Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

181 results about "Border Gateway Protocol" patented technology

Border Gateway Protocol (BGP) is a standardized exterior gateway protocol designed to exchange routing and reachability information among autonomous systems (AS) on the Internet. The protocol is classified as a path vector protocol. The Border Gateway Protocol makes routing decisions based on paths, network policies, or rule-sets configured by a network administrator and is involved in making core routing decisions.

Distributed Source Network Address Translation (SNAT) Enabled LEAF

PendingUS20250323866A1TransmissionDistributed sourceDistributed Computing Environment
Various methods and processing systems for the effective management of network traffic and facilitating data forwarding within distributed computing environments. Network components may be configured to amalgamate the Border Gateway Protocol (BGP) with Source Network Address Translation (SNAT) or network address port translation (NAPT) technologies to facilitate dynamic notification of network address accessibility and use port index identifiers to augment the precision and resilience of routing. A distributed SNAT / NAPT virtual network function (VNF) or cloud-native network function (CNF) may collaborate with LEAF switches or server aggregation devices to refine data transmission via adaptable address mapping and forwarding and enhance network scalability and resilience.
Owner:CHARTER COMM OPERATING LLC

Packet Routing in Disaggregated Scheduled Fabrics

Devices, networks, systems, methods, and processes for packet forwarding and routing are described herein. A leaf switch can be in communication with a host device. The leaf switch may configure a subnet comprising the host device. The leaf switch can assign a next hop interface as a system port of the leaf switch and generate subnet information indicative of the assignment. The leaf switch may distribute the subnet information to one or more network devices through one or more internal Border Gateway Protocol sessions. A data packet destined to the host device can be transmitted to the system port of the leaf switch when a host Media Access Control (MAC) address of the host device is not resolved. The leaf switch can resolve the host MAC address and transmit the data packet to the host device based on the host MAC address.
Owner:CISCO TECHNOLOGY INC

Routing control method and apparatus, system and border gateway protocol peer

The present disclosure relates to a routing control method, a system, and a BGP Peer. The method of the present disclosure can be executed by a first BGP Peer, including: receiving information of adding a new VPN route sent from a second BGP Peer, wherein the information of adding the new VPN route comprises: the new VPN route and an identifier of a first VPN instance; determining whether a number of VPN routes corresponding to the identifier of the first VPN instance reaches or exceeds a limit value after adding the new VPN route; and sending first instruction information to the second BGP Peer to instruct the second BGP Peer, in a case that the number of VPN routes corresponding to the identifier of the first VPN instance reaches or exceeds the limit value, wherein the first BGP Peer is an iBGP Peer inside a first AS.
Owner:CHINA TELECOM CORP LTD

Advertisement of selective EVPN routes based on route types

A router is configured to send an advertisement of selective Ethernet Virtual Private Network (VPN) (EVPN) routes based on the Route Types. The router is configured to determine a requirement for a route refresh from a Border Gateway Protocol (BGP) peer for a subset of Route Types of all of the Route Types, send a route refresh message to the BGP peer with an indication of the subset of Route Types, and receive updated routes from the BGP peer only for the subset of Route Types. The indication can be included in a reserved field and payload of the route refresh message. The route refresh message can be defined in RFC 2918.
Owner:CIENA CORP

Network anomaly detection with graph attention network

A multi-instance learning and weakly supervised BGP anomaly detection framework is provided, that detects and analyzes significant statistical correlations across multiple data sources such as model driven telemetry (MDT), network messages, event data logs, and / or device configuration data for network topology. Specifically, methods are provided that involve obtaining, from a plurality of data sources, data related to operation or configuration of Border Gateway Protocol (BGP) in an enterprise network and extracting one or more BGP features based on at least one correlation among the data from the plurality of data sources. The methods further involve detecting one or more network anomalies by performing a weakly supervised machine learning of the one or more BGP features and providing information about the one or more network anomalies for performing one or more actions associated with the enterprise network.
Owner:CISCO TECHNOLOGY INC

Methods and systems to prioritize border gate protocol (BGP) route target (RT) membership network layer reachability information (NLRI) handling

Embodiments include methods, electronic device, storage medium to prioritize Ethernet Segment(ES) route handling. In one embodiment, a method comprises, upon receiving a BGP update message with a route target (RT) membership Network Layer Reachability Information (NLRI), determining whether to prioritize the BGP update message based on existence of a flag indication within the RT membership NLRI; responsive to the flag indication being set in the RT membership NLRI, processing the RT membership NLRI to advertise a route matching the RT membership indicated in the first BGP update message without waiting on one or more periodic update timers; responsive to the flag indication not being set but the RT membership NLRI including a combination of type and subtype that indicates an ES-import RT, processing the RT membership NLRI without waiting on the timers as well; and otherwise processing the RT membership NLRI to advertise upon expiration of the timers.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Predictive BGP peering

