Method for sending an information element and receiving an information element for reputation management of an IP resource

DE602019070513T2Active Publication Date: 2025-05-28ORANGE SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602019070513
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-05-02
Filing Date
2019-04-24
Publication Date
2025-05-28
Estimated Expiration
2039-04-24

AI Technical Summary

Technical Problem

Existing solutions struggle to accurately identify the size of an IPv6 prefix allocated to a machine, making it difficult to block malicious communications without affecting the quality of experience for other users sharing the same source IP address.

Method used

A method is implemented where a device in one network sends information representative of the prefix size of an IP address assigned to equipment connected to that network to a device in another network, enabling precise identification and management of IP resource reputation across networks.

Benefits of technology

This approach allows for effective action against malicious equipment without impacting other users, by unambiguously identifying equipment based on prefix size and enabling targeted filtering and reputation management.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

Background of the invention

[0001] The invention relates to the general field of telecommunications.

[0002] It concerns more specifically the management of IP resources used to identify equipment making up a network as well as equipment connected to such a network.

[0003] In particular, IP resource management may involve implementing one or more IP resource reputation systems responsible for preventing the dissemination of malicious traffic that would use one of these IP resources, for example.

[0004] An IP resource can be an IP address or a prefix of an IP address.

[0005] As a reminder, an IP resource reputation system is a system that maintains a record reflecting the reputation of IP addresses or prefixes based on past suspicious activity of machines that have sent traffic with these addresses used as source IP addresses. To achieve this, such a system may consist of one or more servers, and host a database containing a list of IP resources and information on their reputation. Such a system may disclose, spontaneously or upon request, a history reflecting said activity.

[0006] IP resources are typically allocated by service providers or network operators. Alternatively, the allocation of IP addresses or prefixes may be handled by an Internet Service Provider (ISP), service provider, or carrier.

[0007] Content providers may refer to a reputation system to decide whether or not to serve a machine identified by at least one IP address based on the history reflecting the activity of that IP address and as maintained by a reputation system.

[0008] A reputation system can be reduced to a database, such as a blacklist, listing IP addresses associated with machines infected with viruses or having been the source of illicit activity such as sending spam, fraudulent traffic, or DoS (denial of service) traffic.

[0009] When a reputation system records an IP address associated with a first machine as having a bad reputation, a content provider that interfaces with that reputation system may decide to take action regarding the IP address used by said first machine and that would attempt to access the content of said provider.

[0010] For example, the action may consist of blocking all or part of the communications coming from this first machine, or redirecting its communications to a dedicated portal.

[0011] Thus, if the same IP address is later assigned to a second machine, that second machine will be subject to the action taken by the content provider, even if that second machine is not infected and has not generated fraudulent traffic. The quality of experience for the user of the second machine is further degraded if that IP address is registered on multiple reputation systems.

[0012] The content provider can apply a filter on the full IP address, encoded on 32 bits in the case of an IPv4 address, or on 128 bits in the case of an IPv6 address.

[0013] The service provider that allocated the IP address to the second machine is not aware of the degraded experience of its customer who owns the second machine, since it is the content provider who has chosen to take action that blocks traffic from the second machine; the service provider is therefore not in a position to anticipate such degradation of service in order to prevent it from happening again for other customers.

[0014] The situation can become more complicated if several addresses are allocated to the first infected machine, all of which are then polluted. Remember that a block of addresses from a service provider is said to be "polluted" if several addresses in this block are present in a blacklist recorded in a database maintained by a reputation system.

[0015] State of the art document US2014143825 describes a policy management system, which generates rules based, at least in part, on reputation information provided by at least one reputation source and on customer event information passed by filtering logic.

[0016] Another prior document US2010057895 describes methods of providing reputation information for a remote device that include receiving a name for the remote device from a client device and wherein, in response to receiving the name for the remote device, the name may be translated into an Internet Protocol (IP) address for the remote device, and reputation information may be provided for the remote device.

[0017] So there is a problem of being able to block communications from one device connected to a network without affecting the quality of experience perceived by the user of another device that may be using the same source IP address.

[0018] This problem occurs regardless of the IPv4 or IPv6 addressing format.

[0019] Additional problems arise in the case of IPv6 addressing. The structure of an IPv6 address is described in RFC 4291.

[0020] Filtering performed by the content provider based on the 128-bit encoded IPv6 address can be easily circumvented by a malicious user. Indeed, a malicious user simply needs to generate a new IPv6 address from a prefix delegated to them by their service provider, for example by using the resources of the algorithm defined in RFC 4941, which allows the random generation of the value of the 64 bits of the address that form the interface identifier (IID).

[0021] A known solution that allows blocking malicious equipment without affecting the quality of experience of other equipment is that the content provider activates a filter based on the IPv6 prefix, and not the full IPv6 address as above.

[0022] This solution has the disadvantage of being difficult to implement. Indeed, a content provider does not have reliable information to deterministically calculate the IPv6 prefix associated with an IPv6 address.

[0023] An IPv6 packet does not reveal the size of the IPv6 prefix allocated to a machine. This information is only visible to the service provider that allocated the IPv6 prefix, and to the machine that received the prefix from that provider's network. However, the same IPv6 address can be obtained using prefixes of different sizes.

[0024] Furthermore, the size of IPv6 prefixes allocated to machines that are connected to the operator's or service provider's network, for example to CPE (Customer Premises Equipment) equipment, is a policy characteristic of the IPv6 connectivity service provided by each access provider: there is no standard or imposed size for the IPv6 prefixes allocated by these providers to customers.

[0025] Furthermore, the size of these prefixes may also vary depending on the service provided by an operator: for example, an IPv6 connectivity service provided to a business may be based on the allocation of a prefix of size / 48 (also known as length / 48), i.e. a prefix with a length of 48 bits, while the IPv6 connectivity service provided to a residential customer may be based on the allocation of a prefix of length / 56, i.e. a length of 56 bits.

[0026] There is therefore a need for a solution that allows better identification of the size of the prefix allocated to a machine, and which does not have the disadvantages of existing solutions. Subject matter and summary of the invention

[0027] The invention relates to a method for sending information enabling reputation management of IP resources in a set of networks comprising at least a first network and a second network. The method being implemented by a device of the first network, called the "transmitting device", it is characterized in that it comprises a step of sending, by the transmitting device to a device of the second network, called the "receiving device", information representative of a prefix size of an IP address assigned to equipment connected to the first network.

[0028] In one embodiment, the information representative of the sent prefix size is used for IP resource reputation management implemented across networks.

[0029] The characteristics and advantages of the method for sending information according to the invention presented below apply in the same way to the method for receiving information, to the transmitting device and to the receiving device according to the invention.

[0030] For the purposes of the invention, the IP address assigned to the equipment connected to the first network may be an address allocated directly to the equipment or used by an address or prefix translation mechanism.

[0031] In one embodiment, the IP address (or prefix) is allocated by a residential gateway, by CPE equipment or by an STB (Set Top Box) decoder.

[0032] In another mode, the IP address is assigned by a NAT (Network Address Translation) or NPTv6 (IPv6 Network Prefix Translation) type address translation mechanism.

[0033] The first and second networks may be operated by the same operator or by different operators.

[0034] In one embodiment, the first or second network is a local area network, for example a home network or a corporate network.

[0035] In one embodiment, the first or second network is a content hosting network.

[0036] The first and second networks may be operated by separate entities.

[0037] In one embodiment, the first and second networks are stand-alone systems.

[0038] It should be remembered that an autonomous system (AS) is a set of IP routers placed under the operational responsibility of a single administrative entity, typically an IP network operator or an IP service provider.

