Intelligent manipulation of denial of service attack traffic

The traffic management system addresses the challenge of routing responses to legitimacy challenges in DDoS mitigation by mirroring traffic and dynamically updating routing policies, ensuring effective filtering of fraudulent traffic in networks with multiple scrubbing devices.

JP2025539226APending Publication Date: 2025-12-04LEVEL 3 COMMUNICATIONS LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025524834
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-11-01
Filing Date
2023-10-11
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

Existing DDoS attack mitigation systems face challenges in ensuring that responses to legitimacy challenges for source IP addresses are routed back to the same scrubbing device that issued the challenge, particularly in networks with multiple scrubbing devices and routers, leading to ineffective filtering of fraudulent traffic.

Method used

A traffic management system that mirrors traffic from scrubbing devices to detect challenges and temporarily updates routing policies to ensure that responses are directed to the same scrubbing device that issued the challenge, using NetFlow analysis to manage and update routing tables dynamically.

Benefits of technology

Ensures that responses to legitimacy challenges are correctly routed, allowing effective filtering of fraudulent traffic and reducing the risk of misidentifying legitimate source IP addresses as fraudulent.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025539226000001_ABST
    Figure 2025539226000001_ABST
Patent Text Reader

Abstract

Systems and methods are provided for improved intelligent handling of distributed denial of service (DDoS) attack traffic. In one implementation, the method may include receiving, at a traffic management system, a mirrored first stream of packets from a router on a first link and a mirrored second stream of packets from the router on a second link. The method may further include determining flow information for the first stream. In an example, the flow information may indicate that a particular source IP address has been challenged to test the validity of the source IP address. The method may further include the traffic management system sending a routing policy update based on the flow information.
Need to check novelty before this filing date? Find Prior Art

Description

[Background technology]

[0001] [CROSS-REFERENCE TO RELATED APPLICATIONS] This application claims the benefit of U.S. Provisional Application No. 63 / 381,833, filed November 1, 2022, entitled "Intelligent Manipulation of Denial of Service Attack Traffic," which is incorporated herein by reference in its entirety.

[0002] A distributed-denial-of-service (DDoS) attack may involve a malicious attempt to disrupt the normal operation of a targeted server, service, and / or network. DDoS attacks can be volumetric or non-volumetric. Flood or volumetric DDoS attacks generally utilize multiple computing systems as sources of traffic to overwhelm the resources of a specific target system. Non-flood or non-volumetric DDoS attacks involve queries focused on overloading or exhausting specific resources of a system. Conducting a DDoS attack may also involve controlling multiple computing machines, potentially including internet-of-things (IoT) devices, to act as bots in a botnet that launch the attack.

[0003] It is with respect to these and other general considerations that the aspects disclosed herein have been made, and although relatively specific problems may be discussed herein, it should be understood that the examples should not be limited to solving the specific problems identified in the background or elsewhere in this disclosure. Summary of the Invention

[0004] Examples of the present disclosure describe systems and methods for intelligent manipulation of distributed denial of service (DDoS) attack traffic. In one example, the method for intelligent manipulation of DDoS attack traffic may include receiving, in a traffic management system, a first stream of packets from a router on a first link and a second stream of packets from a router on a second link. In an example, the first stream of packets may comprise traffic from a first network element operatively connected to the router, and the second stream of packets may comprise traffic from a second network element operatively connected to the router. The method may further include determining flow information regarding the first stream. In an example, the flow information may indicate that the first network element received at least one packet from the router, the packet may include a first source Internet Protocol (IP) address and a first destination IP address. In an example, at least a first parameter of the first stream may indicate that the first network element sent a return packet to the source IP address. The method may further include the traffic management system sending a routing policy update, in an example, the routing policy update may cause at least a routing table in the router to be updated to request that all traffic received by the router having the first source IP address and the first destination IP address be routed to the first network element for a period of time.

[0005] In one example, a system for intelligent manipulation of DDoS attack traffic may include at least one processor and a memory operably coupled to the at least one processor. In an example, the memory stores computer-executable instructions that, when executed by the at least one processor, may cause the system to perform a method. In an example, the method may include receiving, in a traffic management system, a mirrored first stream of packets from a router on a first link and a mirrored second stream of packets from the router on a second link. In an example, the first stream of packets may comprise traffic from a first network element operably connected to the router, and the second stream of packets may comprise traffic from a second network element operably connected to the router. The method may further include determining flow information related to the first stream. In an example, the flow information may indicate that the first network element received at least one packet from the router, the packet may include a first source Internet Protocol (IP) address and a first destination IP address. In an example, at least a first parameter of the first stream may indicate that the first network element sent a return packet to the source IP address. The method may further include the traffic management system sending a routing policy update. In an example, the routing policy update may cause at least a routing table in the router to be updated to request that all traffic received by the router having the first source IP address and the first destination IP address be routed to the first network element for a certain period of time.

