Flagged Address Prefixes for Automatic Network Resource Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing and protecting valuable resources in computer networks, such as those owned by Service Providers, is laborious due to the need for frequent updates and manual intervention in Access Control Lists (ACLs) across multiple border routers.
Innovation Solution
A system and method that flags important address prefixes within a routing table, allowing routers to automatically distribute and use these flags to identify and block or log packets targeting valuable resources, simplifying the protection of these resources by automating the process across all routers in the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual updates and intervention in Access Control Lists (ACLs) are used across multiple border routers, then network security protection can be implemented, but operational intensity and labor requirements increase significantly
Solution Approach 1:
The system enables routers to automatically protect valuable resources by having them self-identify through flag bits in routing tables and self-defend by automatically blocking or logging packets targeting flagged prefixes, eliminating the need for manual ACL updates on each router
Solution Approach 2:
The mechanism uses flag bits as feedback signals that are automatically propagated through the routing system, allowing routers to receive real-time information about which resources need protection and automatically respond without human intervention
2Reliability
If Access Control Lists (ACLs) are manually configured on each border router, then protection against malicious access can be achieved, but the complexity of network management increases
Solution Approach 1:
The invention extracts the protection logic from complex manual ACL configurations and implements it through simple flag bits in the routing table, separating the identification of valuable resources from the actual blocking mechanism and simplifying management
Solution Approach 2:
The flag bit mechanism serves multiple functions: it identifies valuable resources, propagates protection information automatically across the network, and enables consistent blocking behavior across all routers, replacing the need for router-specific ACL configurations
3Reliability
If frequent updates to Access Control Lists (ACLs) are performed, then network security can be maintained, but time consumption and labor requirements increase
Solution Approach 1:
The system performs preliminary action by pre-configuring flag bits in routing tables to identify valuable resources before attacks occur, and automatically propagates these flags throughout the network so that protection is already in place when threats arise, eliminating the need for frequent manual updates
Data Source
AI summary
A method and system for protecting valuable resources within an autonomous system network. Address prefixes within the system are designated as valuable and a flag bit is associated with the address within routing tables of routers of the network. Interfaces to border routers are identified and when packets are received at those interfaces, the packets are flagged with a flag or tag bit. The destination address of the received packet is compared to the flag bit associated with the valuable resource prefix, and if the packet is directed to that resource the packet is dropped and/or logged, but the packet is not forwarded to that resource. In specific cases an interface from an external source may be configured to not create the flag or tag bit, wherein that packet will be delivered to the destination prefix of the packet.