In one embodiment, a device determines a mapping between a network destination and Border Gateway Protocol (BGP) peers located across a plurality of autonomous systems for which the network destination is reachable. The device causes, based on the mapping, performance of probing tests along a plurality of paths to the network destination and via the BGP peers, to obtain path performance measurements for the plurality of paths. The device uses a prediction model to generate predicted performance metrics for the plurality of paths based on the path performance measurements. The device configures, based on the predicted performance metrics for the plurality of paths, the BGP peers with BGP peering policies to convey application traffic associated with the network destination via particular path from among the plurality of paths.
Owner:CISCO TECHNOLOGY INC

BGP LU resiliency using an anycast SID and BGP driven anycast path selection

A node, in a first network, includes circuitry configured to determine a next hop as decided by Border Gateway Protocol (BGP) is an anycast prefix to a Route Reflector (RR) interconnecting the first network with a second network, responsive to the next hop being the anycast prefix to the RR, create a tunnel with a destination based on the anycast prefix, and utilize the tunnel for traffic having the next hop as the anycast prefix to the RR. The anycast prefix is assigned to two or more RRs interconnecting the first network and the second network. A first path is decided by BGP based on a BGP Path Selection Algorithm that is independent of a second path determined by Interior Gateway Protocol (IGP). The first path and the second path can be different, and wherein tunnel is utilized to ensure the traffic always follows the first path.
Owner:CIENA CORP

System and method to discover candidate PTP clock source(s) over IP / MPLS network

Aspects of the subject disclosure may include, for example, a device, including: a processing system including a processor; a clock; and a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations of: advertising via Border Gateway Protocol (BGP) a capability as a precision timing protocol (PTP) master clock through an Internet Protocol (IP) / Multi-Protocol Label Switching (MPLS) network, wherein the advertising includes an IP address of the device; receiving a unicast signaling mechanism from a PTP client node in the network; and sending clock messages to the PTP client node responsive to accepting the PTP client node. Other embodiments are disclosed.
Owner:CIENA CORP

Transport layer protocol state handling for border gateway protocol (BGP) processes

A networking system may perform a border gateway protocol (BGP) switchover from an active BGP process to a standby BGP process. The standby BGP process may obtain transport layer protocol state information, for a given time, of a transport layer session for the active BGP process. The standby BGP process may update the transport layer protocol state information based on BGP messages conveyed, after the given time, over the transport layer session and forwarded to the standby BGP process. Based on a BGP switchover criterion being met, a replacement transport layer session may be set up using the updated transport layer protocol state information. The replacement transport layer session continues the transport layer session after the BGP switchover.
Owner:ARISTA NETWORKS INC

BGP Peering Status-Aware Hitless Reboot

Techniques for implementing Border Gateway Protocol (BGP) peering status-aware hitless reboot on a network device are provided. In one set of embodiments, at the time of shutting down for a hitless reboot, the network device can collect status information regarding its BGP peerings and can write this information to a file on non-volatile storage. Then, upon booting up after the hitless reboot, the network device can retrieve the file from the non-volatile storage and use the status information included therein to restore the BGP peerings as they existed prior to the hitless reboot.
Owner:ARISTA NETWORKS INC

Route selection method and related device

This application discloses a route selection method and a related device. A control entity determines first metric information of a first segment routing (SR) path, generates a first border gateway protocol (BGP) update message including the first metric information, and sends the first BGP update message to an ingress node of the first SR path, where the first metric information represents quality of the first SR path, the first metric information is used for route selection on a plurality of paths, each of the plurality of paths has a same IP prefix of a destination node, and the plurality of paths include the first SR path. According to the method, the control entity can send, to the ingress node of the SR path by using the BGP update message, the metric information that represents the quality of the SR path.
Owner:HUAWEI TECH CO LTD

ROUTE AGGREGATION AS A SERVICE (RaaS)