[0039] In one embodiment, the information representative of the size of the prefix is ​​the size itself. In another embodiment, this information is obtained by processing the size, for example a hash. This hash and an integrity check are used in certain embodiments to prevent fraudulent insertion of identifying information.

[0040] Knowing the prefix size of the IP address assigned to the equipment, this equipment can be identified unambiguously.

[0041] Thanks to the invention, it is possible to perform an action against malicious equipment without affecting the quality of experience of other equipment connected to the network.

[0042] In one embodiment, the IP address is an IPv4 address or an IPv6 address.

[0043] In one embodiment, the method for sending information further comprises a step of sending, by the transmitting device to the receiving device, information representative of a duration of allocation of the prefix.

[0044] A defined action against malicious equipment may be taken if the address assigned to the equipment continues to appear on a blacklist maintained by an IP reputation system. This action may consist, for example, of implementing a filter whose validity period is in line with the prefix allocation period. More precisely, the filter will be valid as long as the address appears on a blacklist.

[0045] In one embodiment, the method for sending information further comprises a step of sending, by the sending device to the receiving device, information representative of an identifier of an IP resource reputation server of the first network, the server being configured to manage at least one list of IP resources associated with equipment connected to the first network.

[0046] Thus, a possible action defined against the equipment can be notified by the reputation system to the network operating entity from which the equipment obtained its IP address. It is then possible to avoid a degradation of service within the first network by avoiding assigning an IP resource identical to that of the equipment concerned by the action, to another equipment.

[0047] In one embodiment, said transmitter and receiver devices are routers communicating according to one of the BGP (Border Gateway Protocol) or BGPSEC (Border Gateway Protocol Security) protocols, and construct a table comprising at least one piece of information representative of the prefix size of an IP address.

[0048] Correlatively, the invention relates to a device of a first network, called a "transmitter device", the first network being capable of joining a second network, the transmitter device being characterized in that it is configured to send, to a device of the second network, information representative of a prefix size of an IP address assigned to equipment connected to the first network.

[0049] The transmitting device according to the invention can implement the method of sending information in accordance with the invention.

[0050] In one embodiment, the transmitting device is a server or network equipment, for example a router.

[0051] Correlatively, the invention relates to a method for receiving information allowing reputation management of IP resources in a set of networks comprising at least a first network and a second network and implementing reputation management of IP resources, the method being implemented by a device of the set of networks, called "receiving device", and characterized in that it comprises the steps of: obtaining information representative of a prefix size of an IP address assigned to a device connected to the first network; and executing an action defined according to the size.

[0052] In one embodiment, the first and second networks are operated by two separate entities.

[0053] In one embodiment, the action is at least one of: an addition of an IP resource associated with the equipment to a blacklist or a whitelist, said IP resource being the IP prefix or address; a removal of the IP resource associated with the equipment from a blacklist or a whitelist; a limitation of traffic exchanged with the equipment; a redirection of communications involving the IP resource associated with the equipment to a dedicated portal; and an update of a routing or reputation table of IP resources.

[0054] In one embodiment, the method for receiving information further comprises, following the step of executing an action, a step of canceling an effect of the action, this cancellation step being triggered upon expiration of a lifetime of the action or upon receipt of a request from a device configured for IP resource reputation management.

[0055] In one embodiment, the step of canceling an effect of the action is preceded by steps of requesting and receiving at least one additional information from the device configured for IP resource reputation management.

[0056] The said additional information may be useful to verify the authenticity of the information representing the size.

[0057] In one embodiment, the receiving device further obtains at least one of: the IP address of the equipment; information representative of a duration of allocation of the prefix; an identifier of an IP resource reputation server of the first network, the server being configured to manage at least one list of IP resources associated with equipment connected to the first network; an identification code of an action already performed by another device; a reason for the action already performed by another device; a list of IP resources associated with a filter; and timestamp information on the allocation of the IP address of the equipment.

[0058] Obtaining the list of IP resources associated with a filter can be used to update a routing table or a table related to an IP resource reputation system. The filter can use an IP address, a prefix, and / or a network identifier.

[0059] Correlatively, the invention relates to a device of a set of networks, called "receiving device", said set of networks comprising at least a first network and a second network, the receiving device being characterized in that it is configured to: obtain information representative of a prefix size of an IP address assigned to equipment connected to the first network; and execute an action defined according to the size of said prefix.

[0060] The receiving device according to the invention can implement the method of receiving information in accordance with the invention.

[0061] The receiving device according to the invention obtains the information representative of the size of the prefix, this information having been sent by the transmitting device according to the invention.

[0062] In one embodiment, the receiving device is a network device of the second network, or a server of an IP resource reputation system of all the networks, or an IP resource reputation server of the first network.

[0063] The invention also relates to a first computer program on a recording medium, this program being capable of being implemented in a device, called a "transmitting device", such as a server or network equipment. This program comprises instructions adapted to the implementation of a method for sending information as described above.

[0064] The invention also relates to a second computer program on a recording medium, this program being capable of being implemented in a device called a "receiving device", such as a server or network equipment. This second program comprises instructions adapted to the implementation of a method for receiving information as described above.

[0065] Each of these programs may use any programming language, and may be in the form of source code, object code, or code intermediate between source code and object code, such as in a partially compiled form, or in any other desirable form.

[0066] The invention also relates to information or recording media readable by a computer, and comprising instructions of the computer programs as mentioned above.

[0067] The information or recording media may be any entity or device capable of storing programs. For example, the media may include a storage medium, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording medium, for example a floppy disk or a hard disk, or a flash memory.

[0068] Furthermore, the information or recording media may be transmissible media such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio link, by wireless optical link or by other means. The programs according to the invention may in particular be downloaded from a network such as the Internet.

[0069] Alternatively, each information or recording medium may be an integrated circuit in which one of the programs is incorporated, the circuit being adapted to carry out or to be used in carrying out the method in question. Brief description of the drawings

[0070] Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended drawings which illustrate an exemplary embodiment thereof without any limiting character. In the figures: there Figure 1 illustrates a network in which a method of sending information and a method of receiving information according to the invention can be implemented in a particular embodiment; Figure 2is a timing diagram representing the steps of a method of sending information and a method of receiving information in a network activating the BGPSEC protocol in accordance with a first embodiment of the invention; Figure 3 is a timing diagram representing the steps of a method of sending information and a method of receiving information in a network capable of implementing TCP communication, in accordance with a second embodiment of the invention; Figure 4 illustrates a second network in which a method of sending information and a method of receiving information in accordance with the invention can be implemented in a particular embodiment; Figure 5 is a timing diagram representing steps of a variant of the method for receiving information in accordance with an embodiment of the invention; Figure 6is a timing diagram representing steps of a variant of the method for sending information in accordance with an embodiment of the invention; Figure 7 illustrates the functional architecture of a so-called “receiving device” in accordance with the invention according to one embodiment; figure 8 illustrates the hardware architecture of a router according to the invention according to one embodiment; and the figure 9 illustrates the hardware architecture of a so-called “receiving device” in accordance with the invention according to one embodiment. Detailed description

[0071] There Figure 1 represents a set of NET networks in which a method of sending and a method of receiving information, in accordance with the invention, are implemented, said information being able to be advantageously used for reputation management of IP resources.

[0072] In this embodiment, the set of networks NET is managed by several operators: the set of networks NET comprises a first network AS1 managed by a first operator OP1 and a second network AS2 managed by a second operator OP2. The first network AS1 and the second network AS2 are connected to each other via an RCX interconnection network, for example the Internet.

[0073] In this embodiment, communications between the two networks AS1 and AS2 pass through at least one intermediate node. Each network AS1, AS2, comprises at least one interconnection router rAS1, rAS2.

