1461168002-0f11e89a-96ec-4d93-acac-d69313f67588

1. A method for reducing the false alarm rate of network intrusion detection systems, comprising:
receiving an alarm indicating a network intrusion may have occurred;
identifying characteristics of the alarm, including at least an attack type, a source address, a target address, an alarm severity, and an alarm description;
accessing a storage location;
determining whether an operating system fingerprint for a target host associated with the target address already exists in the storage location;
if the operating system fingerprint for the target host does not exist, then:
querying the target host for the operating system fingerprint;
receiving the operating system fingerprint that includes the operating system type from the target host;
comparing the attack type to the operating system type; and
indicating whether the target host is vulnerable to the attack based on the comparison;
if the operating system fingerprint for the target host does exist, then:
determining if a cache entry time for the target address is valid; and
if the cache entry time is invalid, then:
querying the target host for the operating system fingerprint;
receiving the operating system fingerprint that includes the operating system type from the target host;
comparing the attack type to the operating system type; and
indicating whether the target host is vulnerable to the attack based on the comparison;
if the cache entry time is valid, then:
comparing the attack type to the operating system type; and
indicating whether the target host is vulnerable to the attack based on the comparison.
2. The method of claim 1, further comprising storing the operating system fingerprint of the target host in the storage location for a time period.
3. The method of claim , further comprising:
monitoring a dynamic configuration protocol server;
detecting that a lease issue has occurred for a new target host;
querying the new target host for a new operating system fingerprint;
receiving the new operating system fingerprint from the new target host; and
storing the new operating system fingerprint of the new target host in the storage location for a length of time.
4. The method of claim 1, further comprising:
monitoring a dynamic configuration protocol server;
detecting that a lease expire has occurred for an existing target host;
accessing the storage location; and
purging the existing operating system fingerprint for the existing target host from the storage location.
5. A computer-readable non-transitory storage medium embodying software this is operable when executed by a computer system to:
receive an alarm indicating a network intrusion may have occurred;
identify characteristics of the alarm, including at least an attack type, a source address, a target address, an alarm severity, and an alarm description;
access a storage location;
determine whether an operating system fingerprint for a target host associated with the target address already exists in the storage location;
if the operating system fingerprint for the target host does not exist, then:
query the target host for the operating system fingerprint;
receive the operating system fingerprint that includes the operating system type from the target host;
compare the attack type to the operating system type; and
indicate whether the target host is vulnerable to the attack based on the comparison;

if the operating system fingerprint for the target host does exist, then:
determine if a cache entry time for the target address is valid; and
if the cache entry time is invalid, then:
query the target host for the operating system fingerprint;
receive the operating system fingerprint that includes the operating system type from the target host;
compare the attack type to the operating system type; and
indicate whether the target host is vulnerable to the attack based on the comparison;

if the cache entry time is valid, then:
compare the attack type to the operating system type; and
indicate whether the target host is vulnerable to the attack based on the comparison.
6. The medium of claim 5, wherein the software is further operable to store the operating system fingerprint of the target host in the storage location for a time period.
7. The medium of claim 5, wherein the software is further operable to:
monitor a dynamic configuration protocol server;
detect that a lease issue has occurred for a new target host;
query the new target host for a new operating system fingerprint;
receive the new operating system fingerprint from the new target host; and
store the new operating system fingerprint of the new target host in the storage location for a length of time.
8. The medium of claim 6, wherein the software is further operable to:
monitor a dynamic configuration protocol server;
detect that a lease expire has occurred for an existing target host;
access the storage location; and
purge the existing operating system fingerprint for the existing target host from the storage location.
