Movatterモバイル変換


[0]ホーム

URL:


USRE49053E1 - System and method for an adaptive TCP SYN cookie with time validation - Google Patents

System and method for an adaptive TCP SYN cookie with time validation
Download PDF

Info

Publication number
USRE49053E1
USRE49053E1US16/235,249US201816235249AUSRE49053EUS RE49053 E1USRE49053 E1US RE49053E1US 201816235249 AUS201816235249 AUS 201816235249AUS RE49053 EUSRE49053 EUS RE49053E
Authority
US
United States
Prior art keywords
transition
cookie
session
secret key
candidate
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active, expires
Application number
US16/235,249
Inventor
Lee Chen
Ronald Wai Lun Szeto
Shih-Tsung Hwang
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
A10 Networks Inc
Original Assignee
A10 Networks Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by A10 Networks IncfiledCriticalA10 Networks Inc
Priority to US16/235,249priorityCriticalpatent/USRE49053E1/en
Assigned to A10 NETWORKS, INC.reassignmentA10 NETWORKS, INC.ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS).Assignors: CHEN, LEE, HWANG, SHIH-TSUNG, SZETO, RONALD WAI LUN
Application grantedgrantedCritical
Publication of USRE49053E1publicationCriticalpatent/USRE49053E1/en
Activelegal-statusCriticalCurrent
Adjusted expirationlegal-statusCritical

Links

Images

Classifications

Definitions

Landscapes

Abstract

Provided is a method and system for TCP SYN cookie validation. The method includes receiving a session SYN packet by a TCP session setup module of a host server, generating a transition cookie including a time value representing the actual time, sending a session SYN/ACK packet, including the transition cookie, in response to the received session SYN packet, receiving a session ACK packet, and determining whether a candidate transition cookie in the received session ACK packet comprises a time value representing a time within a predetermined time interval from the time the session ACK packet is received.