[0074] The NET network set has a global routing table TRG managed by the interconnecting routers rAS1 and rAS2.

[0075] We recall that a TRG routing table maintains all known and available routes as advertised by the routers of the first and second networks.

[0076] The TRG routing table can contain for each AS1, AS2 network, a list of prefixes advertised by this AS1, AS2 network.

[0077] According to this embodiment, the TRG routing table additionally comprises, for each network AS1, AS2, at least one descriptive information of at least one prefix size as allocated to at least one device connected to this network AS1, AS2.

[0078] A TRM device is connected to the first AS1 network. Its associated IP address within the first AS1 network is derived from a prefix of size T.

[0079] The rAS1 router is configured to send this size T to a receiving device in the second AS2 network, for example the rAS2 router or a DEST content server.

[0080] All NET networks include at least one device, hereinafter called a “network reputation system” and noted IP_REP_NET, allowing the implementation of an IP resource reputation policy within the NET network.

[0081] The IP_REP_NET reputation system has one or more servers. Only one server is presented on the Figure 1 .

[0082] The IP_REP_NET reputation system hosts a database that contains a list of IP resources assigned within the NET network and information about the reputation of these IP resources. Remember that an IP resource can be a prefix or an IP address.

[0083] In this embodiment, the database hosted by the NET network IP resource reputation system, IP_REP_NET, is a so-called "blacklist" which records IP resources identified as source IP addresses of machines connected to the NET network, but infected by viruses or having generated illicit activities such as sending spam or having been involved in the implementation of an attack, for example of the DoS (Denial of Service) type, aimed at one or more other target machines.

[0084] We mean by machine connected to the NET network, network equipment, such as a switch or a router, or user equipment such as a telephone terminal, a tablet or a computer.

[0085] In this embodiment, the first AS1 network comprises a network device, hereinafter called the IP resource reputation server of the first AS1 network and noted IP_REP_AS1, configured for managing the reputation of the IP resources associated with equipment connected to the first AS1 network.

[0086] The IP_REP_AS1 reputation server receives and manages notifications about the reputation of IP resources associated with devices connected to the first AS1 network. It is also responsible for contacting reputation systems to retrieve the list of resources for which it is responsible.

[0087] The second AS2 network may also have a reputation server configured to manage the IP resource reputation of the second AS2 network.

[0088] The IP_REP_AS1 server is identified by an identifier, such as an IP address, an email address, a URI, or a domain name, for example, according to the DNS (Domain Name System) formalism.

[0089] In this embodiment, the reputation server IP_REP_AS1 is configured to receive or send messages from or to the network reputation system IP_REP_NET or other reputation servers of other networks.

[0090] The IP_REP_NET network reputation system is configured to receive requests from reputation servers within the NET network, for example the IP_REP_AS1 server, to perform certain actions such as removing an IP resource from a blacklist.

[0091] In this embodiment, at least one server of the IP_REP_NET system for the reputation of IP resources of the set of NET networks is also configured to send to the associated IP resource reputation servers within a network of the set NET, for example IP_REP_AS1, upon consultation or following a modification of the content of its own database, information messages on its database.

[0092] In this embodiment, a DEST network device is connected to the NET network via the second AS2 network. The DEST device then has a source IP address assigned by the OP2 operator. In this embodiment, the DEST device is a content server, for example a server that hosts a website, or a database.

[0093] Each of the IP addresses of the first TRM device and the DEST server can be an IPv4 address or an IPv6 address.

[0094] Subsequently, and by way of examples, we describe embodiments where the methods of the invention are implemented in an IP network activating the BGPSEC protocol or the BGP protocol and capable in particular of implementing IP communications. Implementation of the methods of the invention in a network activating the BGPSEC protocol

[0095] In one embodiment, the method for sending information and the method for receiving information, in accordance with the invention and allowing the reputation management of IP resources, are implemented in a network using the BGPSEC protocol.

[0096] There Figure 2 is an example of a timing diagram representing steps of the methods of the invention in accordance with this embodiment. The order of the steps is provided by way of example. In particular, certain steps may be triggered in an order other than that of the Figure 2. Also note that some steps are not interdependent. For example, step R_AS310 can be triggered at the initiative of an IP_REP_AS reputation server independently of receiving a notification from an IP_REP_NET reputation system.

[0097] The method of sending information is implemented by the router rAS1, with reference to step E010 described later.

[0098] The method of receiving information is implemented by the router rAS2, with reference to step F020 described later.

[0099] The method of receiving information is implemented by the content server DEST, with reference to step D270 described later.

[0100] The method of receiving information is implemented by at least one server of the network reputation system IP_REP_NET, with reference to steps R240, R250, R320 and R330 described later.

[0101] The method of receiving information is implemented by the IP reputation server IP_REP_AS1 of the first AS1 network, with reference to steps R_AS290 and R_AS300 described later.

[0102] On the Figure 2 , we have represented different steps implemented in this example by the first TRM device, the router rAS1, the router rAS2, the server DEST, a server of the reputation system IP_REP_NET and the reputation server IP_REP_AS1.

[0103] In this embodiment, the routing policy implemented within the NET network is based in particular on the activation of the BGPSEC protocol.

[0104] In this embodiment, the first and second networks AS1 and AS2 are autonomous systems.

[0105] As a reminder, the BGPSEC protocol is a secure version of the BGP protocol. Both BGP and BGPSEC protocols allow routes to be announced between the different autonomous systems (AS) that make up a network, such as the Internet. The different routers in the network exchange UPDATE messages to announce these routes.

[0106] It is recalled that an UPDATE message conforming to the BGP protocol or the BGPSEC protocol includes at least one mandatory attribute named "AS_PATH", which identifies the autonomous system(s) taken by a route announced in the UPDATE message to reach one or more networks identified by their prefix.

[0107] It is recalled that an UPDATE message of the BGPSEC protocol also includes an optional attribute, called "BGPSEC_PATH". This attribute contains the information contained in the AS_PATH attribute: a list of autonomous systems, as well as a list of signatures generated by routers of the autonomous systems listed in the AS_PATH attribute.

[0108] Unlike BGP, BGPSEC allows the integrity of a route advertisement to be verified. Propagating a route advertisement using BGPSEC across different ASes requires the implementation of a digital signature corresponding to each AS crossed. These signatures are added to the BGPSEC_PATH attribute of the UPDATE message.

[0109] In this embodiment, routers rAS1 and rAS2 are Autonomous System Border Router (ASBR) border routers of autonomous systems AS1 and AS2. Routers rAS1 and rAS2 are connected to each other and communicate using the BGPSEC protocol.

[0110] During step E010, router rAS1 sends an UPDATE message to router rAS2. Specifically, router rAS1 inserts the BGPSEC_PATH attribute into the UPDATE message. The BGPSEC_PATH attribute then contains a single signature intended to guarantee the integrity of the advertisement and includes information on: the NLRI (Network Layer Reachability Information) attribute describing the prefixes reached by the routes announced in the UPDATE message, in accordance with the prior art; the number “1” of the AS sending the UPDATE message, AS1, in accordance with the prior art; the number “2” of the destination AS, AS2, in accordance with the prior art; and in accordance with the identification method according to the present invention, the size T of the prefix associated with the IP addresses assigned to equipment connected to the set of networks NET via the first autonomous system AS1, and whose routes are announced to the second autonomous system AS2 via the UPDATE message.

[0111] We note that the size T is that of a prefix associated with IP addresses assigned to devices connected to the first autonomous system AS1. This size is not that of a prefix described in the NLRI field of an UPDATE message.