9. An apparatus comprising:
a communication interface;
memory containing instructions for execution by a processor; and
the processor, operable when executing the instructions to:
receive an alarm indicating a network intrusion may have occurred;
identify characteristics of the alarm, including at least an attack type, a source address, a target address, an alarm severity, and an alarm description;
access a storage location;
determine whether an operating system fingerprint for a target host associated with the target address already exists in the storage location;
if the operating system fingerprint for the target host does not exist, then:
query the target host for the operating system fingerprint;
receive the operating system fingerprint that includes the operating system type from the target host;
compare the attack type to the operating system type; and
indicate whether the target host is vulnerable to the attack based on the comparison;

if the operating system fingerprint for the target host does exist, then:
determine if a cache entry time for the target address is valid; and
if the cache entry time is invalid, then:
query the target host for the operating system fingerprint;
receive the operating system fingerprint that includes the operating system type from the target host;
compare the attack type to the operating system type; and
indicate whether the target host is vulnerable to the attack based on the comparison;

if the cache entry time is valid, then:
compare the attack type to the operating system type; and
indicate whether the target host is vulnerable to the attack based on the comparison.
10. The apparatus of claim 9, wherein the processor is further operable to store the operating system fingerprint of the target host in the storage location for a time period.
11. The apparatus of claim 9, wherein the processor is further operable to:
monitor a dynamic configuration protocol server;
detect that a lease issue has occurred for a new target host;
query the new target host for a new operating system fingerprint;
receive the new operating system fingerprint from the new target host; and
store the new operating system fingerprint of the new target host in the storage location for a length of time.
12. The apparatus of claim 9, wherein the processor is further operable to:
monitor a dynamic configuration protocol server;
detect that a lease expire has occurred for an existing target host;
access the storage location; and
purge the existing operating system fingerprint for the existing target host from the storage location.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A method implemented by a slave network edge node at an edge of a service provider network, the slave network edge node to provide accessibility to a wide area network for a customer premise equipment (CPE) upon a failure of a master network edge node, wherein the master network edge node is coupled to the CPE over a wireline link and provides accessibility to the wide area network for the CPE before the failure, the method comprising the steps of:
detecting that the master network edge node has failed;
sending a failure update message (BFU) by the slave network edge node to a Packet Data Network Gateway (PDN GW) of a Long-Term Evolution (LTE) network, wherein the PDN GW provides a backup channel for the CPE to reach the wide area network over a mobile tunnel, and wherein before the failure the mobile tunnel has an end point at the master network edge node, and wherein the failure update message notifies the PDN GW that the end point of the mobile tunnel has changed from the master network edge node to the slave network edge node;
receiving a failure acknowledgement message (BFA) by the slave network edge node from the PDN GW in response to the failure update message; and
routing traffic received by the slave network edge node from the PDN GW over the mobile tunnel to the wide area network.
2. The method of claim 1, wherein the step of detecting further comprises: detecting an absence of a keep-alive message from the master network edge node.
3. The method of claim 2, further comprising the step of: periodically exchanging a state of a second virtual gateway controller in the slave network edge node with a state of a first virtual gateway controller in the master network edge node until the failure of the master network edge node is detected, wherein the first virtual gateway controller and the second virtual gateway controller are adapted to perform control functions for the CPE.
4. The method of claim 1, wherein the step of detecting further comprises: exchanging keep-alive messages with the master network edge node and a virtual gateway controller, wherein the virtual gateway controller is coupled to both the master network edge node and the slave network edge node to perform control functions for the CPE.
5. The method of claim 3, further comprising the step of: notifying the virtual gateway controller that the end point of the mobile tunnel has changed from the master network edge node to the slave network edge node upon detecting the failure of the master network edge node.
6. The method of claim 1, further comprising the steps of:
detecting traffic overload at the slave network edge node;
sending a first traffic offload request (TOR) by the slave network edge node to a peer network edge node, wherein the first traffic offload request includes a range of prefixes to be offloaded to the peer network edge node, such that network traffic identifying an address within the range is to be routed by the PDN GW to the peer network edge node instead of the slave network edge node; and
receiving a first traffic offload acknowledgement (TOA) from the peer network edge node.