Description

CROSS-REFERENCE TO RELATED APPLICATIONS
This application is a continuation reissue application of U.S. Pat. No. 7,675,854 and claims benefit under U.S.C. 120 as a continuation of application Ser. No. 14/151,803, filed on Jan. 9, 2014, which is a continuation reissue application of U.S. Pat. No. 7,675,854 and claims benefit under 35 U.S.C. 120 as a continuation of application Ser. No. 13/413,191 filed on Mar. 6, 2012, which is an application for reissue of U.S. Pat. No. 7,675,854, originally issued on Mar. 9, 2010.
BACKGROUND OF THE INVENTION
When a TCP (Transmission Control Protocol) connection starts, a destination host receives a SYN (synchronize/start) packet from a source host and sends back a SYN ACK (synchronize acknowledge). The destination host normally then waits to receiver an ACK (acknowledge) of the SYN ACK before the connection is established. This is referred to as the TCP “three-way handshake.”
While waiting for the ACK to the SYN ACK, a connection queue of finite size on the destination host keeps track of connections waiting to be completed. This queue typically empties quickly since the ACK is expected to arrive a few milliseconds after the SYN ACK is sent.
A TCP SYN flood attack is a well known denial of service attack that exploits the TCP three-way handshake design by having an attacking source host generate TCP SYN packets with random source addresses toward a victim host. The victim destination host sends a SYN ACK back to the random source address and adds an entry to the connection queue, or otherwise allocates server resources. Since the SYN ACK is destined for an incorrect or non-existent host, the last part of the “three-way handshake” is never completed and the entry remains in the connection queue until a timer expires, typically, for example, for about one minute. By generating phony TCP SYN packets from random IP addresses at a rapid rate, it is possible to fill up the connection queue and deny TCP services (such as e-mail, file transfer, or WWW) to legitimate users. In most instances, there is no easy way to trace the originator of the attack because the IP address of the source is forged. The external manifestations of the problem may include inability to get e-mail, inability to accept connections to WWW or FTP services, or a large number of TCP connections on your host in the state SYN_RCVD.
A malicious client sending high volume of TCP SYN packets without sending the subsequent ACK packets can deplete server resources and severely impact the server's ability to serve its legitimate clients.
Newer operating systems or platforms implement various solutions to minimize the impact of TCP SYN flood attacks. The solutions include better resource management, and the use of a “SYN cookie”.
In an exemplary solution, instead of allocating server resource at the time of receiving a TCP SYN packet, the server sends back a SYN/ACK packet with a specially constructed sequence number known as a SYN cookie. When the server then receives an ACK packet in response to the SYN/ACK packet, the server recovers a SYN cookie from the ACK packet, and validates the recovered SYN cookie before further allocating server resources.
The effectiveness of a solution using a SYN cookie depends on the method with which the SYN cookie is constructed. However, existing solutions using a SYN cookie typically employ a hash function to construct the SYN cookie, which can lead to a high percentage of false validations of the SYN cookie, resulting in less than satisfactory protection again TCP SYN flood attack.
Therefore, there is a need for a better system and method for constructing and validating SYN cookies.
SUMMARY OF THE INVENTION
An aspect of the present invention provides a system for TCP SYN cookie validation. The system includes a host server including a processor and memory. The processor is configured for receiving a session SYN packet, generating a transition cookie, the transition cookie comprising a time value representing the actual time, sending a session SYN/ACK packet, including the transition cookie, in response to the received session SYN packet, receiving a session ACK packet, and determining whether a candidate transition cookie in the received session ACK packet comprises a time value representing a time within a predetermined time interval from the time the session ACK packet is received.
One aspect of the invention includes the system above in which the processor is further configured for regarding the received session ACK packet as valid if the candidate transition cookie in the received session ACK packet comprises a time value representing a time within a predetermined time interval from the time the session ACK packet is received.
In another aspect of the invention, the predetermined time interval is in the range of one to six seconds.
In one aspect of the invention, the predetermined time interval is three seconds.
In another aspect of the invention, the step of generating the transition cookie includes the use of data obtained from the session SYN packet.
In one aspect of the invention, the data obtained from the session SYN packet comprises the source IP address of an IP header associated with the session SYN packet.
In another aspect of the invention, the data obtained from the session SYN packet comprises the sequence number of a TCP header associated with the session SYN packet.
In another aspect of the invention, the data obtained from the session SYN packet comprises a source port associated with the session SYN packet.
In another aspect of the invention, the data obtained from the session SYN packet comprises a destination port associated with the session SYN packet.
Another aspect of the present invention provides a method for TCP SYN cookie validation. The method includes receiving a session SYN packet by a TCP session setup module, generating a transition cookie by the TCP session setup module, the transition cookie comprising a time value representing the actual time, sending a session SYN/ACK packet, including the transition cookie, in response to the received session SYN packet, receiving a session ACK packet, and determining whether a candidate transition cookie in the received session ACK packet comprises a time value representing a time within a predetermined time interval from the time the session ACK packet is received.
In an aspect of the invention, the method further includes indicating the received session ACK packet comprises a valid candidate transition cookie if the time value of the candidate transition cookie is within a predetermined time interval of the time the session ACK packet is received.
In another aspect of the invention, the step of generating the transition cookie includes the use of data obtained from the session SYN packet.
BRIEF DESCRIPTION OF THE DRAWINGS
FIG. 1 is a schematic diagram illustrating a host server including a TCP session setup module and a client server, in accordance with an embodiment of the present invention;
FIG. 2 is a schematic diagram of a TCP/IP handshake in accordance with an embodiment of the present invention;
FIG. 3a illustrates a method including steps for generating a transition cookie data element by atransition cookie generator245, in accordance with an embodiment of the present invention;
FIG. 3b illustrates a method including steps for generating a transition cookie secret key by atransition cookie generator245 based on data obtained from the received session SYN packet, in accordance with an embodiment of the present invention;
FIG. 3c illustrates a method including steps for generating a transition cookie based on a transition cookie data element, a transition cookie secret key, and data obtained from a received session SYN packet in accordance with an embodiment of the present invention;
FIG. 4a illustrates steps for generating a candidate encrypted data element by atransition cookie validator275 based on data obtained from a received session ACK packet, in accordance with an embodiment of the present invention;
FIG. 4b illustrates a method including steps for generating a candidate transition cookie secret key by atransition cookie validator275 based on data obtained from a received session ACK packet and a candidate sequence number, in accordance with an embodiment of the present invention;
FIG. 4c illustrates a method including steps for generating a candidate transition cookie data element by atransition cookie validator275 based on a candidate encrypted data element and a candidate transition cookie secret key, in accordance with an embodiment of the present invention;
FIG. 4d illustrates a method including the steps for validating a candidate transition cookie data element, in accordance with an embodiment of the present invention; and
FIG. 5 illustrates a method including steps for generating information based on a validated candidate transition cookie data element, in accordance with an embodiment of the present invention.
DETAILED DESCRIPTION
In the following description, for purposes of explanation, specific numbers, materials and configurations are set forth in order to provide a thorough understanding of the invention. It will be apparent, however, to one having ordinary skill in the art, that the invention may be practiced without these specific details. In some instances, well-known features may be omitted or simplified so as not to obscure the present invention. Furthermore, reference in the specification to “one embodiment” or “an embodiment” means that a particular feature, structure or characteristic described in connection with the embodiment is included in at least one embodiment of the invention. The appearances of the phrase “in an embodiment” in various places in the specification are not necessarily all referring to the same embodiment.
Transmission Control Protocol (“TCP”) is one of the main protocols in TCP/IP networks. Whereas the Internet Protocol (“IP”) deals only with packets, TCP enables two hosts to establish a connection and exchange streams of data. TCP guarantees delivery of data and also guarantees that packets will be delivered in the same order in which they were sent.
The terms “host server” and “client server” referred to in the descriptions of various embodiments of the invention herein described are intended to generally describe a typical system arrangement in which the embodiments operate. The “host server” generally refers to any computer system interconnected to a TCP/IP network, including but not limited to the Internet, the computer system comprising at a minimum a processor, computer memory, and computer software. The computer system is configured to allow the host server to participate in TCP protocol communications over its connected TCP/IP network. Although the “host server” may be a single personal computer having its own IP address and in communication with the TCP/IP network, it may also be a multi-processor server or server bank. The “client server” is similar to the “host server”, although it is understood that the “client server” may, in fact, be a single personal computer attached to the TCP/IP network. The only difference between the client and the host server for the purposes of the present invention is that the host server receives the SYN from the client server, sends a SYN ACK to the client server, and waits for the ACK from the client server.
FIG. 1 is a schematic diagram illustrating an embodiment of the present invention. Ahost server102 may include aTCP session module104. The TCPsession setup module104 can engage in aTCP handshake108, such as described above, with aclient server106. In an embodiment, the TCPsession setup module104 is a software component of thehost server102. In one embodiment, the TCPsession setup module104 is implemented in an Application Specific Integrated Circuit (“ASIC”) or a Field Programmable Gate Array (“FPGA”). It is the TCP session setup module that handles the “3-way handshake”108 between thehost server102 and theclient server106. The TCP session setup module may itself also incorporate modules for sending and receiving TCP session packets. These modules may include but are not limited to a session SYN packet receiver, a session SYN/ACK packet sender, and a session ACK packet receiver, which are all known to those of ordinary skill in the computer arts.
The TCPsessions setup module104 may itself be embedded in one or more other host server modules (not shown). The TCP session setup module may alternatively comprise a hardware or firmware component. For example, the software which handles theTCP handshake108 on behalf of thehost server102 may be programmed onto a externally programmable read-only memory (“EPROM”) (not shown), and the EPROM may then be integrated into the host server. In another example, the ASIC or FPGA is integrated into the host server.
FIG. 2 illustrates a TCPsession setup module104 processing TCP/IP segments (not shown), such assession SYN packet210, session SYN/ACK packet220, andsession ACK packet230.
A TCP/IP segment includes a TCP header and an IP header as described in IETF RFC 793 “Transmission Control Protocol” section 3.1 “Header Format”, incorporated herein by reference. A TCP header optionally includes a sack-permitted option as described in IETF RFC 2018 “TCP Selective Acknowledgement Options” section 2 “Sack-Permitted Option”, incorporated herein by reference. Asession SYN packet210 is a TCP/IP segment with the SYN control bit in the TCP Header set to “1”. A session SYN/ACK packet220 is a TCP/IP segment with the SYN control bit and the ACK control bit in the TCP header set to “1”. ASession ACK Packet230 is a TCP/IP segment with the ACK control bit in the TCP header set to “1”.
Referring toFIG. 2, in an embodiment, the TCPsession setup module104 receives asession SYN packet210, obtains data from asession SYN packet210, such as but not limited to the source IP address of the IP header, or the sequence number of the TCP header, and uses the data to generate atransition cookie250. Thetransition cookie250 is preferably a 32-bit data element. In response to thesession SYN packet210, the TCPsession setup module104 creates and sends out a session SYN/ACK packet220 in accordance with IETF RFC 793 “Transmission Control Protocol” section 3.4 “Establishing a connection”, incorporated herein by reference. The TCPsession setup module104 preferably includes thetransition cookie250 as the sequence number of the TCP header in the session SYN/ACK packet220.
After the TCPsession setup module104 has sent out the session SYN/ACK packet220, it waits for receipt of a respondingsession ACK packet230. In an embodiment, when a session SYN/ACK packet230 is received, the TCPsession setup module104 generates a 32-bitcandidate transition cookie270 such that the sum ofcandidate transition cookie270 and a value of “1” equal the acknowledgement number of the TCP header in thesession ACK packet230. For example, if the acknowledgement number is “41B4362A” in hexadecimal format thecandidate transition cookie270 is “41B43629” in hexadecimal format; the sum of “41B43629” and a value of “1” equals “41B4362A”. In another example, if the acknowledgement number is “00A30000” in hexadecimal format thecandidate transition cookie270 is “00A2FFFF” in hexadecimal format; the sum of “00A2FFFF” and a value of “1” equals “00A30000”. In another example, if the acknowledgement number is “00000000” in hexadecimal format theCandidate Transition Cookie270 is “FFFFFFFF” in hexadecimal format; the sum of “FFFFFFFF” and a value of “1” equals “00000000”, with the most significant bit carried beyond the 32-bit boundary. The TCPsession setup module104 may thus validate thecandidate transition cookie270 in this manner. If the TCPsession setup module104 determines that thecandidate transition cookie270 is thus valid, thesession ACK packet230 is also valid. In this case, the TCPsession setup module104 obtains data from the validatedsession ACK packet230 and sends the data and information generated during the validation ofcandidate transition cookie270 to a computing module (not shown) for further processing.
In order to generate and validatetransition cookies250,270, the TCPsession setup module104 may include atransition cookie generator245 and atransition cookie validator275, respectively. Alternatively, the generation and validation may be performed directly by the TCPsession setup module104. In the descriptions herein, references to the TCP andtransition cookie validator275 are understood to include any of the alternative embodiments of these components.
Atransition cookie generator245 includes the functionality of generating a transition cookie based on the data obtained from asession SYN210 packet received by the TCPsession setup module104.
Atransition cookie validator275 includes the functionality of validating acandidate transition cookie270 generated based on data obtained from asession ACK packet230 received by the TCPsession setup module104.
In exemplary operation, atransition cookie generator245 is software or firmware that generates atransition cookie250 based on data obtained from asession SYN packet210 received by the TCPsession setup module104. An exemplary method for generating atransition cookie250 by atransition cookie generator245 includes multiple steps as illustrated inFIGS. 3a-3c.
FIG. 3a illustrates exemplary steps for generating a transitioncookie data element330 by atransition cookie generator245. Atransition cookie generator245 includes aclock305 indicating the current time of day in microseconds in a 32-bit format.
The transitioncookie data element330 is preferably a 32-bit data element, generated by thetransition cookie generator245 based on theselective ACK321, theMSS index324 and the 32-bit current time of day indicated byclock305.Selective ACK321 is a 1-bit data element which is set to a value of “1” bytransition cookie generator245 if a TCP header in a receivedsession SYN packet210 includes an optional sack-permitted option, or to “0” if a TCP header in a receivedsession SYN packet210 does not include an optional sack-permitted option.
Maximum Segment Size (“MSS”)322 is the maximum number of bytes that TCP will allow in an TCP/IP packet, such assession SYN packet210, session SYN/ACK packet220, andsession ACK packet230, and is normally represented by an integer value in a TCP packet header. If a TCP header in a receivedsession SYN packet210 includes a maximum segment size option, thetransition cookie generator245 sets theMSS322 to equal the maximum segment size option data of the maximum segment size option. Otherwise, if the TCP header in a receivedsession SYN packet210 does not include a maximum segment size option, thetransition cookie generator245 sets theMSS322 to a default value, for example, such as integer “536”. TheMSS index324 is a 4-bit data element set by thetransition cookie generator245 based on theMSS322. Thetransition cookie generator245 preferably includes an MSS table307, which maps anMSS322 to anMSS index324. Thetransition cookie generator245 maps aMSS322 with the MSS table307 to set the value ofMSS index324. For example,MSS322 has an integer value of “1460”. After the mapping,MSS index324 has a value of “4” as represented in hexadecimal format. In an alternative embodiment, means other than an MSS table307 may be employed to determine theMSS index324 value, such as the use of a mapping algorithm.
In generating a transitioncookie data element330, thetransition cookie generator245 sets a transitioncookie data element330 to equal the 32-bit current time of day indicated byclock305. For example, the 32-bit current time of day may be “A68079E8” as represented in hexadecimal format, so the transitioncookie data element330 has a value of “A68079E8”.
Next, thetransition cookie generator245 replaces the least significant 4 bits (bit0-3) of transitioncookie data element330 with theMSS index324, and replaces bit4 of a transitioncookie data element330 withselective ACK321. For example, if a transitioncookie data element330 has been set to a value of “A68079E8”,selective ACK321 has a value of “1”, andMSS index324 has a value of “4” as represented in hexadecimal format, after the replacements, transitioncookie data element330 has a value of “A68079F4” in hexadecimal format.
FIG. 3b illustrates exemplary steps for generating a transition cookiesecret key360, such as by atransition cookie generator245 based on data obtained from a receivedsession SYN packet210. The data used in generating the transition cookiesecret key360 may include at least thesource IP address312 of an IP header, adestination port314, asource port316 and asequence number318 of a TCP header in a receivedsession SYN packet210. In generating a transition cookiesecret key360, atransition cookie generator245 forms a 96-bit data element, afirst data item340, by concatenating asource IP address312, asequence number318, asource port316, and adestination port314. For example, if thesource IP address312 is 192.168.1.134, the hexadecimal representation being “C0A80186”, thesequence number318 is “9A275B84”, thesource port316 is 4761, the hexadecimal representation being “1299”, and thedestination port314 is 240, the hexadecimal representation being “00F0”, then, after the concatenation, thefirst data item340 has a hexadecimal value of “C0A801869A275B84129900F0”.
Next, since the transition cookiesecret key360 is a 128-bit data element, thetransition cookie generator245 may use a hash function to generate the transition cookie secret key360 from thefirst data item340. Further, thetransition cookie generator245 may use a secret key offset301, which may be a 6-bit integer value, to select a 6-bit non-negative integer fromfirst data item340 starting at the bit indicated by secret key offset301. For example, if the secret key offset301 has a value of “12” and thefirst data item340 has a hexadecimal value of “C0A801869A275B84129900F0”, thetransition cookie generator245 selects a 6-bit non-negative integer from thefirst data item340 starting at bit12 (bit12-17). The selected non-negative integer is of this example is thus “16”. Thetransition cookie generator245 then uses the selected non-negative integer to select 64 bits of data from thefirst data item340, starting at the bit indicated by the selected non-negative integer, to generate thesecond data item350, which has 64 bits.
For example, if the selected non-negative integer is “8” and thefirst data item340 has a hexadecimal value of “C0A801869A275B84129900F0”, thetransition cookie generator245 selects 64 bits (bit8-71) of thefirst data item340 to generate asecond data item350, having a hexadecimal value of “869A275B84129900”. In another example, if the selected non-negative integer is “52”, and thetransition cookie generator245 selects 64 bits (bit52-95 and bit0-19) of thefirst data item340 in a wrap-around fashion, bits52-95 have a hexadecimal value of “C0A801869A2”, and bit0-19 have a hexadecimal value of “900F0”, so the generatedsecond data item350 has a hexadecimal value of “900F0C0A801869A2”. Thetransition cookie generator245 then generates a transition cookiesecret key360 by storing thesecond data item350 in the least significant 64 bits (bit0-63) of the transition cookiesecret key360 and setting the most significant 64 bits (bit64-127) to “0”. For example, if thesecond data item350 has a hexadecimal value of “869A275B84129900”, the transition cookiesecret key360 has a hexadecimal value of “0000000000000000869A275B84129900”.
FIG. 3c illustrates exemplary steps for generating atransition cookie250 based on a transitioncookie data element330, a transition cookiesecret key360, and data obtained from a receivedsession SYN packet210, including asequence number318 of a TCP header in a receivedsession SYN packet210. To generate atransition cookie250, atransition cookie generator245 applies acryptographic method308 on the transition cookiesecret key360 and the transitioncookie data element330, such as an RC5 algorithm described in IETF RFC 2040 “The RC5, RC5-CBC, RC5-CBC-Pad, and RC5-CTS Algorithms” section 1 “Overview”, and sections 2-8 with detailed explanations, incorporated herein by reference. The RC5 algorithm takes a 32-bit plaintext input and a 128-bit encryption key to generate a 32-bit ciphertext output. Thetransition cookie generator245 uses the transitioncookie data element330 as the plaintext input to the RC5 algorithm, and the transition cookiesecret key360 as the encryption key input to the RC5 algorithm. Thetransition cookie generator245 stores the resulting 32-bit ciphertext output of the RC5 algorithm in theencrypted data element370.
Next, thetransition cookie generator245 performs an unsigned binary addition on anencrypted data element370 and thesequence number318, and stores the result in thetransition cookie250. For example, if theencrypted data element370 has a value of “0025BC83” in hexadecimal format, and thesequence number318 has a value of “0743BD55” in hexadecimal format, the result of the addition is hexadecimal “076979D8”. After the addition, thetransition cookie250 has a value of “076979D8” in hexadecimal. In another example, if theencrypted data element370 has a value of “BE43D096” in hexadecimal format, and thesequence number318 has a value of “9A275B84” in hexadecimal format, the result of the addition, and the value oftransition cookie250 is hexadecimal “1586B2C1A”, with the most significant bit carried beyond the 32-bit boundary.
In another embodiment, atransition cookie generator245 may use different steps to generate a transition cookiesecret key360. For example, a secret key offset301 may be an integer of a different bit length, such as a 4-bit integer value, a 3-bit integer value, or a 5-bit integer value. Also, atransition cookie generator245 may use a secret key offset301 to select a non-negative integer value of a different bit length from afirst data item340. For example, atransition cookie generator245 may select a 4-bit non-negative integer value, a 7-bit non-negative integer value, or a 5-bit non-negative value from afirst data item340.
In other embodiments, atransition cookie generator245 may store asecond data item350 in the least significant 64 bits (bit0-63) of a transition cookiesecret key360 or storesecond data item350 in the most significant 64 bits (bit64-127) of a transition cookiesecret key360.
Atransition cookie generator245 may also perform an exclusive-or operation on the most significant 48 bits (bit0-47) of afirst data item340 and the least significant 48 bits (bit48-95) of afirst data element340 to form a 48-bit temporary data element (not shown). Similarly, in another embodiment, atransition cookie generator245 may perform an exclusive-or operation on the 48 even bits (bit0,2,4, . . .90,92,94) and the 48 odd bits (bit1,3,5, . . .93,95,97) to form a 48 bit temporary data element. In yet another embodiment, atransition cookie generator245 may store a 48-bit temporary data element in the least significant 48 bits (bit0-47) and the most significant 48 bits (bit80-127) of a transition cookiesecret key360, and set bit48-79 to “0”, or store a 48-bit temporary data element in the least significant 48 bits (bit0-47) of a transition cookiesecret key360, and set the most significant 80 bits (bit48-127) of a transition cookiesecret key360 to “0”.
In other embodiments of the invention, atransition cookie generator245 may use an encryption algorithm to generate a transition cookie secret key360 from thefirst data item340.
In another embodiment, atransition cookie generator245 includes a secret key and an encryption algorithm, and uses afirst data element340 as a plaintext input, and a secret key as an encryption key input to the encryption algorithm to generate a 128-bit ciphertext output. Next, atransition cookie generator245 generates a transition cookiesecret key360 as a 128-bit ciphertext output. Alternatively, the ciphertext output may be a 96-bit data element, and atransition cookie generator245 stores a 96-bit ciphertext output in the least significant 96 bits (bit0-95) of a transition cookiesecret key360, and sets the most significant 32 bits (bit96-127) to “0”. In another alternative, atransition cookie generator245 stores the least significant 32 bits (bit0-31) of a 96-bit ciphertext output in the most significant 32 bits (bit96-127) of a transition cookiesecret key360.
As seen inFIG. 2, atransition cookie validator275 validates acandidate transition cookie270 generated from asession ACK packet230 received by the TCPsession setup module104. An exemplary method for validating acandidate transition cookie270 by atransition cookie validator275 may include multiple steps as illustrated inFIGS. 4a-4d.
FIG. 4a illustrates exemplary steps for generating a candidateencrypted data element470 by atransition cookie validator275 based on data obtained from a receivedsession ACK packet230. The candidateencrypted data element470 may be a 32-bit data element generated based on thesequence number418 of the TCP header in the receivedsession ACK packet230, and thecandidate transition cookie270 generated from the receivedsession ACK packet230 as illustrated inFIG. 2.
Thecandidate sequence number428 may be a 32-bit data element generated by atransition cookie validator275 such that the sum ofcandidate sequence number428 and a value of “1” equals thesequence number418.
The candidateencrypted data element470 is generated by thetransition cookie validator275 such that the result of performing an unsigned binary addition of the candidateencrypted data element470 and thecandidate sequence number428 equals thecandidate transition cookie270.
FIG. 4b illustrates exemplary steps for generating a candidate transition cookiesecret key460 by thetransition cookie validator275 based on data obtained from the receivedsession ACK packet230 and acandidate sequence number428. The data used for generating the candidate transition cookiesecret key460 may include at least asource IP address412 of the IP header in a receivedsession ACK packet230, adestination port414 and asource port416 of the TCP header in a receivedsession ACK packet230. In the process, a 96-bitfirst data item440 is formed by atransition cookie validator275 by concatenating asource IP address412, acandidate sequence number428, asource port416, and adestination port414. For example, if thesource IP address412 is 192.168.1.134, having a hexadecimal representation of “C0A80186”, thecandidate sequence number428 is hexadecimal “9A275B84”, thesource port416 is 4761, having a hexadecimal representation of “1299”, and thedestination port414 is 240, having a hexadecimal representation of “00F0”, after the concatenation, thefirst data item440 has a hexadecimal value of “C0A801869A275B84129900F0”.
Next, the 128-bit candidate transition cookiesecret key460 is generated from afirst data item440 by atransition cookie validator275 using a hash function. In an embodiment, atransition cookie validator275 uses a 6-bit secret key offset401 to select a 6-bit non-negative integer from afirst data item440 starting at a bit indicated by secret key offset401. For example, if the secret key offset401 has a value of “12” and thefirst data item440 is “C0A801869A275B84129900F0”, thetransition cookie validator275 selects a 6-bit non-negative integer from thefirst data item440 starting at bit12 (bits12-17), selecting the non-negative integer “16”. Thetransition cookie validator275 then generates a 64-bitsecond data item350 by using the selected non-negative integer to select 64 bits of data from thefirst data item440, starting at the bit indicated by the selected non-negative integer.
For example, if the selected non-negative integer is “8” and thefirst data item440 has a hexadecimal value of “C0A801869A275B84129900F0”, thetransition cookie validator275 selects 64 bits (bit8-71) of thefirst data item440 to generate asecond data item450 having a hexadecimal value of “869A275B84129900”. In another example, if thefirst data item440 has a hexadecimal value of “C0A801869A275B84129900F0”, and the selected non-negative integer is “52”, thetransition cookie validator275 selects 64 bits (bit52-95 and bit0-19) in a wrap-around fashion. Bits52-95 have a hexadecimal value of “C0A801869A2”, and bits0-19 have a hexadecimal value of “900F0”, so the generatedsecond data item450 has a hexadecimal value of “900F0C0A801869A2”.
Next, thetransition cookie validator275 generates a candidate transition cookiesecret key460 by storing thesecond data item450 in the least significant 64 bits (bit0-63) of the candidate transition cookiesecret key460 and setting the most significant 64 bits (bit64-127) to “0”. For example, if thesecond data item450 has a hexadecinmal value of “869A275B84129900”, the candidate transition cookiesecret key460 has a hexadecimal value of “0000000000000000869A275B84129900”.
FIG. 4C illustrates exemplary steps for generating a candidate transitioncookie data element430 by atransition cookie validator275 based on a candidateencrypted data element470 and a candidate transition cookiesecret key460.
In an embodiment, atransition cookie validator275 applies acryptographic method408 on a candidate transition cookiesecret key460 and a candidateencrypted data element470. Anexemplary cryptographic method408 is an RC5 algorithm described in IETF RFC 2040 “The RC5, RC5-CBC, RC5-CBC-Pad, and RC5-CTS Algorithms” section 1 “Overview”, and sections 2-8 with detailed explanations, incorporated herein by reference. The RC5 algorithm takes a 32-bit ciphertext input and a 128-bit decryption key to generate a 32-bit plaintext output. Atransition cookie validator275 uses a candidateencrypted data element470 as a ciphertext input to the RC5 algorithm, and a candidate transition cookiesecret key460 as a decryption key input to the RC5 algorithm, to generate a 32-bit candidate transitioncookie data element430 as the plaintext output of the RC5 decryption algorithm.
FIG. 4d illustrates exemplary steps by atransition cookie validator275 of validating a candidate transitioncookie data element430. In an embodiment, atransition cookie validator275 includes aclock305. Theclock305 indicates the current time of day, preferably in microseconds in a 32-bit format. The modifiedcurrent time409 is a 32-bit data element set by atransition cookie validator275 sets to the current time indicated byclock305. Atransition cookie validator275 then sets the least significant 5 bits (bit0-4) of the modifiedcurrent time409 to “0”. For example, if the modifiedcurrent time409 has a value of “89AE03F6” in hexadecimal format, after setting the least significant 5 bits to “0”, the modifiedcurrent time409 has a hexadecimal value of “89AE03E0”.
Next, atransition cookie validator275 sets a 32-bit adjusted candidate transitioncookie data element431 to equal the candidate transitioncookie data element430, and then sets the least significant 5 bits (bit0-4) of the adjusted candidate transitioncookie data element431 to “0”. For example, if the adjusted candidate transitioncookie data element431 has a hexadecimal value of “89DB468F”, after setting the least significant 5 bits to “0”, the adjusted candidate transitioncookie data element431 has a hexadecimal value of “89DB4680”.
Thetransition cookie validator275 may then determine if the candidate transitioncookie data element430 is valid by determining if the adjusted candidate transitioncookie data element431 is within a time margin of 3 seconds of the modifiedcurrent time409. In an embodiment, in order to determine if the adjusted candidate transitioncookie data element431 is within a time margin of 3 seconds of the modifiedcurrent time409, the transition cookie stores the modifiedcurrent time409 in the least significant 32 bits (bit0-31) of a first 33-bit time data element, sets the most significant bit (bit32) to “0”, and adds 6 seconds to the first 33-bit time data element. Adding 6 seconds is to add 6,000,000 micro seconds as represented by “5B8D80” in hexadecimal format. For example, if before the addition, the first 33-bit time data element has a hexadecimal value of “0FFFFFAE2”, After the addition of “5B8D80”, the first 33-bit time data element has a hexadecimal value of “1005B8862”. Thetransition cookie validator275 stores the adjusted candidate transitioncookie data element431 in the least significant 32 bits (bit0-31) of a second 33-bit time data element, sets the most significant bit (bit32) to “0”, and adds 3 seconds to the second 33-bit time data element. Adding 3 seconds is to add 3,000,000 micro seconds as represented by hexadecimal “2DC6C0”. Thetransition cookie validator275 stores the modifiedcurrent time409 in the least significant 32 bits (bit0-31) of a third 33-bit time data element, and sets the most significant bit (bit32) to “0”. If the second 33-bit time data element is smaller than the first 33-bit time data element and the second 33-bit time data element is larger than the third 33-bit time data element, thetransition cookie validator275 determines that the adjusted candidate transitioncookie data element431 is within 3 seconds of the modifiedcurrent time409, and thus that the candidate transitioncookie data element430 is valid.
FIG. 5 illustrates exemplary steps of generating information based on a validated candidate transitioncookie data element430. In an embodiment,candidate MSS522 is an integer. Atransition cookie validator275 includes a reversed MSS table507, which includes information that maps a 4-bit data element to acandidate MSS522. Atransition cookie validator275 extracts the least significant 4-bit (bit0-3) data from candidate transitioncookie data element430, maps the extracted 4-bit data to a reversed MSS table507, and stores the result in acandidate MSS522. Atransition cookie validator275 may then generate a maximum segment size option as described in IETF RFC 793 “Transmission Control Protocol” section 3.1 “Header Format”, incorporated herein by reference, and sets a maximum segment size option data of the maximum segment size option to equal acandidate MSS522. Atransition cookie validator275 may further examine bit4 of a candidate transitioncookie data element430. If bit4 of candidate transitioncookie data element430 has a value of “1”, atransition cookie validator275 may generate a sack-permitted option as described in IETF RFC 2018 “TCP Selective Acknowledgement Options” section 2, incorporated herein by reference. A TCPsession setup module104 may then send a sack-permitted option, a maximum segment size option, and data obtained from a receivedsession ACK packet230 to a computing module (not shown) for further processing.
There are many different encryption algorithms that use encryption keys of different bit lengths, such as, for example, 56-bit, 64-bit, 96-bit, 128-bit. These may generate ciphertext outputs of different bit lengths, for example, 96-bit, 64-bit, 128-bit, or 32-bit. Persons of ordinary skill in the cipher arts will be able to apply different methods, for example a hash function, to generate the transition cookie secret key360 from the ciphertext output.
Atransition cookie validator275 may also use different steps to generate a candidate transition cookiesecret key460. The steps used by atransition cookie validator275 to generate a candidate transition cookiesecret key460 are similar to the steps used by atransition cookie generator245 to generate a transition cookiesecret key360.
Alternative embodiments of the invention may employ a different algorithm for thecryptographic methods308,408. In one example, the different algorithm is an RC2 algorithm described in IETF RFC 2268 “A Description of the RC2(r) Encryption Algorithm” section 1 “Introduction” and section 2-4 with detailed explanation, incorporated herein by reference. In another example, the different algorithm is a Blowfish algorithm. In one other example, the different algorithm is a Data Encryption Standards (“DES”) algorithm based on Federal Information Processing Standards Publication “Data Encryption Standard (DES) FIPS PUB 46-3”, which is incorporated herein by reference in its entirety. Other algorithms are also usable.
Also, atransition cookie validator275 may use different time margins of modifiedcurrent time409 to determine if the candidate transition cookie data element is valid. Different time margins include but are not limited to 1 second, 4 seconds, 6 seconds, 2 seconds, or 11 seconds.
In an embodiment, the method of generating a transition cookie includes MD5 signature option information in the TCP options field. When this method is used, the method of validating acandidate transition cookie270 correspondingly includes the MD5 signature option information in the TCP options field.
In another embodiment,transition cookie generator245 may include a plurality of transition cookie generation methods forgenerating transition cookie250. For example, the secret key offset301 may have a different value, such as an integer value of different bit length, such as 4-bit, or 8-bit. In other examples, the selected non-negative integer fromfirst data item340 may be of different bit length, such as 8-bit, or 10-bit, thecryptographic method308 may be a different algorithm than RC5, or the generating of transitioncookie data element330 may include MD5 signature option information in the TCP options field ofsession SYN packet210. A transition cookie generation method may include steps different from the steps in the exemplary method illustrated inFIGS. 3a-3c.
In an embodiment, thetransition cookie generator245 may selects method to generatetransition cookie250 based on random data.
The random data may include time. In one embodiment,transition cookie generator245 selects a method based on the time of day. Alternatively, thetransition cookie generator245 may select a method after a time period, such as 10 seconds, 30 seconds, 2 minutes or 3 hours.
In another embodiment, the random data may include a source IP address insession SYN packet210, or a destination IP address insession SYN packet210.
The random data may include the network interface at which a TCPsession setup module104 receives asession SYN packet210, or a Virtual Local Area Network (VLAN) information associated with asession SYN packet210.
In one embodiment,transition cookie validator275 includes a plurality of transition cookie validation methods for validatingcandidate transition cookie270. A transition cookie validation method may include steps different from the steps in the exemplary method illustrated inFIGS. 4a-4d. Atransition cookie validator275 may select a method to validatecandidate transition cookie270 based on random data.
In these embodiments it is understood to be preferred that thetransition cookie validator275 selects a complementary method to the method selected bytransition cookie generator245.
Although the invention herein has been described with reference to particular embodiments, it is to be understood that these embodiments are merely illustrative of the principles and applications of the present invention. It is therefore to be understood that numerous modifications may be made to the illustrative embodiments and that other arrangements may be devised without departing from the spirit and scope of the present invention as defined by the appended claims.