[0112] For example, an NLRI field describes an IPv6 prefix with a length of 32 bits. The router rAS1 thus announces the IPv6 prefix of length / 32 in accordance with the state of the art but also information representative of the size / 56 of the prefixes delegated to the client equipment connected to the autonomous system AS1, and which are extracted from the prefix / 32. This announcement indicates that this router is capable of reaching any address of the prefix 2001:db8:: / 32 and that the machines connected to the network of this ASBR are identified by addresses derived from the prefixes of size 56.

[0113] For an IPv6 address, the size T of the associated IPv6 prefix typically has a value between 0 and 64. However, values ​​greater than 64 can be considered. A single descriptive attribute of size T is associated with an IPv6 prefix as advertised by an UPDATE message used by the BGPSEC protocol or the BGP protocol.

[0114] The T prefix size attribute is used to determine the size of the prefix with which an IP address is associated.

[0115] In this embodiment, during step E010, the router rAS1 also adds, to the signature of the UPDATE message, an attribute which represents a duration D of allocation of the IP prefixes within the first autonomous system AS1, including the prefix allocated to the first TRM equipment.

[0116] A value of "infinite" can be used to indicate permanent allocation of the prefix.

[0117] A single descriptive attribute of the allocation duration D is associated with an IPv6 prefix announced by an UPDATE message used by the BGPSEC protocol or the BGP protocol.

[0118] In this embodiment, during step E010, the router rAS1 also adds, to the signature of the UPDATE message, an attribute representing an identifier of the reputation server IP_REP_AS1.

[0119] During a step F020 and in accordance with the method for receiving information according to the present invention, the router rAS2 receives the UPDATE message from the router rAS1. From this message, the router rAS2 extracts the information on the prefix size T allocated by the operator OP1, and possibly the duration D and the identifier of the server IP_REP_AS1, and updates the routing table TRG.

[0120] The destination router rAS2 is configured to propagate the UPDATE message, adding a new signature to the BGPSEC_PATH attribute. This message will be sent to ASBR routers in the ASes to which AS2 is connected. The new signature guarantees the integrity of the contents of the UPDATE message, which was initially digitally signed by router rAS1.

[0121] This procedure is repeated from one autonomous system to another. This dissemination phase allows the information on the prefix size T, the duration D of the IP resource delegation, and the identifier of the IP_REP_AS1 server to be announced by the AS1 system to the other autonomous systems making up the set of NET networks.

[0122] In this embodiment, this information is maintained in the global routing table TRG which records all the routes available on the set of NET networks.

[0123] Using the BGPSEC protocol, it is possible to build a TRG table for the entire NET network that maintains structured records, for example in the following way: a prefix allocated within the NET network, for example an IPv6 type prefix, such as 2001:db:: / 32; an autonomous system number AS having allocated IP addresses from a block falling under this prefix; a size T of the prefixes derived from this prefix, of length / 32 in this example; and a duration D of validity of the addresses or prefixes derived from this prefix, of length / 32 in this example, and allocated to the different devices connected to the first AS1 network.

[0124] It is assumed that the user of the TRM device wants to access the contents of the DEST server of the second autonomous system AS2. According to the TRG routing table, the route between the TRM device and the DEST receiver device passes through the routers rAS1 and rAS2.

[0125] During a T200 step, the TRM equipment generates an illicit activity, not in accordance with the usage charter of the service offered by the DEST server, for example an attack on the DEST content server or sending spam to the DEST server.

[0126] The DEST server detects the illicit activity during a step D210.

[0127] The DEST server identifies and executes, during an optional step D220, an action A0 against the TRM equipment.

[0128] This A0 action may consist of adding the IP address(es) associated with the TRM equipment to a blacklist, or limiting traffic received or destined for the TRM equipment, or redirecting communications from the TRM equipment to a dedicated portal.

[0129] During a step D230, the DEST server sends a message to the network's IP resource reputation system, IP_REP_NET, to inform it of the detection of the illicit activity. The message includes the IP address(es) of the TRM device. At least one server of the IP_REP_NET system receives this message during a step R240.

[0130] During a step R250 in accordance with the method for receiving information, the reputation system IP_REP_NET consults the table TRG by providing the IP address of the TRM equipment and obtains information on this address, such as the size T of its prefix, the duration D of its allocation and the identifier IP_REP_AS1 of the reputation server of the first system AS1.

[0131] At least one server in the IP_REP_NET system thus defines an action A1(T) based on the size T and executes said action A1. This action A1 is the update of its database, for example by adding the size prefix T of the IP address of the TRM equipment to its blacklist.

[0132] In a step R260, the server that is part of the IP_REP_NET reputation system transmits the information retrieved from the TRG routing table regarding the prefix of size T to the DEST content server.

[0133] The DEST server receives this information during a step D270.

[0134] Knowing the prefix size T of the IP address allocated by the operator OP1, the DEST server defines an action A2(T) based on the size T and executes it against the TRM device. For example, if the information search (step R250) returns the prefix size 56 for the IPv6 address "2001:db8::1 / 128" of the TRM device, then the action A2 must take as input argument: "2001:db8::1 / 56". The information representing the size T makes it possible to deterministically apply the action required to restrict the access of the TRM device.

[0135] Action A2 cancels the effect of action A0 previously executed during step D220.

[0136] The DEST server, for example, applies a filter using the size T and using the IP address of the TRM equipment.

[0137] According to the previous example where the IP resource of the TRM device is an IPv6 address whose prefix size T is 56 bits, the DEST server applies a filter on all source IP addresses having as first 56 bits, bits identical to the first 56 bits of the IPv6 address of the TRM device.

[0138] Thanks to the invention, a malicious user of the TRM equipment could not generate another IPv6 address to bypass the filter applied by the DEST server because the entire block of addresses sharing the same prefix is ​​filtered.

[0139] In this modeimplementation, the DEST server obtains, during step D270, the duration D of delegation of the prefix of size T. The DEST server then associates a lifetime with its action. This lifetime is calculated on the basis of the duration D of allocation of the IP resource. For example, if the prefix is ​​allocated for 24 hours, the DEST server terminates its action after the expiration of the 24 hours.

[0140] Associating a lifetime with an action makes it possible to streamline the management of filters installed by the DEST server and thus avoid access to the service being restricted for another machine when this lifetime expires.

[0141] In this embodiment, the IP_REP_NET system is informed, during step R250, that the TRM equipment has an IP resource within the first autonomous system AS1.

[0142] During a step R280, the network reputation system IP_REP_NET sends a NOTIF notification message to the reputation server IP_REP_AS1 of the system AS1 to inform it that an action has been carried out against a prefix allocated by the operator OP1.

[0143] In this embodiment, the NOTIF notification message includes the following information: a CODE code corresponding to an action executed by the reputation system IP_REP_NET when updating its database during step R250, for example: ∘ 0: Addition to a blacklist ∘ 1: Removal from a blacklist ∘ 2: Removal from a whitelist ∘ 3: Addition to a whitelist ∘ 4: Rate-limit the IP resource concerned by the action. the reason R_CODE for the action, for example: ∘ 0: denial of service ∘ 1: SPAM ∘ 2: machine infected by a virus ∘ 3: presence in a database of another reputation system

[0144] Other information, such as the timestamp of the IP address allocation to the TRM device, may be communicated. The timestamp communicated in the NOTIF notification message allows the AS1 system to determine the TRM client that initiated the illegal action.

[0145] The IP_REP_AS1 server receives the NOTIF notification message during a step R_AS290. In this embodiment, the reputation server IP_REP_AS1 of the operator OP1 receives the notification message directly from the network's reputation system IP_REP_NET.

[0146] The operator OP1 is then dynamically informed that the IP resource of the TRM equipment has undergone at least one action (A1, A2) relating to its reputation.