Example solutions for providing route aggregation as a service (RaaS) are disclosed. A RaaS server receives original routing tables from routers in a wide area network (WAN), aggregates the routes by identifying common prefixes, and returns more compact aggregated routing tables to the routers. The routers use the aggregated routing tables to efficiently route data traffic in the WAN. Multiple resiliency approaches are disclosed, in order to prevent the routers from flushing the aggregated routes in the event that the RaaS server experiences an outage and the border gateway protocol (BGP session between each router and the RaaS server is lost. Example resiliency measures includes the use of a long lived stale time (LLST), reaching a length of perhaps weeks, during which the routers continue to use the aggregated routing tables, and the use of mirroring the aggregated routing tables in other RaaS
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Network defense method and device, equipment, storage medium and computer program product

The invention relates to the technical field of network security, and discloses a network defense method, device and equipment, a storage medium and a computer program product.The method comprises the steps that whether malicious oscillation exists or not is judged according to at least one of route change information of a border gateway protocol, a time window threshold value and a route updating frequency threshold value; and analyzing the current traffic characteristics through an attack detection model, judging whether an attack behavior of distributed denial of service exists, limiting the speed of the current network traffic according to the malicious oscillation characteristics, and guiding the attack traffic of the attack behavior to a black hole address based on the extracted attack characteristics. According to the application, malicious oscillation and attack behaviors are monitored and identified in real time, when malicious oscillation is detected, the speed of the current network flow is limited according to the characteristics of the malicious oscillation, for the attack behaviors, the attack flow is guided to the black hole address based on the extracted attack characteristics, the attack source is quickly blocked, and a dual detection and response mechanism is adopted. And the timeliness and effectiveness of network defense are improved.
Owner:SHENZHEN FENGRUNDA TECH CO LTD

Method, device and equipment for predicting network security state of border gateway protocol

The invention discloses a network security state prediction method and device of a border gateway protocol, equipment and a readable storage medium, and relates to the technical field of Internet. Comprising the following steps: acquiring relevant parameters of a border gateway protocol; the related parameters comprise the attack prefix injection rate, the network defense capability and the attacked prefix importance of the border gateway protocol; determining the attack risk of the border gateway protocol based on the related parameters of the border gateway protocol; and calculating a network security state prediction result of the border gateway protocol based on the attack risk and the initial transition probability matrix of the border gateway protocol. According to the method, the accuracy of network security state prediction is improved.
Owner:SUZHOU IND PARK SERVICE OUTSOURCING VOCATIONAL COLLEGE (SUZHOU SERVICE OUTSOURCING TALENT TRAINING & TRAINING CENT)

Method and Apparatus for Processing Router Advertisement Message, Storage Medium, and Electronic Apparatus

Provided are a method and apparatus for processing a router advertisement message, a storage medium, and an electronic apparatus. The method includes acquiring, on a current node, a border gateway protocol (BGP) router advertisement message transmitted by a previous node, the BGP router advertisement message indicates a BGP next-hop node in a forwarding direction, and the forwarding direction is a direction from the network ingress node to the network egress node; and determining, in a case that the BGP next-hop node and the current node are two adjacent nodes on the propagation path, an underlying transport path from the current node to the BGP next-hop node according to instruction information corresponding to the current node of the information of the propagation path. According to examples of the disclosure, the technical problem that an underlying transport path cannot be flexibly determined in the related art is solved.
Owner:ZTE CORP

Transmission method of computing power information, electronic equipment, storage medium and computer program product

The invention discloses a computing power information transmission method, electronic equipment, a storage medium and a computer program product, and belongs to the technical field of communication. The method comprises: a target network device node receiving a first border gateway protocol (BGP) message, the first BGP message carrying a first computing power metric and a computing power type corresponding to the first computing power metric, the first computing power metric being a computing power metric obtained by measuring target computing power information corresponding to a target computing power service based on a computing power service type, and the target network device node receiving a first BGP message, the first BGP message carrying a first BGP message, the first BGP message carrying a first BGP message, the first BGP message carrying a second BGP message, the second BGP message carrying a second BGP message, the second BGP message carrying a second BGP message, and the second BGP message carrying a second BGP message. The target computing power information comprises computing power information which is acquired from a cloud management platform and corresponds to the target computing power service; and the target network equipment node sends a second BGP message based on the first BGP message, the second BGP message carrying a second computing power metric and a computing power type corresponding to the second computing power metric.
Owner:ZTE CORP

Cross-system hierarchical perception routing decision method, apparatus and device, and storage medium

