Flagged Address Prefixes for Automatic Network Resource Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and protecting valuable resources in computer networks, such as those owned by Service Providers, is laborious due to the need for frequent updates and manual intervention in Access Control Lists (ACLs) across multiple border routers.

Innovation Solution

A system and method that flags important address prefixes within a routing table, allowing routers to automatically distribute and use these flags to identify and block or log packets targeting valuable resources, simplifying the protection of these resources by automating the process across all routers in the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual updates and intervention in Access Control Lists (ACLs) are used across multiple border routers, then network security protection can be implemented, but operational intensity and labor requirements increase significantly

Engineering Contradiction:
Improvenetwork security protectionVSAvoidoperational intensity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables routers to automatically protect valuable resources by having them self-identify through flag bits in routing tables and self-defend by automatically blocking or logging packets targeting flagged prefixes, eliminating the need for manual ACL updates on each router

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The mechanism uses flag bits as feedback signals that are automatically propagated through the routing system, allowing routers to receive real-time information about which resources need protection and automatically respond without human intervention

Inventive Principle:
Principle #23Feedback

2Reliability

If Access Control Lists (ACLs) are manually configured on each border router, then protection against malicious access can be achieved, but the complexity of network management increases

Engineering Contradiction:
Improveprotection against malicious accessVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention extracts the protection logic from complex manual ACL configurations and implements it through simple flag bits in the routing table, separating the identification of valuable resources from the actual blocking mechanism and simplifying management

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The flag bit mechanism serves multiple functions: it identifies valuable resources, propagates protection information automatically across the network, and enables consistent blocking behavior across all routers, replacing the need for router-specific ACL configurations

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If frequent updates to Access Control Lists (ACLs) are performed, then network security can be maintained, but time consumption and labor requirements increase

Engineering Contradiction:
Improvenetwork securityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-configuring flag bits in routing tables to identify valuable resources before attacks occur, and automatically propagates these flags throughout the network so that protection is already in place when threats arise, eliminating the need for frequent manual updates

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7639688B2Automatic protection of an SP infrastructure against exterior traffic
Publication Date: 2009.12.29 CISCO TECHNOLOGY INC
  • US7639688B2 patent drawing
  • US7639688B2 patent drawing
  • US7639688B2 patent drawing

AI summary

A method and system for protecting valuable resources within an autonomous system network. Address prefixes within the system are designated as valuable and a flag bit is associated with the address within routing tables of routers of the network. Interfaces to border routers are identified and when packets are received at those interfaces, the packets are flagged with a flag or tag bit. The destination address of the received packet is compared to the flag bit associated with the valuable resource prefix, and if the packet is directed to that resource the packet is dropped and/or logged, but the packet is not forwarded to that resource. In specific cases an interface from an external source may be configured to not create the flag or tag bit, wherein that packet will be delivered to the destination prefix of the packet.