Updating ingress filters of ingress nodes providing load balancing functionality

Through the collaborative work of the ingress node and the security node, the security functions of the ingress filter and the security node are utilized to effectively block malicious services and load balancing forwarding, solving the problems of computing resource consumption and network security in the prior art.

CN119945699APending Publication Date: 2025-05-06HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311828197.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-11-06
Filing Date
2023-12-28
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

When the prior art provides load balancing functions across security nodes, both the ingress nodes and the security node consume computing resources to process and forward services, and cannot effectively prevent malicious services, affecting network security.

Method used

Receive services through the inlet node and determine whether the services are allowed based on the inlet filter, and select a secure node for load balancing forwarding. After the security node determines that the service is to be blocked, it sends a message to the ingress node to update the filter to block the service from the host device.

Benefits of technology

Effectively prevent malicious service transmission, reduce the computing resource consumption of ingress nodes and security nodes, improve the overall security of the network, and reduce unnecessary service forwarding.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945699A_ABST
    Figure CN119945699A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to updating an ingress filter of an ingress node providing a load balancing function. In some implementations, an ingress node may receive first traffic from a host device. The ingress node may determine that traffic from the host device is allowed based on an ingress filter of the ingress node. The ingress node may select a secure node of a plurality of secure nodes to which the ingress node is to forward the first traffic using a load balancing function and based on a determination that the traffic from the host device is allowed. The ingress node may forward the first traffic to the selected security node. The ingress node may receive a message indicating that traffic from the host device is to be blocked based on forwarding the first traffic. The ingress node may use the message to update an ingress filter of the ingress node to indicate that traffic from the host device is to be blocked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of computer networks, and more particularly to updating an ingress filter of an ingress node that provides a load balancing function across security nodes. Background Art

[0002] An ingress node can provide an entry point to a network (eg, a cloud network). An ingress node can receive incoming traffic and forward the traffic to another node within the network (eg, to allow a service or function to be performed on the traffic). Summary of the invention

[0003] In some implementations, a method includes: receiving, by an ingress node, a first service from a host device; determining, by the ingress node, based on an ingress filter of the ingress node, that the service from the host device is allowed; selecting, by the ingress node, using a load balancing function and based on determining that the service from the host device is allowed, a security node from a plurality of security nodes to which the ingress node is to forward the first service; forwarding, by the ingress node, the first service to the selected security node; receiving, by the ingress node, a message indicating that the service from the host device is to be blocked based on forwarding the first service; and updating, by the ingress node, the ingress filter to indicate that the service from the host device is to be blocked using the message.

[0004] In some implementations, the security node includes one or more memories, and one or more processors, to: receive a first service forwarded by an entry node and originating from a host device; determine that the first service is to be blocked by providing a security function; block the first service based on the determination that the first service is to be blocked; and send a message to the entry node indicating that the service from the host device is to be blocked based on the determination that the first service is to be blocked.

[0005] In some implementations, a non-transitory computer-readable medium storing a set of instructions includes: one or more instructions that, when executed by one or more processors of an ingress node, cause the ingress node to: receive a first service from a host device; select a security node from among multiple security nodes based on an ingress filter of the ingress node, to which the ingress node is to forward the first service; forward the first service to the selected security node; based on forwarding the first service, receive a message indicating that the service from the host device is to be blocked; and update the ingress filter of the ingress node by the ingress node and using the message.

[0006] One aspect of the present disclosure provides a method, comprising: receiving, by an ingress node, a first service from a host device; determining, by the ingress node, that the service from the host device is allowed based on an ingress filter of the ingress node; selecting, by the ingress node, a security node from a plurality of security nodes, to which the ingress node is to forward the first service, based on determining that the service from the host device is allowed; forwarding, by the ingress node, the first service to the selected security node; receiving, by the ingress node, a message indicating that the service from the host device is to be blocked, based on forwarding the first service; and updating, by the ingress node, the ingress filter to indicate that the service from the host device is to be blocked, using the message.

[0007] According to one or more embodiments of the present disclosure, it also includes: after updating the ingress filter of the ingress node, receiving a second service from the host device; determining that the service from the host device is not allowed based on the ingress filter of the ingress node; and blocking the second service based on determining that the service from the host device is not allowed.

[0008] According to one or more embodiments of the present disclosure, the message is sent by the selected security node.

[0009] According to one or more embodiments of the present disclosure, the selected safety node is associated with a service chain of safety nodes, and the message is sent by another safety node associated with the service chain of the safety node.

[0010] According to one or more embodiments of the present disclosure, the ingress node is configured to provide security functions associated with layer 3 of the Open Systems Interconnection (OSI) model.

[0011] According to one or more embodiments of the present disclosure, the selected security node is configured to provide security functions associated with at least one layer of layer 4 to layer 7 of the Open Systems Interconnection (OSI) model.

[0012] According to one or more embodiments of the present disclosure, the message includes a generic network virtualization encapsulation geneve packet.

[0013] According to one or more embodiments of the present disclosure, the method further includes: after updating the ingress filter of the ingress node, sending another message to the selected security node indicating that the ingress filter is successfully updated.

[0014] Another aspect of the present disclosure provides a security node, comprising: one or more memories; and one or more processors, for: receiving a first service forwarded by an entry node and originating from a host device; determining that the first service is to be blocked by providing a security function; blocking the first service based on determining that the first service is to be blocked; and sending a message to the entry node indicating that the service from the host device is to be blocked based on determining that the first service is to be blocked.

[0015] According to one or more embodiments of the present disclosure, sending the message allows the ingress node to update an ingress filter of the ingress node to indicate that traffic from the host device is to be blocked.

[0016] According to one or more embodiments of the present disclosure, sending the message allows the ingress node to block the second traffic from the host device.

[0017] According to one or more embodiments of the present disclosure, the security node is associated with a service chain of security nodes, and the one or more processors used to send the message to the entry node are used to send the message to another security node associated with the service chain to allow the message to be forwarded to the entry node.

[0018] According to one or more embodiments of the present disclosure, the ingress node is configured to provide another security function associated with layer 3 of the Open Systems Interconnection (OSI) model.

[0019] According to one or more embodiments of the present disclosure, the security function is associated with at least one layer of layer 4 to layer 7 of the Open Systems Interconnection (OSI) model.