Claims (31)

The invention claimed is:
1. A system for TCP SYN cookie validation at a host server comprising:
a session SYN packet receiver for receiving a session SYN packet;
a transition cookie generator operating to generate a transition cookie with the use of a transition cookie secret key, the transition cookie comprising a time value representing the actual time, wherein the transition cookie generator generates the transition cookie secret key based on data obtained from the received session SYN packet, the data obtained from the SYN packet including at least one of a source IP address of an IP header, a destination port, a source port, and a sequence number of a TCP header in the received session SYN packet, wherein the transition cookie generator concatenates the obtained data from the session SYN packet to generate a first data item of the generator and the transition cookie generator uses a first hash function to generate the transition cookie secret key from the first data item of the generator;
a session SYN/ACK packet sender for sending the transition cookie in response to the received session SYN packet;
a session ACK packet receiver for receiving a session ACK packet, the session ACK packet including a candidate transition cookie; and
a transition cookie validator, for determining whether the candidate transition cookie in the received session ACK packet comprises a time value representing a time within a predetermined time interval from the time the session ACK packet is received, wherein the transition cookie validator generates a candidate transition cookie secret key based on data obtained from the received session ACK packet, the data obtained from the ACK packet including at least one of a source IP address of the IP header, a destination port, and a source port, wherein the transition cookie validator concatenates the obtained data from the session ACK packet to generate a first data item of the validator and the transition cookie validator uses the first or another hash function to generate the candidate transition cookie secret key from the first data item of the validator,
wherein at least one of:
the transition cookie generator uses a secret key offset to select one or more bits of data from the first data item of the generator in order to generate a second data item of the generator, and
the transition cookie validator uses a candidate secret key offset to select one or more bits of data from the first data item of the validator in order to generate a second data item of the validator.
2. The system according toclaim 1, in which the transition cookie validator determines that the received session ACK packet is valid if the candidate transition cookie in the received session ACK packet comprises a time value representing a time within a predetermined time interval from the time the session ACK packet is received.
3. The system according toclaim 1, in which the predetermined time interval is in the range of one to six seconds.
4. The system according toclaim 1, in which the predetermined time interval is three seconds.
5. The system according toclaim 1, in which the generating of the transition cookie includes the use of random data.
6. The system according toclaim 1, in which the generating of the transition cookie includes the use of data obtained from the session SYN packet.
7. A system for TCP SYN cookie validation at a host server comprising:
a session SYN packet receiver for receiving a session SYN packet;
a transition cookie generator operating to generate a transition cookie with the use of a transition cookie secret key, the transition cookie comprising a time value representing the actual time, wherein the transition cookie generator generates the transition cookie by (i) generating an encrypted data element of the generator by applying a cryptographic method on the transition cookie secret key and a transition cookie data element, (ii) performing an unsigned binary addition on the encrypted data element of the generator and a sequence number of a TCP header in the received session SYN packet, and (iii) storing the result in the transition cookie;
a session SYN/ACK packet sender for sending the transition cookie in response to the received session SYN packet;
a session ACK packet receiver for receiving a session ACK packet, the session ACK packet including a candidate transition cookie; and
a transition cookie validator, for determining whether the candidate transition cookie in the received session ACK packet comprises a time value representing a time within a predetermined time interval from the time the session ACK packet is received.
8. The system according toclaim 7, wherein the transition cookie data element comprises data based on at least one of: a selective ACK, an MSS index, and a 32-bit current time of day indicated by a clock.
9. A system for TCP SYN cookie validation at a host server comprising:
a session SYN packet receiver for receiving a session SYN packet;
a transition cookie generator operating to generate a transition cookie with the use of a transition cookie secret key, the transition cookie comprising a time value representing the actual time;
a session SYN/ACK packet sender for sending the transition cookie in response to the received session SYN packet;
a session ACK packet receiver for receiving a session ACK packet, the session ACK packet including a candidate transition cookie; and
a transition cookie validator, for determining whether the candidate transition cookie in the received session ACK packet comprises a time value representing a time within a predetermined time interval from the time the session ACK packet is received, wherein the transition cookie validator generates:
a candidate sequence number such that a sequence number of a TCP header in the received session ACK packet equals the sum of the candidate sequence number and a value of 1,
a candidate encrypted data element such that the result of performing an unsigned binary addition of the candidate encrypted data element and a candidate sequence number equals the candidate transition cookie, and
a candidate transition cookie data element by applying a cryptographic method on a candidate transition cookie secret key and the candidate encrypted data element.
10. The system according toclaim 9, wherein the transition cookie validator validates the candidate transition cookie data element by adjusting the candidate transition cookie data element to generate, and determining if the adjusted candidate transition cookie data element is within a predetermined time margin of a modified current time.
11. A system for TCP SYN cookie validation at a host server, the system comprising:
a session SYN packet receiver hardware configured to receive a session SYN packet;
a transition cookie generator hardware configured to generate a transition cookie using a transition cookie secret key, the transition cookie comprising a time value representing the actual time, wherein the transition cookie generator hardware generates the transition cookie secret key based on data obtained from the received session SYN packet, wherein the transition cookie generator hardware generates the transition cookie secret key by:
(i) generating an encrypted data element of the transition cookie generator hardware by applying a cryptographic method on the transition cookie secret key and a transition cookie data element;
(ii) performing an unsigned binary addition on the encrypted data element of the transition cookie generator hardware and a sequence number of a TCP header in the session SYN packet to obtain a result; and
(iii) storing the result in the transition cookie;
a session SYN/ACK packet sender hardware configured to send the transition cookie in response to the received session SYN packet;
a session ACK packet receiver hardware configured to receive a session ACK packet including a candidate transition cookie; and
a transition cookie validator hardware configured to determine whether the candidate transition cookie in the received session ACK packet comprises a time value representing a time within a predetermined time interval from the time the session ACK packet is received, wherein the transition cookie validator hardware generates a candidate transition cookie secret key based on data obtained from the received session ACK packet.
12. The system of claim 11, wherein the data obtained from the session SYN packet includes at least one of a source IP address, a destination port, a source port, and a sequence number of a TCP header.
13. The system of claim 11, wherein the transition cookie secret key is generated by:
concatenating the data obtained from the session SYN packet;
forming a first secret key transition data item based on the concatenation; and
generating the transition cookie secret key from the first secret key transition data item.
14. The system of claim 13, wherein generating the transition cookie secret key from the first secret key transition data item comprises using a hash function.
15. The system of claim 13, wherein the transition cookie secret key is further generated by:
selecting one or more bits of data from the first secret key transition data item using a secret key offset;
forming a second secret key transition data item based on the selected one or more bits; and
generating the transition cookie secret key from the first secret key transition data item and the second secret key transition data item.
16. The system of claim 11, wherein the data obtained from the session ACK packet includes at least one of a source IP address, a destination port, and a source port.
17. The system of claim 11, wherein the candidate transition cookie secret key is generated by:
concatenating data obtained from the session ACK packet;
forming a secret key candidate data item based on the concatenation; and
generating the candidate transition cookie secret key from the secret key candidate data item of the validation.
18. The system of claim 17, wherein the candidate transition cookie secret key is further generated by using a hash function to generate the candidate transition cookie secret key from the first secret key candidate data item.
19. The system of claim 11, further comprising determining that the received session ACK packet is valid if the candidate transition cookie in the session ACK packet comprises the time value representing a time within a predetermined time interval from the time the session ACK packet is received.
20. The system of claim 19, wherein the predetermined time interval is between one and eleven seconds.
21. The system of claim 11, wherein the candidate transition cookie secret key is generated based on data obtained from the session ACK packet and a candidate sequence number.
22. A host for validating a TCP SYN cookie, comprising:
a memory device storing instructions; and
a processor that, when executing the instructions, configures the host to:
receive a session SYN packet;
generate a transition cookie using a transition cookie secret key, the transition cookie comprising a time value representing the actual time, the transition cookie secret key being generated based on data obtained from the session SYN packet, the transition cookie secret key being generated by:
(i) generating an encrypted data element by applying a cryptographic method on the transition cookie secret key and a transition cookie data element;
(ii) performing an unsigned binary addition on the encrypted data element and a sequence number of a TCP header in the session SYN packet to obtain a result; and
(iii) storing the result in the transition cookie;
send the transition cookie in response to the received session SYN packet;
receive a session ACK packet including a candidate transition cookie; and
determine whether the candidate transition cookie in the received session ACK packet comprises a time value representing a time within a predetermined time interval from the time the session ACK packet is received, wherein the processor generates a candidate transition cookie secret key based on data obtained from the received session ACK packet.
23. The host of claim 22, wherein the data obtained from the session SYN packet includes at least one of a source IP address, a destination port, a source port, and a sequence number of a TCP header.
24. The host of claim 22, wherein the transition cookie secret key is generated by:
concatenating the data obtained from the session SYN packet;
forming a first secret key transition data item based on the concatenation; and
generating the transition cookie secret key from the first secret key transition data item.
25. The host of claim 24, wherein the transition cookie secret key is further generated by:
selecting one or more bits of data from the first secret key transition data item using a secret key offset;
forming a second secret key transition data item based on the selected one or more bits; and
generating the transition cookie secret key from the first secret key transition data item and the second secret key transition data item.
26. The host of claim 22, wherein the data obtained from the session ACK packet includes at least one of a source IP address, a destination port, and a source port.
27. The host of claim 22, wherein the candidate transition cookie secret key is generated by:
concatenating data obtained from the session ACK packet;
forming a secret key candidate data item based on the concatenation; and
generating the candidate transition cookie secret key from the secret key candidate data item of the validation.
28. The host of claim 22, wherein the processor further configures the host to determine that the session ACK packet is valid if the candidate transition cookie in the session ACK packet comprises the time value representing a time within a predetermined time interval from the time the session ACK packet is received.
29. The host of claim 28, wherein the predetermined time interval is between one and eleven seconds.
30. The host of claim 22, wherein the candidate transition cookie secret key is generated based on data obtained from the session ACK packet and a candidate sequence number.
31. A non-transitory computer-readable medium storing instructions that, when executed, cause a computing device to perform a method for validating a TCP SYN cookie, the method comprising:
receiving a session SYN packet;
generating a transition cookie using a transition cookie secret key, the transition cookie comprising a time value representing the actual time, the transition cookie secret key being generated based on data obtained from the session SYN packet, the transition cookie secret key being generated by:
(i) generating an encrypted data element by applying a cryptographic method on the transition cookie secret key and a transition cookie data element;
(ii) performing an unsigned binary addition on the encrypted data element and a sequence number of a TCP header in the session SYN packet to obtain a result; and
(iii) storing the result in the transition cookie;
sending the transition cookie in response to the received session SYN packet;
receiving a session ACK packet including a candidate transition cookie; and
determining whether the candidate transition cookie in the received session ACK packet comprises a time value representing a time within a predetermined time interval from the time the session ACK packet is received, wherein a candidate transition cookie secret key is generated based on data obtained from the received session ACK packet.
US16/235,2492006-02-212018-12-28System and method for an adaptive TCP SYN cookie with time validationActive2029-01-09USRE49053E1 (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
US16/235,249USRE49053E1 (en)2006-02-212018-12-28System and method for an adaptive TCP SYN cookie with time validation