7. The method of claim 6, wherein the step of sending the traffic offload request further comprises:
sending a second traffic offload request by the slave network edge node to the PDN GW, wherein the second traffic offload request includes the range of prefixes to be offloaded to the peer network edge node and an address of the peer network edge node; and
receiving a second traffic offload acknowledgement from the PDN GW by the slave network edge node.
8. The method of claim 6, wherein the step of sending the traffic offload request further comprises: determining the range of prefixes based on a current workload of the peer network edge node.
9. A network element serving as a slave network edge node at an edge of a service provider network, the network element to provide accessibility to a wide area network for a customer premise equipment (CPE) upon a failure of a master network edge node, wherein the master network edge node is coupled to the CPE over a wireline link and provides accessibility to the wide area network for the CPE before the failure, the network element comprising:
an uplink module to communicate with the wide area network;
a masterslave interface module to communicate with the master network edge node;
a Packet Data Network Gateway (PDN GW) interface module to communicate with a PDN GW of a Long-Term Evolution (LTE) network, wherein the PDN GW provides a backup channel for the RGW to reach the wide area network over a mobile tunnel, and wherein before the failure the mobile tunnel has an end point at the master network edge node; and
a network processor communicatively coupled to the uplink module, the masterslave interface module, and the PDN GW interface module, the network processor adapted to:
detect that the master network edge node has failed;
send a failure update message (BFU) to the PDN GW, wherein the failure update message notifies the PDN GW that the end point of the mobile tunnel has changed from the master network edge node to the slave network edge node;
receive a failure acknowledgement message (BFA) from the PDN GW in response to the failure update message; and
route traffic received from the PDN GW over the mobile tunnel to the wide area network.
10. The network element of claim 9, wherein the network processor is further adapted to detect an absence of a keep-alive message from the master network edge node.
11. The network element of claim 10, wherein the network processor is further adapted to periodically exchange a state of a second virtual gateway controller in the slave network edge node with a state of a first virtual gateway controller in the master network edge node until the failure of the master network edge node is detected, wherein the first virtual gateway controller and the second virtual gateway controller are adapted to perform control functions for the CPE.
12. The network element of claim 9, wherein the network processor is further adapted to exchange keep-alive messages with the master network edge node and a virtual gateway controller, wherein the virtual gateway controller is coupled to both the master network edge node and the slave network edge node to perform control functions for the CPE.
13. The network element of claim 12, wherein the network processor is further adapted to notify the virtual gateway controller that the end point of the mobile tunnel has changed from the master network edge node to the slave network edge node upon detecting the failure of the master network edge node.
14. The network element of claim 9, wherein the network processor is further adapted to:
detect traffic overload at the slave network edge node;
send a first traffic offload request (TOR) by the slave network edge node to a peer network edge node, wherein the first traffic offload request includes a range of prefixes to be offloaded to the peer network edge node, such that network traffic identifying an address within the range is to be routed by the PDN GW to the peer network edge node instead of the slave network edge node; and
receive a first traffic offload acknowledgement (TOA) from the peer network edge node.
15. The network element of claim 14, wherein the network processor is further adapted to:
send a second traffic offload request by the slave network edge node to the PDN GW, wherein the second traffic offload request includes the range of prefixes to be offloaded to the peer network edge node and an address of the peer network edge node; and
receive a second traffic offload acknowledgement from the PDN GW by the slave network edge node.
16. The method of claim 14, wherein the network processor is further adapted to determine the range of prefixes based on a current workload of the peer network edge node.
17. The network element of claim 9, wherein the slave network edge node is a slave Broadband Network Gateway (BNG), and the master network edge node is a master BNG, and the CPE is a Residential Gateway (RGW).