[0020] According to one or more embodiments of the present disclosure, the one or more processors are further configured to: after sending the message, receive another message indicating that the ingress filter of the ingress node is successfully updated.

[0021] Yet another aspect of the present disclosure provides a non-transitory computer-readable medium storing an instruction set, the instruction set comprising: one or more instructions, which, when executed by one or more processors of an entry node, cause the entry node to: receive a first service from a host device; select, based on an entry filter of the entry node, a security node from a plurality of security nodes to which the entry node is to forward the first service; forward the first service to the selected security node; based on forwarding the first service, receive a message indicating that the service from the host device is to be blocked; and use the message by the entry node to update the entry filter of the entry node.

[0022] According to one or more embodiments of the present disclosure, the one or more instructions, when executed by the one or more processors, also cause the ingress node to: receive a second service from the host device after updating the ingress filter of the ingress node; and block the second service based on the ingress filter of the ingress node.

[0023] According to one or more embodiments of the present disclosure, the message is sent by the selected security node.

[0024] According to one or more embodiments of the present disclosure, the selected safety node is associated with a service chain of safety nodes, and the message is sent by another safety node associated with the service chain of the safety node.

[0025] According to one or more embodiments of the present disclosure, the ingress node and the selected security node are configured to provide security functions associated with different layers of the Open Systems Interconnection (OSI) model. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1A-Figure 1C is a diagram of an example implementation associated with updating an ingress filter of an ingress node that provides load balancing functionality across security nodes.

[0027] Figure 2A-2C is a diagram of an example of a general network virtualization encapsulation packet that may be included in the messages described herein.

[0028] Figure 3 is an illustration of an example environment in which the systems and / or methods described herein may be implemented.

[0029] Figure 4 is a diagram of example components of an apparatus associated with updating an ingress filter of an ingress node that provides load balancing functionality across security nodes.

[0030] Figure 5 is a diagram of example components of an apparatus associated with updating an ingress filter of an ingress node that provides load balancing functionality across security nodes.

[0031] Figure 6 is a flow diagram of an example process associated with updating an ingress filter of an ingress node that provides load balancing functionality across security nodes.

[0032] Figure 7 is a flow diagram of an example process associated with updating an ingress filter of an ingress node that provides load balancing functionality across security nodes. DETAILED DESCRIPTION

[0033] The following detailed description of example implementations refers to the accompanying drawings.The same reference numbers in different drawings may identify the same or similar elements.

[0034] The entry node associated with the network can receive the business from the host device and can select a security node from a plurality of security nodes associated with the network, that is, provide one or more security functions associated with the business (e.g., firewall function, packet inspection function, content inspection function, intrusion protection function and / or other security functions). The entry node can then forward the business to the security node (e.g., the selected security node). In some cases, the security node determines (e.g., by executing the security function associated with the business) that the business and / or the host device (e.g., as the initiator of the business) is malicious, damaged or otherwise untrustworthy. Therefore, the security node can discard the business and update the filter on the security node to indicate that the security node is to discard the business from the host device (e.g., additional business). This prevents the additional business from being forwarded by the security device, improving the overall security of the network. However, the entry node still consumes computing resources (e.g., other examples such as processing resources, memory resources, communication resources and / or power resources) to process the additional business, determine where to forward the additional business, and forward the additional business. In addition, the entry node can forward the additional business to another security node (e.g., a security node that does not analyze the initial business from the host device). The other security node then expends computing resources to process the additional traffic, such as determining that the additional traffic and / or the host device is malicious, compromised, or otherwise untrustworthy; to discard the additional traffic; and to update filters on the other security node to discard traffic from the host device. Worse still, in some cases, the other security node may not identify any problems with the additional traffic and thus forward the additional traffic, which compromises the overall security of the network.

[0035] Some implementations described herein include an entry node and multiple security nodes. The entry node provides a load balancing function across multiple security nodes. For example, the entry node receives a first service from a host device and selects a security node from multiple security nodes to which the entry node is to forward the first service. The entry node then forwards the first service to the selected security node.

[0036] The selected security node (or another security node associated with the service chain, when the selected security node is part of the service chain) can determine (e.g., by providing at least one security function) that the first traffic is to be blocked. The selected security node then blocks the first traffic (e.g., prevents the first traffic from being forwarded), and sends a message to the ingress node indicating that traffic from the host device (e.g., additional traffic) is to be blocked. The ingress node thereby updates an ingress filter of the ingress node to indicate that traffic from the host device is to be blocked.

[0037] Therefore, the ingress node then receives the second traffic from the host device. The ingress node determines based on the ingress filter (eg, after updating the ingress filter based on the message) that the traffic from the host device is not allowed. The ingress node thereby blocks the second traffic.

[0038] In this way, the security node (e.g., the selected security node) prevents the first business from being forwarded from a malicious, compromised, or otherwise untrustworthy host device, which improves the overall security of the network (e.g., including multiple security nodes). In addition, by providing a message that allows the entry node to update the entry filter of the entry node, the entry node is able to block the second business from the host device. Therefore, the computing resources of the entry node (e.g., other examples such as processing resources, memory resources, communication resources, and / or power resources) are not needed to process the second business and prevent the second business from being forwarded to another node within the network. This improves the overall security of the network. In addition, because the entry node maintains an entry filter for allowing or blocking business from the host device, each security node does not need to consume computing resources to maintain its own filter for allowing or blocking business.

[0039] Figures 1A-1C 1 is a diagram of an example implementation 100 associated with updating an ingress filter of an ingress node that provides load balancing functionality across security nodes. Figures 1A-1C As shown, the example implementation 100 includes a plurality of host devices (shown as host devices 1 to M, where M≥2), an entry node and a plurality of security nodes and a plurality of security nodes (shown as security nodes 1-1 to NX, where N≥2 and X≥1). Figure 3-Figure 5 These devices are described in more detail.

[0040] The ingress node and the plurality of security nodes may be associated with a network (e.g., associated with a cloud environment). For example, the ingress node and the plurality of security nodes may provide a plurality of security functions (e.g., a firewall function, a packet inspection function, a content inspection function, an intrusion prevention function, and / or other security functions) for traffic originating from a plurality of host devices (and going to another network such as the Internet). Each security function may be associated with at least one of layers 3 to 7 of an open systems interconnection (OSI) model.

