Patent · US Active

Anti-spoofing techniques for overlay networks

US11706196B1 · kind B1 · utility

0Cited by
1References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateAug 31, 2020
Grant dateJul 18, 2023
Priority date
Expiry dateJun 2, 2041

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L12/4641
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A network device is configured to receive an inbound packet from a first server device via a network tunnel, the first inbound packet including an outer header, a virtual private network (VPN) label, an inner header, and a data payload, the inner header including an inner source IP address of a source virtual machine. The processors are also configured to determine a first tunnel identifier, determine, based on the inner source IP address, a second tunnel identifier associated with a second server device hosting the source virtual machine, compare the second tunnel identifier with the first tunnel identifier to determine whether the tunnel on which the first inbound packet was received is the same as a tunnel used for forwarding traffic to the source virtual machine, and drop the inbound packet when the second tunnel identifier does not match the first tunnel identifier.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.