Invention Grant
- Patent Title: Securing a managed forwarding element that operates within a data compute node
-
Application No.: US14954497Application Date: 2015-11-30
-
Publication No.: US10078526B2Publication Date: 2018-09-18
- Inventor: Donghai Han
- Applicant: Nicira, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: NICIRA, INC.
- Current Assignee: NICIRA, INC.
- Current Assignee Address: US CA Palo Alto
- Agency: Adeli LLP
- Main IPC: G06F9/455
- IPC: G06F9/455 ; G06F12/1009 ; H04L12/46 ; H04L12/741 ; H04L29/08 ; H04L29/06

Abstract:
Some embodiments provide a method for securing a managed forwarding element (MFE) that operates within a data compute node (DCN) executing in a host machine. The method receives, from the MFE, a message to increase a local counter value by a first number when the MFE sends the first number of packets to a network interface controller (NIC). The method receives, from the NIC, a second number that indicates a total number of packets that the NIC has received from the MFE. The method compares the received second number with the local counter value after increasing the local counter value by the first number. The method determines that the DCN is under a malicious attack when the local counter value does not match the second number.
Public/Granted literature
- US20170126726A1 SECURING A MANAGED FORWARDING ELEMENT THAT OPERATES WITHIN A DATA COMPUTE NODE Public/Granted day:2017-05-04
Information query