CA2902206C

Protecting networks from cyber attacks and overloading

Abstract

Packets may be received by a packet security gateway. Responsive to a determination that an overload condition has occurred in one or more networks associated with the packet security gateway, a first group of packet filtering rules may be applied to at least some of the packets. Applying the first group of packet filtering rules may include allowing at least a first portion of the packets to continue toward their respective destinations. Responsive to a determination that the overload condition has been mitigated, a second group of packet filtering rules may be applied to at least some of the packets. Applying the second group of packet filtering rules may include allowing at least a second portion of the packets to continue toward their respective destinations.

CA2902206C, drawing sheet 1
Sheet 1 of 8

Term

7.5 yearsleft in the term

Expires 14 March 2034.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

20 claims: 3 independent, 17 dependent

  1. 1
    CLAIMS:1. A method, comprising: at each packet security gateway of a plurality of packet security gateways interfacing, at peering points, a plurality of different autonomous system, AS, networks: receiving, by that packet security gateway, a plurality of packets;responsive to a determination that an overload condition has occurred in one or more networks associated with the packet security gateway, applying, by that packet security gateway and to at least some first received portion of the plurality of packets, a first group of packet-filtering rules that comprises at least one five-tuple indicating a first set of packets that is allowed to continue toward their respective destinations, wherein applying the first group of packet-filtering rules comprises allowing at least a first portion of the plurality of packets that fall within the first set of packets to continue toward their respective destinations;and responsive to a determination that the overload condition has been mitigated, applying, by that packet security gateway and to at least some second received portion of the plurality of packets, a second group of packet-filtering rules that comprises at least one five-tuple indicating a second set of packets from a plurality of required users comprising data for at least one Internetbased application that is allowed io continue toward their respective destinations, wherein the plurality of required users are communicatively coupled with the plurality of different autonomous system networks, wherein the applying the second group of packet-filtering rules comprises allowing at least a second portion of the plurality of packets that fall within the second set of packets from the plurality of required users to continue toward their respective destinations, and wherein the second group of packet-filtering rules is less restrictive than the first group of packetfiltering rules;and responsive to a determination that the overload condition has been further mitigated, applying, by that packet security gateway and to at least some third received portion of the plurality of packets, a third group of packet-filtering rules that comprises at least one five-tuple indicating a third set of packets that is allowed to continue toward their respective destinations, wherein the applying the third group of packet-filtering rules comprises allowing at least a third portion of the plurality of packets that fall within the third set of packets to continue toward their respective -24CA 2902206 2018-07-23 destinations, wherein the third group of packet-filtering rules is less restrictive than the second group of packet-filtering rules.
  2. 11
    A packet security gateway, comprising:at least one processor;and a memory storing instructions that when executed by the at least one processor cause the packet security gateway to: receive a plurality of packets;determine that an overload condition has occurred in one or more networks associated with the packet security gateway;responsive to determining that the overload condition has occurred in the one or more networks: apply, by the packet security gateway and to at least some first received portion of the plurality of packets, a first group of packet-filtering rules that comprises at least one five-tuple indicating a first set of packets that is allowed to continue toward their respective destinations;and forward at least a first portion of the plurality of packets that fall within the first set of packets toward their respective destinations;determine that the overload condition has been mitigated;and responsive to determining that the overload condition has been mitigated: apply, by the packet security gateway and to at least some second received portion of the plurality of packets, a second group of packet-filtering rules that comprises at least one five-tuple indicating a second set of packets from a plurality of required users comprising data for at least one Internet-based application that is allowed to continue toward their respective destinations, wherein the plurality of required users is communicatively coupled with at least one autonomous system CA 2902206 2018-07-23 network protected by the packet security gateway, and wherein the second group of packet-filtering rules is less restrictive than the first group of packet-filtering rules;and forward at least a second portion of the plurality of packets that fall within the second set of packets from the plurality of required users toward their respective destinations;determine that the overload condition has been further mitigated;and responsive to determining that the overload condition has been further mitigated: apply, by the packet security gateway and to at least some third received portion of the plurality of packets, a third group of packet-filtering rules that comprises at least one five-tuple indicating a third set of packets that is allowed to continue toward their respective destinations, and wherein the third group of packet-filtering rules is less restrictive than the second group of packet-filtering rules;and forward at least a third portion of the plurality of packets that fall within the third set of packets toward their respective destinations.
  3. 16
    One or more non-transitory computer-readable media having instructions stored thereon that when executed by one or more computers cause the one or more computers to:receive a plurality of packets;determine that an overload condition has occurred in one or more networks associated with a packet security gateway;responsive to determining that the overload condition has occurred in the one or more networks: apply, by the packet security gateway and to at least some first received portion of the plurality of packets, a first group of packet-filtering rules that comprises at least one five-tuple indicating a first set of packets that is allowed to continue toward their respective destinations;and CA 2902206 2018-07-23 forward at least a first portion of the plurality of packets that fall within the first set of packets toward their respective destinations;determine that the overload condition has been mitigated;and responsive to determining that the overload condition has been mitigated: apply, by the packet security gateway and to at least some second received portion of the plurality of packets, a second group of packet-filtering rules that comprises at least one five-tuple indicating a second set of packets from a plurality of required users comprising data for at least one Internet-based application that is allowed to continue toward their respective destinations, wherein the plurality of required users are communicatively coupled with at least one autonomous system network, and wherein the second group of packet-filtering rules is less restrictive than the first group of packet-filtering rules;and forward at least a second portion of the plurality of packets that fall within the second set of packets from the plurality of required users toward their respective destinations;determine that the overload condition has been further mitigated;and responsive to determining that the overload condition has been further mitigated: apply, by the packet security gateway and to at least some third received portion of the plurality of packets, a third group of packet-filtering rules that comprises at least one five-tuple indicating a third set of packets that is allowed to continue toward their respective destinations, and wherein the third group of packet-filtering rules is less restrictive than the second group of packet-filtering rules;and forward at least a third portion of the plurality of packets that fall within the third set of packets toward their respective destinations..