The invention belongs to the technical field of cross-domain network communication, and discloses a cross-system hierarchical sensing routing decision method, device and equipment and a storage medium. According to the method, a routing optimization scheme oriented to a cross-domain network is provided, hierarchical network performance collection is carried out by embedding a service level identifier and a time stamp in a detection data packet, differential thresholds are set according to different service types, and collected time delay, jitter, packet loss and bandwidth utilization data are comprehensively evaluated. And quantitatively adjusting the path priority attribute in the border gateway protocol according to the evaluation result, and driving the automatic switching of the transmission path. According to the method, the defect that data and services are disjointed in traditional detection is overcome; according to the method, a dynamic threshold value is set in combination with service requirements, multi-index comprehensive judgment is carried out, finally, a performance evaluation result and routing protocol attributes are linked, an automatic closed loop from sensing to decision making is established, and therefore the overall reliability and experience of cross-domain service transmission are improved under the condition that opposite-end cooperation is not needed.
Owner:PENG CHENG LAB

Fault detection method, apparatus, and system

This application provides a fault detection method, an apparatus, and a system. The method includes: A transmit end apparatus includes, when sending a border gateway protocol BGP message used for advertising a route, a bidirectional forwarding detection discriminator BFD discriminator configured by the transmit end apparatus, to trigger a receive end apparatus to automatically create an SBFD session used for detecting reachability of a target object associated with the transmit end apparatus, where the target object may be a locator address or a next-hop address of the route.
Owner:HUAWEI TECH CO LTD

Route leakage detection method based on probabilistic reasoning and path scoring

The invention discloses a route leakage detection method based on probabilistic reasoning and path scoring, and the method comprises the steps: obtaining an autonomous system path in a border gateway protocol route, and enabling the autonomous system path to comprise a plurality of autonomous system links, obtaining autonomous system business relationship probability data about the plurality of autonomous system links through an autonomous system business relationship probability inference algorithm, and obtaining autonomous system business relationship determination data about the plurality of autonomous system links through an autonomous system provider authorization object; the autonomous system business relation probability inference algorithm is set according to a valley-free rule, and the autonomous system business relation comprises provider-to-customer, customer-to-provider and peer-to-peer; according to the autonomous system business relationship probability data and the autonomous system business relationship determination data, calculating the score of the autonomous system path through a path score calculation formula; and comparing the score of the autonomous system path with a preset threshold value, and judging whether the border gateway protocol route of the autonomous system path is a leaked route or not.
Owner:COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI

Systems and methods for offloading stateful sessions from a firewall to a router

Aspects of the subject disclosure may include, for example, offloading one or more flows or stateful sessions from a firewall to a gateway router. The flows may be qualified for offloading using any criteria. The flows may be injected into the gateway router using border gateway protocol (BGP) Flowspec route over a BGP neighborship between the gateway router and the firewall. Other embodiments are disclosed.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Overlay network for improved real-time packet flows

An overlay network system includes point-of-presence (POP) devices each comprising a telemetry component, a billboard agent, and a packet routing daemon. The telemetry components generate latency measurements for the POP on which each is disposed. A centralized billboard service provides border gateway protocol (BGP) announcements and point-of-presence (POP) peering decisions to each of the billboard agent components. On each of the POPs, the path finding component and corresponding telemetry component, agent component, and routing daemon cooperate to transform the BGP announcements, peering decisions, and latency measurements into routing tables and link selections for packet streams routed through the POPs.
Owner:NEOATOMIC LLC

Route advertisement method and related apparatus

A route advertisement method and a related apparatus, to avoid a packet loss caused by introduction of an aggregated route. The method includes: a first network device determines that a first route to a second network device is unreachable. The first network device sends routing information to a third network device according to border gateway protocol (BGP), where the routing information indicates that the first route is unreachable, to enable the third network device to generate the first route and mark the first route as an unreachable route.
Owner:HUAWEI TECH CO LTD

Network fault diagnosis method, device, equipment and storage medium

Embodiments of the present application provide a network fault diagnosis method, device, equipment and storage medium. The method comprises: receiving a first border gateway protocol (BGP) message, the first BGP message comprising a derived relationship graph of a network corresponding to a first network device, the derived relationship graph being used to indicate five-tuple information and a routing relationship of each network device, the first network device being any network device in the network; determining a target verification result, the target verification result being obtained by verifying configuration information of the first network device according to the first BGP message. The reliability of network fault diagnosis and repair is improved.
Owner:RUIJIE NETWORKS CO LTD

X-over-y tunnel signaling and configuration, and use of configured x-over-y tunnel(s)