[0041] In some implementations, the ingress node may be configured to provide at least one security function associated with layer 3 of the OSI model (e.g., a filtering function, a firewall function, or another type of function). For example, the ingress node may include an ingress filter (e.g., may include an access control list (ACL) or another type of filter) that the ingress node may use to determine whether to allow or block traffic. The ingress filter may indicate, for example, whether traffic associated with a particular source Internet Protocol (IP) address, a particular destination IP address, a particular source port, and / or a particular destination port is allowed (e.g., allowed to be forwarded by the ingress node) or not allowed (e.g., not allowed to be forwarded by the ingress node, and / or is to be blocked by the ingress node).

[0042] Each security node of the plurality of security nodes may be configured to provide at least one security function associated with layers 4 to 7 of the OSI model (e.g., a packet inspection function, a content inspection function, an intrusion protection function, and / or another type of security function). The ingress node may be configured to provide a load balancing function across the plurality of security nodes. For example, the ingress node may be configured to select a security node to which the ingress node is to forward traffic (e.g., a host device from a plurality of host devices). In this manner, the ingress node may distribute incoming traffic (e.g., from a plurality of host devices) across the plurality of security nodes to prevent overloading of the individual security nodes.

[0043] like Figure 1A As shown, the plurality of security nodes may be grouped into a plurality of service chains (e.g., shown as service chains 1 to N). Each service chain may include a collection of one or more security nodes in the plurality of security nodes, wherein each security node in the service chain provides at least one specific security function (e.g., associated with at least one of layers 4 to 7 of the OSI model). For example, regarding Figure 1A, the security node 1-1 of service chain 1 can provide a packet inspection function (e.g., a secure socket layer (SSL) or transport layer security (TLS) inspection function), the security node 1-X of service chain 1 can provide an intrusion prevention function (e.g., a suspicious business signature matching function), etc. Therefore, the business forwarded to the service chain (e.g., by the entry node) can be processed and forwarded sequentially by each security node in the service chain. Each service chain can be configured similarly. For example, the security nodes 1-1 to 1-X of service chain 1 can respectively provide the same or similar security functions as the security nodes N-1 to NX of service chain N (in the same or similar order).

[0044] Thus, the ingress node can be configured to provide a load balancing function across multiple service chains. For example, the ingress node can be configured to select a security node (e.g., the first security node of a service chain) to which the ingress node is to forward traffic (e.g., a host device from multiple host devices). In this way, the ingress node can distribute incoming traffic (e.g., from multiple host devices) across multiple service chains to prevent overloading of individual service chains.

[0045] like Figure 1A As shown, and indicated by reference numeral 102, a host device 1 among the plurality of host devices may send a first service to the entry node. The host device 1 may send the first service to the entry node via a connection between the host device 1 and the entry node. Thus, the entry node may receive the first service from the host device 1 (e.g., via a connection between the host device 1 and the entry node).

[0046] The host device 1 may send the first traffic to the ingress node to allow the ingress node and one or more security nodes to provide at least one security function associated with the first traffic and / or allow the first traffic to be forwarded (e.g., to a destination indicated by the first traffic). Figure 1A Host device 1 is shown sending the first traffic to the entry node, but any host device of the plurality of host devices connected to the entry node (e.g., via a connection between the host device and the entry node) may send traffic to the entry node. Thus, any operations described herein as being performed by an entry node or a security node in association with traffic originating from host device 1 (e.g., the first traffic or the second traffic) may similarly be performed by an entry node or a security node in association with traffic originating from any other host device of the plurality of host devices.

[0047] As indicated by reference numeral 104, the entry node may determine whether traffic from host device 1 is allowed (e.g., forwarded by the entry node, such as forwarded to a security node among a plurality of security nodes). The entry node may determine whether traffic from host device 1 is allowed based on an entry filter of the entry node. For example, the entry node may process (e.g., parse and / or read) a first traffic to identify information associated with the first traffic (e.g., a source IP address, a source port, and / or similar information associated with host device 1), and may search the entry filter based on the information to identify an entry in the entry filter associated with host device 1. When the entry indicates that traffic from host device 1 is not allowed (e.g., because host device 1 has been determined to be malicious, compromised, or otherwise untrustworthy), the entry node may determine that traffic from host device 1 is not allowed, and may therefore block the first traffic (e.g., prevent the first traffic from being forwarded by the entry node).

[0048] Alternatively, when the entry indicates that traffic from host device 1 is allowed (e.g., because host device 1 has not been determined to be malicious, compromised, or otherwise untrustworthy), the ingress node can determine that traffic from host device 1 is allowed. In addition, the ingress node can determine that the first traffic is to be forwarded based on providing at least one security function associated with the first traffic (e.g., associated with layer 3 of the OSI model) (e.g., because the ingress node determines that the first traffic is not malicious, not compromised, and not otherwise untrustworthy).

[0049] Therefore, as shown in reference numeral 106, the entry node may select a security node (e.g., to which the entry node is to forward the first service). The entry node may use a load balancing function to select a security node. For example, the entry node may select a security node (e.g., a separate security node or the first security node of a service chain) based on the loads of multiple security nodes and / or the loads of multiple service chains. Figure 1A As shown, the entry node can select security node 1-1.

[0050] As shown at reference numeral 108, the entry node may forward the first traffic to the safety node 1-1 (e.g., to the selected safety node). The entry node may send the first traffic to the safety node 1-1 via the connection between the entry node and the safety node 1-1. Thus, the safety node 1-1 may receive the first traffic from the entry node (e.g., via the connection between the entry node and the safety node 1-1).

[0051] like Figure 1BAs shown, and by reference numeral 110, security node 1-1 may determine whether the first service is to be forwarded (e.g., by security node 1-1). For example, security node 1-1 may determine that the first service is to be forwarded (e.g., because security node 1-1 determines that the first service is non-malicious, non-compromised, and not otherwise untrustworthy) based on providing at least one security function associated with the first service (e.g., associated with at least one layer of layers 4 to 7 of the OSI model). Security node 1-1 may therefore forward the first service (e.g., to a destination indicated by the first service, or to another security node in service chain 1). As an alternative example, security node 1-1 may determine that the first service is to be blocked (e.g., because security node 1-1 determines that the first service is malicious, compromised, or otherwise untrustworthy) based on providing at least one security function. Therefore, as shown by reference numeral 112, security node 1-1 may block the first service (e.g., prevent security node 1-1 from forwarding the first service).

