×

System, method and apparatus that isolate virtual private network (VPN) and best effort traffic to resist denial of service attacks

  • US 8,543,734 B2
  • Filed: 03/16/2010
  • Issued: 09/24/2013
  • Est. Priority Date: 03/20/2001
  • Status: Expired due to Term
First Claim
Patent Images

1. A method comprising:

  • establishing a virtual private network (VPN) that includes a first ingress boundary router and a first egress boundary router, the first egress boundary router being configured to communicate with a destination host, wherein the first ingress boundary router is configured to communicate with a second ingress boundary router of a public data network, and wherein the first egress boundary router is configured to communicate with a second egress boundary router of the public data network, the second egress boundary router being configured to communicate with the destination host;

    transmitting only packets originating from sources within the VPN and targeting the destination host to the first egress boundary router via the VPN to prevent denial of service attacks originating from sources outside the VPN; and

    transmitting packets originating from sources outside the VPN and targeting the destination host to the second egress boundary router via the public data network.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×