[0006] In another example, a system for intelligent manipulation of DDoS attack traffic may include a router, a first network element operably connected to the router, a second network element operably connected to the router, and a traffic management system operably connected to the router. In one example, the traffic management system may be configured to receive a mirrored first stream of packets from the router over a first link and a mirrored second stream of packets from the router over a second link. In an example, the first stream of packets may comprise traffic from the first network element, and the second stream of packets may comprise traffic from the second network element. The traffic management system may be further configured to determine flow information regarding the first stream. In an example, the flow information may indicate that the first network element received at least one packet from the router, the packet may include a first source Internet Protocol (IP) address and a first destination IP address. In an example, at least a first parameter of the first stream may indicate that the first network element sent a return packet to the source IP address. The traffic management system may be further configured to send a routing policy update, in an example, that causes at least a routing table in the router to be updated to request that all traffic received by the router having the first source IP address and the first destination IP address be routed to the first network element for a period of time.

[0007] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter. Additional aspects, features, and / or advantages of examples will be set forth in part in the description that follows, and in part will be obvious from the description, or may be learned by practice of the disclosure. [Brief explanation of the drawings]

[0008] Non-limiting and non-exhaustive examples are described with reference to the following figures:

[0009] [Figure 1] 1 illustrates an exemplary system for intelligent manipulation of distributed denial of service (DDoS) attack traffic.

[0010] [Figure 2] 1 illustrates an exemplary traffic manager.

[0011] [Figure 3] SUMMARY OF THE INVENTION An exemplary method for intelligent manipulation of distributed denial of service (DDoS) attack traffic is presented.

[0012] [Figure 4] 1 illustrates an exemplary computing environment in which aspects of the present application may be practiced. DETAILED DESCRIPTION OF THE INVENTION

[0013] In an example, a DDoS attack may overwhelm or overload a target system with unauthorized, malicious traffic. While a target system is overloaded with malicious traffic, its ability to handle legitimate traffic is reduced. Mitigating a DDoS attack generally involves filtering malicious traffic (e.g., part of a DDoS attack) directed at the target system. After the malicious traffic is filtered out, clean (e.g., valid) traffic may be sent to the target system for processing. In an example, filtering may be performed by one or more network devices, such as a scrubbing device.

[0014] The scrubbing device may operate to test the legitimacy of source addresses in packets destined for the protected target system. For example, one form of DDoS attack may involve spoofing the source address of a packet. To mitigate this type of attack, the scrubbing device may query (e.g., provide a challenge in return) the source address contained in a packet having a destination address of the protected target system. The response to such a challenge will indicate whether the source address contained in the packet is legitimate. If not, the fraudulent source address may be added to a filter list of the scrubbing device for the network, and additional traffic (e.g., packets) from that source address may be filtered out before being delivered to the destination address of the protected target system.

[0015] However, for a challenge / response mechanism to be effective, the response to a challenge from a scrubbing device must be routed back to the same scrubbing device that issued the challenge. This can be complicated by the fact that multiple scrubbing devices and multiple managed security routers may be employed within a network. Additionally, during a DDoS attack mitigation event, the network's routers may typically be configured to route traffic for a particular destination address (target system) to any available scrubbing device, or to rotate / split the routing of traffic for a particular destination address to different scrubbing devices. While this is useful for load balancing, it does not guarantee that the response to a challenge from a particular scrubbing device will be routed back to that same scrubbing device. Therefore, a challenge / response mechanism for verifying the legitimacy of a source address can be complicated in networks with multiple scrubbing devices and / or multiple routers.

[0016] The present technology provides systems and methods for intelligent manipulation of distributed denial-of-service (DDoS) attack traffic. In examples, the provided systems and methods strategically manipulate routing information on a network based on detecting incoming traffic from a network device, such as a scrubbing device. For example, a traffic management system may: (a) detect when a scrubbing device issues a challenge to a source address for traffic with a particular destination address; and (b) temporarily direct all traffic with the same source address / destination address pair to the particular scrubbing device that issued the challenge. This is useful for ensuring that any responses to the challenge are directed to the same scrubbing device that issued the challenge. In examples, the systems and methods include dynamically determining the period during which traffic will be routed to a particular scrubbing device during a DDoS mitigation event.

[0017] As discussed, a network device (e.g., a scrubbing device) may test the legitimacy of a source IP address by issuing a challenge to the source IP address and examining the returned response. The challenge is delivered from the scrubbing device through a router (e.g., a managed security router in a scrubbing center) to the source IP address specified in the packet. In an implementation, the system may include a traffic manager that receives mirrored traffic received by the router in return from the scrubbing device. In an example, the traffic manager may detect certain characteristics of the traffic to determine whether a challenge has been issued to the source address. For example, the traffic manager may detect a return packet from a network element, where the return packet has a certain transmission control protocol (TCP) flag set indicating that a challenge has been issued. From the return packet, the traffic manager may determine the challenged source IP address and the destination address to which the suspect source IP address was attempting to send traffic. Additionally, in examples, the traffic manager may distinguish between traffic from different scrubbing devices based on the link on which the management device receives the mirrored traffic from the router.