[0052] As indicated by reference numeral 114, the security node 1-1 may send a message to the ingress node (e.g., based on determining that the first service is to be blocked and / or based on blocking the first service). The message may indicate that services from the host device 1 (e.g., any services originating from the host device 1 and / or indicating the host device 1 as a source of services) are to be blocked. The message may include a generic network virtualization encapsulation (geneve) packet, such as described herein with respect to Figures 2A-2C As further described, the safety node 1-1 may send a message to the entry node via the connection between the entry node and the safety node 1-1. Thus, the entry node may receive a message from the safety node 1-1 (eg, via the connection between the entry node and the safety node 1-1).

[0053] Therefore, as shown at reference numeral 116, the ingress node may update the ingress filter of the ingress node. The ingress node may update the ingress filter based on the message. For example, the ingress node may update the ingress filter using a message (e.g., a message indicating that traffic from host device 1 is to be blocked) to indicate that traffic from host device 1 is to be blocked. In a specific example, the ingress node may update the ingress filter to include an entry indicating that traffic from host device 1 (e.g., indicating a source IP address, a source port, and / or other information of host device 1) is to be blocked.

[0054] As shown at 118, the ingress node may send a message (e.g., a response message) to the security node 1-1 (e.g., after updating the ingress filter). The message may indicate that the ingress node was successfully updated (e.g., by the ingress node). The message may include a geneve packet, as described herein with respect to Figures 2A-2CAs further described, the entry node may send a message to the safety node 1-1 via the connection between the entry node and the safety node 1-1. Thus, the safety node 1-1 may receive a message from the entry node (eg, via the connection between the entry node and the safety node 1-1).

[0055] Although security node 1-1 is described as executing Figure 1B The operations shown, however, may be performed by any security node within the service chain to which the entry node forwards the first service. For example, each operation may be performed by security node 1-X (e.g., after the first service is forwarded to security node 1-X by security node 1-1 and any other security node of service chain 1). Thus, security node 1-X may send a message to the entry node by sending the message to another security node associated with service chain 1 (e.g., in a manner similar to that described herein with respect to reference numeral 114) to allow the message to be forwarded (e.g., through one or more other security nodes of service chain 1, including security node 1-1) to the entry node. Additionally or alternatively, security node 1-X may receive a message sent by the entry node based on a message forwarded (e.g., through one or more other security nodes of service chain 1, including security node 1-1) to security node 1-X (e.g., in a manner similar to that described herein with respect to reference numeral 118).

[0056] like Figure 1C As shown, and by reference numeral 120, a host device 1 among the plurality of host devices may send a second service to the entry node (eg, after the entry node updates the information described herein). Figure 1B and the ingress filter of the ingress node described by reference numeral 116). Host device 1 can send the second service to the ingress node via the connection between host device 1 and the ingress node. Thus, the ingress node can receive the second service from host device 1 (e.g., via the connection between host device 1 and the ingress node). Host device 1 can send the second service to the ingress node to allow the ingress node and one or more security nodes to provide at least one security function associated with the second service and / or allow the second service to be forwarded (e.g., to a destination indicated by the second service).

[0057] As shown at 122, the ingress node may determine whether traffic from the host device 1 is allowed (eg, based on receiving the second traffic). The ingress node may determine whether traffic from the host device 1 is allowed (eg, based on receiving the second traffic) based on the ingress filter of the ingress node. Figure 1AThe ingress node may determine whether the traffic from the host device 1 is allowed in a manner similar to that described with reference numeral 104. For example, the ingress node may process (e.g., parse and / or read) the second traffic to identify information associated with the second traffic (e.g., source IP address, source port, and / or similar information associated with the host device 1), and may search the ingress filter based on the information to identify an entry in the ingress filter associated with the host device 1. The entry may indicate (e.g., based on the information described herein) Figure 1B The traffic from the host device 1 is not allowed as shown in the ingress node updating the ingress filter as described with reference numeral 116. Therefore, as shown in reference numeral 124, the ingress node may block the second traffic (eg, prevent the ingress node from forwarding the second traffic).

[0058] As mentioned above, providing Figures 1A-1C As an example. Other examples can be related to Figures 1A-1C Different than described. Figures 1A-1C The number and arrangement of devices shown in are provided as examples. Figures 1A-1C There may be additional devices, fewer devices, different devices, or differently arranged devices than those shown. Figures 1A-1C Two or more of the devices shown may be implemented in a single device, or Figures 1A-1C The single device shown in can be implemented as multiple distributed devices. Additionally or alternatively, Figures 1A-1C The device set (e.g., one or more devices) shown in FIG. 1 may perform the operations described by Figures 1A-1C One or more functions performed by another set of devices shown in .

[0059] Figures 2A-2C is a diagram of an example 200 of a geneve packet that may be included in a message described herein. Figure 2A The header of the geneve packet is shown, where the protocol type field (0x6558) may indicate that the payload of the geneve packet is an Ethernet frame. Figure 2B An option type length value (TLV) for a geneve packet is shown, where the option class field (0x14E) and the type field (0x1) may indicate that the geneve packet is intended for updating an ingress filter of an ingress node and / or reporting updates to the ingress filter by the ingress node. Figure 2CAn options header associated with a TLV is shown, wherein a sequence field may indicate a sequence number associated with a geneve packet, a type field may indicate whether the geneve packet is to be used to update an ingress filter (e.g., having a value of 0x1) or to report an update of an ingress filter (e.g., having a value of 0x2), a version field may indicate the version of the options header, a status field may indicate the status of updating the ingress filter (e.g., success or failure), a source IP field may indicate an IP address of a node (e.g., an ingress node or a security node) that initiated the geneve packet, a destination IP field may indicate an IP address of a node (e.g., an ingress node or a security node) that is an intended recipient of the geneve packet, source and destination port fields may indicate a source port and / or destination port associated with the geneve packet, and a protocol field may indicate a protocol associated with the geneve packet.