Applications Claiming Priority (4)

Application NumberPriority DateFiling DateTitle
US11/358,245US7675854B2 (en)2006-02-212006-02-21System and method for an adaptive TCP SYN cookie with time validation
US13/413,191USRE44701E1 (en)2006-02-212012-03-06System and method for an adaptive TCP SYN cookie with time validation
US14/151,803USRE47296E1 (en)2006-02-212014-01-09System and method for an adaptive TCP SYN cookie with time validation
US16/235,249USRE49053E1 (en)2006-02-212018-12-28System and method for an adaptive TCP SYN cookie with time validation

Related Parent Applications (1)

Application NumberTitlePriority DateFiling Date
US11/358,245ReissueUS7675854B2 (en)2006-02-212006-02-21System and method for an adaptive TCP SYN cookie with time validation

Publications (1)

Publication NumberPublication Date
USRE49053E1true USRE49053E1 (en)2022-04-26

Family

ID=38428122

Family Applications (4)

Application NumberTitlePriority DateFiling Date
US11/358,245CeasedUS7675854B2 (en)2006-02-212006-02-21System and method for an adaptive TCP SYN cookie with time validation
US13/413,191Active2029-01-09USRE44701E1 (en)2006-02-212012-03-06System and method for an adaptive TCP SYN cookie with time validation
US14/151,803Active2029-01-09USRE47296E1 (en)2006-02-212014-01-09System and method for an adaptive TCP SYN cookie with time validation
US16/235,249Active2029-01-09USRE49053E1 (en)2006-02-212018-12-28System and method for an adaptive TCP SYN cookie with time validation

Family Applications Before (3)

Application NumberTitlePriority DateFiling Date
US11/358,245CeasedUS7675854B2 (en)2006-02-212006-02-21System and method for an adaptive TCP SYN cookie with time validation
US13/413,191Active2029-01-09USRE44701E1 (en)2006-02-212012-03-06System and method for an adaptive TCP SYN cookie with time validation
US14/151,803Active2029-01-09USRE47296E1 (en)2006-02-212014-01-09System and method for an adaptive TCP SYN cookie with time validation

Country Status (1)

CountryLink
US (4)US7675854B2 (en)

Families Citing this family (54)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US7720977B1 (en)2003-02-112010-05-18Foundry Networks, Inc.Cookie invalidation or expiration by a switch
US7675854B2 (en)*2006-02-212010-03-09A10 Networks, Inc.System and method for an adaptive TCP SYN cookie with time validation
US8149708B2 (en)*2006-04-202012-04-03Cisco Technology, Inc.Dynamically switching streams of packets among dedicated and shared queues
US8312507B2 (en)2006-10-172012-11-13A10 Networks, Inc.System and method to apply network traffic policy to an application session
US8584199B1 (en)2006-10-172013-11-12A10 Networks, Inc.System and method to apply a packet routing policy to an application session
US8296835B2 (en)*2007-05-112012-10-23Microsoft CorporationOver the air communication authentication using a service token
US8205080B2 (en)*2007-05-112012-06-19Microsoft CorporationOver the air communication authentication using a device token
US7921282B1 (en)*2007-08-202011-04-05F5 Networks, Inc.Using SYN-ACK cookies within a TCP/IP protocol
CN102014110A (en)*2009-09-082011-04-13华为技术有限公司Method for authenticating communication flows, communication system and protective device
US9960967B2 (en)*2009-10-212018-05-01A10 Networks, Inc.Determining an application delivery server based on geo-location information
KR101263329B1 (en)*2009-12-022013-05-16한국전자통신연구원Method and apparatus for preventing network attacks, method and apparatus for processing transmission and receipt of packet comprising the same
US8380994B2 (en)2009-12-232013-02-19Citrix Systems, Inc.Systems and methods for generating and managing cookie signatures for prevention of HTTP denial of service in multi-core system
US9215275B2 (en)2010-09-302015-12-15A10 Networks, Inc.System and method to balance servers based on server load status
US9609052B2 (en)2010-12-022017-03-28A10 Networks, Inc.Distributing application traffic to servers based on dynamic service response time
KR101510432B1 (en)*2010-12-222015-04-10한국전자통신연구원Apparatus for analizing traffic
US8595477B1 (en)*2011-03-242013-11-26Google Inc.Systems and methods for reducing handshake delay in streaming protocol web requests
US8897154B2 (en)2011-10-242014-11-25A10 Networks, Inc.Combining stateless and stateful server load balancing
US9386088B2 (en)2011-11-292016-07-05A10 Networks, Inc.Accelerating service processing using fast path TCP
US9094364B2 (en)2011-12-232015-07-28A10 Networks, Inc.Methods to manage services over a service gateway
US10044582B2 (en)2012-01-282018-08-07A10 Networks, Inc.Generating secure name records
US9027129B1 (en)2012-04-302015-05-05Brocade Communications Systems, Inc.Techniques for protecting against denial of service attacks
US9596286B2 (en)2012-05-252017-03-14A10 Networks, Inc.Method to process HTTP header with hardware assistance
CN103491061B (en)*2012-06-132017-02-15华为技术有限公司Attack mitigation method, serial number providing method and equipment
US8782221B2 (en)2012-07-052014-07-15A10 Networks, Inc.Method to allocate buffer for TCP proxy session based on dynamic network conditions
US9106561B2 (en)2012-12-062015-08-11A10 Networks, Inc.Configuration of a virtual service network
KR101692751B1 (en)2012-09-252017-01-04에이10 네트워크스, 인코포레이티드Load distribution in data networks
US9843484B2 (en)2012-09-252017-12-12A10 Networks, Inc.Graceful scaling in software driven networks
US10021174B2 (en)2012-09-252018-07-10A10 Networks, Inc.Distributing service sessions
US10002141B2 (en)2012-09-252018-06-19A10 Networks, Inc.Distributed database in software driven networks
US9338225B2 (en)2012-12-062016-05-10A10 Networks, Inc.Forwarding policies on a virtual service network
US8978143B2 (en)*2013-01-022015-03-10Verisign, Inc.Reverse authorized SYN cookie
US9531846B2 (en)2013-01-232016-12-27A10 Networks, Inc.Reducing buffer usage for TCP proxy session based on delayed acknowledgement
US9900252B2 (en)2013-03-082018-02-20A10 Networks, Inc.Application delivery controller and global server load balancer
WO2014144837A1 (en)2013-03-152014-09-18A10 Networks, Inc.Processing data packets using a policy based network path
US10038693B2 (en)2013-05-032018-07-31A10 Networks, Inc.Facilitating secure network traffic by an application delivery controller
US10027761B2 (en)2013-05-032018-07-17A10 Networks, Inc.Facilitating a secure 3 party network session by a network device
US10230770B2 (en)2013-12-022019-03-12A10 Networks, Inc.Network proxy layer for policy-based application proxies
KR20150084307A (en)*2014-01-132015-07-22삼성전자주식회사Apparatus and method for controlling an web loading time in a network
US9942152B2 (en)2014-03-252018-04-10A10 Networks, Inc.Forwarding data packets using a service-based forwarding policy
US10020979B1 (en)2014-03-252018-07-10A10 Networks, Inc.Allocating resources in multi-core computing environments
US9942162B2 (en)2014-03-312018-04-10A10 Networks, Inc.Active application response delay time
US9806943B2 (en)2014-04-242017-10-31A10 Networks, Inc.Enabling planned upgrade/downgrade of network devices without impacting network sessions
US9848067B2 (en)*2014-04-252017-12-19Cisco Technology, Inc.Managing sequence values with added headers in computing devices
US9906422B2 (en)2014-05-162018-02-27A10 Networks, Inc.Distributed system to determine a server's health
US10129122B2 (en)2014-06-032018-11-13A10 Networks, Inc.User defined objects for network devices
US9986061B2 (en)2014-06-032018-05-29A10 Networks, Inc.Programming a data network device using user defined scripts
US9992229B2 (en)2014-06-032018-06-05A10 Networks, Inc.Programming a data network device using user defined scripts with licenses
US10581976B2 (en)2015-08-122020-03-03A10 Networks, Inc.Transmission control of protocol state exchange for dynamic stateful service insertion
US10243791B2 (en)2015-08-132019-03-26A10 Networks, Inc.Automated adjustment of subscriber policies
US10318288B2 (en)2016-01-132019-06-11A10 Networks, Inc.System and method to process a chain of network applications
US10158666B2 (en)*2016-07-262018-12-18A10 Networks, Inc.Mitigating TCP SYN DDoS attacks using TCP reset
US10389835B2 (en)2017-01-102019-08-20A10 Networks, Inc.Application aware systems and methods to process user loadable network applications
US11323529B2 (en)*2017-07-182022-05-03A10 Networks, Inc.TCP fast open hardware support in proxy devices
US11019022B1 (en)2020-01-282021-05-25F5 Networks, Inc.Processing packets with returnable values