[0018] In implementation, the traffic manager may temporarily update the routing policy of a router (e.g., a managed security router at a scrubbing center) to ensure that responses to a challenge are routed to the same network device (e.g., a scrubbing device) that issued the challenge. For the time that the temporary routing policy is in effect, all traffic from the challenged source IP address to the protected target system (with the identified destination IP address) is routed to the same scrubbing device that issued the challenge. The scrubbing device that issued the challenge may then (based on any responses to the challenge) determine whether the source IP address is fraudulent. If so, the source IP address may be added to a filter list for the scrubbing device, and future traffic from the source IP address destined for the protected target system may be appropriately filtered.

[0019] 1 illustrates an exemplary system 100 for intelligent manipulation of distributed denial of service (DDoS) attack traffic. In an example, a provider system 101 may include one or more networks and multiple networking devices that receive packets from a source computing device 108 for delivery to a destination computing device 110. In some examples, the destination computing device 110 may be owned or controlled by a customer of services offered by the provider system 101, including DDoS mitigation services for protecting the destination computing device 110 from unwanted traffic.

[0020] In one implementation, one or more managed security routers 106 may receive data packets from one or more source computing devices 108. The managed security routers 106 may receive packets from the source computing devices 108 via one or more networks or intervening devices, such as, in examples, the routers and switches that comprise the provider system 101. In various implementations, each data packet may include a source Internet Protocol (IP) address and a destination Internet Protocol (IP) address. In such examples, the source IP address may identify a particular source computing device that appears (from the packet) to have sent the data packet (unless the source IP address is spoofed). The destination IP address may identify a particular destination computing device to which the data packet was intended to be sent.

[0021] In an example, managed security router 106 (and / or intervening devices between source computing device 108 and managed security router 106) may be configured to cause data packets destined for one or more destination computing devices 110 to be routed to managed security router 106 under certain conditions. For example, managed security router 106 may be part of or operatively connected to a scrubbing center having various network elements (e.g., 102 and 104) used to filter out suspected DDoS traffic before delivering packets to destination computing device 110. In an example, packets received by provider system 101 and destined for destination computing device 110 may be routed to managed security router 106 if a DDoS attack against destination computing device 110 has been detected or is suspected (collectively, a DDoS attack condition). Such a determination of a DDoS attack condition may be made, for example, by a customer (e.g., the owner of destination computing device 110), automatically by a threat intelligence service (which may or may not be part of provider system 101), by an administrator of provider system 101, or in other ways. In an example, when a DDoS attack condition against a particular customer is detected, all packets received by provider system 101 from source computing device 108 destined for that customer's destination computing device 110 may be routed to managed security router 106. In another example, for some customers, all traffic received by provider system 101 destined for that customer's destination computing device 110 is routed to managed security router 110 regardless of any DDoS attack condition.

[0022] In the example, managed security router 106 sends data packets to network element 102 or network element 104 for filtering. In the example, network elements 102 and 104 may include scrubbing devices, scrubbing servers, or the like, and although two are shown, more network elements may be provided. In the example, each of network elements 102 and 104 is configured to receive traffic from managed security router 106 on a "dirty" virtual local area network (VLAN). Network elements 102 and 104 apply filters to the unfiltered traffic received on the dirty VLAN and return the filtered traffic to managed security router 106 on a separate clean VLAN. In the example, a dirty VLAN and a clean VLAN may be defined between each of network elements 102, 104 and each of managed security router 106. In the example, the VLAN may be port-based (static) or usage-based (dynamic). In an example, each VLAN may be identified by a VLAN identifier, which may be converted into a VLAN tag used in the headers of packets transmitted between network elements (e.g., 102, 104) and managed security router 106 to identify the associated VLAN.

[0023] In examples, the filters applied by network elements 102 and 104 may include access deny lists, access grant lists, filtering logic rules, or others. In examples, the filters may be based, at least in part, on a combination of a source IP address and a destination IP address in a packet. In some examples, network elements 102 and 104 may not have any information about the source IP address contained in a packet received on a dirty VLAN, and they may be configured to test the validity of the source IP address to determine whether to add the source IP address (and / or source IP address / destination IP address pair) to their filters.

[0024] In some examples, testing the validity of a source IP address may include sending a challenge to the source IP address. In examples, if the source IP address is spoofed (i.e., the source computing device that sent the packet is not legitimately associated with the source IP address in the packet), a challenge returned to the source IP address is generally ignored (by the legitimate device associated with that source IP address). If a challenge from a network element (e.g., 102 or 104) is not properly responded to within a predetermined period of time, the source IP address may be deemed spoofed, and the spoofed source IP address may be added to a filter applied by network element 102, 104. In other examples, the failure to receive a proper response, along with other information, is used in weighing the validity of the source IP address. In an example, if an appropriate response to the challenge is received, the source IP address may be considered valid and the source IP address may be added to a verified list of source IP addresses (e.g., an access-permit list) or may otherwise be used in a weighting decision on whether to allow traffic from the source IP address to be delivered to the destination computing device 110.

