IP Library Granted Patent US 7,433,943
Granted Patent B1
US 7,433,943 · App. 10/027,101 · Granted Oct 7, 2008

Volume-based network management scheme

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,433,943
App. No.
10/027,101
Granted
Oct 7, 2008
Kind
B1
Abstract

Methods, apparatuses and systems allowing for deployment of volume-based network policies across a computer network. In one embodiment, the present invention monitors network utilization of a plurality of users and detects the occurrence of network utilization milestones or other events for individual users, such as exceeding a data transfer allotment or threshold. To enforce the allotment or threshold, the present invention is operative to deny, degrade, or otherwise affect a characteristic associated with network access provided to such users.

Claims (45)

1. A method facilitating deployment of volume-based network policies across a computer network, the method comprising:

monitoring, over a given time interval, an aggregate volume of data transfer corresponding to each user of a plurality of users, wherein the given time interval spans at least one week;

detecting, for a first user in the plurality of users, a network utilization milestone, wherein the network utilization milestone occurs when, within the given time interval, the aggregate volume of data transfer associated with the first user crosses a threshold, and wherein the detecting the network utilization milestone comprises comparing the aggregate number of transferred bytes associated with the first user over the given time interval against a threshold level defining the network utilization milestone; and

allowing but degrading, only with respect to a predefined subset of traffic types, the network access provided to the first user identified in the detecting step.

2. The method of claim 1 further comprising:

charging the first user identified in the detecting step for further network access.

3. The method of claim 1 further comprising

notifying the first user when the aggregate volume of data transfer associated with the first user approaches the threshold.

4. The method of claim 1 wherein the monitoring step is performed only with respect to a predefined set of traffic types.

5. The method of claim 1 wherein the given time interval spans one month.

6. A method facilitating deployment of volume-based network policies across a computer network, the method comprising:

monitoring, over a given time interval, an aggregate volume of data transfer corresponding to each user of a plurality of users, wherein the given time interval spans at least one week;

detecting, for a first user in the plurality of users, a network utilization milestone, wherein the network utilization milestone occurs when, within the given time interval, the aggregate volume of data transfer associated with the first user crosses a threshold, and wherein the detecting the network utilization milestone comprises comparing the aggregate number of transferred bytes associated with the first user over the given time interval against a threshold level defining the network utilization milestone; and

denying further network access to the first user identified in the detecting step only with respect to a predefined subset of traffic types.

7. A method facilitating deployment of volume-based network policies across a computer network, the method comprising

monitoring, over a given time interval, an aggregate volume of data transfer corresponding to each user of a plurality of users within a given time interval, wherein the aggregate volume of data transfer characterizes the volume of data corresponding to past and current data flows over the given time interval, and wherein the given time interval spans at least one week;

detecting, for a first user in the plurality of users, a network utilization milestone, wherein the network utilization milestone occurs when, within the given time interval, the aggregate volume of data transfer associated with the first user crosses a threshold, and wherein the detecting the network utilization milestone comprises comparing the aggregate number of transferred bytes associated with the first user over the given time interval against a threshold level defining the network utilization milestone; and,

denying, for the remainder of the time interval, further network access only with respect to a predefined subset of traffic types to the first user identified in the detecting step.

8. The method of claim 7 further comprising:

degrading the network access provided to the first user identified in the detecting step.

9. The method of claim 7 further comprising:

charging the first user identified in the detecting step for further network access.

10. The method of claim 7 further comprising the step of

notifying the first user when the aggregate volume of data transfer associated with the first user approaches the threshold.

11. The method of claim 7 wherein the time interval is a fixed time interval.

12. The method of claim 7 wherein the time interval is a sliding time interval.

13. The method of claim 7 wherein the monitoring step is performed only with respect to a predefined set of traffic types.

14. The method of claim 7 wherein the given time interval spans one month.

15. A method facilitating deployment of volume-based network policies across a computer network, the method comprising the steps of

registering a user at a network access device connected to a first computer network, the network access device including an IP address;

associating the IP address with the user;

providing the user access to a second computer network by changing the configuration of a network device in a communication path between the first computer network and the second computer network;

monitoring, over a given time interval, an aggregate volume of data transfer associated with the IP address, wherein the given time interval spans at least one week;

detecting a network utilization milestone based on the aggregate volume of data transfer within the given time interval associated with the IP address relative to a threshold, and wherein the detecting the network utilization milestone comprises comparing the aggregate number of transferred bytes associated with the first user over the given time interval against a threshold level defining the network utilization milestone;

changing the configuration of the network device to allow, but degrade access to the second network provided to the user only with respect to a predefined subset of traffic types.

16. The method of claim 15 wherein the given time interval spans one month.

17. An apparatus facilitating the deployment of volume-based network policies across a first computer network, the first computer network comprising at least one traffic monitoring device operative to monitor the volume of network traffic generated by individual users, and at least one network control device operative to control access to a second computer network, comprising

a user account database maintaining respective aggregate volumes of data transfer corresponding to each user of a plurality of users;

a data logging engine operative to collect the aggregate volume of data transfer within a given time interval for the plurality of users collected data in the user account database, wherein the given time interval spans at least one week;

a network usage monitor operative to:

scan the user account database to detect, for a first user in the plurality of users, a network utilization milestone reached by the first user based on the aggregate volume of data transfer associated with the first user in relation to a threshold and the given time interval by comparing the aggregate number of transferred bytes associated with the first user over the given time interval against a threshold level defining the network utilization milestone, and

modify the configuration of the network control device to allow access to the second computer network for the first user only as to a predefined subset of network traffic types.

18. The apparatus of claim 17 further comprising a user interface module operative to register new users and create corresponding user accounts in the user account database.

19. The apparatus of claim 17 wherein the given time interval spans one month.

20. The apparatus of claim 18 wherein the apparatus, in response to registration of a new user, is operative to modify the configuration of the network control device to allow access to the second computer network for the new user.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 27727/0144 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035798/0006 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 027727/0178 Recorded Oct 16, 2012
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 029140/0170 →