Citations (29)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US5958053A (en)*1997-01-301999-09-28At&T Corp.Communications protocol with improved security
US6047268A (en)*1997-11-042000-04-04A.T.&T. CorporationMethod and apparatus for billing for transactions conducted over the internet
US20010042200A1 (en)2000-05-122001-11-15International Business MachinesMethods and systems for defeating TCP SYN flooding attacks
US6321338B1 (en)*1998-11-092001-11-20Sri InternationalNetwork surveillance
US20020103916A1 (en)*2000-09-072002-08-01Benjie ChenThwarting connection-based denial of service attacks
US20030135625A1 (en)*2002-01-152003-07-17International Business Machines CorporationBlended SYN cookies
US6772334B1 (en)*2000-08-312004-08-03Networks Associates, Inc.System and method for preventing a spoofed denial of service attack in a networked computing environment
US6779033B1 (en)*2000-12-282004-08-17Networks Associates Technology, Inc.System and method for transacting a validated application session in a networked computing environment
US20050240989A1 (en)*2004-04-232005-10-27Seoul National University Industry FoundationMethod of sharing state between stateful inspection firewalls on mep network
US20060023721A1 (en)*2004-07-292006-02-02Ntt Docomo, Inc.Server device, method for controlling a server device, and method for establishing a connection using the server device
US20060069804A1 (en)*2004-08-252006-03-30Ntt Docomo, Inc.Server device, client device, and process execution method
US20060230129A1 (en)2005-02-042006-10-12Nokia CorporationApparatus, method and computer program product to reduce TCP flooding attacks while conserving wireless network bandwidth
US20060280121A1 (en)*2005-06-132006-12-14Fujitsu LimitedFrame-transfer control device, DoS-attack preventing device, and DoS-attack preventing system
US20070019543A1 (en)*2005-07-062007-01-25Fortinet, Inc.Systems and methods for detecting and preventing flooding attacks in a network environment
US7254133B2 (en)2002-07-152007-08-07Intel CorporationPrevention of denial of service attacks
US7269850B2 (en)*2002-12-312007-09-11Intel CorporationSystems and methods for detecting and tracing denial of service attacks
US7301899B2 (en)*2001-01-312007-11-27Comverse Ltd.Prevention of bandwidth congestion in a denial of service or other internet-based attack
US7370353B2 (en)*2001-11-052008-05-06Cisco Technology, Inc.System and method for managing dynamic network sessions
US7391725B2 (en)*2004-05-182008-06-24Christian HuitemaSystem and method for defeating SYN attacks
US7430755B1 (en)*2002-09-032008-09-30Fs Networks, Inc.Method and system for providing persistence in a secure network access
US7506360B1 (en)*2002-10-012009-03-17Mirage Networks, Inc.Tracking communication for determining device states
US7512980B2 (en)*2001-11-302009-03-31Lancope, Inc.Packet sampling flow-based detection of network intrusions
US7552323B2 (en)*2002-11-182009-06-23Liquidware Labs, Inc.System, apparatuses, methods, and computer-readable media using identification data in packet communications
US7610622B2 (en)2006-02-062009-10-27Cisco Technology, Inc.Supporting options in a communication session using a TCP cookie
US7675854B2 (en)*2006-02-212010-03-09A10 Networks, Inc.System and method for an adaptive TCP SYN cookie with time validation
US7733866B2 (en)2004-04-152010-06-08Qualcomm IncorporatedPacket concatenation in wireless networks
US7826487B1 (en)*2005-05-092010-11-02F5 Network, IncCoalescing acknowledgement responses to improve network communications
US7979694B2 (en)2003-03-032011-07-12Cisco Technology, Inc.Using TCP to authenticate IP source addresses
US20120240185A1 (en)*2000-09-252012-09-20Harsh KapoorSystems and methods for processing data flows