[0025] One challenge that can arise when using a challenge / response mechanism to test the validity of a source IP address is the need to ensure that the network element 102, 104 that issued the challenge receives the response. For example, if a network element 102 issues a challenge and a legitimate source computing device 108 responds, but the response is routed to the network element 104 by a managed security router 106, the network element 102 may (after a period of time) assume that the source IP address is spoofed. As a result, the challenged source IP address may be improperly considered spoofed by the network element 102 (and traffic from that source IP address may subsequently be filtered out).

[0026] In an example, the system may include a traffic manager that receives mirrored traffic that managed security router 106 receives in return from network elements 102, 104 on their respective Dirty VLANs. In an example, the Dirty VLANs allow for bidirectional communication, but very little traffic is returned to managed security router 106 from network elements 102, 104 on the Dirty VLANs. Therefore, mirroring traffic received from network elements 102, 104 does not impose a significant burden on managed security router 106.

[0027] In an example, the traffic manager 112 may also detect certain characteristics of the mirrored traffic to determine whether a challenge has been issued to the source IP address from one of the network elements 102, 104. For example, the mirrored traffic received at the managed security router 106 on the dirty VLAN from the network elements 102, 104 may include one or more flags (e.g., TCP flags) or other indicators that demonstrate that the network element 102 or 104 has issued a challenge back to the source IP address. The challenge is delivered to the source IP address by the managed security router 106, and the mirrored traffic from the dirty VLAN is used by the traffic manager 112 to ensure that any response to the challenge is routed back to the network element 102, 104 that issued the challenge.

[0028] In an example, the traffic manager 112 may distinguish between different network elements 102, 104 based on the link over which the traffic manager receives mirrored traffic from the managed security router 106. This is discussed further below in connection with FIG. 2. In various implementations, the traffic manager 112 may be responsible for ensuring that a response to a challenge issued to a particular source IP address is returned to the same network element that issued the challenge. As shown in FIG. 1, the managed security router 106 may be operatively connected to the traffic manager 112 and the management system 114. In one implementation, the traffic manager 112 may detect when the network element 102 and / or the network element 104 issues a challenge to a particular source IP address. In an example, the mirrored return packet containing the challenge indicates both: (a) the source IP address (to which the challenge was issued); and (b) the destination IP address of the destination computing device 110 (to which the original traffic was directed).

[0029] In various implementations, traffic manager 112 may temporarily direct all traffic with the same source IP address and destination IP address to the particular network element that issued the challenge (e.g., network element 102 or network element 104). In implementations, traffic manager 112 may ensure that responses to the challenge are routed to the correct network element by temporarily updating the routing policy of managed security router 106, for example, by providing instructions to management system 114. Management system 114, which may include one or more management servers / networks, may then issue routing policy instructions to managed security router 106 to temporarily direct all traffic with that source IP address / destination IP address pair to the particular network element 102, 104 that issued the challenge. In various implementations, while the temporary routing policy is in effect, all traffic with that source IP address / destination IP address pair is routed by managed security router 106 to the same network element that issued the challenge (e.g., network element 102 or network element 104). In examples, the network element that issued the challenge (or some other operatively connected threat mitigation system) may then determine whether the source IP address is legitimate based on the response to the challenge (or failure to respond within a preset time period). In various implementations, if the source IP address is determined to be fraudulent, the source IP address may be added to a filter list for the network element 102, 104, and future traffic from the source IP address destined for the provider system 101 may be appropriately filtered, blocked, or the like.

[0030] Referring now to FIG. 2, an exemplary traffic manager 112 is shown. As shown, traffic manager 112 may include multiple network interface cards (NICs), such as NIC 202, NIC 204, and NIC 210. In various implementations, NICs 202, 204, and 210 may be network interface controllers, network adapters, LAN adapters, or the like. In implementations, NIC 202 and NIC 204 may be configured to enable traffic manager 112 to communicate with a managed security router, such as managed security router 106 as shown in FIG. 1. In examples, the physical or virtual connection between managed security router 106 and NICs 202 and 204 may be referred to as a "link." In various implementations, return traffic on the dirty VLAN from network device 102 may be mirrored by managed security router 106 and received on NIC 202 via a first link. Similarly, return traffic on the Dirty VLAN from network device 104 may be mirrored by managed security router 106 and received on NIC 204 via a second link.

[0031] In an example, mirrored packets received on NICs 202 and 204 may themselves be dropped by traffic manager 112, but flow information about such packets may be extracted and analyzed by network data analyzer 206. For example, network data analyzer 206 may include a NetFlow collector, which may include a device that collects NetFlow protocol information about traffic received on NICs 202 and 204. Network data analyzer 206 may also include a NetFlow data analyzer daemon, which may include one or more applications, modularity, devices, or other systems for analyzing the flow information and determining any actions to take based on such flow information. In an example, the flow information (e.g., NetFlow information) may include metadata about packets received on NICs 202 and 204, such as a source IP address, a destination IP address, and whether the packets include any parameters (e.g., a particular flag or other indicator) that indicate that the packets are a challenge sent back to the source IP address. As discussed, the challenge packet mirrored to the NIC 202 or 204 may include: (a) the source IP address (contained in the original packet that caused the challenge to be issued); (b) the destination IP address contained in the original packet; and (c) a parameter indicating that the challenge is being sent to the source IP address. Because each NIC 202, 204 is correlated to a particular network device 102, 104 based on the NIC (e.g., 202 or 204) that receives the mirrored traffic, the flow information may also indicate which network device 102, 104 issued the challenge.