[0147] The IP_REP_AS1 server is therefore informed that a block of IP addresses associated within the AS1 system is filtered, and can then react to this action.

[0148] During step R_AS290, the IP_REP_AS1 server identifies the TRM equipment. The identification of the TRM equipment (in the case of direct connection of the TRM equipment to the AS1 network) or of a network equipment associated with the TRM equipment (in the case of connection of the TRM equipment to the AS1 network via an intermediate equipment such as a CPE or an STB) can be done in collaboration with other functional modules of the AS1 system. This identification results in obtaining information representative of the size T of the prefix of the IP address assigned to the TRM terminal within the AS1 network.

[0149] During a step R_AS300, the server IP_REP_AS1 executes, according to a reputation policy, an action A3(T) defined according to the size T. This action A3 can consist of: avoid allocating the IP resource or prefix included in the NOTIF notification message to a new client; redirect the traffic of the TRM equipment concerned to an anti-virus platform; redirect the traffic of the TRM equipment concerned to a platform for detecting and mitigating denial of service attacks; restrict the access of the TRM equipment to the AS1 system service; and / or request a monitoring platform to check whether communications have been sent to the DEST server from the IP resource concerned.

[0150] Thanks to the invention, the OP1 operator is able to anticipate a degradation of service by avoiding allocating an IP address whose prefix is ​​filtered, to new equipment which connects to the NET network.

[0151] Depending on the result of action A3 executed by the autonomous system AS1, the IP_REP_AS1 server automatically undertakes a negotiation phase with the IP_REP_NET reputation system to indicate that the IP resource, having been filtered, no longer represents threats and that measures have been applied locally to comply with the charter of the remote server DEST.

[0152] During a step R_AS310, the IP_REP_AS1 server of the operator OP1 sends to the network reputation server IP_REP_NET a message requesting cancellation of the effect of the action A1 executed by the IP_REP_NET system, for example a request to delete the prefix of size T from the blacklist, which was assigned to the TRM equipment, to avoid a degraded experience or a prevention of access to a service by a machine having the same prefix as the TRM equipment.

[0153] In this embodiment, the message sent during step R_AS310 includes the following information: an identifierID of a transaction established between the IP_REP_NET reputation system and the IP_REP_AS1 server, this identifier is used by AS1 to identify the corresponding request unambiguously; a code corresponding to the request expressed to the IP_REP_NET reputation system, for example: ∘ 0: request to remove from a blacklist, ∘ 1 request to add to a whitelist, or ∘ 2: request to remove any conditioning of the traffic associated with this resource; the IP resource concerned by the request. This IP resource can be a prefix or an IP address; and a justification for the request, for example: ∘ 0: denial of service mitigation action implemented, ∘ 1: anti-SPAM action implemented, ∘ 2: anti-virus filtering action implemented, or ∘ 4: contestation of the action described in a NOTIF notification message.

[0154] The IP_REP_NET network reputation system receives this request during an R320 step.

[0155] In this embodiment, the reputation system IP_REP_NET decides, during a step R330, to accept the request issued by the system AS1. It then cancels the effect of its action A1 by updating its database, for example by deleting from a blacklist, or by adding to a whitelist, the IP resource having been allocated to the TRM equipment.

[0156] In this embodiment, the reputation system of the IP_REP_NET network relies on a mechanism for verifying the authenticity of the messages received, to verify whether an AS is legitimate in issuing actions, for example an RPKI type mechanism (for “Resource Public Key Infrastructure” in English).

[0157] The IP_REP_NET system informs the DEST server of this update and sends it, during a step R340, a request to cancel the effect of the action A2 executed by the DEST server. The DEST server receives this request during a step D345 and cancels the effect of the action A2 during a step D350. Note that the update information (R340) can be retrieved upon request from the DEST server.

[0158] The embodiment presented at the Figure 2 is particularly interesting in a network using IPv6 addressing and / or IPv4 addressing with a variable-length subnet mask (VLSM).

[0159] This embodiment where the BGPSEC protocol is used as a vector for announcing the attributes of size T, duration D and identifier “IP_REP_AS1” advantageously takes advantage of the authentication and integrity verification functions offered by BGPSEC. Implementation of the methods of the invention in a BGP network

[0160] In one embodiment, the method of sending information and the method of receiving information are implemented in a network using the BGP protocol.

[0161] In this embodiment, the first and second networks AS1 and AS2 are autonomous systems.

[0162] The BGP protocol is used in a NET network to advertise routes between different autonomous systems AS1 and AS2.

[0163] The rAS1 router adds in the AS_PATH attribute the prefix size T of a group of IP addresses allocated within the AS1 autonomous system.

[0164] In one embodiment, the router rAS1 also adds to the AS_PATH attribute the prefix allocation duration D of size T and / or the identifier of the IP resource reputation server of the autonomous system AS1, IP_REP_AS1.

[0165] The methods of the invention comprise the same steps described previously in the case of the implementation of these methods in a network activating the BGPSEC protocol, with the exception of the addition of the BGPSEC_PATH type attributes and their signatures. Implementation of the methods of the invention in a network capable of implementing TCP communications

[0166] There Figure 3 is a timing diagram representing steps of the method of sending information and of the method of receiving information, implemented in a network capable of implementing TCP (for “Transmission Control Protocol” in English) communications and in accordance with an embodiment of the invention.

[0167] The method of sending information is implemented by the router rAS1, with reference to step E110 described later.

[0168] The method of receiving information is implemented by the content server DEST, with reference to step D221 described later and to step D270 as described for the implementation of the method in a network activating the BGPSEC protocol.

[0169] The method of receiving information is implemented by at least one server of the IP_REP_NET network reputation system, with reference to steps R250, R320 and R330 as described for the implementation of the method in a network activating the BGPSEC protocol.

[0170] The method of receiving information is implemented by the IP reputation server IP_REP_AS1 of the first network AS1, with reference to steps R_AS290 and R_AS300 as described for the implementation of the method in a network activating the BGPSEC protocol.

[0171] On the Figure 3, we have represented different steps implemented in this example by the TRM equipment, the router rAS1, the router rAS2, the DEST server, a server of the network reputation system IP_REP_NET and the IP_REP_AS1 server of IP resource reputation of the first network AS1.

[0172] In this embodiment, the user of the TRM device wants to access the content of the DEST server. For this, a TCP connection must be established between the TRM device and the DEST server. According to the TRG routing table, the route between the TRM device and the DEST server passes through the routers rAS1 and rAS2.

[0173] During a TCP connection establishment phase CX and during a step T100, the TRM equipment sends a connection establishment request in the form of a SYN type packet (synchronization request) to the DEST server.

[0174] During a step E110 and in accordance with the identification method according to the invention, the router rAS1 intercepts the SYN type message, adds to the SYN message an indicator which indicates the size T of the prefix of the IP address assigned to the TRM equipment connected to the first network AS1, and sends the modified SYN message to the DEST server via the router rAS2 as indicated by the routing table TRG.

[0175] In this embodiment, during step E110, the router rAS1 also adds, to the SYN message, an indicator which represents a duration D of allocation of the prefix of size T.

[0176] In this embodiment, during step E110, the router rAS1 also adds, to the SYN message, an indicator which represents an identifier of the reputation server IP_REP_AS1.

[0177] In step F120, router rAS2 receives the SYN packet and forwards it to its destination, the DEST server.

[0178] During a step D130, the DEST server receives the SYN message and extracts the information on the size T of the prefix of the IP address assigned to the TRM equipment, the duration D of allocation of the prefix and the identifier of the IP_REP_AS1 server. Optionally, the DEST server communicates the identification information received in a TCP message to a reputation system IP_REP_NET which will then feed its reputation management table TRG.

