Dynamic Control Plane Admission for BGP Session Resilience

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current routing systems face challenges in dynamically managing packet rates and priorities for the control plane, particularly under DoS and DDoS attacks, which can lead to resource exhaustion and compromise network security due to the lack of automated, dynamic admission control mechanisms for BGP peering sessions.

Innovation Solution

A routing device with mechanisms to identify packets destined for the control plane, dynamically update admission parameters based on communication session status, and enforce admission control policies using policing, shaping, and priority settings, utilizing ternary content-addressable memory to categorize and manage packet processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static ACL and MQC rate limits are used to control packet access to the control plane, then some level of security is provided, but the system cannot dynamically adapt to changing BGP session states and requires manual configuration

Engineering Contradiction:
Improvedynamic adaptation to BGP session changesVSAvoidmanual configuration requirement
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The patent implements dynamic admission control parameters that automatically adjust based on BGP session state changes. The system monitors BGP peer establishment, maintenance, and teardown events, and dynamically modifies packet rate limits and priority levels accordingly. This transforms static security policies into adaptive ones that respond to real-time network conditions without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes feedback loops that continuously monitor BGP session status and automatically adjust admission control parameters in response. When BGP sessions are established or torn down, the system receives feedback about these state changes and automatically modifies the corresponding packet admission rates and priorities, eliminating the need for manual reconfiguration.

Inventive Principle:
Principle #23Feedback

2Reliability

If automated dynamic admission control is implemented to adapt to BGP session changes, then security and resource management are improved, but system complexity increases

Engineering Contradiction:
Improvecontrol plane resiliencyVSAvoidadmission control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the routing device automatically monitors its own BGP session state and autonomously adjusts admission control parameters without external intervention. The system services itself by detecting session changes and triggering appropriate parameter modifications, reducing the need for complex external management systems while improving reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary configuration of admission control parameters for potential BGP sessions before they are actually established. When BGP peering is configured, the system pre-sets the admission control parameters that will apply when the session becomes active, allowing for rapid automatic response when sessions are established or torn down without complex real-time calculations.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If packet rate limits are enforced to protect against DoS attacks, then control plane resource exhaustion is prevented, but legitimate traffic may be inadvertently limited

Engineering Contradiction:
ImproveDoS attack impactVSAvoidlegitimate traffic throughput
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent applies different admission control parameters to different packets based on their specific characteristics and source. Instead of uniform rate limiting, the system configures distinct packet rate limits and priority levels for each BGP peer session, allowing legitimate traffic from established sessions to receive higher rates and priorities while malicious traffic from unknown sources receives stricter limits.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes admission control parameters including packet rate limits and internal priority levels based on BGP session state. Established BGP sessions receive higher rate limits and priorities, while sessions that are being established or have been torn down receive lower or zero rates. This parameter differentiation ensures legitimate traffic is prioritized while still protecting against DoS attacks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7580351B2Dynamically controlling the rate and internal priority of packets destined for the control plane of a routing device
Publication Date: 2009.08.25 CISCO TECHNOLOGY INC
  • US7580351B2 patent drawing
  • US7580351B2 patent drawing
  • US7580351B2 patent drawing

AI summary

Disclosed are, inter alia, methods, apparatus, data structures, computer-readable media, and mechanisms, for identifying admission control policies and enforcement of these admission control policies on packets destined for a route processor. A typical routing device includes: a route processor, a forwarding lookup mechanism for identifying packets destined for the route processor; a lookup mechanism for identifying admission control parameters for packets destined for the route processor; and an admission control enforcement mechanism for enforcing the identified admission control policy parameters for the packets.