Method and apparatus for automatically optimizing routing operations at the edge of a network
    1.
    发明授权
    Method and apparatus for automatically optimizing routing operations at the edge of a network 有权
    用于自动优化网络边缘的路由操作的方法和装置

    公开(公告)号:US08073968B1

    公开(公告)日:2011-12-06

    申请号:US10980550

    申请日:2004-11-03

    IPC分类号: G06F15/173 G06F15/16

    摘要: An Optimized Edge Routing (OER) technique provides efficiently data routing at the edge of a network or subnetwork. The technique employs a Master node that manages a set of border nodes located at the edge of the network or subnetwork. The Master node may be a stand-alone network management node or may be incorporated into a network node, such as a border node. Unlike prior implementations, the Master node instructs the border nodes to dynamically acquire (“learn”) prefixes of incoming and outgoing data flows and to selectively filter a set of learned address prefixes whose corresponding data flows match a predetermined set of criteria. The criteria may be based on routing metrics other than, or in addition to, conventional cost-based or distance-based metrics. Further, the criteria may include a set of filtering parameters that may be reconfigured, e.g., by the Master node, from time to time. Using the learned prefixes filtered by the border nodes, the Master node can distribute network traffic and utilize network bandwidth more efficiently than conventionally done.

    摘要翻译: 优化的边缘路由(OER)技术可在网络或子网的边缘高效地提供数据路由。 该技术采用主节点来管理位于网络或子网边缘的一组边界节点。 主节点可以是独立的网络管理节点,或者可以并入到诸如边界节点的网络节点中。 与先前的实现不同,主节点指示边界节点动态地获取(“学习”)入局和出站数据流的前缀,并且选择性地过滤一组学习的地址前缀,其相应的数据流与预定标准集匹配。 该标准可以基于除了常规的基于成本或基于距离的度量之外的除了或附加的路由度量。 此外,标准可以包括可以例如由主节点不时地重新配置的一组过滤参数。 使用由边界节点过滤的学习前缀,主节点可以比传统方式更高效地分配网络流量并利用网络带宽。

    Method and apparatus for updating best path based on real-time congestion feedback
    2.
    发明授权
    Method and apparatus for updating best path based on real-time congestion feedback 有权
    基于实时拥塞反馈更新最佳路径的方法和装置

    公开(公告)号:US07606159B2

    公开(公告)日:2009-10-20

    申请号:US11216589

    申请日:2005-08-30

    IPC分类号: H04L12/28

    摘要: Techniques are provided for updating best path based on real-time congestion feedback. A method comprises monitoring packets received from an internetworked system, wherein the packets are received on one of a plurality of external interfaces of a networking device; detecting that a received packet includes real-time information that signals a present or pending congestion condition on a path from the external interfaces of the networking device to the internetworked system; notifying a control logic of the real-time information; receiving from the control logic control information defining a change in one or more paths from the external interfaces to the internetworked system; and changing the one or more paths from the external interfaces to the internetworked system. Examining ingress traffic on external interfaces of an internetworked system can cause changes to routes, routing policies and PBRs in routers of the first internetworked system in response to real-time congestion.

    摘要翻译: 提供了基于实时拥塞反馈来更新最佳路径的技术。 一种方法包括监视从互联网络系统接收的分组,其中分组在网络设备的多个外部接口之一上被接收; 检测所接收的分组包括实时信息,所述实时信息表示从所述网络设备的外部接口到所述互联网络系统的路径上的当前或未完成拥塞状况; 通知实时信息的控制逻辑; 从控制逻辑控制信息接收定义从外部接口到互联网系统的一个或多个路径的变化; 并将一个或多个路径从外部接口改变为互联网络系统。 检查互联网络系统的外部接口上的入口流量可能会导致第一个互联网络系统的路由器中的路由,路由策略和PBR的更改,以响应实时拥塞。

    Detecting network denial of service attacks
    3.
    发明授权
    Detecting network denial of service attacks 有权
    检测网络拒绝服务攻击

    公开(公告)号:US07266754B2

    公开(公告)日:2007-09-04

    申请号:US10641494

    申请日:2003-08-14

    IPC分类号: H03M13/00

    摘要: A method for detecting a suspicious packet flow in a packet-switched network comprises the computer-implemented step of receiving a first packet in which the SYN bit but not the ACK or RST bit of the packet's TCP header is set. If a specified first time has elapsed, a packet counter associated with the destination address of the flow is incremented. A determination as to whether the packet counter is greater than a specified threshold values is made. If the packet counter is greater than the threshold value, a notification message is generated. In one embodiment, information identifying a packet flow is aggregated to an aggregation cache based on the destination address of the flow.