[0179] The TCP connection establishment phase continues with sending an ACK / SYN message from the DEST server to the TRM device to accept the synchronization request, and with sending an ACK message from the TRM device to the DEST server to end the control phase and finalize the establishment of the TCP connection. The steps relating to the exchange of ACK / SYN and ACK messages of the CX phase of TCP connection establishment are known from the state of the art and not described here in detail.

[0180] It is assumed that the TRM equipment carries out an illicit activity during a step T200 and that the DEST content server detects this illicit activity during a step D210.

[0181] During a step D221, the content server DEST defines an action against the TRM equipment based on the size T and executes it.

[0182] Step D221 is followed by steps D230 to D350, as described previously with reference to the implementation of the methods of the invention in a network activating the BGPSEC protocol.

[0183] The embodiment presented at the Figure 3 is particularly interesting in a network using IPv6 addressing and / or IPv4 addressing using a VLSM variable-size subnet mask.

[0184] This embodiment presented at the Figure 3, where step E110 of the method takes place during the connection establishment phase, is particularly interesting since it allows the second network AS2, upon initialization of the connection, to obtain the size T of the prefix allocated within the first network AS1 and to inform the IP resource reputation system IP_REP_NET as quickly as possible about any possible illicit activity. Implementation of the methods of the invention in an IP network using a specific extension header

[0185] In one embodiment, the method of sending information and the method of receiving information are implemented in a network using the IP protocol.

[0186] The process of sending information is implemented by the rAS1 router or by the TRM equipment.

[0187] In this embodiment and in accordance with the method for sending information according to the invention, the TRM equipment or the rAS1 router adds to the IP packets sent by the TRM equipment an attribute representing the prefix size T of the source IP address of the TRM equipment allocated within the first AS1 network, before these IP packets leave the first AS1 network.

[0188] The addition of the extra attribute, representing the size T of the prefix, is recorded in a specific extension header EH (for "Extended Header" in English) in the case of the IPv6 protocol. This information can be recorded in the Options field of an IPv4 packet header.

[0189] In this embodiment, the TRM equipment or the rAS1 router adds other additional attributes to the packets sent by the TRM equipment representing for example the duration D of allocation of the prefix, and / or an identifier of the IP_REP_AS1 server of IP resource reputation of the first AS1 network.

[0190] This step of sending the size T of the prefix according to the method allowing identification, can be followed by steps T200 to D350 similar to steps T200 to D350 of the implementation of the methods of the invention in a network supporting TCP connections.

[0191] The method of receiving information is implemented by the content server DEST, with reference to steps D221 and D270 as described for the implementation of the method in a network supporting TCP connections.

[0192] The method of receiving information is implemented by the network reputation server IP_REP_NET, with reference to steps R250, R320 and R330 as described for the implementation of the method in a network supporting TCP (or BGPSEC) connections.

[0193] The method of receiving information is implemented by the IP reputation server IP_REP_AS1 of the first network AS1, with reference to steps R_AS290 and R_AS300 as described for the implementation of the method in a network capable of implementing TCP (or BGPSEC) connections.

[0194] The advantages of the methods implemented in a network deploying the IPv6 protocol capable of exploiting the specific extension header mentioned above are identical to the advantages of their implementation in a network activating the BGPSEC protocol, as described above. Other embodiments

[0195] In one embodiment, a DEST network device is connected to the NET network via a third AS3 network. The DEST device then has a source IP address assigned by an OP3 operator. The reputation system and the DEST server are not connected to the same AS.

[0196] In one embodiment, the first and second networks AS1 and AS2 are directly connected and share a single router rAS1 (or rAS2). Figure 4 illustrates a NET2 network according to this embodiment of the invention.

[0197] In one embodiment, the reputation server IP_REP_AS1 of the first network AS1 is a module of the router rAS1.

[0198] In one embodiment, a server of the IP_REP_NET reputation system is the same network equipment that hosts the global routing table TRG.

[0199] In one embodiment, the NET set of the first and second networks AS1 and AS2 comprises several IP resource reputation systems.

[0200] In one embodiment, the first network AS1 has several IP_REP_AS1 reputation servers. These several IP_REP_AS1 reputation servers are informed during step E010 or step E110.

[0201] In one embodiment, the reputation server IP_REP_AS1 of the first network AS1 has several identifiers. These identifiers are included in the attribute “IP_REP_AS1” sent during step E010 or step E110.

[0202] In one embodiment, the content server DEST and a network reputation system IP_REP_NET are co-located.

[0203] In one embodiment, the DEST content server is located in a network other than the second network.

[0204] In one embodiment, the prefix size T, IP resource delegation duration D, and IP resource reputation server identifier IP_REP_AS1 information are maintained in a dedicated table other than the global routing table TRG.

[0205] In one embodiment, the TRG routing table is maintained by dedicated systems other than the border routers rAS1 and rAS2.

[0206] In one embodiment of implementing the methods of the invention in a network capable of implementing TCP connections, the router rAS1 intercepts a packet sent by the TRM equipment to the DEST server, other than the SYN type packet, in a step subsequent to the CX connection establishment phase.

[0207] In one embodiment, the first network AS1 has several prefixes. It sends as many UPDATE messages according to the BGP or BGPSEC protocol, each including a single NLRI. Each of the prefixes can be associated with specific values ​​of prefix size T, prefix allocation duration D and identifier of a reputation server IP_REP_AS. These values ​​can be different or identical for all the prefixes.

[0208] In one embodiment, before the DEST content server provides service to the TRM device, the DEST server consults the IP resource reputation system database IP_REP_NET to verify the reputation of this address. If this address is in a blacklist, the DEST content server may refuse to serve the TRM device or perform additional checks to verify that the TRM device is not a rebot or an infected machine.

[0209] In another embodiment relating to the application of the methods of the invention in a network capable of implementing TCP communications, the insertion of identification information, such as the size, the validity period, the identifier of the reputation server, is not done systematically for all communications to the same DEST server. This mode assumes that the DEST server caches the information received in a first SYN message for the validity period indicated in this first message.

[0210] In one embodiment, following the detection (step D210), by the DEST content server, of an illicit activity, the DEST server directly informs the IP_REP_NET reputation system (step D230) without performing any action (without step D220 or D221).

[0211] In the embodiments presented to the figures 2 And 3, it is the DEST content server that detects illicit activity and reports this detection. In another embodiment, a terminal device detects illicit activity and reports it to the network's IP resource reputation system.

[0212] In one embodiment, following the reception (step R240) of information on an illicit activity generated by the TRM equipment, a server of the IP_REP_NET reputation system executes a prior action while the phase (step R250) of searching for additional information is in progress. This action is possibly updated, at the end of step R250, when the search for additional information is complete.

[0213] In one embodiment, at least one of action A2 defined by the content server DEST and action A1 defined by a server of the reputation system IP_REP_NET depends on the identity of the first network AS1 within which the source IP address of an illicit activity has been allocated.

[0214] In one embodiment, the execution of action A1 by a server of the IP_REP_NET system (step R250) is preceded by a step of requesting and a step of receiving at least one piece of additional information from the DEST server. The steps of requesting and receiving at least one piece of additional information may be executed several times until the end of a negotiation phase between the server of the IP_REP_NET system and the DEST server, in a manner similar to the NEGOT negotiation phase described later with reference to the Figure 5 .

[0215] In one embodiment, the reputation server IP_REP_AS1 of the autonomous system AS1 receives the notification message NOTIF (step R_AS290) from the reputation system IP_REP_NET of the network via intermediate network reputation servers.