Family Cites Families (398)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US5218602A (en)1991-04-041993-06-08Dsc Communications CorporationInterprocessor switching network
TW269763B (en)1995-09-121996-02-01Ind Tech Res InstSeamless handoff for a wireless/wired LAN internetworking
JP2962203B2 (en)1995-09-281999-10-12日本電気株式会社 Load balancing method for online information processing system
US5875185A (en)1995-10-101999-02-23Industrial Technology Research Inst.Seamless handoff for a wireless lan/wired lan internetworking
US5935207A (en)1996-06-031999-08-10Webtv Networks, Inc.Method and apparatus for providing remote site administrators with user hits on mirrored web sites
US5862339A (en)1996-07-091999-01-19Webtv Networks, Inc.Client connects to an internet access provider using algorithm downloaded from a central server based upon client's desired criteria after disconnected from the server
US5774660A (en)1996-08-051998-06-30Resonate, Inc.World-wide-web server with delayed resource-binding for resource-based load balancing on a distributed resource multi-node network
US6075783A (en)1997-03-062000-06-13Bell Atlantic Network Services, Inc.Internet phone to PSTN cellular/PCS system
US5995981A (en)1997-06-161999-11-30Telefonaktiebolaget Lm EricssonInitialization of replicated data objects
EP1021757A1 (en)1997-07-252000-07-26Starvox, Inc.Apparatus and method for integrated voice gateway
JP3346234B2 (en)1997-08-122002-11-18ケイディーディーアイ株式会社 Inter-route control communication system between circuit switching network and Internet network.
JP3369445B2 (en)1997-09-222003-01-20富士通株式会社 Network service server load adjusting device, method and recording medium
US6226680B1 (en)1997-10-142001-05-01Alacritech, Inc.Intelligent network interface system method for protocol processing
US6434620B1 (en)1998-08-272002-08-13Alacritech, Inc.TCP/IP offload network interface device
US7167927B2 (en)1997-10-142007-01-23Alacritech, Inc.TCP/IP offload device with fast-path TCP ACK generating and transmitting mechanism
US8782199B2 (en)1997-10-142014-07-15A-Tech LlcParsing a packet header
US7237036B2 (en)1997-10-142007-06-26Alacritech, Inc.Fast-path apparatus for receiving data corresponding a TCP connection
US6003069A (en)1997-12-161999-12-14Lexmark International, Inc.Client/server printer driver system
US6167062A (en)1998-02-022000-12-26Tellabs Operations, Inc.System and associated method for the synchronization and control of multiplexed payloads over a telecommunications network
US6131163A (en)1998-02-172000-10-10Cisco Technology, Inc.Network gateway mechanism having a protocol stack proxy
US6459682B1 (en)1998-04-072002-10-01International Business Machines CorporationArchitecture for supporting service level agreements in an IP network
JPH11338836A (en)1998-05-251999-12-10Nippon Telegr & Teleph Corp <Ntt> Computer Network Load Balancing System
US6578066B1 (en)1999-09-172003-06-10Alteon WebsystemsDistributed load-balancing internet servers
US6219706B1 (en)1998-10-162001-04-17Cisco Technology, Inc.Access control for networks
US7418504B2 (en)1998-10-302008-08-26Virnetx, Inc.Agile network protocol for secure communications using secure domain names
US6571274B1 (en)1998-11-052003-05-27Beas Systems, Inc.Clustered enterprise Java™ in a secure distributed processing system
US6850965B2 (en)1998-11-172005-02-01Arthur Douglas AllenMethod for connection acceptance and rapid determination of optimal multi-media content delivery over network
TW444478B (en)1998-12-102001-07-01Ind Tech Res InstEthernet switch IC with shared memory structure and its network
US6483600B1 (en)1999-02-262002-11-193Com CorporationSystem and method for communicating real-time facsimiles over data networks
AU3740500A (en)1999-03-122000-09-28Nortel Networks LimitedMethod and apparatus for accessing network information on a network device
JP2000276432A (en)1999-03-242000-10-06Nec CorpDynamic load distribution system for transaction message
JP2000307634A (en)1999-04-152000-11-02Kdd Corp Congestion control method by relay station in packet switching network
EP1049307A1 (en)1999-04-292000-11-02International Business Machines CorporationMethod and system for dispatching client sessions within a cluster of servers connected to the World Wide Web
TW425821B (en)1999-05-312001-03-11Ind Tech Res InstKey management method
US20010049741A1 (en)1999-06-182001-12-06Bryan D. SkeneMethod and system for balancing load distribution on a wide area network
EP1067458A1 (en)1999-07-092001-01-10CANAL+ Société AnonymeRunning and testing applications
US6374300B2 (en)1999-07-152002-04-16F5 Networks, Inc.Method and system for storing load balancing information with an HTTP cookie
JP2001051859A (en)1999-08-112001-02-23Hitachi Ltd Load information communication method
WO2001013228A2 (en)1999-08-132001-02-22Sun Microsystems, Inc.Graceful distribution in application server load balancing
AU6795100A (en)1999-08-212001-03-19Webever, Inc.Method for content delivery over the internet
US7463648B1 (en)1999-08-232008-12-09Sun Microsystems, Inc.Approach for allocating resources to an apparatus based on optional resource requirements
US7703102B1 (en)1999-08-232010-04-20Oracle America, Inc.Approach for allocating resources to an apparatus based on preemptable resource requirements
US8179809B1 (en)1999-08-232012-05-15Oracle America, Inc.Approach for allocating resources to an apparatus based on suspendable resource requirements
US8019870B1 (en)1999-08-232011-09-13Oracle America, Inc.Approach for allocating resources to an apparatus based on alternative resource requirements
US8032634B1 (en)1999-08-232011-10-04Oracle America, Inc.Approach for allocating resources to an apparatus based on resource requirements
US6600738B1 (en)1999-10-022003-07-29Ericsson, Inc.Routing in an IP network based on codec availability and subscriber preference
US6748414B1 (en)1999-11-152004-06-08International Business Machines CorporationMethod and apparatus for the load balancing of non-identical servers in a network environment
US6952728B1 (en)1999-12-012005-10-04Nortel Networks LimitedProviding desired service policies to subscribers accessing internet
US6754706B1 (en)1999-12-162004-06-22Speedera Networks, Inc.Scalable domain name system with persistence and load balancing
US6587866B1 (en)2000-01-102003-07-01Sun Microsystems, Inc.Method for distributing packets to server nodes using network client affinity and packet distribution table
US6820133B1 (en)2000-02-072004-11-16Netli, Inc.System and method for high-performance delivery of web content using high-performance communications protocol between the first and second specialized intermediate nodes to optimize a measure of communications performance between the source and the destination
US6725272B1 (en)2000-02-182004-04-20Netscaler, Inc.Apparatus, method and computer program product for guaranteed content delivery incorporating putting a client on-hold based on response time
US6804224B1 (en)2000-02-292004-10-123Com CorporationSystem and method for providing telephone service having private branch exchange features in a voice-over-data network telephony system
US8380854B2 (en)2000-03-212013-02-19F5 Networks, Inc.Simplified method for processing multiple connections from the same client
JP2001298449A (en)2000-04-122001-10-26Matsushita Electric Ind Co Ltd Security communication method, communication system and its device
US20020032799A1 (en)2000-05-022002-03-14Globalstar L.P.Deferring DNS service for a satellite ISP system using non-geosynchronous orbit satellites
US20030061506A1 (en)2001-04-052003-03-27Geoffrey CooperSystem and method for security policy
US8204082B2 (en)2000-06-232012-06-19Cloudshield Technologies, Inc.Transparent provisioning of services over a network
US7013482B1 (en)2000-07-072006-03-14802 Systems LlcMethods for packet filtering including packet invalidation if packet validity determination not timely made
US7031267B2 (en)2000-12-212006-04-18802 Systems LlcPLD-based packet filtering methods with PLD configuration data update of filtering rules
US7814180B2 (en)2000-07-132010-10-12Infoblox, Inc.Domain name service server
CN1200368C (en)2000-08-182005-05-04清华大学Local re-transmission method of using TCP for un-reliable transmission network
US7711790B1 (en)*2000-08-242010-05-04Foundry Networks, Inc.Securing an accessible computer system
US7010605B1 (en)*2000-08-292006-03-07Microsoft CorporationMethod and apparatus for encoding and storing session data
EP1189404A1 (en)2000-08-292002-03-20AlcatelData network
JP3501361B2 (en)2000-09-042004-03-02インターナショナル・ビジネス・マシーンズ・コーポレーション Computer network system, computer system, communication method between computer systems, method for measuring computer system performance, and recording medium
JP2002091936A (en)2000-09-112002-03-29Hitachi Ltd Load distribution device and load estimation method
US7454500B1 (en)2000-09-262008-11-18Foundry Networks, Inc.Global server load balancing
EP1330725B1 (en)2000-09-292012-03-21Alacritech, Inc.Intelligent network storage interface system and devices
US6813635B1 (en)2000-10-132004-11-02Hewlett-Packard Development Company, L.P.System and method for distributing load among redundant independent stateful world wide web server sites
WO2002035359A2 (en)2000-10-262002-05-02Prismedia Networks, Inc.Method and system for managing distributed content and related metadata
US7739398B1 (en)2000-11-212010-06-15Avaya Inc.Dynamic load balancer
US20020078164A1 (en)2000-12-132002-06-20Marnetics Ltd.System and method for data transfer acceleration in a TCP network environment
US7218722B1 (en)2000-12-182007-05-15Westell Technologies, Inc.System and method for providing call management services in a virtual private network using voice or video over internet protocol
US7155515B1 (en)2001-02-062006-12-26Microsoft CorporationDistributed load balancing for single entry-point systems
US7149817B2 (en)2001-02-152006-12-12Neteffect, Inc.Infiniband TM work queue to TCP/IP translation
US7454523B2 (en)2001-03-162008-11-18Intel CorporationGeographic location determination including inspection of network address
US7313822B2 (en)2001-03-162007-12-25Protegrity CorporationApplication-layer security method and system
US7533409B2 (en)2001-03-222009-05-12Corente, Inc.Methods and systems for firewalling virtual private networks
US20020141386A1 (en)2001-03-292002-10-03Minert Brian D.System, apparatus and method for voice over internet protocol telephone calling using enhanced signaling packets and localized time slot interchanging
US7349970B2 (en)2001-03-292008-03-25International Business Machines CorporationWorkload management of stateful program entities
US6839700B2 (en)2001-05-232005-01-04International Business Machines CorporationLoad balancing content requests using dynamic document generation cost information
US7269632B2 (en)2001-06-052007-09-11Xdyne, Inc.Networked computer system for communicating and operating in a virtual reality environment
US20040103315A1 (en)2001-06-072004-05-27Geoffrey CooperAssessment tool
GB0113844D0 (en)2001-06-072001-08-01Marconi Comm LtdReal time processing
WO2002103970A1 (en)2001-06-182002-12-27Tatara Systems, Inc.Method and apparatus for converging local area and wide area wireless data networks
US6944678B2 (en)2001-06-182005-09-13Transtech Networks Usa, Inc.Content-aware application switch and methods thereof
US8180921B2 (en)2001-06-192012-05-15Intel CorporationMethod and apparatus for load balancing
US7343399B2 (en)2001-06-252008-03-11Nortel Networks LimitedApparatus and method for managing internet resource requests
ATE286641T1 (en)2001-07-032005-01-15Ericsson Telefon Ab L M METHOD AND SYSTEM FOR HANDLING MULTIPLE REGISTRATIONS
US7305492B2 (en)2001-07-062007-12-04Juniper Networks, Inc.Content service aggregation system
US7509369B1 (en)2001-07-112009-03-24Swsoft Holdings, Ltd.Balancing shared servers in virtual environments
US7366794B2 (en)2001-07-132008-04-29Certicom Corp.Method and apparatus for resolving a web site address when connected with a virtual private network (VPN)
US7072958B2 (en)2001-07-302006-07-04Intel CorporationIdentifying network management policies
US20040187032A1 (en)2001-08-072004-09-23Christoph GelsMethod, data carrier, computer system and computer progamme for the identification and defence of attacks in server of network service providers and operators
US7039037B2 (en)2001-08-202006-05-02Wang Jiwei RMethod and apparatus for providing service selection, redirection and managing of subscriber access to multiple WAP (Wireless Application Protocol) gateways simultaneously
FR2830397B1 (en)2001-09-282004-12-03Evolium Sas METHOD FOR IMPROVING THE PERFORMANCE OF A TRANSMISSION PROTOCOL USING A RETRANSMISSION TIMER
EP2403219B1 (en)2001-09-282014-10-22Level 3 CDN International, Inc.Method for name to address resolution
US7958199B2 (en)2001-11-022011-06-07Oracle America, Inc.Switching systems and methods for storage management in digital networks
JP3730563B2 (en)2001-11-022006-01-05キヤノンソフトウェア株式会社 Session management apparatus, session management method, program, and recording medium
JP2003186776A (en)2001-12-132003-07-04Hitachi Ltd Congestion control system
WO2003060671A2 (en)2002-01-042003-07-24Lab 7 Networks, Inc.Communication security system
US6633835B1 (en)2002-01-102003-10-14Networks Associates Technology, Inc.Prioritized data capture, classification and filtering in a network monitoring environment
US8090866B1 (en)2002-01-182012-01-03Cisco Technology, Inc.TCP proxy connection management in a gigabit environment
US7076555B1 (en)2002-01-232006-07-11Novell, Inc.System and method for transparent takeover of TCP connections between servers
CN1714545A (en)2002-01-242005-12-28艾维西系统公司System and method for fault tolerant data communication
WO2003065177A2 (en)2002-02-012003-08-07John FairweatherSystem and method for navigating data
US7584262B1 (en)2002-02-112009-09-01Extreme NetworksMethod of and system for allocating resources to resource requests based on application of persistence policies
US7228359B1 (en)2002-02-122007-06-05Cisco Technology, Inc.Methods and apparatus for providing domain name service based on a client identifier
CA2372092C (en)2002-02-152010-04-06Cognos IncorporatedA queuing model for a plurality of servers
US20030195962A1 (en)2002-04-102003-10-16Satoshi KikuchiLoad balancing of servers
US7707295B1 (en)2002-05-032010-04-27Foundry Networks, Inc.Connection rate limiting
US8554929B1 (en)2002-05-032013-10-08Foundry Networks, LlcConnection rate limiting for server load balancing and transparent cache switching
US7340535B1 (en)2002-06-042008-03-04Fortinet, Inc.System and method for controlling routing in a virtual router system
US6888807B2 (en)2002-06-102005-05-03Ipr Licensing, Inc.Applying session services based on packet flows
US7944920B2 (en)2002-06-112011-05-17Pandya Ashish AData processing system using internet protocols and RDMA
SE525271C2 (en)2002-06-192005-01-18Marratech Ab Device and method for transmitting private information within a group communication system
US7277963B2 (en)2002-06-262007-10-02Sandvine IncorporatedTCP proxy providing application layer modifications
US7418494B2 (en)2002-07-252008-08-26Intellectual Ventures Holding 40 LlcMethod and system for background replication of data objects
US7069438B2 (en)*2002-08-192006-06-27Sowl Associates, Inc.Establishing authenticated network connections
US7337241B2 (en)2002-09-272008-02-26Alacritech, Inc.Fast-path apparatus for receiving data corresponding to a TCP connection
US7236457B2 (en)2002-10-042007-06-26Intel CorporationLoad balancing in a network
US7487248B2 (en)2002-10-082009-02-03Brian MoranMethod and system for transferring a computer session between devices
US7792113B1 (en)2002-10-212010-09-07Cisco Technology, Inc.Method and system for policy-based forwarding
US7310686B2 (en)2002-10-272007-12-18Paxfire, Inc.Apparatus and method for transparent selection of an Internet server based on geographic location of a user
US7406087B1 (en)2002-11-082008-07-29Juniper Networks, Inc.Systems and methods for accelerating TCP/IP data stream processing
US7269348B1 (en)2002-11-182007-09-11At&T Corp.Router having dual propagation paths for packets
US7945673B2 (en)2002-12-062011-05-17Hewlett-Packard Development Company, L.P.Reduced wireless internet connect time
US7379958B2 (en)2002-12-302008-05-27Nokia CorporationAutomatic and dynamic service information delivery from service providers to data terminals in an access point network
US7194480B2 (en)2002-12-312007-03-20International Business Machines CorporationSystem and method for invoking methods on place objects in a distributed environment
US7089231B2 (en)2002-12-312006-08-08International Business Machines CorporationSystem and method for searching a plurality of databases distributed across a multi server domain
US7234161B1 (en)2002-12-312007-06-19Nvidia CorporationMethod and apparatus for deflecting flooding attacks
US6904439B2 (en)2002-12-312005-06-07International Business Machines CorporationSystem and method for aggregating user project information in a multi-server system
US20040141005A1 (en)2003-01-222004-07-22International Business Machines CorporationSystem and method for integrating online meeting materials in a place
US7167874B2 (en)2003-01-222007-01-23International Business Machines CorporationSystem and method for command line administration of project spaces using XML objects
US7835363B2 (en)2003-02-122010-11-16Broadcom CorporationMethod and system to provide blade server load balancing using spare link bandwidth
US20040210623A1 (en)2003-03-062004-10-21Aamer HydrieVirtual network topology generation
WO2004084085A1 (en)2003-03-182004-09-30Fujitsu LimitedLoad distributing system by intersite cooperation
US20040210663A1 (en)2003-04-152004-10-21Paul PhillipsObject-aware transport-layer network processing engine
US7373500B2 (en)2003-04-152008-05-13Sun Microsystems, Inc.Secure network processing
US7308499B2 (en)2003-04-302007-12-11Avaya Technology Corp.Dynamic load balancing for enterprise IP traffic
US7181524B1 (en)2003-06-132007-02-20Veritas Operating CorporationMethod and apparatus for balancing a load among a plurality of servers in a computer system
US7613822B2 (en)2003-06-302009-11-03Microsoft CorporationNetwork load balancing with session information
US7590736B2 (en)2003-06-302009-09-15Microsoft CorporationFlexible network load balancing
US7636917B2 (en)2003-06-302009-12-22Microsoft CorporationNetwork load balancing with host status information
US20050027862A1 (en)2003-07-182005-02-03Nguyen Tien LeSystem and methods of cooperatively load-balancing clustered servers
US7814093B2 (en)2003-07-252010-10-12Microsoft CorporationMethod and system for building a report for execution against a data store
KR100568231B1 (en)2003-08-112006-04-07삼성전자주식회사 Domain Name Service System and Method
US7385923B2 (en)2003-08-142008-06-10International Business Machines CorporationMethod, system and article for improved TCP performance during packet reordering
US7467202B2 (en)2003-09-102008-12-16Fidelis Security SystemsHigh-performance network content analysis platform
CN100456690C (en)2003-10-142009-01-28北京邮电大学 Global load balancing method based on global network location
KR100570836B1 (en)2003-10-142006-04-13한국전자통신연구원 Load Balancer and Method Between Servers Using Load Balancing Session Labels
US7472190B2 (en)2003-10-172008-12-30International Business Machines CorporationMethod, system and program product for preserving a user state in an application
JP2005141441A (en)2003-11-062005-06-02Hitachi Ltd Load balancing system
US6996070B2 (en)2003-12-052006-02-07Alacritech, Inc.TCP/IP offload device with reduced sequential processing
US20050125276A1 (en)2003-12-052005-06-09Grigore RusuSystem and method for event tracking across plural contact mediums
US20050213586A1 (en)2004-02-052005-09-29David CyganskiSystem and method to increase network throughput
US7881215B1 (en)2004-03-182011-02-01Avaya Inc.Stateful and stateless data processing
US20060064478A1 (en)2004-05-032006-03-23Level 3 Communications, Inc.Geo-locating load balancing
US20060112170A1 (en)2004-05-032006-05-25Craig SirkinGeo-locating load balancing
US7584301B1 (en)2004-05-062009-09-01Foundry Networks, Inc.Host-level policies for global server load balancing
US8423758B2 (en)2004-05-102013-04-16Tara Chand SinghalMethod and apparatus for packet source validation architecture system for enhanced internet security
US8179786B2 (en)2004-05-192012-05-15Mosaid Technologies IncorporatedDynamic traffic rearrangement and restoration for MPLS networks with differentiated services capabilities
US7979072B2 (en)2004-06-042011-07-12Nortel Networks LimitedMethod and system for soft handoff in mobile broadband systems
US7990849B2 (en)2004-06-172011-08-02Hewlett-Packard Development Company, L.P.Automated recovery from a split segment condition in a layer2 network for teamed network resources of a computer system
US20060069774A1 (en)2004-06-172006-03-30International Business Machine CorporationMethod and apparatus for managing data center using Web services
FI20040888A0 (en)2004-06-282004-06-28Nokia Corp Management of services in a packet switching data network
US8688834B2 (en)2004-07-092014-04-01Toshiba America Research, Inc.Dynamic host configuration and network access authentication
CN1317853C (en)2004-07-202007-05-23联想网御科技(北京)有限公司Network safety equipment and assemblied system and method for implementing high availability
TW200606667A (en)2004-08-132006-02-16Reallusion IncSystem and method of converting and sharing data
US7423977B1 (en)2004-08-232008-09-09Foundry Networks Inc.Smoothing algorithm for round trip time (RTT) measurements
US7292592B2 (en)2004-10-082007-11-06Telefonaktiebolaget Lm Ericsson (Publ)Home network-assisted selection of intermediary network for a roaming mobile terminal
US20060092950A1 (en)2004-10-282006-05-04Cisco Technology, Inc.Architecture and method having redundancy in active/active stateful devices based on symmetric global load balancing protocol (sGLBP)
US20060098645A1 (en)2004-11-092006-05-11Lev WalkinSystem and method for providing client identifying information to a server
US8458467B2 (en)2005-06-212013-06-04Cisco Technology, Inc.Method and apparatus for adaptive application message payload content transformation in a network infrastructure element
US7634564B2 (en)2004-11-182009-12-15Nokia CorporationSystems and methods for invoking a service from a plurality of event servers in a network
US20070022479A1 (en)2005-07-212007-01-25Somsubhra SikdarNetwork interface and firewall device
US7539132B2 (en)2005-01-212009-05-26At&T Intellectual Property Ii, L.P.Methods, systems, and devices for determining COS level
US20060190997A1 (en)2005-02-222006-08-24Mahajani Amol VMethod and system for transparent in-line protection of an electronic communications network
US20060187901A1 (en)2005-02-232006-08-24Lucent Technologies Inc.Concurrent dual-state proxy server, method of providing a proxy and SIP network employing the same
US8533473B2 (en)2005-03-042013-09-10Oracle America, Inc.Method and apparatus for reducing bandwidth usage in secure transactions
US20060206586A1 (en)2005-03-092006-09-14Yibei LingMethod, apparatus and system for a location-based uniform resource locator
JP4413965B2 (en)2005-03-172010-02-10富士通株式会社 Load balancing communication device and load balancing management device
KR101141645B1 (en)2005-03-292012-05-17엘지전자 주식회사Method for Controlling Transmission of Data Block
US7606147B2 (en)2005-04-132009-10-20Zeugma Systems Inc.Application aware traffic shaping service node positioned between the access and core networks
US7990847B1 (en)2005-04-152011-08-02Cisco Technology, Inc.Method and system for managing servers in a server cluster
KR100642935B1 (en)2005-05-062006-11-10(주)아이디스 Name service system and method
JP4101251B2 (en)2005-05-242008-06-18富士通株式会社 Load distribution program, load distribution method, and load distribution apparatus
IES20050376A2 (en)2005-06-032006-08-09Asavie R & D LtdSecure network communication system and method
US20060277303A1 (en)2005-06-062006-12-07Nikhil HegdeMethod to improve response time when clients use network services
US7774402B2 (en)2005-06-292010-08-10Visa U.S.A.Adaptive gateway for switching transactions and data on unreliable networks using context-based rules
US7496566B2 (en)2005-08-032009-02-24Intenational Business Machines CorporationPriority based LDAP service publication mechanism
US8982778B2 (en)2005-09-192015-03-17Qualcomm IncorporatedPacket routing in a wireless communications environment
EP1770915A1 (en)2005-09-292007-04-04Matsushita Electric Industrial Co., Ltd.Policy control in the evolved system architecture
US20070086382A1 (en)2005-10-172007-04-19Vidya NarayananMethods of network access configuration in an IP network
JP4650203B2 (en)2005-10-202011-03-16株式会社日立製作所 Information system and management computer
US7606232B1 (en)2005-11-092009-10-20Juniper Networks, Inc.Dynamic virtual local area network (VLAN) interface configuration
US20070118881A1 (en)2005-11-182007-05-24Julian MitchellApplication control at a policy server
CN100461692C (en)2005-11-282009-02-11华为技术有限公司 Network device configuration system and method
US7694011B2 (en)2006-01-172010-04-06Cisco Technology, Inc.Techniques for load balancing over a cluster of subscriber-aware application servers
CN100452041C (en)2006-01-182009-01-14腾讯科技(深圳)有限公司Method and system for reading information at network resource site, and searching engine
US8149771B2 (en)2006-01-312012-04-03Roundbox, Inc.Reliable event broadcaster with multiplexing and bandwidth control functions
US8116312B2 (en)2006-02-082012-02-14Solarflare Communications, Inc.Method and apparatus for multicast packet reception
US7492766B2 (en)2006-02-222009-02-17Juniper Networks, Inc.Dynamic building of VLAN interfaces based on subscriber information strings
US7808994B1 (en)2006-02-222010-10-05Juniper Networks, Inc.Forwarding traffic to VLAN interfaces built based on subscriber information strings
US8832247B2 (en)2006-03-242014-09-09Blue Coat Systems, Inc.Methods and systems for caching content at multiple levels
JP5108244B2 (en)2006-03-302012-12-26株式会社エヌ・ティ・ティ・ドコモ Communication terminal and retransmission control method
US8170572B2 (en)2006-04-142012-05-01Qualcomm IncorporatedMethods and apparatus for supporting quality of service in communication systems
US7907970B2 (en)2006-04-142011-03-15Qualcomm IncorporatedProviding quality of service for various traffic flows in a communications environment
US8539075B2 (en)2006-04-212013-09-17International Business Machines CorporationOn-demand global server load balancing system and method of use
US7733781B2 (en)2006-04-242010-06-08Broadcom CorporationDistributed congestion avoidance in a network switching system
US7680478B2 (en)2006-05-042010-03-16Telefonaktiebolaget Lm Ericsson (Publ)Inactivity monitoring for different traffic or service classifications
EP2076874A4 (en)2006-05-132011-03-09Sap Ag DERIVED CONSISTENT SET OF INTERFACES DERIVED FROM A BUSINESS OBJECT MODEL
KR100830413B1 (en)2006-05-252008-05-20(주)씨디네트웍스 Server access system for clients and load balancing network system including the same
US20070283429A1 (en)2006-05-302007-12-06A10 Networks Inc.Sequence number based TCP session proxy
GB0611249D0 (en)2006-06-072006-07-19Nokia CorpCommunication system
US20070288247A1 (en)2006-06-112007-12-13Michael MackayDigital life server
US20070294209A1 (en)2006-06-202007-12-20Lyle StrubCommunication network application activity monitoring and control
EP2060087A1 (en)2006-07-032009-05-20Telefonaktiebolaget L M Ericsson (Publ)Topology hiding of mobile agents
US20080016161A1 (en)2006-07-142008-01-17George TsirtsisMethods and apparatus for using electronic envelopes to configure parameters
US7970934B1 (en)2006-07-312011-06-28Google Inc.Detecting events of interest
EP1885096B1 (en)2006-08-012012-07-04Alcatel LucentApplication session border element
JP4916809B2 (en)2006-08-042012-04-18日本電信電話株式会社 Load balancing control apparatus and method
US7580417B2 (en)2006-08-072009-08-25Cisco Technology, Inc.Method and apparatus for load balancing over virtual network links
US8332925B2 (en)2006-08-082012-12-11A10 Networks, Inc.System and method for distributed multi-processing security gateway
US8079077B2 (en)2006-08-082011-12-13A10 Networks, Inc.System and method for distributed multi-processing security gateway
JP4724629B2 (en)2006-09-142011-07-13富士通株式会社 Broadcast distribution system and broadcast distribution method
US8312507B2 (en)2006-10-172012-11-13A10 Networks, Inc.System and method to apply network traffic policy to an application session
US8584199B1 (en)2006-10-172013-11-12A10 Networks, Inc.System and method to apply a packet routing policy to an application session
US7716378B2 (en)2006-10-172010-05-11A10 Networks, Inc.System and method to associate a private user identity with a public user identity
JP4680866B2 (en)2006-10-312011-05-11株式会社日立製作所 Packet transfer device with gateway load balancing function
US8149807B2 (en)2006-11-012012-04-03Panasonic CorporationCommunication control method, communication system, home agent allocation server, and mobile node
US8584195B2 (en)2006-11-082013-11-12Mcafee, IncIdentities correlation infrastructure for passive network monitoring
CN101193089B (en)2006-11-202010-11-03阿里巴巴集团控股有限公司Stateful session system and its realization method
CN101094225B (en)2006-11-242011-05-11中兴通讯股份有限公司Network, system and method of differentiated security service
US7974286B2 (en)2006-12-042011-07-05International Business Machines CorporationReduced redundant security screening
WO2008078593A1 (en)2006-12-222008-07-03International Business Machines CorporationMessage hub, program, and method
US7992192B2 (en)2006-12-292011-08-02Ebay Inc.Alerting as to denial of service attacks
US9155118B2 (en)2007-01-222015-10-06Qualcomm IncorporatedMulti-link support for network based mobility management systems
US8548520B2 (en)2007-01-262013-10-01Wi-Lan Inc.Multiple network access system and method
US8379515B1 (en)2007-02-012013-02-19F5 Networks, Inc.TCP throughput control by imposing temporal delay
US8631147B2 (en)2007-03-122014-01-14Citrix Systems, Inc.Systems and methods for configuring policy bank invocations
CN100531098C (en)2007-03-132009-08-19华为技术有限公司Point-to-point network system and intercommunicating method for overlapped network node
US8352634B2 (en)2007-04-062013-01-08International Business Machines CorporationOn-demand propagation of routing information in distributed computing system
US7809002B2 (en)2007-04-162010-10-05Alcatel-Lucent Usa Inc.Method and apparatus for priority services management
US7743155B2 (en)2007-04-202010-06-22Array Networks, Inc.Active-active operation for a cluster of SSL virtual private network (VPN) devices with load distribution
US20080271130A1 (en)2007-04-302008-10-30Shankar RamamoorthyMinimizing client-side inconsistencies in a distributed virtual file system
US9143558B2 (en)2007-05-092015-09-22Radware, Ltd.Geographic resiliency and load balancing for SIP application services
US20080291911A1 (en)2007-05-212008-11-27Ist International, Inc.Method and apparatus for setting a TCP retransmission timer
US8191106B2 (en)2007-06-072012-05-29Alcatel LucentSystem and method of network access security policy management for multimodal device
US7743157B2 (en)2007-06-262010-06-22Sap AgSystem and method for switching between stateful and stateless communication modes
US20090024722A1 (en)2007-07-172009-01-22International Business Machines CorporationProxying availability indications in a failover configuration
US7992201B2 (en)2007-07-262011-08-02International Business Machines CorporationDynamic network tunnel endpoint selection
US8032632B2 (en)2007-08-142011-10-04Microsoft CorporationValidating change of name server
US9407693B2 (en)2007-10-032016-08-02Microsoft Technology Licensing, LlcNetwork routing of endpoints to content based on content swarms
JP4964735B2 (en)2007-10-242012-07-04株式会社日立製作所 Network system, management computer, and filter reconfiguration method
US8553537B2 (en)2007-11-092013-10-08International Business Machines CorporationSession-less load balancing of client traffic across servers in a server group
CN101163336B (en)2007-11-152010-06-16中兴通讯股份有限公司Method of implementing mobile phone terminal access authority authentication
CN101169785A (en)2007-11-212008-04-30浪潮电子信息产业股份有限公司 A Dynamic Load Balancing Method for Cluster Database System
CN101442425B (en)2007-11-222012-03-21华为技术有限公司 Gateway management method, device, and system
GB0723422D0 (en)2007-11-292008-01-09Level 5 Networks IncVirtualised receive side scaling
US8125908B2 (en)2007-12-042012-02-28Extrahop Networks, Inc.Adaptive network traffic classification using historical context
US8756340B2 (en)2007-12-202014-06-17Yahoo! Inc.DNS wildcard beaconing to determine client location and resolver load for global traffic load balancing
JP5296373B2 (en)2007-12-262013-09-25インターナショナル・ビジネス・マシーンズ・コーポレーション Technology that provides processing time in advance
US9100268B2 (en)2008-02-272015-08-04Alcatel LucentApplication-aware MPLS tunnel selection
US7930427B2 (en)2008-03-032011-04-19Microsoft CorporationClient-side load balancing
JP2009211343A (en)2008-03-042009-09-17Kddi CorpServer device and communication system
US8185628B2 (en)2008-03-072012-05-22At&T Mobility Ii LlcEnhanced policy capabilities for mobile data services
CN101247349A (en)2008-03-132008-08-20华耀环宇科技(北京)有限公司Network flux fast distribution method
CN101547189B (en)2008-03-282011-08-10华为技术有限公司Method, system and device for establishing CoD service
US8151019B1 (en)2008-04-222012-04-03Lockheed Martin CorporationAdaptive network traffic shaper
US7886021B2 (en)2008-04-282011-02-08Oracle America, Inc.System and method for programmatic management of distributed computing resources
CN101261644A (en)2008-04-302008-09-10杭州华三通信技术有限公司Method and device for accessing united resource positioning symbol database
CN101577661B (en)2008-05-092013-09-11华为技术有限公司Method and equipment for switching path
US8345691B2 (en)2008-05-152013-01-01Cellco PartnershipScheduling with quality of service support in wireless system
US8352594B2 (en)2008-06-122013-01-08Panasonic CorporationNetwork monitoring device, bus system monitoring device, method and program
US7990855B2 (en)2008-07-112011-08-02Alcatel-Lucent Usa Inc.Method and system for joint reverse link access and traffic channel radio frequency overload control
CN101631065B (en)2008-07-162012-04-18华为技术有限公司Method and device for controlling congestion of wireless multi-hop network
US8271652B2 (en)2008-07-242012-09-18Netapp, Inc.Load-derived probability-based domain name service in a network storage cluster
US7890632B2 (en)2008-08-112011-02-15International Business Machines CorporationLoad balancing using replication delay
US8307422B2 (en)2008-08-142012-11-06Juniper Networks, Inc.Routing device having integrated MPLS-aware firewall
JP5571667B2 (en)2008-08-182014-08-13エフ5 ネットワークス、インコーポレイテッド How to upgrade a network traffic management device while maintaining availability
JP5211987B2 (en)2008-09-262013-06-12ブラザー工業株式会社 Terminal device and time adjustment method thereof
JP5557840B2 (en)2008-10-032014-07-23テレフオンアクチーボラゲット エル エム エリクソン(パブル) Distributed database monitoring mechanism
US7958247B2 (en)2008-10-142011-06-07Hewlett-Packard Development Company, L.P.HTTP push to simulate server-initiated sessions
US8266288B2 (en)2008-10-232012-09-11International Business Machines CorporationDynamic expiration of domain name service entries
US20100106854A1 (en)2008-10-292010-04-29Hostway CorporationSystem and method for controlling non-existing domain traffic
JP2010108409A (en)2008-10-312010-05-13Hitachi LtdStorage management method and management server
US8359402B2 (en)2008-11-192013-01-22Seachange International, Inc.Intercept device for providing content
US8260926B2 (en)2008-11-252012-09-04Citrix Systems, Inc.Systems and methods for GSLB site persistence
US8125911B2 (en)2008-11-262012-02-28Cisco Technology, Inc.First-hop domain reliability measurement and load balancing in a computer network
US8844018B2 (en)2008-12-182014-09-23At&T Intellectual Property I, L.P.Methods and apparatus to enhance security in residential networks
US20100205310A1 (en)2009-02-122010-08-12Yaniv AltshulerSystem and method for dynamically optimizing tcp window size
US9112871B2 (en)2009-02-172015-08-18Core Wireless Licensing S.A.R.LMethod and apparatus for providing shared services
US8364163B2 (en)2009-02-232013-01-29Research In Motion LimitedMethod, system and apparatus for connecting a plurality of client machines to a plurality of servers
US20100228819A1 (en)2009-03-052010-09-09Yottaa IncSystem and method for performance acceleration, data protection, disaster recovery and on-demand scaling of computer applications
CN101834777B (en)2009-03-112015-07-29瞻博网络公司The HTTP of dialogue-based high-speed cache accelerates
EP2234333B1 (en)2009-03-232015-07-15Corvil LimitedSystem and method for estimation of round trip times within a tcp based data network
US8259726B2 (en)2009-05-282012-09-04Force10 Networks, Inc.Method and apparatus for forwarding table reduction
US8296434B1 (en)2009-05-282012-10-23Amazon Technologies, Inc.Providing dynamically scaling computing load balancing
US8266088B2 (en)2009-06-092012-09-11Cisco Technology, Inc.Tracking policy decisions in a network
WO2010142335A1 (en)2009-06-102010-12-16Telefonaktiebolaget Lm Ericsson (Publ)Performance monitoring in a communication network
US8060579B2 (en)2009-06-122011-11-15Yahoo! Inc.User location dependent DNS lookup
US8289975B2 (en)2009-06-222012-10-16Citrix Systems, Inc.Systems and methods for handling a multi-connection protocol between a client and server traversing a multi-core system
US8863111B2 (en)2009-06-262014-10-14Oracle International CorporationSystem and method for providing a production upgrade of components within a multiprotocol gateway
US9137301B1 (en)2009-06-302015-09-15Amazon Technologies, Inc.Client based opportunistic routing
US9749387B2 (en)2009-08-132017-08-29Sap SeTransparently stateful execution of stateless applications
US9960967B2 (en)2009-10-212018-05-01A10 Networks, Inc.Determining an application delivery server based on geo-location information
WO2011049135A1 (en)2009-10-232011-04-28日本電気株式会社Network system, control method thereof, and controller
JP5378946B2 (en)2009-10-262013-12-25株式会社日立製作所 Server management apparatus and server management method
US8370920B2 (en)2009-10-282013-02-05Aunigma Network Security Corp.System and method for providing unified transport and security protocols
US8311014B2 (en)2009-11-062012-11-13Telefonaktiebolaget L M Ericsson (Publ)Virtual care-of address for mobile IP (internet protocol)
CN102714657B (en)2009-11-252015-02-04思杰系统有限公司Systems and methods for client IP address insertion via TCP options
US8190736B2 (en)2009-12-162012-05-29Quantum CorporationReducing messaging in a client-server system
US8335853B2 (en)2009-12-172012-12-18Sonus Networks, Inc.Transparent recovery of transport connections using packet translation techniques
US8255528B2 (en)2009-12-232012-08-28Citrix Systems, Inc.Systems and methods for GSLB spillover
US8285298B2 (en)2009-12-232012-10-09At&T Mobility Ii LlcChromatic scheduler for network traffic with disparate service requirements
US8224971B1 (en)2009-12-282012-07-17Amazon Technologies, Inc.Using virtual networking devices and routing information to initiate external actions
US7991859B1 (en)2009-12-282011-08-02Amazon Technologies, Inc.Using virtual networking devices to connect managed computer networks
WO2011079381A1 (en)2009-12-312011-07-07Bce Inc.Method and system for increasing performance of transmission control protocol sessions in data networks
US8789061B2 (en)2010-02-012014-07-22Ca, Inc.System and method for datacenter power management
US8301786B2 (en)2010-02-102012-10-30Cisco Technology, Inc.Application session control using packet inspection
US8804513B2 (en)2010-02-252014-08-12The Trustees Of Columbia University In The City Of New YorkMethods and systems for controlling SIP overload
JP5557590B2 (en)2010-05-062014-07-23株式会社日立製作所 Load balancing apparatus and system
US8533337B2 (en)2010-05-062013-09-10Citrix Systems, Inc.Continuous upgrading of computers in a load balanced environment
US8499093B2 (en)2010-05-142013-07-30Extreme Networks, Inc.Methods, systems, and computer readable media for stateless load balancing of network traffic flows
US20110289496A1 (en)2010-05-182011-11-24North End Technologies, Inc.Method & apparatus for load balancing software update across a plurality of publish/subscribe capable client devices
US8539068B2 (en)2010-06-072013-09-17Salesforce.Com, Inc.Methods and systems for providing customized domain messages
US20110307541A1 (en)2010-06-102011-12-15Microsoft CorporationServer load balancing and draining in enhanced communication systems
US9680750B2 (en)2010-07-062017-06-13Nicira, Inc.Use of tunnels to hide network addresses
US8837493B2 (en)2010-07-062014-09-16Nicira, Inc.Distributed network control apparatus and method
US9363312B2 (en)2010-07-282016-06-07International Business Machines CorporationTransparent header modification for reducing serving load based on current and projected usage
US8520672B2 (en)2010-07-292013-08-27Cisco Technology, Inc.Packet switching device using results determined by an application node
US8675488B1 (en)2010-09-072014-03-18Juniper Networks, Inc.Subscriber-based network traffic management
US8949410B2 (en)2010-09-102015-02-03Cisco Technology, Inc.Server load balancer scaling for virtual servers
US9215275B2 (en)2010-09-302015-12-15A10 Networks, Inc.System and method to balance servers based on server load status
US20120084460A1 (en)2010-10-042012-04-05Openwave Systems Inc.Method and system for dynamic traffic steering
US9237194B2 (en)2010-11-052016-01-12Verizon Patent And Licensing Inc.Load balancer and firewall self-provisioning system
US8533285B2 (en)2010-12-012013-09-10Cisco Technology, Inc.Directing data flows in data centers with clustering services
US9609052B2 (en)2010-12-022017-03-28A10 Networks, Inc.Distributing application traffic to servers based on dynamic service response time
EP2649858B1 (en)2010-12-072018-09-19Telefonaktiebolaget LM Ericsson (publ)Method for enabling traffic acceleration in a mobile telecommunication network
US9152293B2 (en)2010-12-092015-10-06Verizon Patent And Licensing Inc.Server IP addressing in a computing-on-demand system
US8965957B2 (en)2010-12-152015-02-24Sap SeService delivery framework
US8755283B2 (en)2010-12-172014-06-17Microsoft CorporationSynchronizing state among load balancer components
WO2012092269A1 (en)2010-12-292012-07-05Citrix Systems, Inc.Systems and methods for policy based integration to horizontally deployed wan optimization appliances
US8477730B2 (en)2011-01-042013-07-02Cisco Technology, Inc.Distributed load management on network devices
JP5948345B2 (en)2011-01-112016-07-06エイ10 ネットワークス インコーポレイテッドA10 Networks, Inc. Virtual application delivery chassis system
JP5743589B2 (en)2011-02-182015-07-01キヤノン株式会社 Web service system, server management apparatus, and Web service providing method
US8732267B2 (en)2011-03-152014-05-20Cisco Technology, Inc.Placement of a cloud service using network topology and infrastructure performance
CN102143075B (en)2011-03-282013-08-07中国人民解放军国防科学技术大学Method and system for achieving load balance
KR101246889B1 (en)2011-04-152013-03-25서강대학교산학협력단Method and system of controlling data transfer rate for downward vertical handover in overlayed network environment
US9397949B2 (en)2011-04-182016-07-19Nec CorporationTerminal, control device, communication method, communication system, communication module, program, and information processing device
US9154577B2 (en)2011-06-062015-10-06A10 Networks, Inc.Sychronization of configuration file of virtual application distribution chassis
US8804620B2 (en)2011-10-042014-08-12Juniper Networks, Inc.Methods and apparatus for enforcing a common user policy within a network
US8885463B1 (en)2011-10-172014-11-11Juniper Networks, Inc.Path computation element communication protocol (PCEP) extensions for stateful label switched path management
US8897154B2 (en)2011-10-242014-11-25A10 Networks, Inc.Combining stateless and stateful server load balancing
US8918501B2 (en)2011-11-102014-12-23Microsoft CorporationPattern-based computational health and configuration monitoring
EP2749118B1 (en)2011-11-232018-01-10Telefonaktiebolaget LM Ericsson (publ)Improving tcp performance in a cellular network
US8660006B2 (en)2011-11-292014-02-25Hughes Network Systems, LlcMethod and system for traffic management and resource allocation on a shared access network
US9386088B2 (en)2011-11-292016-07-05A10 Networks, Inc.Accelerating service processing using fast path TCP
US9094364B2 (en)2011-12-232015-07-28A10 Networks, Inc.Methods to manage services over a service gateway
US8874790B2 (en)2011-12-302014-10-28Verisign, Inc.DNS package in a partitioned network
US9380635B2 (en)2012-01-092016-06-28Google Technology Holdings LLCDynamic TCP layer optimization for real-time field performance
JP2013152095A (en)2012-01-242013-08-08Sony CorpTime control device, time control method and program
US10044582B2 (en)2012-01-282018-08-07A10 Networks, Inc.Generating secure name records
KR101348739B1 (en)2012-02-222014-01-08유대영LED Lighting apparatus and LED Lighting system having the same
US9386128B2 (en)2012-03-232016-07-05Qualcomm IncorporatedDelay based active queue management for uplink traffic in user equipment
WO2013158098A1 (en)2012-04-192013-10-24Empire Technology Development LlcMigration in place
US9027129B1 (en)2012-04-302015-05-05Brocade Communications Systems, Inc.Techniques for protecting against denial of service attacks
US8782221B2 (en)2012-07-052014-07-15A10 Networks, Inc.Method to allocate buffer for TCP proxy session based on dynamic network conditions
US9641650B2 (en)2012-08-232017-05-02Telefonaktiebolaget Lm Ericsson (Publ)TCP proxy server
US9106561B2 (en)2012-12-062015-08-11A10 Networks, Inc.Configuration of a virtual service network
KR101692751B1 (en)2012-09-252017-01-04에이10 네트워크스, 인코포레이티드Load distribution in data networks
US10002141B2 (en)2012-09-252018-06-19A10 Networks, Inc.Distributed database in software driven networks
US9843484B2 (en)2012-09-252017-12-12A10 Networks, Inc.Graceful scaling in software driven networks
US10021174B2 (en)2012-09-252018-07-10A10 Networks, Inc.Distributing service sessions
US9338225B2 (en)2012-12-062016-05-10A10 Networks, Inc.Forwarding policies on a virtual service network
US9531846B2 (en)2013-01-232016-12-27A10 Networks, Inc.Reducing buffer usage for TCP proxy session based on delayed acknowledgement
US9900252B2 (en)2013-03-082018-02-20A10 Networks, Inc.Application delivery controller and global server load balancer
US20140258465A1 (en)2013-03-112014-09-11Cisco Technology, Inc.Identification of originating ip address and client port connection to a web server via a proxy server
WO2014144837A1 (en)2013-03-152014-09-18A10 Networks, Inc.Processing data packets using a policy based network path
US9645811B2 (en)2013-04-012017-05-09Oc Acquisition LlcFault tolerance for a distributed computing system
US10027761B2 (en)2013-05-032018-07-17A10 Networks, Inc.Facilitating a secure 3 party network session by a network device
US10038693B2 (en)2013-05-032018-07-31A10 Networks, Inc.Facilitating secure network traffic by an application delivery controller
US9225638B2 (en)2013-05-092015-12-29Vmware, Inc.Method and system for service switching using service tags
US9319476B2 (en)2013-05-282016-04-19Verizon Patent And Licensing Inc.Resilient TCP splicing for proxy services
US9461967B2 (en)2013-07-182016-10-04Palo Alto Networks, Inc.Packet classification for network routing
US10230770B2 (en)2013-12-022019-03-12A10 Networks, Inc.Network proxy layer for policy-based application proxies
US9825808B2 (en)2014-02-242017-11-21Red Hat Israel, Ltd.Network configuration via abstraction components and standard commands
US9942152B2 (en)2014-03-252018-04-10A10 Networks, Inc.Forwarding data packets using a service-based forwarding policy
US9942162B2 (en)2014-03-312018-04-10A10 Networks, Inc.Active application response delay time
US9806943B2 (en)2014-04-242017-10-31A10 Networks, Inc.Enabling planned upgrade/downgrade of network devices without impacting network sessions
US9917851B2 (en)2014-04-282018-03-13Sophos LimitedIntrusion detection using a heartbeat
US9906422B2 (en)2014-05-162018-02-27A10 Networks, Inc.Distributed system to determine a server's health
US10129122B2 (en)2014-06-032018-11-13A10 Networks, Inc.User defined objects for network devices
US9986061B2 (en)2014-06-032018-05-29A10 Networks, Inc.Programming a data network device using user defined scripts
US10581976B2 (en)2015-08-122020-03-03A10 Networks, Inc.Transmission control of protocol state exchange for dynamic stateful service insertion
US10243791B2 (en)2015-08-132019-03-26A10 Networks, Inc.Automated adjustment of subscriber policies