    摘要翻译: 用于检测分组交换网络中的可疑分组流的方法包括计算机实现的步骤,用于接收其中设置了该分组的TCP报头的SYN位而不是ACK或RST位的第一分组。 如果指定的第一次已经过去,则与流的目的地地址相关联的分组计数器递增。 确定分组计数器是否大于指定的阈值。 如果分组计数器大于阈值,则生成通知消息。 在一个实施例中,基于流的目的地地址将标识分组流的信息聚合到聚合高速缓存。

    Method and apparatus for updating best path based on real-time congestion feedback
    4.
    发明申请
    Method and apparatus for updating best path based on real-time congestion feedback 有权
    基于实时拥塞反馈更新最佳路径的方法和装置

    公开(公告)号:US20070047446A1

    公开(公告)日:2007-03-01

    申请号:US11216589

    申请日:2005-08-30

    IPC分类号: H04L12/26 H04L12/56

    摘要: Techniques are provided for updating best path based on real-time congestion feedback. A method comprises monitoring packets received from an internetworked system, wherein the packets are received on one of a plurality of external interfaces of a networking device; detecting that a received packet includes real-time information that signals a present or pending congestion condition on a path from the external interfaces of the networking device to the internetworked system; notifying a control logic of the real-time information; receiving from the control logic control information defining a change in one or more paths from the external interfaces to the internetworked system; and changing the one or more paths from the external interfaces to the internetworked system. Examining ingress traffic on external interfaces of an internetworked system can cause changes to routes, routing policies and PBRs in routers of the first internetworked system in response to real-time congestion.

    摘要翻译: 提供了基于实时拥塞反馈来更新最佳路径的技术。 一种方法包括监视从互联网络系统接收的分组,其中分组在网络设备的多个外部接口之一上被接收; 检测所接收的分组包括实时信息,所述实时信息表示从所述网络设备的外部接口到所述互联网络系统的路径上的当前或未完成拥塞状况; 通知实时信息的控制逻辑; 从控制逻辑控制信息接收定义从外部接口到互联网系统的一个或多个路径的变化; 并将一个或多个路径从外部接口改变为互联网络系统。 检查互联网络系统的外部接口上的入口流量可能会导致第一个互联网络系统的路由器中的路由,路由策略和PBR的更改,以响应实时拥塞。

    Detecting network denial of service attacks
    5.
    发明申请
    Detecting network denial of service attacks 有权
    检测网络拒绝服务攻击

    公开(公告)号:US20050039104A1

    公开(公告)日:2005-02-17

    申请号:US10641494

    申请日:2003-08-14

    IPC分类号: H03M13/00 H04L29/06

    摘要: A method for detecting a suspicious packet flow in a packet-switched network comprises the computer-implemented step of receiving a first packet in which the SYN bit but not the ACK or RST bit of the packet's TCP header is set. If a specified first time has elapsed, a packet counter associated with the destination address of the flow is incremented. A determination as to whether the packet counter is greater than a specified threshold values is made. If the packet counter is greater than the threshold value, a notification message is generated. In one embodiment, information identifying a packet flow is aggregated to an aggregation cache based on the destination address of the flow.

    摘要翻译: 用于检测分组交换网络中的可疑分组流的方法包括计算机实现的步骤,用于接收其中设置了该分组的TCP报头的SYN位而不是ACK或RST位的第一分组。 如果指定的第一次已经过去,则与流的目的地地址相关联的分组计数器递增。 确定分组计数器是否大于指定的阈值。 如果分组计数器大于阈值,则生成通知消息。 在一个实施例中,基于流的目的地地址将标识分组流的信息聚合到聚合高速缓存。

    Method and apparatus for route optimization enforcement and verification
    6.
    发明授权
    Method and apparatus for route optimization enforcement and verification 有权
    路由优化实施和验证的方法和装置

    公开(公告)号:US08456987B1

    公开(公告)日:2013-06-04

    申请号:US11297280

    申请日:2005-12-08

    摘要: A technique dynamically enforces a best exit selection for a controlled prefix based on policies and real-time performance statistics in a computer network. A Master Controller (e.g., an Optimized Edge Routing, OER, Master Controller) of an autonomous system (AS) in the network selects a best exit from the AS for the controlled prefix, and conveys the selection to a border router having the selected exit. In response, the border router performs a parent lookup to determine whether the controlled prefix is reachable via the best exit. If so, the border router influences routing in the AS for the controlled prefix through the best exit by, e.g., injecting routes or modifying metrics of existing routes. The Master Controller (or border router) then verifies that the routes for the controlled prefix traverse the selected best exit. Notably, if a route does not traverse the selected best exit, the border router may try to influence the route again or remove the influence.