[0216] The exchanges between the IP_REP_NET system and the IP_REP_AS1 server are not direct in the case where UPDATE announcements have been aggregated by intermediate networks. When UPDATE announcement aggregation is enabled, an ASi intermediate network provides an identifier from its own IP_REP_ASi reputation server as the point of contact for the aggregated prefix. However, an ASi intermediate network must keep in memory the information of the IP_REP_AS1 server identifier as received from the AS1 source network.

[0217] When an intermediate IP_REP_ASi server receives a NOTIF notification message, it consults its local routing table and relays the message to the IP_REP_AS1 server responsible for the IP resource contained in the NOTIF notification message. This operation is repeated until the notification message is received by the first AS1 network that owns the resource in question.

[0218] In another embodiment, the NOTIF notification message is only transmitted upon consultation, by the IP_REP_AS1 server, of the IP_REP_NET system.

[0219] In another embodiment, step R340 of transmitting information from the IP_REP_NET reputation system to the DEST content server is only executed upon consultation, by the DEST server, of the IP_REP_NET reputation system.

[0220] In one embodiment, illustrated by the Figure 5 ,when the reputation system of the IP_REP_NET network receives (during step R320) a request to modify the content of its database from the IP_REP_AS1 reputation system, the IP_REP_NET system requests more information from the IP_REP_AS1 server. To this end, it sends it, during a step R322, a message comprising for example: the ID of the transaction established between the IP_REP_NET reputation system and the IP_REP_AS1 server, as sent in the request; and a list of missing information that will allow the IP_REP_NET reputation system to accept the request.

[0221] Upon receipt of this message by the reputation server IP_REP_AS1, the latter IP_REP_AS1 responds, during a step R_AS324, with a message which includes the following arguments: the transaction ID, identical to the request ID; and the list of missing information requested by IP_REP_NET.

[0222] The IP_REP_NET network reputation system receives this response during an R326 step.

[0223] One or more messages requesting / providing additional information may be exchanged between the IP_REP_NET system and the IP_REP_AS1 server for a given resource. At the end of this NEGOT negotiation phase, the IP_REP_NET reputation system may decide, during step R330, to honor the request issued by the first AS1 network.

[0224] This embodiment illustrated by the Figure 5 can be implemented in a network enabling BGP or BGPSEC protocols, capable of implementing IP communications.

[0225] In one embodiment, during step R330 (respectively D350), at least one server of the IP_REP_NET system (the DEST server) modifies an effect of the action A1 (A2) that it executed during step R250 (D270). For example, if the action A1 was a restriction of access of the terminal to a set of services offered within the set of NET networks, the action A1 is modified by a restriction to a reduced part of this set.

[0226] In one embodiment, illustrated by the Figure 6 , the reputation server IP_REP_AS1 of the first AS1 network sends a REQ message to the reputation system IP_REP_NET to request to retrieve a list of resources from an AS, including itself, for the purpose of consistency checking or consistency of the databases of these servers.

[0227] In this embodiment, at least one server of the IP_REP_NET reputation system implements the method of sending information in accordance with the invention.

[0228] The REQ message may include: an identifier ID' used to correlate the request REQ and the response REP; and a filter F, for example an IP address, a prefix, an AS number, etc.

[0229] The IP_REP_NET reputation system responds with a REP message containing: the same ID' identifier used to correlate the REQ request and the REP response; a code C indicating whether the request was honored or failed, for example ∘ 0: success, ∘ 1: not compatible, ∘ 2: access denied, or ∘ 3: temporarily unavailable; and a list LIST of resources associated with the filter F of the REQ request, including the sizes T of IP prefixes.

[0230] This embodiment illustrated by the Figure 6can be implemented in a network enabling BGP or BGPSEC protocols, capable of implementing TCP communications or any other IP network. Description of the transmitting device according to the invention

[0231] The router rAS1 of the first network AS1 is a transmitting device according to the invention. This router rAS1 makes it possible to send information representative of a prefix size of an IP address allocated within the first network AS1 in the network NET comprising the first network AS1 and at least one second network AS2.

[0232] The router rAS1 is characterized in that it is configured to send, to a receiving device of said second network AS2, a prefix size T associated with said IP address.

[0233] In one embodiment, the first router rAS1 also sends, to the receiving device, a prefix allocation duration D and an identifier of an IP reputation server IP_REP_AS1 of the first AS1 network.

[0234] The rAS1 router implements the method, described previously, allowing the identification of a first TRM device.

[0235] In the embodiment where the NET network is a network enabling the BGP protocol or the BGPSEC protocol, as described previously, the receiving device is an rAS2 router of said at least one second AS2 network.

[0236] In the embodiment where the network NET is a network capable of implementing TCP connections, or an IPv6 network using the resources of a specific EH extension header and as described previously, the receiving device may be a network device, for example the content server DEST, or a terminal device connected to the second network AS2. Description of the receiving device according to the invention

[0237] The invention relates to a piece of equipment, called a "receiving device", of the NET network set. The NET set comprises the first network AS1 and at least the second network AS2. The receiving device enables the reputation management of IP resources of the NET network, and is configured to: obtain the prefix size T of an IP address assigned to the TRM device connected to the first AS1 network; and execute an ACT(T) action based on the size T.

[0238] Note that the TRM terminal can be directly connected to the AS1 network or via a connection device such as a CPE or a residential gateway.

[0239] There Figure 7 represents the functional architecture of the receiving device.

[0240] In one embodiment, the receiving device further obtains at least one piece of information from the duration D of allocation of said prefix and an identifier of the IP_REP_AS1 IP reputation server of the first AS1 network.

[0241] The receiving device may be the second router rAS2. The router rAS2 obtains the size T during step F020 when the invention is implemented in a network enabling the BGP or BGPSEC protocols. The router rAS2 defines and executes, depending on the size T, an action which is the update of the routing table TRG.

[0242] The receiving device may be the content server DEST. The DEST server obtains the size T during step D130 when the invention is implemented in an IP network. The DEST server defines and executes during step D221, depending on the size T, an action as described previously.

[0243] The DEST server also obtains the size T during step D270 when the invention is implemented in a network activating the BGP or BGPSEC protocols, capable of implementing IP communications. The DEST server defines and executes, depending on the size T, an action during step D270.

[0244] The receiving device may be the IP resource reputation server IP_REP_AS1 of the first AS1 network. The IP_REP_AS1 server obtains the size T during step R_AS290. In one embodiment, the IP_REP_AS1 server obtains a code defining a preliminary action executed against the first TRM equipment and / or a timestamp information. The IP_REP_AS1 server defines and executes, depending on the size T obtained, an action during step R_AS300.

[0245] The receiving device may be the IP_REP_NET system for IP resource reputation of the NET network. At least one server of the IP_REP_NET system obtains the size T during step R240. In one embodiment, at least one server of the IP_REP_NET system obtains a code defining a preliminary action executed against the first TRM equipment and / or a timestamp information and / or the IP address of the TRM equipment. At least one server of the IP_REP_NET system defines and executes, depending on the size T obtained, an action during step R250.

[0246] Also, a server of the IP_REP_NET system obtains the size T during step R320, then defines and executes, depending on the size T obtained, an action during step R330.

[0247] In the embodiment described herein, the rAS1 router has the hardware architecture of a computer, as illustrated in figure 8 .

[0248] The architecture of the transmitter device rAS1 comprises in particular a processor 7, a random access memory 8, a read only memory 9, a non-volatile flash memory 10 in a particular embodiment of the invention, as well as communication means 11. Such means are known per se and are not described in more detail here.

[0249] The read-only memory 9 of the router according to the invention constitutes a recording medium in accordance with the invention, readable by the processor 7 and on which a computer program Prog1 in accordance with the invention is recorded here.

