paths in the network from the local network domain to the trace target, where the Traceroute is adapted to obtain per-hop measurements along the respective traced path. The measurements may then be stored, for example, to be used for optimal path selection, fault identification reporting, etc.

    摘要翻译: 在一个实施例中,网络设备(例如,主控制器)可以检测计算机网络中的当前路径上的从本地网络域到远程域的目的地地址前缀的事件。 作为响应,设备可以动态地(例如,智能地)确定目的地地址前缀内的跟踪目的地目的地地址,并且可以执行(或请求执行)当前路径的Traceroute和网络中的备选路径的选择 本地网络域到跟踪目标,其中Traceroute适用于沿着相应的跟踪路径获取每跳测量。 然后可以存储测量结果,例如用于最佳路径选择,故障识别报告等。

    IDENTIFYING THE BEST SERVICE PROVIDER LINK FOR PERFORMANCE ROUTING
    10.
    发明申请
    IDENTIFYING THE BEST SERVICE PROVIDER LINK FOR PERFORMANCE ROUTING 有权
    识别性能路由的最佳服务提供商链接

    公开(公告)号:US20130336167A1

    公开(公告)日:2013-12-19

    申请号:US13525586

    申请日:2012-06-18

    IPC分类号: H04L12/28 H04L12/56

    CPC分类号: H04L45/04

    摘要: In one embodiment, a method includes obtaining a first packet included in a flow to be forwarded to a border router, and replicating the first packet to create a duplicate. The first packet is forwarded onto a first set of links, and the duplicate is forwarded onto a second set of links, to the border router. First information relating to the first packet and the first set of links, and second information relating to the duplicate and the second set of links, is obtained. The first information and the second information are used to determine whether to forward the flow on the first set of links. The first set of links is used to forward the flow if it is determined that the first set of links is to be used to forward the flow, otherwise the second set of links is used to forward the flow.

    摘要翻译: 在一个实施例中,一种方法包括获得包含在要转发到边界路由器的流中的第一分组,以及复制第一分组以创建副本。 第一个分组被转发到第一组链路上,并且将该副本转发到第二组链路到边界路由器。 获得与第一分组和第一组链接有关的第一信息,以及与重复和第二组链接有关的第二信息。 第一信息和第二信息用于确定是否转发第一组链路上的流。 如果确定第一组链接用于转发流,则第一组链接用于转发流,否则第二组链接用于转发流。