首页> 外国专利> SYSTEM, METHOD AND APPARATUS THAT ISOLATE VIRTUAL PRIVATE NETWORKS (VPN) AND BEST EFFORT TO RESIST DENIAL OF SERVICE ATTACKS

SYSTEM, METHOD AND APPARATUS THAT ISOLATE VIRTUAL PRIVATE NETWORKS (VPN) AND BEST EFFORT TO RESIST DENIAL OF SERVICE ATTACKS

机译:隔离虚拟专用网络(VPN)并尽最大努力抵抗拒绝服务攻击的系统,方法和装置

摘要

A network architecture in accordance with the present invention includes a communication network that supports one or more network-based Virtual Private Networks (VPNs). The communication network includes a plurality of boundary routers that are connected by access links to CPE edge routers belonging to the one or more VPNs. To prevent traffic from outside a customer's VPN (e.g., traffic from other VPNs or the Internet at large) from degrading the QoS provided to traffic from within the customer's VPN, the present invention gives precedence to intra-VPN traffic over extra-VPN traffic on each customer's access link through access link prioritization or access link capacity allocation, such that extra-VPN traffic cannot interfere with inter-VPN traffic. Granting precedence to intra-VPN traffic over extra-VPN traffic in this manner entails special configuration of network elements and protocols, including partitioning between intra-VPN and extra-VPN traffic on the physical access link using layer 2 multiplexing and the configuration of routing protocols to achieve logical traffic separation between intra-VPN traffic and extra-VPN traffic at the VPN boundary routers and CPE edge routers. By configuring the access networks, the VPN boundary routers and CPE edge routers, and the routing protocols of the edge and boundary routers in this manner, the high-level service of DoS attack prevention is achieved.
机译:根据本发明的网络体系结构包括支持一个或多个基于网络的虚拟专用网(VPN)的通信网络。该通信网络包括多个边界路由器,这些边界路由器通过访问链路连接到属于一个或多个VPN的CPE边缘路由器。为了防止来自客户的VPN外部的业务(例如,来自其他VPN或整个互联网的业务)降低提供给从客户的VPN内部的业务的QoS,本发明将VPN内业务优先于业务上的额外VPN业务。每个客户的访问链接都通过访问链接优先级分配或访问链接容量分配,从而使额外VPN流量不会干扰VPN间流量。以这种方式授予VPN内流量优先于Extra-VPN流量的权限需要对网络元素和协议进行特殊配置,包括使用第2层多路复用在物理访问链路上在VPN内部流量和Extra-VPN流量之间进行分区以及路由协议的配置在VPN边界路由器和CPE边缘路由器上实现VPN内部流量与Extra-VPN流量之间的逻辑流量分离。通过以这种方式配置接入网络,VPN边界路由器和CPE边缘路由器以及边缘和边界路由器的路由协议,可以实现DoS攻击防御的高级服务。

著录项

  • 公开/公告号US2010175125A1

    专利类型

  • 公开/公告日2010-07-08

    原文格式PDF

  • 申请/专利权人 DAVID E. MCDYSAN;

    申请/专利号US20100725193

  • 发明设计人 DAVID E. MCDYSAN;

    申请日2010-03-16

  • 分类号G06F15/16;H04L12/56;

  • 国家 US

  • 入库时间 2022-08-21 18:51:02

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号