[0060] As mentioned above, providing Figures 2A-2C As an example. Other examples can be related to Figures 2A-2C Different than described.

[0061] Figure 3 3 is a diagram of an example environment 300 in which the systems and / or methods described herein may be implemented. Figure 3 As shown, environment 300 may include one or more host devices 310, a set of nodes 320, and a network 330. The devices of environment 300 may be interconnected via wired connections, wireless connections, or a combination of wired and wireless connections.

[0062] The host device 310 includes one or more devices capable of providing services. For example, the host device 310 may include a router, a gateway, a switch, a firewall, a hub, a bridge, a reverse proxy, a server (e.g., a proxy server), a security device, an intrusion detection device, a load balancer, or a similar type of device. In some implementations, the host device 310 may include an endpoint device as a service source. For example, the host device 310 may include a wireless communication device, a mobile phone, a user equipment, a laptop computer, a tablet computer, a desktop computer, a game console, a set-top box, a wearable communication device (e.g., a smart watch, a pair of smart glasses, a head-mounted display, or a virtual reality headset) or a similar type of device. The host device 310 may provide services to other devices such as devices outside the network 330 via the network 330 (e.g., by using the node 320 as an intermediary).

[0063] Node 320 includes one or more devices that can receive, process, store, route and / or provide services in the manner described herein. For example, node 320 may include a router, such as a label switching router (LSR), a label edge router (LER), an entry router, an exit router, a provider router (e.g., a provider edge router, a provider core router, etc.), a virtual router, or another type of router. Additionally or alternatively, node 320 may include a gateway, a switch, a firewall, a hub, a bridge, a reverse proxy, a server (e.g., a proxy server, a cloud server, a data center server, etc.), a load balancer, and / or similar devices. Node 320 may be an entry node, a security node, or another type of node.

[0064] In some implementations, node 320 may be a physical device implemented within a housing such as a chassis. In some implementations, node 320 may be a virtual device implemented by one or more computer devices in a cloud computing environment or data center.

[0065] The network 330 includes one or more wired and / or wireless networks. For example, the network 330 may include a cellular network (e.g., a fifth generation (5G) network, a fourth generation (4G) network such as a long term evolution (LTE) network, a third generation (3G) network, a code division multiple access (CDMA) network, a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., a public switched telephone network (PSTN)), a private network, an ad hoc network, an intranet, the Internet, a fiber-based network, a cloud computing network, etc., and / or a combination of these or other types of networks.

[0066] Figure 3 The number and arrangement of devices and networks shown in the figure are provided as one or more examples. In practice, there may be additional devices and / or networks, fewer devices and / or networks, different devices and / or networks, or different Figure 3 In addition, the devices and / or networks are arranged differently as shown in FIG. Figure 3 Two or more of the devices shown in may be implemented in a single device, or Figure 3 The single device shown in FIG. 300 may be implemented as multiple distributed devices. Additionally or alternatively, a set of devices (eg, one or more devices) of environment 300 may perform one or more functions described as being performed by another set of devices of environment 300.

[0067] Figure 4is a diagram of example components of a device 400 associated with updating an ingress filter of an ingress node that provides load balancing functionality across security nodes. Device 400 may correspond to host device 310 and / or node 320. In some implementations, host device 310 and / or node 320 may include one or more devices 400 and / or one or more components of device 400. Figure 4 As shown, device 400 may include a bus 410 , a processor 420 , a memory 430 , an input component 440 , an output component 450 , and / or a communication component 460 .

[0068] Bus 410 may include one or more components that enable wired and / or wireless communications between components of device 400. Bus 410 may include one or more components that enable wired and / or wireless communications between components of device 400. Figure 4 Two or more components of a computer system may be coupled together, for example, by operational coupling, communication coupling, electronic coupling, and / or electrical coupling. For example, bus 410 may include electrical connections (e.g., wires, traces, and / or leads) and / or wireless buses. Processor 420 may include a central processing unit, a graphics processing unit, a microprocessor, a controller, a microcontroller, a digital signal processor, a programmable gate array, an application specific integrated circuit, and / or other types of processing components. Processor 420 may be implemented in hardware, firmware, or a combination of hardware and software. In some implementations, processor 420 may include one or more processors that can be programmed to perform one or more operations or processes described elsewhere herein.

[0069] The memory 430 may include volatile and / or non-volatile memory. For example, the memory 430 may include random access memory (RAM), read-only memory (ROM), a hard drive, and / or other types of memory (e.g., flash memory, magnetic memory, and / or optical memory). The memory 430 may include internal memory (e.g., RAM, ROM, or hard drive) and / or removable memory (e.g., removable via a universal serial bus connection). The memory 430 may be a non-temporary computer-readable medium. The memory 430 may store information, one or more instructions, and / or software (e.g., one or more software applications) related to the operation of the device 400. In some implementations, the memory 430 may include one or more memories such as coupled (e.g., communicatively coupled) to one or more processors (e.g., processor 420) via bus 410. The communicative coupling between the processor 420 and the memory 430 may enable the processor 420 to read and / or process information stored in the memory 430 and / or store information in the memory 430.

[0070] Input component 440 can enable device 400 to receive input, such as user input and / or sensed input. For example, input component 440 can include touch screen, keyboard, keypad, mouse, button, microphone, switch, sensor, GPS sensor, GNSS sensor, accelerometer, gyroscope and / or actuator. Output component 450 can enable device 400 to provide output such as via display, speaker and / or light emitting diode. Communication component 460 can enable device 400 to communicate with other devices via wired connection and / or wireless connection. For example, communication component 460 can include receiver, transmitter, transceiver, modem, network interface card and / or antenna.

[0071] The device 400 may perform one or more operations or processes described herein. For example, a non-transitory computer-readable medium (e.g., memory 430) may store an instruction set (e.g., one or more instructions or codes) executed by the processor 420. The processor 420 may execute the instruction set to perform one or more operations or processes described herein. In some implementations, the execution of the instruction set by one or more processors 420 causes one or more processors 420 and / or the device 400 to perform one or more operations or processes described herein. In some implementations, hard-wired circuits may be used instead of instructions or in combination with instructions to perform one or more operations or processes described herein. Additionally or alternatively, the processor 420 may be configured to perform one or more operations or processes described herein. Therefore, the implementation described herein is not limited to any particular combination of hardware circuits and software.

