IP Library Granted Patent US 12706818
Granted Patent B2
US 12706818 · App. 18/837,973 · Granted Aug 11, 2026

Collecting device, collecting method, and collecting program

Inventors: Akinori Furuta (Tokyo, JP); Yuhei Hayashi (Tokyo, JP); Atsushi Suto (Tokyo, JP); Chiharu Morioka (Tokyo, JP); Yuki Miyoshi (Tokyo, JP); Satomi Inoue (Tokyo, JP); Masato Yamada (Tokyo, JP)
Assignee: NTT, Inc.
H04L43/026G01R19/0092G06F40/289G06Q10/06H04L47/25
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706818
App. No.
18/837,973
Granted
Aug 11, 2026
Kind
B2
Abstract

A specification unit ( 15 b ) specifies a path of traffic on the basis of past flow information. A determination unit ( 15 c ) determines a network device on the specified path for traffic related to a designated event.

Claims (35)

1 . A collection device comprising a processor configured to execute operations comprising:

receiving a designated event that has occurred in a first network device;

identifying a path of traffic on the basis of past flow information of a normal data traffic, and the normal data traffic describes data at least in the first network device;

determining a second network device on the specified path for traffic related to the designated event, wherein the second network device collects flow statistical information of the normal data traffic according a first collection granularity and transmits the flow statistical information over a network for storing in a memory device; and

causing the second network device to collect, future flow statistical information of a future data traffic according a second collection granularity and transmit the future flow statistical information over the network for storing in the memory device, wherein the second collection granularity is distinct from the first collection granularity.

2 . The collection device according to claim 1 , the processor further configured to execute operations comprising:

transmitting an instruction code over the network to the determined second network device, wherein the instruction code comprises collecting the future flow statistical information of a part of data traffic associated with the designated event on the network by the determined second network device.

3 . The collection device according to claim 2 , wherein the causing to collect further comprises causing the determined second network device to transmit the future flow statistical information, the second collection granularity specifies a sampling rate of collecting the future flow statistical information of the future data traffic, and the second collection granularity that is higher than the first collection granularity.

4 . The collection device according to claim 1 , wherein the past flow information of data over the network represents a normal operation of computing devices in the network.

5 . The collection device according to claim 1 , wherein the designated event represents a security threat to the first network device for causing an enhanced monitoring of network traffic.

6 . The collection device according to claim 1 , wherein the second network device is distinct from the first network device.

7 . The collection device according to claim 1 , wherein the memory device comprises a data lake.

8 . A computer-executable method, comprising:

a receiving step of receiving a designated event that has occurred in a first network device;

a specification step of specifying a path of traffic on the basis of past flow information of a normal data traffic, and the normal data traffic describes data at least in the first network device;

a determination step of determining a second network device on the specified path for traffic related to the designated event, wherein the second network device collects flow statistical information of the normal data traffic according a first collection granularity and transmits the flow statistical information over a network for storing in a memory device; and

causing the second network device to collect, future flow statistical information of a future data traffic according a second collection granularity and transmit the future flow statistical information over the network for storing in the memory device, wherein the second collection granularity is distinct from the first collection granularity.

9 . The computer-executable method according to claim 8 , further comprising:

transmitting an instruction code over the network to the determined second network device, wherein the instruction code comprises collecting the future flow statistical information of a part of data traffic associated with the designated event on the network by the determined second network device.

10 . The computer-executable method according to claim 9 , wherein the causing to collect further comprises causing the determined second network device to transmit the future flow statistical information, the second collection granularity specifies a sampling rate of collecting the future flow statistical information of the future data traffic, and the second collection granularity that is higher than the first collection granularity.

11 . The computer-executable method according to claim 8 , wherein the past flow information of data over the network represents a normal operation of computing devices in the network.

12 . The computer-executable method according to claim 8 , wherein the designated event represents a security threat to the first network device for causing an enhanced monitoring of network traffic.

13 . The computer-executable method according to claim 8 , wherein the second network device is distinct from the first network device.

14 . The computer-executable method according to claim 8 , wherein the memory device comprises a data lake.

15 . A computer-readable non-transitory recording medium storing a computer-executable program instructions that when executed by a processor cause a computer to execute operations comprising:

a receiving step of receiving a designated event that has occurred in a first network device;

a specification step of specifying a path of traffic on the basis of past flow information of a normal data traffic, and the normal data traffic describes data at least in the first network device;

a determination step of determining a second network device on the specified path for traffic related to the designated event, wherein the second network device collects flow statistical information of the normal data traffic according a first collection granularity and transmits the flow statistical information over a network for storing in a memory device; and

causing the second network device to collect, future flow statistical information of a future data traffic according a second collection granularity and transmit the future flow statistical information over the network for storing in the memory device, wherein the second collection granularity is distinct from the first collection granularity.

16 . The computer-readable non-transitory recording medium according to claim 15 , the computer-executable program instructions when executed further causing the computer to execute operations comprising:

transmitting an instruction code over the network to the determined second network device, wherein the instruction code comprises collecting the future flow statistical information of a part of data traffic associated with the designated event on the network by the determined second network device.

17 . The computer-readable non-transitory recording medium according to claim 16 , wherein the causing to collect further comprises causing the determined second network device to transmit the future flow statistical information, the second collection granularity specifies a sampling rate of collecting the future flow statistical information of the future data traffic, and the second collection granularity that is higher than the first collection granularity.

18 . The computer-readable non-transitory recording medium according to claim 15 , wherein the past flow information of data over the network represents a normal operation of computing devices in the network.

19 . The computer-readable non-transitory recording medium according to claim 15 , wherein the designated event represents a security threat to the first network device for causing an enhanced monitoring of network traffic.

20 . The computer-readable non-transitory recording medium according to claim 15 , wherein the second network device is distinct from the first network device, and the memory device comprises a data lake.