    摘要翻译: 一种技术基于计算机网络中的策略和实时性能统计信息,动态地实施受控前缀的最佳出口选择。 网络中的自治系统(AS)的主控制器(例如,优化边缘路由,OER,主控制器)为控制的前缀选择来自AS的最佳出口,并将选择传送到具有所选出口的边界路由器 。 作为响应,边界路由器执行父查找以确定受控前缀是否可通过最佳出口访问。 如果是这样,边界路由器通过例如注入路由或修改现有路由的度量,通过最佳出口来影响AS中针对受控前缀的路由。 主控制器(或边界路由器)然后验证受控前缀的路由遍历所选的最佳出口。 值得注意的是,如果一个路由没有经过所选择的最佳出口,边界路由器可能会尝试再次影响该路由或者消除影响。

    Method and apparatus for mobility agent recovery
    7.
    发明授权
    Method and apparatus for mobility agent recovery 有权
    移动剂回收的方法和装置

    公开(公告)号:US08767527B2

    公开(公告)日:2014-07-01

    申请号:US13091813

    申请日:2011-04-21

    IPC分类号: H04J1/16 G06F15/16

    CPC分类号: H04W8/12 H04W80/04

    摘要: Techniques for recovering Mobile Internet Protocol (IP) session(s) of a mobility agent in a Mobile IP network are described herein. In one embodiment of the invention, for each mobility session associated with a mobility agent, the mobility agent distributively backs up mobility agent specific information to the mobility agent peer associated with that mobility session. The mobility agent specific information is not used by the mobility agent peer. Upon the mobility agent inadvertently losing at least one mobility session, the mobility agent recovers the stored mobility agent specific information associated with those sessions from the mobility agent peers respectively associated with those sessions. Other methods and apparatuses are also described.

    摘要翻译: 本文描述了用于恢复移动IP网络中的移动性代理的移动因特网协议(IP)会话的技术。 在本发明的一个实施例中,对于与移动代理相关联的每个移动性会话,移动性代理将移动性代理特定信息分散地备份到与该移动性会话相关联的移动性代理对等体。 移动代理对等体不使用移动代理特定信息。 在移动代理无意中丢失至少一个移动性会话时,移动性代理从与这些会话相关联的移动性代理对等体恢复与这些会话相关联的所存储的移动代理特定信息。 还描述了其它方法和装置。

    Method and apparatus for mobility agent recovery
    9.
    发明授权
    Method and apparatus for mobility agent recovery 有权
    移动剂回收的方法和装置

    公开(公告)号:US07948871B2

    公开(公告)日:2011-05-24

    申请号:US12055311

    申请日:2008-03-26

    IPC分类号: H04J1/16 G06F15/16

    CPC分类号: H04W8/12 H04W80/04

    摘要: Techniques for recovering Mobile Internet Protocol (IP) session(s) of a mobility agent in a Mobile IP network are described herein. In one embodiment of the invention, for each mobility session associated with a mobility agent, the mobility agent distributively backs up mobility agent specific information to the mobility agent peer associated with that mobility session. The mobility agent specific information is not used by the mobility agent peer. Upon the mobility agent inadvertently losing at least one mobility session, the mobility agent recovers the stored mobility agent specific information associated with those sessions from the mobility agent peers respectively associated with those sessions. Other methods and apparatuses are also described.

    摘要翻译: 本文描述了用于恢复移动IP网络中的移动性代理的移动因特网协议(IP)会话的技术。 在本发明的一个实施例中,对于与移动代理相关联的每个移动性会话,移动性代理将移动性代理特定信息分散地备份到与该移动性会话相关联的移动性代理对等体。 移动代理对等体不使用移动代理特定信息。 在移动代理无意中丢失至少一个移动性会话时,移动性代理从与这些会话相关联的移动性代理对等体恢复与这些会话相关联的所存储的移动代理特定信息。 还描述了其它方法和装置。

    Method and Apparatus for Mobility Agent Recovery
    10.
    发明申请
    Method and Apparatus for Mobility Agent Recovery 有权
    移动代理恢复的方法和装置

    公开(公告)号:US20090248708A1

    公开(公告)日:2009-10-01

    申请号:US12055311

    申请日:2008-03-26

    IPC分类号: G06F17/30

    CPC分类号: H04W8/12 H04W80/04

    摘要: Techniques for recovering Mobile Internet Protocol (IP) session(s) of a mobility agent in a Mobile IP network are described herein. In one embodiment of the invention, for each mobility session associated with a mobility agent, the mobility agent distributively backs up mobility agent specific information to the mobility agent peer associated with that mobility session. The mobility agent specific information is not used by the mobility agent peer. Upon the mobility agent inadvertently losing at least one mobility session, the mobility agent recovers the stored mobility agent specific information associated with those sessions from the mobility agent peers respectively associated with those sessions. Other methods and apparatuses are also described.

    摘要翻译: 本文描述了用于恢复移动IP网络中的移动性代理的移动因特网协议(IP)会话的技术。 在本发明的一个实施例中,对于与移动代理相关联的每个移动性会话,移动性代理将移动性代理特定信息分散地备份到与该移动性会话相关联的移动性代理对等体。 移动代理对等体不使用移动代理特定信息。 在移动代理无意中丢失至少一个移动性会话时,移动性代理从与这些会话相关联的移动性代理对等体恢复与这些会话相关联的所存储的移动代理特定信息。 还描述了其它方法和装置。