[0032] As described above, the traffic manager 112 may be responsible for ensuring that responses to a challenge from a source IP address are routed to the same network element 102 or 104 that sent the challenge. Accordingly, and in various implementations, a routing policy update may be generated or initiated by the traffic manager 112. For example, the network data analyzer 206 may determine that flow information indicates that the network device 102 issued a challenge to a first source IP address, and that the challenge packet specifies a first destination IP address. The network data analyzer may check whether a current routing policy already exists for that first source IP address / first destination IP address pair. In an example, the network data analyzer 206 may query the routing policy database 208. In various implementations, the routing policy database 208 may store the routing policy applied for a period determined by the traffic manager 112 in the provider system 111. In examples, the query may determine, for example, whether the routing policy database 208 includes a routing policy for the first source IP address / first destination IP address pair and whether the routing policy is still valid (e.g., whether its time-to-live has expired). In some examples, if a routing policy is already valid for the first source IP address / first destination IP address pair, the network data analyzer 206 may not take any further action. In other examples, the network data analyzer 206 may extend the time-to-live for the current routing policy or take other action.

[0033] If no current routing policy exists for the first source IP address / first destination IP address pair, the network data analyzer 206 may generate such a policy (or instruct the management system 114 to generate such a policy). For example, the network data analyzer 206 may generate a routing policy that instructs the managed security router 106 to route all traffic received from the source computing device 108 having the first source IP address / first destination IP address pair to the network device 102 (the network device that issued the challenge indicated by the flow information) for a determined period of time. In an example, the period of time for which the routing policy is in effect may be expressed as a time-to-live parameter or in other manner, and may be preset or dynamically determined based on, for example, network conditions. In an example, the determined period of time should be long enough to capture any responses to the challenge, but not so long as to adversely affect the load balancing normally performed by the managed security router 106.

[0034] In an example, network data analyzer 206 may cause routing policy database 208 to be updated to reflect the new policy for at least a determined period of time (e.g., as indicated by a time remaining). For example, the policy (or instructions to create the policy) may be sent by network data analyzer 206 to management system 114 via NIC 210. In an example, management system 114 may include an application programming interface to enable programmatic management of routing policies applied to managed security router 106.

[0035] In an example, a routing policy update applied to a managed security router 106 by management system 114 may cause the routing table in the managed security router 106 to be updated to request that all packets received by the managed security router 106 having a specified source IP address / destination IP address pair be routed to the network element (e.g., network element 102) specified in the routing policy update. As discussed, the routing policy update may be applied for a determined (e.g., temporary) period or length of time or may automatically expire. In this way, it is guaranteed that any response to a challenge from network element 102, 104 will be returned to the same network element for a certain period of time. After the routing policy expires, the managed security device 106 may successfully resume sending traffic to a different network element 102, 104, such as by implementing a load balancing algorithm.

[0036] As shown, traffic manager 112 may also include a log database 212. In various implementations, log database 212 may store records of routing policies applied, the duration for which the routing policies were applied, flow information received, and the like.

[0037] 3 illustrates an exemplary method for intelligent manipulation of distributed denial of service (DDoS) attack traffic. In an aspect, method 300 may be performed by one or more components of a system, such as system 100 of FIG. 1 and / or traffic manager 112 of FIG. 2. However, method 300 is not limited to such examples. Exemplary method 300 begins at operation 302, in which a first stream of packets is received from a router on a first link and a second stream of packets is received from the router on a second link. In an example, the router may be a managed security router, such as managed security router 106 as shown in FIG. 1, and the first stream may be received by traffic manager 112 on NIC 202 and the second stream may be received by traffic manager 112 on NIC 204. In various implementations, the first stream of packets may include traffic from a first network element (e.g., network element 102) operably connected to the router, and the second stream of packets may have traffic from a second network element (e.g., network element 104) operably connected to the router. In an example, the first and second network elements (e.g., 102, 104) may be scrubbing devices operably connected to a router.

[0038] The example method 300 continues at operation 304 with flow information for a first stream of packets being determined. In an example, the flow information may be collected (e.g., by the network data analyzer 206) according to a network flow analysis protocol such as NetFlow or the like. In an example, the flow information for the first stream of packets may indicate that a first network element (e.g., 102) received at least one packet from a router having a first source Internet Protocol (IP) address and a first destination IP address. In an example, at least a first parameter of the first stream may indicate that the first network element (e.g., 102) sent a return data packet to the source IP address. For example, as discussed, the return data packet may include (and provide an indicator of) a challenge issued by the first network element to test the validity of the source IP address, and the return packet including the challenge may include both the first source IP address and the first destination IP address. Additionally, the link over which the return packet is received (e.g., via NIC 202) may indicate that the return packet was sent by the first network element (e.g., 102) rather than a different network element (e.g., 104).

