US2015334089A1PendingUtilityA1

Managing mac moves with secure port groups

Assignee: HEWLETT PACKARD DEVELOPMENT COPriority: Nov 1, 2010Filed: Jul 29, 2015Published: Nov 19, 2015
Est. expiryNov 1, 2030(~4.3 yrs left)· nominal 20-yr term from priority
H04L 45/02H04L 45/745H04L 12/467H04L 63/104H04L 63/0236
35
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method includes determining that a source MAC address is associated with a particular port that is a member of a secure group ( 34, 36 ) of ports ( 1 - 14 ) of a network edge device ( 20, 50 ). A move of the source MAC address to any port of the network edge device ( 20, 50 ) that is a member of the secure group of ports is allowed. Moves of the MAC address to any port of the network edge device ( 20, 50 ) that is outside the secure group of ports are disallowed. An apparatus and at least one computer-readable medium for implementing the method also are described.

Claims

exact text as granted — not AI-modified
1 - 15 . (canceled) 
     
     
         16 . A method, comprising:
 determining an associated port of a source address of a received packet is different than a port on which the packet is received;   processing the packet if the associated port and the port on which the packet is received are members of a secure port group; and   if the associated port is a member of the secure port group and the port on which the packet is received is not a member of the secure port group, initiating a security action.   
     
     
         17 . The method of claim  15 , wherein determining an associated port of a source address of a received packet is different than a port on which the packet is received comprises:
 receiving a packet on the port;   performing a lookup in an address table based on the source address to determine the associated port; and   determining whether the port on which the packet is received and the associated packet determined from the lookup are the same or different.   
     
     
         18 . The method of  claim 17 , comprising:
 if the port on which the packet is received and the associated port determined from the lookup are the same, processing the packet.   
     
     
         19 . The method of  claim 16 , comprising:
 if the associated port is not a member of the secure group, processing the packet.   
     
     
         20 . The method of  claim 16 , wherein the port on which the packet is receiving is on a network device, and the method comprises:
 allowing a move of the source MAC address to any port of the network device that is a member of the secure group; and   disallowing moves of the source MAC address to any port of the network edge device that is outside the secure group.   
     
     
         21 . The method of  claim 16 , comprising:
 receiving the packet on the port, wherein the port is on a network edge device.   
     
     
         22 . The method of  claim 16 , wherein the source address is a MAC address. 
     
     
         23 . A network device comprising:
 a plurality of ports; and   a hardware controller to:
 determine an associated port of a source address of a packet received on a port of the plurality of ports based on an address table; 
 determine whether the associated port is different than the port on which the packet is received; 
 processing the packet if the associated port and the port on which the packet is received are members of a secure port group; and 
 if the associated port is a member of the secure port group and the port on which the packet is received is not a member of the secure port group, initiating a security action. 
   
     
     
         24 . The network device of  claim 23 , comprising:
 a storage device storing the address table, and the controller is to perform a lookup on the address table based on the source address to determine the associated port.   
     
     
         25 . The network device of  claim 23 , wherein the controller is to determine if the port on which the packet is received and the associated port are the same, and if the ports are the same, the packet is processed by the network device. 
     
     
         26 . The network device of  claim 23 , wherein the controller is to determine if the associated port is not a member of the secure group, and if the associated port is not a member of the secure group, the packet is processed by the network device processing the packet. 
     
     
         27 . The network device of  claim 23 , wherein the controller is to:
 allow a move of the source MAC address to any port of the network device that is a member of the secure group; and   disallow a move of the source MAC address to any port of the network edge device that is outside the secure group.   
     
     
         28 . The network device of  claim 23 , wherein the secure group comprises a subset of the plurality of ports. 
     
     
         29 . The network device of  claim 23 , wherein the network device is a network edge device. 
     
     
         30 . A non-transitory computer readable medium storing machine readable instructions executable by a hardware controller to:
 determine an associated port of a source address of a received packet is different than a port on which the packet is received;   process the packet if the associated port and the port on which the packet is received are members of a secure port group; and   if the associated port is a member of the secure port group and the port on which the packet is received is not a member of the secure port group, initiate a security action.   
     
     
         31 . The non-transitory computer-readable medium of  claim 30 , wherein the security action comprises at least one of filtering the packet and issuing security warning. 
     
     
         32 . The non-transitory computer-readable medium of  claim 30 , wherein the security action comprises at least one of filtering the packet and issuing security warning. 
     
     
         33 . The non-transitory computer-readable medium of  claim 30 , wherein the machine readable instructions are executable by the hardware controller to process the packet if the port on which the packet is received and the associated port determined are the same. 
     
     
         34 . The non-transitory computer-readable medium of  claim 30 , wherein the machine readable instructions are executable by the hardware controller to process the packet if the associated port is not a member of the secure group. 
     
     
         35 . The non-transitory computer-readable medium of  claim 30 , the machine readable instructions are executable by the hardware controller to:
 allow a move of the source MAC address to any port of the network device that is a member of the secure group; and   disallow a move of the source MAC address to any port of the network edge device that is outside the secure group.

Join the waitlist — get patent alerts

Track US2015334089A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.