US2017374021A1PendingUtilityA1

Role based router functionality

Assignee: CABLE TELEVISION LABORATORIES INCPriority: Oct 11, 2012Filed: Sep 11, 2017Published: Dec 28, 2017
Est. expiryOct 11, 2032(~6.2 yrs left)· nominal 20-yr term from priority
H04L 49/00H04L 63/02H04L 41/08H04L 61/2015H04L 61/5014H04L 61/5038H04L 2101/668H04L 2101/604H04L 61/2535
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Configuration of fireball functionality for rooters operating within a multi-router network is contemplated. The firewall functionality configured for one or more of the routers may be based router positioning within the multi-router network. The firewall functionality may be automatically selected according to the router positioning in order to facilitate dynamic and/or adaptive router configuring.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for automatically configuring firewall functionality within a multi-router network, the multi-router network including a plurality of routers arranged in a logical hierarchy, the method comprising: automatically determining a first position within the logical hierarchy for a first router of the plurality of routers, the first position being one of a plurality of positions defined within the multi-router network according to connections between the plurality of routers; and automatically configuring firewall functionality for the first router as a function of the first position. 
     
     
         2 . The method  claim 1  further comprising determining the first position to be one of an edge position and an internal position, the edge position and the internal position being defined within the plurality of positions, the edge position defining the first router as an edge router (ER) within the multi-router network and the internal position defining the first router as an internal router (IR) within the multi-router network. 
     
     
         3 . The method of  claim 2  further comprising determining the first position automatically from addressing related information communicated to the first router over the multi-router network. 
     
     
         4 . The method  claim 2  further comprising configuring the firewall functionality for the first router according to an edge security profile if the first router is determined to be in the edge position and according to an internal security profile if the first router is determined to be in the internal position. 
     
     
         5 . The method of  claim 4  further comprising: determining the first router to have moved from the first position to a second position, the first position being associated with the edge position and the second position being associated with the internal position; re-configuring firewall functionality for the first router from the edge security profile to the internal security profile after determining the first router to have moved from the first position to the second position. 
     
     
         6 . The method  claim 4  further comprising: configuring the firewall functionality for the first router according to the edge security profile by configuring the first router to implement one of more edge security rules, the edge security rules being specified within the edge security profile; and configuring the firewall functionality for the first router according to the internal security profile by configuring the first router to implement one of more internal security rules, the internal security rules being specified within the internal security profile. 
     
     
         7 . The method of  claim 6  further comprising defining one or more of the edge security rules to include: a first edge rule for denying most incoming traffic on an up interface except for DHCP, Neighbor Discovery, ICMP, or pre-established TCP, UDP, and/or multicast streams; a second edge rule for blocking outgoing Port Control Protocol (PCP) and UPnP IGD messages on the up interface, except for a default list for peer-to-peer, SIP/VoIP, gaming, and/or http; a third edge rules for blocking site-scoped multicast messages from being sent to the up interface, while IRs forward site-scoped multicast messages passing a Reverse Path Forwarding check out all interfaces. 
     
     
         8 . The method of  claim 6  further comprising defining one or more of the internal security rules to include: a first internal rule for enabling the first router to act as a UPnP/PCP gateway; a second internal rule for enabling simple security; a third internal rule for providing intrusion detection and/or intrusion protection; and a fourth internal rule for filtering PCP messages from the multi-router network to a special security zone network. 
     
     
         9 . The method of  claim 6  further comprising defining at least one of: defining a majority of the edge security rules to be different from the internal security rules; and defining all of the edge security rules to be different from the internal security rules. 
     
     
         10 . The method of  claim 2  further comprising configuring firewall functionality for the first router according to edge instructions associated with the edge security profile and internal instructions associated with the internal security profile, both of the edge instructions and the internal instructions being stored within a memory of the first router. 
     
     
         11 . The method of  claim 2  further comprising configuring the firewall functionality for the first router by one of enabling and disabling a stateful firewall of the first router, including enabling the stateful firewall if the first router is determined to be in the edge position and disabling the stateful firewall if the router is determined to be in the internal position. 
     
     
         12 . The method of  claim 2  further comprising configuring the firewall functionality for the first router by one of enabling and disabling a network address translator (NAT) of the first router, including enabling the NAT if the first router is determined to be in the edge position and disabling the NAT if the router is determined to be in the internal position. 
     
     
         13 . The method of  claim 2  further comprising: automatically determining a second position within the logical hierarchy for a second router of the plurality of routers, the second position being one of a plurality of positions defined within the multi-router network according to connections between the plurality of routers; determining the second position to be one of the edge position and the internal position; automatically configuring firewall functionality for the second router as a function of the second position, including configuring the firewall functionality for the second router according to the edge security profile if the second router is determined to be in the edge position and according to the internal security profile if the second router is determined to be in the internal position. 
     
     
         14 . The method of  claim 13  further comprising: preventing configuring firewall functionality for the first router and the second router in the event both of the first router and the second router are determined to be in the edge position; permitting configuring firewall functionality for the first router and the second router in the event both of the first router and the second router are determined to be in the internal position; and permitting configuring firewall functionality for the first router and the second router in the event one of the first router and the second router is determined to be in the edge position and the other one of the first router and the second router is determined to be in the internal position. 
     
     
         15 . A computer program product embedded in a non-transitory computer readable medium, the medium storing instructions sufficient for use with a processor to facilitate configuring firewall functionality for routers, the medium including instructions sufficient for: determining router positioning within a logical hierarchy of a multi-router network comprised of plurality of routers, the router positioning being determined to be one of an edge position and an internal position; and configuring use of firewall functionality according to an edge security profile when router positioning is determined to be the edge position and according to an internal security profile when router positioning is determined to be the internal position. 
     
     
         16 . The computer program product of  claim 15  wherein the medium includes instructions sufficient for enabling stateful firewall functionality if the router positioning corresponds with the edge position and for disabling stateful firewall functionality if the router positioning corresponds with the internal position. 
     
     
         17 . The computer program product of  claim 15  wherein the medium includes instructions sufficient for selecting at least one of a plurality of firewall functionality options defined within the internal security profile, the internal security profile including at least the following firewall functionality options: disabling filtering; implementing simple security and PCP; and implementing advanced security. 
     
     
         18 . The computer program product of  claim 15  wherein the medium includes instructions sufficient for determining router positioning as a function of messaging routed over the multi-router network without use of routing tables associated with a routing protocol. 
     
     
         19 . A router comprising: a plurality of interfaces configured for routing data packets, including at least one up interface and at least one down interface; a position detection module configured to detect a position of the router within a multi-router network; a profile selection module configured to selection a functionality profile from a plurality of functionality profiles based on the position determined with the position detection module; and a functionality controller configured to control packet passage between the interfaces according to the functionality profile selected with the profile selection module. 
     
     
         20 . The router of  claim 19  wherein: the position detection module is configured for determining the position to be one of an edge position and an internal position, the edge position defining the first router as an edge router (ER) within the multi-router network and the internal position defining the first router as an internal router (IR) within the multi-router network; and the profile selection module includes an edge profile and an internal profile, the edge profile for use with the functionality controller if the position is determined to be in the edge position and the internal security profile for use with the functionality controller if the position is determined to be in the internal position.

Join the waitlist — get patent alerts

Track US2017374021A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.