18. A slave Broadband Network Gateway (BNG) in a service provider network to provide accessibility to a wide area network for a Residential Gateway (RGW) upon a failure of a master BNG, the slave BNG comprising:
an uplink module to communicate with the wide area network;
a masterslave interface module to communicate with the master BNG, the master BNG coupled to the RGW over a wireline link;
a Packet Data Network Gateway (PDN GW) interface module to communicate with a PDN GW of a Long-Term Evolution (LTE) network, wherein the PDN GW provides a backup channel for the RGW to reach the wide area network over a mobile tunnel, and wherein before the failure the mobile tunnel has an end point at the master BNG; and
a network processor communicatively coupled to the uplink module, the BNG interface module, and the PDN GW interface module, the network processor adapted to:
detect that the master BNG has failed;
send a failure update message (BFU) to the PDN GW, wherein the failure update message notifies the PDN GW that the end point of the mobile tunnel has changed from the master BNG to the slave BNG;
receive a failure acknowledgement message (BFA) from the PDN GW in response to the failure update message; and
route traffic received from the PDN GW over the mobile tunnel to the wide area network.
19. A method implemented by a first network edge node at an edge of a service provider network for dynamically balancing network traffic load among a plurality of peer network edge nodes, the first network edge node to provide accessibility to a wide area network for a customer premise equipment (CPE), the method comprising the steps of:
detecting traffic overload at the first network edge node;
sending a first traffic offload request (TOR) by the first network edge node to a peer network edge node, wherein the first traffic offload request includes a range of prefixes to be offloaded to the peer network edge node, such that network traffic identifying an address within the range is to be routed by a Packet Data Network Gateway (PDN GW) of a Long-Term Evolution (LTE) network to the peer network edge node instead of the first network edge node, wherein the PDN GW provides a backup channel for the CPE to reach the wide area network over a mobile tunnel; and
receiving a first traffic offload acknowledgement (TOA) from the peer network edge node.
20. The method of claim 1, wherein the step of sending the traffic offload request further comprises:
sending a second traffic offload request by the first network edge node to the PDN GW, wherein the second traffic offload request includes the range of prefixes to be offloaded to the peer network edge node and an address of the peer network edge node; and
receiving a second traffic offload acknowledgement from the PDN GW by the first network edge node.
21. The method of claim 1, wherein the step of sending the traffic offload request further comprises: determining the range of prefixes based on a current workload of the peer network edge node.
22. The method of claim 1, further comprising the steps of:
receiving an indication of current workload from each of the plurality of peer network edge nodes; and
identifying the peer edge nodes that have capacity to support workload shifted from the first network edge node.
23. The method of claim 22, wherein the step of identifying the peer edge nodes further comprises: exchanging current workload information among the first network edge node and the peer edge nodes.
24. The method of claim 22, wherein the step of identifying the peer edge nodes further comprises: receiving current workload information from one or more virtual gateway controllers coupled to the first network edge node and the peer edge nodes.
25. A network element serving as a first network edge node at an edge of a service provider network for dynamically balancing network traffic load among a plurality of peer network edge nodes, the first network edge node to provide accessibility to a wide area network for a customer premise equipment (CPE), the network element comprising:
an uplink module to communicate with the wide area network;
a BNG interface module to communicate with the peer network edge nodes;
a Packet Data Network Gateway (PDN GW) interface module to communicate with a PDN GW of a Long-Term Evolution (LTE) network, wherein the PDN GW provides a backup channel for the RGW to reach the wide area network over a mobile tunnel; and
a network processor communicatively coupled to the uplink module, the BNG interface module, and the PDN GW interface module, the network processor adapted to:
detect traffic overload at the first network edge node;
send a first traffic offload request (TOR) by the first network edge node to a peer network edge node, wherein the first traffic offload request includes a range of prefixes to be offloaded to the peer network edge node, such that network traffic identifying an address within the range is to be routed by the PDN GW to the peer network edge node instead of the first network edge node; and
receive a first traffic offload acknowledgement (TOA) from the peer network edge node.