Patent Citations (33)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US5958053A (en)*1997-01-301999-09-28At&T Corp.Communications protocol with improved security
US6047268A (en)*1997-11-042000-04-04A.T.&T. CorporationMethod and apparatus for billing for transactions conducted over the internet
US6321338B1 (en)*1998-11-092001-11-20Sri InternationalNetwork surveillance
US20010042200A1 (en)2000-05-122001-11-15International Business MachinesMethods and systems for defeating TCP SYN flooding attacks
US6772334B1 (en)*2000-08-312004-08-03Networks Associates, Inc.System and method for preventing a spoofed denial of service attack in a networked computing environment
US20020103916A1 (en)*2000-09-072002-08-01Benjie ChenThwarting connection-based denial of service attacks
US20120240185A1 (en)*2000-09-252012-09-20Harsh KapoorSystems and methods for processing data flows
US6779033B1 (en)*2000-12-282004-08-17Networks Associates Technology, Inc.System and method for transacting a validated application session in a networked computing environment
US7301899B2 (en)*2001-01-312007-11-27Comverse Ltd.Prevention of bandwidth congestion in a denial of service or other internet-based attack
US7370353B2 (en)*2001-11-052008-05-06Cisco Technology, Inc.System and method for managing dynamic network sessions
US7512980B2 (en)*2001-11-302009-03-31Lancope, Inc.Packet sampling flow-based detection of network intrusions
US20030135625A1 (en)*2002-01-152003-07-17International Business Machines CorporationBlended SYN cookies
US7058718B2 (en)*2002-01-152006-06-06International Business Machines CorporationBlended SYN cookies
US7254133B2 (en)2002-07-152007-08-07Intel CorporationPrevention of denial of service attacks
US7430755B1 (en)*2002-09-032008-09-30Fs Networks, Inc.Method and system for providing persistence in a secure network access
US7506360B1 (en)*2002-10-012009-03-17Mirage Networks, Inc.Tracking communication for determining device states
US7552323B2 (en)*2002-11-182009-06-23Liquidware Labs, Inc.System, apparatuses, methods, and computer-readable media using identification data in packet communications
US7269850B2 (en)*2002-12-312007-09-11Intel CorporationSystems and methods for detecting and tracing denial of service attacks
US7979694B2 (en)2003-03-032011-07-12Cisco Technology, Inc.Using TCP to authenticate IP source addresses
US7733866B2 (en)2004-04-152010-06-08Qualcomm IncorporatedPacket concatenation in wireless networks
US8559437B2 (en)2004-04-152013-10-15Qualcomm IncorporatedPacket concatenation in wireless networks
US20050240989A1 (en)*2004-04-232005-10-27Seoul National University Industry FoundationMethod of sharing state between stateful inspection firewalls on mep network
US7391725B2 (en)*2004-05-182008-06-24Christian HuitemaSystem and method for defeating SYN attacks
US20060023721A1 (en)*2004-07-292006-02-02Ntt Docomo, Inc.Server device, method for controlling a server device, and method for establishing a connection using the server device
US20060069804A1 (en)*2004-08-252006-03-30Ntt Docomo, Inc.Server device, client device, and process execution method
US20060230129A1 (en)2005-02-042006-10-12Nokia CorporationApparatus, method and computer program product to reduce TCP flooding attacks while conserving wireless network bandwidth
US7826487B1 (en)*2005-05-092010-11-02F5 Network, IncCoalescing acknowledgement responses to improve network communications
US20060280121A1 (en)*2005-06-132006-12-14Fujitsu LimitedFrame-transfer control device, DoS-attack preventing device, and DoS-attack preventing system
US20070019543A1 (en)*2005-07-062007-01-25Fortinet, Inc.Systems and methods for detecting and preventing flooding attacks in a network environment
US7610622B2 (en)2006-02-062009-10-27Cisco Technology, Inc.Supporting options in a communication session using a TCP cookie
US7675854B2 (en)*2006-02-212010-03-09A10 Networks, Inc.System and method for an adaptive TCP SYN cookie with time validation
USRE44701E1 (en)*2006-02-212014-01-14A10 Networks, Inc.System and method for an adaptive TCP SYN cookie with time validation
USRE47296E1 (en)*2006-02-212019-03-12A10 Networks, Inc.System and method for an adaptive TCP SYN cookie with time validation