[0072] Figure 4 The number and arrangement of components shown are provided as examples. Device 400 may include Figure 4 The components shown may be additional components, fewer components, different components, or differently arranged components. Additionally or alternatively, one set of components (e.g., one or more components) of device 400 may perform one or more functions described as being performed by another set of components of device 400.

[0073] Figure 5 is a diagram of example components of a device 500 associated with updating an ingress filter of an ingress node that provides load balancing functionality across security nodes. Device 500 may correspond to host device 310 and / or node 320. In some implementations, host device 310 and / or node 320 may include one or more devices 500 and / or one or more components of device 500. Figure 5As shown, the device 500 may include one or more input components 510-1 to 510-B (B≥1) (hereinafter collectively referred to as input component 510, and individually referred to as input component 510), a switching component 520, one or more output components 530-1 to 530-C (C≥1) (hereinafter collectively referred to as output component 530, and individually referred to as output component 530), and a controller 540.

[0074] The input component 510 may be one or more connection points for a physical link and may be one or more entry points for incoming traffic, such as packets. The input component 510 may process incoming traffic, such as by performing data link layer encapsulation or decapsulation. In some implementations, the input component 510 may transmit and / or receive packets. In some implementations, the input component 510 may include an input line card that includes one or more packet processing components (e.g., in the form of an integrated circuit), such as one or more interface cards (IFCs), a packet forwarding component, a line card controller component, an input port, a processor, a memory, and / or an input queue. In some implementations, the device 500 may include one or more input components 510.

[0075] The switching component 520 can interconnect the input component 510 with the output component 530. In some implementations, the switching component 520 can be implemented via one or more crossbar switches, via a bus, and / or with a shared memory. The shared memory can serve as a temporary buffer to store packets from the input component 510 before the packets are ultimately scheduled for transport to the output component 530. In some implementations, the switching component 520 can enable the input component 510, the output component 530, and / or the controller 540 to communicate with each other.

[0076] The output component 530 can store packets and can schedule packets for transmission on an output physical link. The output component 530 can support data link layer encapsulation or decapsulation, and / or various higher-level protocols. In some implementations, the output component 530 can transmit packets and / or receive packets. In some implementations, the output component 530 may include an output line card, which includes one or more packet processing components (e.g., in the form of an integrated circuit), such as one or more IFCs, packet forwarding components, line card controller components, output ports, processors, memories, and / or output queues. In some implementations, the device 500 may include one or more output components 530. In some implementations, the input component 510 and the output component 530 can be implemented by the same set of components (e.g., the input / output component can be a combination of the input component 510 and the output component 530).

[0077] The controller 540 includes a processor in the form of, for example, a CPU, a graphics processing unit (GPU), an accelerated processing unit (APU), a microprocessor, a microcontroller, a digital signal processor (DSP), a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), and / or another type of processor. The processor is implemented in hardware, firmware, or a combination of hardware and software. In some implementations, the controller 540 may include one or more processors that can be programmed to perform a function.

[0078] In some implementations, the controller 540 may include RAM, ROM, and / or another type of dynamic or static storage device (eg, flash memory, magnetic storage, optical storage, etc.) that stores information and / or instructions for use by the controller 540 .

[0079] In some implementations, the controller 540 can communicate with other devices, networks, and / or systems connected to the device 500 to exchange information about the network topology. The controller 540 can create a routing table based on the network topology information, can create a forwarding table based on the routing table, and can forward the forwarding table to the input component 510 and / or the output component 530. The input component 510 and / or the output component 530 can use the forwarding table to perform routing lookups for incoming and / or outgoing packets.

[0080] The controller 540 may perform one or more processes described herein. The controller 540 may perform these processes in response to executing software instructions stored by a non-transitory computer-readable medium. A computer-readable medium is defined herein as a non-transitory memory device. A memory device includes a memory space within a single physical memory device or a memory space spread across multiple physical memory devices.

[0081] The software instructions may be read from another computer-readable medium or from another device into a memory and / or storage component associated with the controller 540 via a communication interface. When executed, the software instructions stored in the memory and / or storage component associated with the controller 540 may cause the controller 540 to perform one or more processes described herein. Additionally or alternatively, hardwired circuitry may be used in place of or in combination with software instructions to perform one or more processes described herein. Thus, the implementations described herein are not limited to any specific combination of hardware circuitry and software.

[0082] Figure 5 The number and arrangement of components shown are provided as examples. In practice, device 500 may include more Figure 5Additional components, fewer components, different components, or differently arranged components as shown in. Additionally or alternatively, a set of components (e.g., one or more components) of device 500 may perform one or more functions described as being performed by another set of components of device 500.

[0083] Figure 6 is a flow chart of an exemplary process 600 associated with updating an ingress filter of an ingress node that provides load balancing functionality across security nodes. Figure 6 One or more processing blocks of are performed by an entry node (e.g., node 320 configured as an entry node). In some implementations, Figure 6 One or more processing blocks of are performed by another device or group of devices separate from or including the entry node, such as a host device (e.g., host device 310) and / or another node (e.g., another node 320). Additionally or alternatively, Figure 6 One or more processing blocks may be performed by one or more components of device 400, such as processor 420, memory 430, input component 440, output component 450, and / or communication component 460; of device 500, such as input component 510, switching component 520, output component 530, and / or controller 540; and / or another device.

[0084] like Figure 6 As shown, process 600 may include receiving a first traffic from a host device (block 610). For example, as described above, a portal node may receive the first traffic from a host device.

[0085] like Figure 6 As further shown in FIG. 6 , process 600 may include determining that traffic from the host device is allowed (block 620). For example, as described above, the ingress node may determine that traffic from the host device is allowed based on an ingress filter of the ingress node.

[0086] like Figure 6 As further shown in FIG. 6 , process 600 may include selecting a safety node from among the plurality of safety nodes (block 630). For example, as described above, the ingress node may use a load balancing function and based on determining that the traffic from the host device is allowed, select a safety node from among the plurality of safety nodes to which the ingress node is to forward the first traffic.

[0087] like Figure 6 As further shown in FIG. 6 , process 600 may include forwarding the first traffic to the selected safety node (block 640). For example, as described above, the ingress node may forward the first traffic to the selected safety node.