Network operators can define port mappings for UDP destination ports and the encapsulated protocol / traffic type (X) in UDP. BGP may be used to notify the UDP destination port-to-traffic type mapping to an encapsulator. A generic UDP encapsulation mechanism (X-in-UDP), where UDP can be used to encapsulate packets of any user configured protocol / traffic type X (e.g., IPv4, IPv6, MPLS, etc.), is described. Primary benefits of using UDP for encapsulation are to leverage UDP port numbers for load-balancing. Generic UDP encapsulation of any protocol / traffic type using user defined port-maps provides flexibility to network operators in constructing different overlay networks. UDP encapsulation helps leverage fine-grade load balancing over Equal-Cost Multipath (ECMP).
Owner:JUNIPER NETWORKS INC

Border gateway protocol anomaly detection model training method and device, and computer device

The present application relates to the technical field of communication detection, and discloses a training method and device of a border gateway protocol anomaly detection model and computer equipment, wherein the historical route statistical features and historical graph topology features corresponding to historical BGP data are extracted, and the features are trained by using the border gateway protocol anomaly detection model, the drift detection score between the historical anomaly detection result and the historical BGP data is calculated in the training process, and the drift detection threshold is used as a reference benchmark to adaptively update the multiple parameter values of the border gateway protocol anomaly detection model in combination with the drift detection score. Therefore, even if the BGP abnormal condition caused by the dynamic change of the network environment is faced, the BGP abnormal data can be accurately detected, and the high efficiency of the BGP abnormal data anomaly detection can be ensured.
Owner:HANGZHOU INST FOR ADVANCED STUDY UCAS +1

Method for detecting prefix hijacking anomaly based on dynamic graph and related device

The application provides a prefix hijacking anomaly detection method based on a dynamic graph and related equipment. The method comprises the following steps: constructing a border gateway protocol heterogeneous graph based on first packet data in an acquired start time window and second packet data in a to-be-detected time window; setting different self-loop relationships for different node types in the second heterogeneous graph, and obtaining a first embedding vector matrix based on the self-loop relationships; extracting changes of the first embedding vector matrix in a time dimension to obtain a second embedding vector matrix; flattening the second embedding vector matrix as an input of a multilayer perception machine to output a detection result. By constructing a BGP heterogeneous topology graph in combination with the characteristics of prefix hijacking, the graph characteristics of the BGP network are fully mined on the basis of the characteristics of prefix hijacking. In addition, the autonomous domain network naturally has a topology characteristic, and the characteristic is effectively extracted through a BGP heterogeneous graph convolution network, so that the effectiveness of detection is ensured.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Routing for static border gateway protocol

A system can determine by which path / tunnel an Internet destination can be best reached for a user with an IP address from a static BGP range. The system looks up the destination address in an egress map. This map can either specify a tunnel that should be used for encapsulation for static BGP, or (when tunnel is not present) cause the system to send out unencapsulated traffic, in which the traffic follows normal BGP routing on a border network.
Owner:AMAZON TECH INC

Edge device communication processing method and system, electronic device, and storage medium

The application provides an edge device communication processing method and system, electronic equipment and a storage medium. The method comprises the following steps: a multicast receiving end PE monitors first state information of a locally stored virtual routing forwarding table in real time, and a multicast sending end PE monitors second state information of a locally stored virtual routing forwarding table in real time; the multicast receiving end PE encapsulates the first state information through a border gateway protocol module to obtain routing information, and sends the routing information to the multicast sending end PE; and the multicast sending end PE determines whether to establish a communication connection with the multicast receiving end PE according to the routing information and the second state information. The purpose of batch and rapid cutting off of multicast traffic is achieved, and the forwarding of redundant traffic in a backbone network is reduced.
Owner:MAIPU COMM TECH CO LTD

A method and system for detecting prefix hijacking for uncertain information sources

The present invention provides a method and system for detecting prefix hijacking for uncertain sources. The method comprises: obtaining data from the routing information base, resource public key infrastructure, and Internet routing registry in the Border Gateway Protocol; constructing prefix cloud droplets from the time, space, and data source dimensions based on cloud model theory, and deriving deterministic data and uncertain data based on the discreteness of the cloud model; performing spatiotemporal stability analysis on the deterministic data, dynamically scoring each prefix cloud droplet, and establishing a dynamic deterministic information base; for the uncertain data, performing online route detection using a custom dictionary tree; utilizing prefix coverage and matching rules in combination with a dual verification mechanism to determine whether the route is legitimate, thereby completing anomaly detection and online updating. The present invention proposes a prefix hijacking detection method based on cloud model theory and a Trie tree to overcome the characteristics of the Border Gateway Protocol, such as dynamic changes, complex and large-scale networks, and uncertain data.
Owner:NANJING UNIV OF POSTS & TELECOMM