Also Published As

Publication numberPublication date
US20070195792A1 (en)2007-08-23
USRE47296E1 (en)2019-03-12
US7675854B2 (en)2010-03-09
USRE44701E1 (en)2014-01-14

Similar Documents

PublicationPublication DateTitle
USRE49053E1 (en)System and method for an adaptive TCP SYN cookie with time validation
KR100431231B1 (en)Method and system for defeating tcp syn flooding attacks
CN101764799B (en) Establish a connection using a server capability profile
JP4271451B2 (en) Method and apparatus for fragmenting and reassembling Internet key exchange data packets
US8984268B2 (en)Encrypted record transmission
US7584352B2 (en)Protection against denial of service attacks
US8418242B2 (en)Method, system, and device for negotiating SA on IPv6 network
US20070283429A1 (en)Sequence number based TCP session proxy
US20120227088A1 (en)Method for authenticating communication traffic, communication system and protective apparatus
EP3208989A1 (en)Secure shell (ssh2) protocol data collection method and device
US10911581B2 (en)Packet parsing method and device
US8683572B1 (en)Method and apparatus for providing continuous user verification in a packet-based network
WO2010000171A1 (en)Communication establishing method, system and device
CN110392128A (en) Method and system for providing quasi-addressless IPv6 open world wide web service
Luo et al.A keyed-hashing based self-synchronization mechanism for port address hopping communication
CN109067774B (en)Security access system based on trust token and security access method thereof
CN102427452B (en)Synchronize (SYN) message transmitting method and device and network equipment
JP4183664B2 (en) Authentication method, server computer, client computer, and program
US8364949B1 (en)Authentication for TCP-based routing and management protocols
CN110417804B (en)Bidirectional identity authentication encryption communication method and system suitable for single-chip microcomputer implementation
Kim et al.Efficient design for secure multipath TCP against eavesdropper in initial handshake
Fung et al.A denial-of-service resistant public-key authentication and key establishment protocol
CN107579984B (en) A method for establishing a secure communication link for network layer
CN116389169B (en)Method for avoiding disorder and fragmentation of data packets of national security IPSecVPN gateway
US20250007910A1 (en)Network apparatus and network authentication method thereof

Legal Events

DateCodeTitleDescription
ASAssignment

Owner name:A10 NETWORKS, INC., CALIFORNIA

Free format text:ASSIGNMENT OF ASSIGNORS INTEREST;ASSIGNORS:CHEN, LEE;SZETO, RONALD WAI LUN;HWANG, SHIH-TSUNG;REEL/FRAME:047994/0613

Effective date:20060217

FEPPFee payment procedure

Free format text:ENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: BIG.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITY


[8]ページ先頭

©2009-2025 Movatter.jp