[0039] The example method 300 continues at operation 306 with a routing policy update being performed for the combination of the first source IP address and the first destination IP address. As discussed, the routing policy update may be sent to a managed security router (e.g., managed security router 106 as shown in FIG. 1) by a traffic manager (e.g., traffic manager 112 as shown in FIG. 1) and / or by a management system (e.g., management system 114 as shown in FIG. 1). In various implementations, the managed security router may be instructed via a routing policy to route network traffic having the first source IP address and the first destination IP address to a first network element (e.g., 102). In various implementations, the routing policy update may cause a routing table in the router to be updated to request that all traffic received by the router having the first source IP address and the first destination IP address be routed to the first network element. In implementations, the routing policy may be temporary, and the managed security router may be instructed to apply the updated routing policy only for a specific period of time. In further examples, the specific period of time may be preset or dynamically determined. For example, it may be based on current network conditions or other factors. In examples, as discussed, a determination may be made whether the current routing policy is valid for the first source IP address / first destination IP address pair before operation 306 (or any routing policy is updated). For ease of discussion, this is addressed below with respect to operation 310 regarding flow information for the second stream, although one skilled in the art will understand that a similar procedure can be followed with respect to the first stream.

[0040] The example method 300 continues at operation 308 with flow information for the second stream being determined. In an example, the flow information may be collected (e.g., by the network data analyzer 206) according to a network flow analysis protocol such as NetFlow or the like. In an example, the second parameter of the second stream may indicate that the second network element (e.g., 104) sent a return data packet to the source IP address. For example, as discussed, the return data packet may include (and provide an indicator of) a challenge issued by the second network element to test the validity of the source IP address, and the return packet may include both a source IP address and a destination IP address. In some examples, the source IP address may be the same as or a different source IP address from the first source IP address detected in the first stream. Further, in an example, the destination IP address may be the same as or a different destination IP address from the first destination IP address detected in the first stream. The source IP address and destination IP address pair contained in the return packet detected in the second stream may be referred to as a second source / destination IP tuple (or pair). Additionally, the link over which the return packet is received (e.g., via NIC 204) may indicate that the return packet was sent by a second network element (e.g., 104) rather than a different network element (e.g., 102).

[0041] The exemplary method 300 continues at operation 310, where it is determined whether a current routing policy exists for the second source / destination IP address pair. As described above, routing policies may be stored in a routing policy database, such as routing policy database 208 as shown in FIG. 2. In various implementations, determining whether a current routing policy exists for the second source / destination IP address may include querying the routing policy database. In an example, the second source / destination IP address pair may match the first source / destination IP address pair or another source / destination IP address pair that is already subject to the current routing policy. In such an example, a routing policy for the particular network element may already be in place. Therefore, if a current routing policy exists for the second source / destination IP address pair, no second routing policy update is performed, and the exemplary method 300 may end at operation 314. Otherwise, if there is no current routing policy for the second source / destination IP address pair, the example method 300 may complete at operation 312, as a second routing policy update is performed, for example, in a manner similar to operation 306.

[0042] 4 is a block diagram of an example computing device 400. The computing device 400, or various components and systems of the computing device 400, may be integrated with or associated with the network elements 102, 104, the managed security router 106, the source computing device 108, the destination computing device 110, the traffic manager 112, the management system 114, and / or other elements of the system 100. As shown in FIG. 4, physical components (e.g., hardware) of the computing device are illustrated, and these physical components may be used to practice various aspects of the present disclosure. The elements described above may be implemented via one or more computing devices 400.

[0043] The computing device 400 may include at least one processing unit 410 and a system memory 420. The system memory 420 may include, but is not limited to, volatile storage (e.g., random access memory), non-volatile storage (e.g., read-only memory), flash memory, or any combination of such memory. The system memory 420 may also include an operating system 430, which controls the operation of the computing device 400, and one or more program modules 440. The program modules 440 may be responsible for collecting or determining event data 450, including endpoint data and / or network data. Several different program modules and data files may be stored in the system memory 420. While executing on the processing unit 410, the program modules 440 may perform the various processes described above.

[0044] Computing device 400 may also have additional features or functionality. For example, computing device 400 may include additional data storage devices (e.g., removable and / or non-removable storage devices), such as magnetic disks, optical disks, or tape. These additional storage devices are labeled removable storage 460 and non-removable storage 470.