[0088] like Figure 6As further shown in FIG. 6 , process 600 may include receiving a message (block 650). For example, as described above, the ingress node may receive a message indicating that traffic from the host device is to be blocked based on forwarding the first traffic.

[0089] like Figure 6 As further shown in FIG. 6 , process 600 may include updating an ingress filter of an ingress node (block 660). For example, as described above, an ingress node may use a message to update an ingress filter of an ingress node to indicate that traffic from a host device is to be blocked.

[0090] Process 600 may include additional implementations, such as any single implementation or any combination of implementations described below and / or in conjunction with one or more other processes described elsewhere herein.

[0091] In a first implementation, process 600 includes receiving a second traffic from a host device after updating an ingress filter of an ingress node; determining based on the ingress filter of the ingress node that the traffic from the host device is not allowed; and blocking the second traffic based on determining that the traffic from the host device is not allowed.

[0092] In a second implementation, either alone or in combination with the first implementation, the message is sent by a selected safety node.

[0093] In a third implementation, alone or in combination with one or more of the first and second implementations, the selected safety node is associated with a service chain of safety nodes, and the message is sent by another safety node associated with the service chain of the safety node.

[0094] In a fourth implementation, alone or in combination with one or more of the first to third implementations, the ingress node is configured to provide security functions associated with layer 3 of the OSI model.

[0095] In a fifth implementation, alone or in combination with one or more of the first to fourth implementations, the selected security node is configured to provide security functionality associated with at least one of layers 4 to 7 of the OSI model.

[0096] In a sixth implementation, alone or in combination with one or more of the first to fifth implementations, the message includes a generic network virtualization encapsulation (geneve) packet.

[0097] In a seventh implementation, alone or in combination with one or more of the first to sixth implementations, process 600 includes, after updating the ingress filter of the ingress node, sending another message to the selected safety node indicating that the ingress filter was successfully updated.

[0098] Although Figure 6An example block diagram of process 600 is shown, but in some implementations, process 600 includes Figure 6 Additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in the process 600. Additionally or alternatively, two or more blocks of the process 600 can be performed in parallel.

[0099] Figure 7 is a flow chart of an exemplary process 700 associated with updating an ingress filter of an ingress node that provides load balancing functionality across security nodes. Figure 7 One or more processing blocks of are performed by a safety node (e.g., node 320 configured as a safety node). In some implementations, Figure 7 One or more processing blocks of are performed by another device or a group of devices separate from or including the safety node, such as a host device (e.g., host device 310) and / or another node (e.g., another node 320). Additionally or alternatively, Figure 7 One or more processing blocks may be performed by one or more components of device 400, such as processor 420, memory 430, input component 440, output component 450, and / or communication component 460; of device 500, such as input component 510, switching component 520, output component 530, and / or controller 540; and / or another device.

[0100] like Figure 7 As shown, process 700 may include receiving a first transaction (block 710). For example, as described above, a security node may receive a first transaction forwarded by an ingress node and originating from a host device.

[0101] like Figure 7 As further shown in FIG. 7 , process 700 may include determining that the first service is to be blocked (block 720). For example, as described above, the security node may determine that the first service is to be blocked by providing security functionality.

[0102] like Figure 7 As further shown in FIG. 7 , process 700 may include blocking the first transaction (block 730 ). For example, as described above, the security node may block the first transaction based on determining that the first transaction is to be blocked.

[0103] like Figure 7 As further shown in FIG. 7 , process 700 may include sending a message (block 740 ). For example, as described above, the security node may send a message to the ingress node indicating that traffic from the host device is to be blocked based on determining that the first traffic is to be blocked.

[0104] Process 700 may include additional implementations, such as any single implementation or any combination of implementations described below and / or in conjunction with one or more other processes described elsewhere herein.

[0105] In a first implementation, sending the message allows the ingress node to update the ingress filter of the ingress node to indicate that traffic from the host device is to be blocked.

[0106] In a second implementation, alone or in combination with the first implementation, sending the message allows the ingress node to block the second traffic from the host device.

[0107] In a third implementation, either alone or in combination with one or more of the first and second implementations, the security node is associated with a service chain of security nodes, and sending the message to the entry node includes sending the message to another security node associated with the service chain to allow the message to be forwarded to the entry node.

[0108] In a fourth implementation, alone or in combination with one or more of the first to third implementations, the ingress node is configured to provide another security function associated with layer 3 of the OSI model.

[0109] In a fifth implementation, alone or in combination with one or more of the first to fourth implementations, the security functionality is associated with at least one of layers 4 to 7 of the OSI model.

[0110] In a sixth implementation, alone or in combination with one or more of the first to fifth implementations, process 700 includes receiving another message after sending the message indicating that the ingress filter of the ingress node was successfully updated.

[0111] Although Figure 7 An example block diagram of process 700 is shown, but in some implementations, process 700 includes Figure 7 In some embodiments, the process 700 may include additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in the process 700. Additionally or alternatively, two or more blocks of the process 700 may be performed in parallel.

[0112] The above disclosure provides illustration and description, but is not intended to be exhaustive or to limit the implementation to the precise form disclosed. Modifications and variations may be made in light of the above disclosure or may be acquired from practice of the implementation.

[0113] As used herein, a service or content may include a set of packets. A packet may refer to a communication structure for conveying information, such as a protocol data unit (PDU), a service data unit (SDU), a network packet, a datagram, a segment, a message, a block, a frame (e.g., an Ethernet frame), a portion of any of the above, and / or another type of formatted or unformatted data unit capable of being transmitted via a network.

[0114] As used herein, the term "component" is intended to be broadly interpreted as hardware, firmware, or a combination of hardware and software. It is apparent that the systems and / or methods described herein may be implemented in various forms of hardware, firmware, and / or a combination of hardware and software. The actual dedicated control hardware or software code used to implement these systems and / or methods is not a limitation on implementation. Therefore, the operation and behavior of the systems and / or methods are described herein without reference to specific software code - it should be understood that software and hardware may be used to implement the systems and / or methods based on the description herein.