[0250] The memory 10 of the router rAS1 makes it possible to record variables used for the execution of the steps of the method for identifying a first TRM device according to the invention, such as the size T of a prefix, the duration D of allocation of an IP resource, and an identifier of the server IP_REP_AS1.

[0251] The computer program Prog1 defines functional and software modules here, configured to enable the identification of a first TRM device. These functional modules rely on and / or control the hardware elements 7-11 of the rAS1 router mentioned above.

[0252] In the embodiment described herein, the receiving device according to the invention each has the hardware architecture of a computer, as illustrated in figure 9 . The receiving device can be the second router rAS2, a network reputation system server, IP_REP_NET, or the reputation server of the first network IP_REP_AS1.

[0253] The architecture of the receiving device comprises in particular a processor 7, a random access memory 8, a read only memory 9, a non-volatile flash memory 10 in a particular embodiment of the invention, as well as communication means 11. Such means are known per se and are not described in more detail here.

[0254] The read-only memory 9 of the receiving device according to the invention constitutes a recording medium in accordance with the invention, readable by the processor 7 and on which a computer program Prog2 in accordance with the invention is recorded here.

[0255] The memory 10 of the receiving device makes it possible to record variables used for the execution of the steps of the method for receiving information according to the invention, such as the size T of a prefix, the duration D of allocation of an IP resource, an IP reputation database, the code CODE of an action, the reason R_CODE of an action, etc.

[0256] The computer program Prog2 defines functional and software modules here, configured to enable IP reputation management in a network. These functional modules rely on and / or control the hardware elements 7-11 of the receiver device mentioned above.

Claims

1. Method for sending information in a set of networks (NET) implementing management of IP resource reputation and comprising at least a first network (AS1) and a second network (AS2), said method being implemented by a device (rAS1) of said first network (AS1), called the "sending device" (rAS1), and characterized in that it comprises a step (E010, E110) of said sending device (rAS1) sending, to a device (DEST, rAS2) of said second network (AS2), called the "receiving device" (DEST, rAS2), a piece of information representative of a length (T) of a second prefix extracted from a first prefix of IP addresses allocated to the first network (AS1), the second prefix having been delegated to at least one equipment (TRM) connected to said first network (AS1), said at least one equipment being identified by an IP address derived from this second prefix.

2. Method according to Claim 1, further comprising a step (E010, E110) of said sending device (rAS1) sending, to the receiving device (DEST, rAS2), a piece of information representative of a period (D) of attribution of said second prefix.

3. Method according to either of Claims 1 and 2, further comprising a step (E010, E110) of said sending device (rAS1) sending, to the receiving device (DEST, rAS2), a piece of information representative of an identifier of an IP resource reputation server (IP_REP_AS1) of said first network (AS1), said server (IP_REP_AS1) being configured to manage at least one list of IP resources associated with equipment connected to the first network (AS1).

4. Method according to any of Claims 1 to 3, wherein said sending and receiving devices are routers (rAS1, rAS2) that communicate according to either the BGP or BGPSEC protocol and that construct a table (TRG) containing at least one piece of information representative of said length (T) of the second prefix.

5. Method for receiving, from a sending device (rAS1), information in a set of networks (NET) implementing management of IP resource reputation and comprising at least a first network (AS1) and a second network (AS2), said method being implemented by a device of said set of networks (NET), called the "receiving device" (rAS2, DEST, IP_REP_AS1, IP_REP_NET), and characterized in that it comprises the steps of: - obtaining (F020, D130, D270, R_AS290, R240) a piece of information representative of a length (T) of a second prefix extracted from a first prefix of IP addresses allocated to the first network (AS1), the second prefix having been delegated to at least equipment (TRM) connected to said first network (AS1), said at least one equipment (TRM) being identified by an IP address derived from this second prefix, said IP address being of IPv6 type or of IPv4 type with a variable length subnet mask; and - executing (F020, D221, D270, R_AS300, R250) an action defined depending on said length (T).

6. Method according to Claim 5, wherein said action is at least one action among: - adding an IP resource associated with said equipment (TRM) to a blacklist or whitelist, said IP resource being said prefix or said IP address; - removing the IP resource associated with said equipment (TRM) from a blacklist or whitelist; - limiting traffic exchanged with said equipment (TRM) ; - redirecting communications involving the IP resource associated with said equipment (TRM) to a dedicated portal; and - updating a routing table or IP resource reputation table (TRG).

7. Method according to either of Claims 5 and 6, further comprising, following the step (R250, D270) of executing an action (A1, A2), a step (R330, D350) of cancelling the effect of said action (A1, A2), this step (R330, D350) being triggered on expiry of a lifetime of said action or on receipt (R320, D345) of a request (R_AS310, R340) from a device (IP_REP_AS1, IP_REP_NET) configured for management of IP resource reputation.

8. Method according to Claim 7, wherein the step (R330) of cancelling an effect of said action (A1) is preceded by steps of requesting (R322) and receiving (R326) at least one complementary piece of information from said device (IP_REP_AS1) configured for management of IP resource reputation.

9. Method according to any of Claims 5 to 8, wherein said receiving device (rAS2, DEST, IP_REP_AS1, IP_REP_NET) further obtains (F020, D130, D270, R_AS290, R240, R326) at least one piece of information among: - said IP address of said equipment (TRM); - a piece of information representative of a period (D) of attribution of said prefix; - an identifier of an IP resource reputation server (IP_REP_AS1) of said first network (AS1), said server (IP_REP_AS1) being configured to manage at least one list of IP resources associated with equipment connected to said first network (AS1) and identified by an IP resource reputation system (IP_REP_NET) of said set of networks (NET); - an identification code of an action already done (D220, R_AS290) by another device; - a reason for said action already done by another device; - a list of IP resources associated with a filter; and - time-stamp information on the assignment of the IP address of said equipment (TRM).

10. Method according to any of Claims 1 to 9, wherein said piece of information representative of the length (T) of the second prefix is the length of the second prefix or a piece of information obtained by processing carried out on the length of the second prefix.

11. Method according to any of Claims 1 to 10, wherein said piece of information representative of the length (T) of the second prefix is distinct from the second prefix.

12. Device, called the "sending device" (rAS1), of a first network (AS1), said first network being capable of joining a second network (AS2), said sending device (rAS1) being characterized in that it is configured to send, to a device (DEST, rAS2) of said second network (AS2), a piece of information representative of a length (T) of a second prefix extracted from a first prefix of IP addresses allocated to the first network (AS1), the second prefix having been delegated to at least one equipment (TRM) connected to said first network (AS1), said at least one equipment being identified by an IP address derived from this second prefix.

13. Device (rAS2, DEST, IP_REP_AS1, IP_REP_NET) of a set of networks (NET), called the "receiving device", said set of networks (NET) comprising at least a first network (AS1) and a second network (AS2), said receiving device (rAS2, DEST, IP_REP_AS1, IP_REP_NET) being characterized in that it is configured to: - obtain (F020, D130, D270, R_AS290, R240), from a sending device (rAS1), a piece of information representative of a length (T) of a second prefix extracted from a first prefix of IP addresses allocated to the first network (AS1), the second prefix having been delegated to at least one equipment (TRM) connected to said first network (AS1), said at least one equipment (TRM) being identified by an IP address derived from this second prefix, said IP address being of IPv6 type or of IPv4 type with a variable length subnet mask; and - executing (F020, D221, D270, R_AS300, R250) an action (ACT(T)) defined depending on said length (T).

14. Receiving device according to Claim 13, being a device among: - a network equipment (rAS2, DEST) of said second network (AS2); - a server of an IP resource reputation system (IP_REP_NET) of said set of networks (NET); or - an IP resource reputation server (IP_REP_AS1) of said first network (AS1).