×

Protecting networks from access link flooding attacks

  • US 7,356,596 B2
  • Filed: 01/25/2002
  • Issued: 04/08/2008
  • Est. Priority Date: 12/07/2001
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • establishing a packet tunnel between a first local area network and a second local area network, the packet tunnel having a source network address within an address space of the first local area network and a destination network address within an address space of the second local area network;

    reserving for the packet tunnel an amount of bandwidth within an access link;

    detecting a network attack;

    in response to the detected network attack, splitting the packet tunnel by selecting an intermediate network device, wherein the intermediate network device has a network address from a network address space other than the address space of the first local area network and the address space of the second local area network, wherein the first local area network and the second local area network are separated by a public network, and wherein the intermediate network device has a network address from a network address space of the public network;

    establishing a first packet tunnel from the first local area network to the intermediate network device;

    establishing a second packet tunnel that originates from the intermediate network device to the second local area network;

    canceling the reserved bandwidth for the packet tunnel;

    reserving for the second packet tunnel an amount of bandwidth within the access link; and

    communicating a virtual private network (VPN) traffic from the first local area network to the second local area network by redirecting the VPN traffic from the first local area network to the intermediate network device through the first packet tunnel and forwarding the VPN traffic from the intermediate network device to the second local area network through the second packet tunnel.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×