Validation and implementation of flow specification (Flowspec) rules
US11930037B2 · kind B2 · utility
Assignee
Inventor
Key dates
| Filing date | Oct 8, 2020 |
| Grant date | Mar 12, 2024 |
| Priority date | — |
| Expiry date | Apr 9, 2041 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L63/1416
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A valid route origin authorization (ROA) for a specified IP address is published and a distributed denial-of-service (DDoS) attack to a given IP address is detected. A flowspec rule is advertised from a given autonomous system network to one or more neighboring autonomous system networks in response to the detection of the distributed denial-of-service (DDoS) attack. A modified Resource Public Key Infrastructure (RPKI) validation is performed using the published valid route origin authorization (ROA) in response to the advertisement of the flowspec rule. The flowspec rule is implemented to mitigate the distributed denial-of-service (DDoS) attack in response to the validation of the flowspec rule.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.