[0045] Examples of the present disclosure may also be practiced in electrical circuits including discrete electronic elements, packaged or integrated electronic chips including logic gates, circuits utilizing a microprocessor, or on a single chip including electronic elements or a microprocessor. For example, examples of the present disclosure may be practiced via a system-on-a-chip (SOC) in which each or many of the components shown in FIG. 4 may be integrated onto a single integrated circuit. Such an SOC device may include one or more processing units, graphics units, communications units, system virtualization units, and various application functions, all of which are integrated (or "burned") onto the chip substrate as a single integrated circuit.

[0046] When operating via a SOC, the functionality described herein may operate via application-specific logic integrated with other components of computing device 400 on a single integrated circuit (chip). The present disclosure may also be practiced using other technologies capable of performing logical operations such as AND, OR, and NOT, including, but not limited to, mechanical, optical, fluidic, and quantum technologies.

[0047] Computing device 400 may include one or more communication systems 480 that enable computing device 400 to communicate with other computing devices 495, such as, for example, servers, routers, network devices, client computing devices, etc. Examples of communication systems 480 include, but are not limited to, wireless communication, wired communication, cellular communication, radio frequency (RF) transmitter, receiver, and / or transceiver circuitry, a Controller Area Network (CAN) bus, a universal serial bus (USB), a parallel port, a serial port, etc.

[0048] Computing device 400 may also have one or more input devices and / or one or more output devices, shown as input / output devices 490. These input / output devices 490 may include keyboards, sound or voice input devices, haptic devices, touch, force, and / or swipe input devices, displays, speakers, etc. The devices listed above are examples, and others may be used.

[0049] As used herein, the term computer-readable media may include non-transitory computer storage media, which may include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information, such as computer-readable instructions, data structures, or program modules.

[0050] System memory 420, removable storage 460, and non-removable storage 470 are all examples of computer storage media (e.g., memory storage). Computer storage media may include RAM, ROM, electrically erasable read-only memory (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other article of manufacture that can be used to store information and that can be accessed by computing device 400. Any such computer storage media may be part of computing device 400. Computer storage media is tangible and non-transitory and does not include carrier waves or other propagated or modulated data signals.

[0051] Communication media may be embodied by computer-readable instructions, data structures, program modules, or other data in a modulated data signal, such as a carrier wave or other transport mechanism, and includes any information delivery media. The term "modulated data signal" may describe a signal that has one or more characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, communication media may include wired media such as a wired network or direct-wired connection, and wireless media such as acoustic, radio frequency (RF), infrared and other wireless media.

[0052] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the inventive concepts. Moreover, unless expressly stated otherwise, the embodiments described herein are not mutually exclusive. Aspects of the embodiments described herein may be combined in some implementations.

[0053] With respect to the process in the flow diagram of FIG. 3, it should be understood that, as will be appreciated by those skilled in the art, the order of the steps of the process is not fixed and may be modified, reordered, performed differently, performed sequentially, in parallel, or simultaneously, or rearranged in any desired order.

[0054] The embodiments described herein may be employed to implement and perform the systems and methods disclosed herein using software, hardware, or a combination of software and hardware. Although specific devices are recited throughout this disclosure as performing certain functions, those skilled in the art will understand that these devices are provided for illustrative purposes and that other devices may be employed to perform the functions disclosed herein without departing from the scope of the present disclosure. Additionally, some aspects of the present disclosure are described above with reference to block diagrams and / or operational illustrations of systems and methods according to aspects of the present disclosure. The functions, operations, and / or acts noted in the blocks may occur in a different order than shown in any respective flowchart. For example, two blocks shown in succession may in fact be performed or executed substantially in parallel or in the reverse order, depending on the functionality and implementation involved.

[0055] This disclosure describes some embodiments of the technology with reference to the accompanying drawings, in which only some of the possible embodiments are shown. However, other aspects may be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of possible embodiments to those skilled in the art. Furthermore, as used herein and in the claims, the phrase "at least one of element A, element B, or element C" is intended to convey any of: element A, element B, element C, elements A and B, elements A and C, elements B and C, and elements A, B, and C. Furthermore, those skilled in the art will understand the extent conveyed by terms such as "about" or "substantially" in light of the measurement techniques used herein.

[0056] Although specific embodiments are described herein, the scope of the present technology is not limited to those specific embodiments. Moreover, although different examples and embodiments may be described separately, such embodiments and examples may be combined with each other when implementing the technology described herein. Those skilled in the art will recognize other embodiments or improvements that are within the scope and spirit of the present technology. Therefore, specific structures, acts, or mediums are disclosed only as exemplary embodiments. The scope of the present technology is defined by the following claims and any equivalents therein.

Claims

1. receiving, in a traffic management system, a first stream of packets from a router on a first link and a second stream of packets from the router on a second link, wherein the first stream of packets comprises traffic from a first network element operatively connected to the router and the second stream of packets comprises traffic from a second network element operatively connected to the router; determining flow information for the first stream, wherein the flow information indicates that the first network element received at least one packet from the router having a first source Internet Protocol (IP) address and a first destination IP address, and at least a first parameter of the first stream indicates that the first network element sent a return packet to the source IP address; the traffic management system sending a routing policy update, wherein the routing policy update causes at least a routing table in the router to be updated to request that all traffic received by the router having the first source IP address and the first destination IP address be routed to the first network element; A method for providing the above.