[0115] Even though particular combinations of features are detailed in the claims and / or disclosed in the specification, these combinations are not intended to limit the disclosure of the various implementations. In fact, many of these features may be combined in ways that are not specifically detailed in the claims and / or disclosed in the specification. Although each dependent claim listed below may be directly dependent on only one claim, the disclosure of the various implementations includes each dependent claim in combination with every other claim in the claim set. As used herein, a phrase referring to "at least one" of a list of items refers to any combination of these items, including single members. As an example, "at least one of: a, b, or c" is intended to cover a, b, c, ab, ac, bc, and abc, as well as any combination of multiple identical items.

[0116] When a "processor" or "one or more processors" (or another device or component, such as a "controller" or "one or more controllers") is described or claimed (within a single claim or across multiple claims) as performing multiple operations or being configured to perform multiple operations, the language is intended to broadly cover a variety of processing architectures and environments. For example, unless otherwise stated (e.g., via the use of "a first processor" and "a second processor" or other language that distinguishes the processors in the claims), the language is intended to cover a single processor that performs or is configured to perform all of the operations, a group of processors that collectively perform or are configured to perform all of the operations, a first processor that performs or is configured to perform a first operation and a second processor that performs or is configured to perform a second operation, or any combination of processors that perform or are configured to perform operations. For example, when a claim has "one or more processors that: perform X; perform Y; and perform Z;", the claim should be interpreted as "one or more processors that perform X; one or more (possibly different) processors that perform Y; and one or more (possibly different) processors that perform Z". Elements, acts, or instructions used herein should not be interpreted as critical or essential unless explicitly described as such. In addition, as used herein, the articles "one" and "an" are intended to include one or more items and can be used interchangeably with "one or more". In addition, as used herein, the article "the" is intended to include one or more items related to the article "the" and can be used interchangeably with "the one or more". In addition, as used herein, the term "set" is intended to include one or more items (e.g., related items, unrelated items, or a combination of related and unrelated items) and can be used interchangeably with "one or more". In the case of only one item, the phrase "only one" or similar language is used. In addition, as used herein, the terms "have", "have", "have" and the like are intended to be open terms. In addition, the phrase "based on" is intended to mean "based at least in part on", unless otherwise explicitly stated. In addition, as used herein, the term "or" is intended to be inclusive when used in a series, and can be used interchangeably with "and / or", unless otherwise explicitly stated (e.g., if used in combination with "either" or "only one").

Claims

1. A method comprising: Receiving, by the ingress node, a first service from a host device; Determining, by the ingress node based on an ingress filter of the ingress node, that the service from the host device is allowed; selecting, by the ingress node using a load balancing function and based on determining that the traffic from the host device is allowed, a security node from a plurality of security nodes to which the ingress node is to forward the first traffic; Forwarding the first service by the ingress node to the selected security node; Receiving, by the ingress node, a message indicating that traffic from the host device is to be blocked based on forwarding the first traffic; as well as The message is used by the ingress node to update the ingress filter of the ingress node to indicate that traffic from the host device is to be blocked.

2. The method according to claim 1, further comprising: receiving a second service from the host device after updating the ingress filter of the ingress node; Determining, based on the ingress filter of the ingress node, that traffic from the host device is not permitted; as well as Based on determining that the traffic from the host device is not allowed, blocking the second traffic. The method of claim 1 , wherein the message is sent by the selected security node.

4. The method of claim 1 , wherein the selected security node is associated with a service chain of security nodes, and The message is sent by another safety node associated with a service chain of the safety node.

5. The method of claim 1, wherein the ingress node is configured to provide security functions associated with layer 3 of the Open Systems Interconnection (OSI) model.

6. The method of claim 1, wherein the selected security node is configured to provide security functions associated with at least one of layers 4 to 7 of an Open Systems Interconnection (OSI) model.

7. The method of claim 1, wherein the message comprises a generic network virtualization encapsulation (geneve) packet.

8. The method according to claim 1, further comprising: After updating the ingress filter of the ingress node, another message is sent to the selected security node indicating that the ingress filter was successfully updated.

9. A security node, comprising: one or more memories; as well as One or more processors to: receiving first traffic forwarded by an ingress node and originating from a host device; Determining that the first service is to be blocked by providing a security function; Based on determining that the first service is to be blocked, blocking the first service; as well as Based on determining that the first traffic is to be blocked, a message is sent to the ingress node indicating that traffic from the host device is to be blocked.

10. The security node of claim 9, wherein sending the message allows the ingress node to update an ingress filter of the ingress node to indicate that traffic from the host device is to be blocked.

11. The security node of claim 9, wherein sending the message allows the ingress node to block second traffic from the host device.

12. The safety node of claim 9, wherein the safety node is associated with a service chain of safety nodes, and The one or more processors configured to send the message to the ingress node are configured to send the message to another security node associated with the service chain to allow the message to be forwarded to the ingress node.

13. The security node of claim 9, wherein the ingress node is configured to provide another security function associated with layer 3 of the Open Systems Interconnection (OSI) model.

14. The security node of claim 9, wherein the security function is associated with at least one of layers 4 to 7 of an Open Systems Interconnection (OSI) model.

15. The security node of claim 9, wherein the one or more processors are further configured to: After sending the message, another message is received indicating that the ingress filter of the ingress node was successfully updated.

16. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising: One or more instructions that, when executed by one or more processors of a portal node, cause the portal node to: receiving a first service from a host device; Selecting, based on an ingress filter of the ingress node, a security node from among a plurality of security nodes, to which the ingress node is to forward the first service; Forwarding the first service to the selected security node; receiving a message indicating that traffic from the host device is to be blocked based on forwarding the first traffic; as well as The message is used by the ingress node to update the ingress filter of the ingress node.

17. The non-transitory computer readable medium of claim 16, wherein the one or more instructions, when executed by the one or more processors, further cause the entry node to: After updating the ingress filter of the ingress node, receiving a second service from the host device; and Based on the ingress filter of the ingress node, the second service is blocked.

18. The non-transitory computer-readable medium of claim 16, wherein the message is sent by the selected security node.

19. The non-transitory computer-readable medium of claim 16, wherein the selected security node is associated with a service chain of security nodes, and The message is sent by another safety node associated with a service chain of the safety node.

20. The non-transitory computer-readable medium of claim 16, wherein the ingress node and the selected security node are configured to provide security functions associated with different layers of an Open Systems Interconnection (OSI) model.