2. The method of claim 1 , wherein the routing policy update is applied for a determined period of time.

3. The method of claim 2 , wherein the determined period is based on the flow information.

4. determining flow information for the second stream, wherein the flow information indicates that the second network element received at least one packet from the router having a second source Internet Protocol (IP) address and a second destination IP address, and at least a second parameter of the second stream indicates that the second network element sent a return packet to the second source IP address; the traffic management system sending a second routing policy update, wherein the second routing policy update causes at least a second routing table in the router to be updated to request that all traffic received by the router having the second source IP address and the second destination IP address be routed to the second network element; The method of claim 1 further comprising:

5. The method of claim 1 , wherein the first network element is a scrubber.

6. The method of claim 5 , wherein the first parameter of the first stream indicates that the source IP address has been challenged by the scrubber.

7. determining flow information for the second stream, wherein the flow information indicates that the second network element received at least one packet from the router having a second source Internet Protocol (IP) address and a second destination IP address, and at least a second parameter of the second stream indicates that the second network element sent a return packet to the second source IP address; determining that a current routing policy exists for the second source IP address and the second destination IP address; and determining, based on the step of determining that a current routing policy exists, that the traffic management system not send a second routing policy update. The method of claim 1 further comprising:

8. at least one processor; and a memory operatively coupled to the at least one processor; wherein the memory stores computer-executable instructions that, when executed by the at least one processor, cause the system to: receiving, in a traffic management system, a first stream of packets from a router on a first link and a second stream of packets from the router on a second link, wherein the first stream of packets comprises traffic from a first network element operatively connected to the router and the second stream of packets comprises traffic from a second network element operatively connected to the router; determining flow information for the first stream, wherein the flow information indicates that the first network element received at least one packet from the router having a first source Internet Protocol (IP) address and a first destination IP address, and at least a first parameter of the first stream indicates that the first network element sent a return packet to the source IP address; the traffic management system sending a routing policy update, wherein the routing policy update causes at least a routing table in the router to be updated to request that all traffic received by the router having the first source IP address and the first destination IP address be routed to the first network element; A system for performing a method having the steps of:

9. The system of claim 8 , wherein the routing policy updates are applied for a determined period of time.

10. The system of claim 9 , wherein the determined period is based on the flow information.

11. The method comprises: determining flow information for the second stream, wherein the flow information indicates that the second network element received at least one packet from the router having a second source Internet Protocol (IP) address and a second destination IP address, and at least a second parameter of the second stream indicates that the second network element sent a return packet to the second source IP address; the traffic management system sending a second routing policy update, wherein the second routing policy update causes at least a second routing table in the router to be updated to request that all traffic received by the router having the second source IP address and the second destination IP address be routed to the second network element; The system of claim 8 further comprising:

12. The system of claim 8 , wherein the first network element is a scrubber.

13. The system of claim 12 , wherein the first parameter of the first stream indicates that the source IP address has been challenged by the scrubber.

14. The method comprises: determining flow information for the second stream, wherein the flow information indicates that the second network element received at least one packet from the router having a second source Internet Protocol (IP) address and a second destination IP address, and at least a second parameter of the second stream indicates that the second network element sent a return packet to the second source IP address; determining that a current routing policy exists for the second source IP address and the second destination IP address; and determining, based on the step of determining that a current routing policy exists, that the traffic management system not send a second routing policy update. The system of claim 8 further comprising:

15. Router; a first network element operably connected to said router; a second network element operatively connected to the router; and a traffic management system operatively connected to said router; the traffic management system comprising: receiving a first stream of packets from the router over a first link and a second stream of packets from the router over a second link, wherein the first stream of packets comprises traffic from the first network element and the second stream of packets comprises traffic from the second network element; determining flow information for the first stream, where the flow information indicates that the first network element received at least one packet from the router having a first source Internet Protocol (IP) address and a first destination IP address, and at least a first parameter of the first stream indicates that the first network element sent a return packet to the source IP address; sending a routing policy update, wherein the routing policy update causes at least a routing table in the router to be updated to request that all traffic received by the router having the first source IP address and the first destination IP address be routed to the first network element; The system is configured as follows:

16. The system of claim 15 , wherein the routing policy updates are applied for a determined period of time.

17. The system of claim 16 , wherein the determined period is based on the flow information.

18. The system of claim 15 , wherein the first network element is a scrubber.

19. 20. The system of claim 18, wherein the first parameter of the first stream indicates that the source IP address has been challenged by the scrubber.

20. The traffic management system: determining flow information for the second stream, where the flow information indicates that the second network element received at least one packet from the router having a second source Internet Protocol (IP) address and a second destination IP address, and at least a second parameter of the second stream indicates that the second network element sent a return packet to the second source IP address; determining that a current routing policy exists for the second source IP address and the second destination IP address; and determining not to send a second routing policy update based on determining that the current routing policy exists; The system of claim 15 further configured to: