IP Library Granted Patent US 7,991,827
Granted Patent B1
US 7,991,827 · App. 10/294,363 · Granted Aug 2, 2011

Network analysis system and method utilizing collected metadata

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,991,827
App. No.
10/294,363
Granted
Aug 2, 2011
Kind
B1
Abstract

A system, method and computer program product are provided for analyzing network traffic associated with network services. Initially, network traffic and metadata are collected from a network. Thereafter, the network traffic is analyzed utilizing the metadata.

Claims (110)

1. A method for analyzing network traffic associated with network services, comprising:

collecting network traffic from a network; collecting metadata associated with the network traffic from the network;

analyzing the network traffic utilizing the metadata, the analyzing including generating a plurality of parsers based on the metadata, utilizing a processor; and identifying an application service provider from the network traffic;

wherein the metadata is correlated with the network traffic, and the correlated metadata is stored in a memory;

wherein the correlating of the metadata with the network traffic is carried out by generating commands based on the network traffic and a software configuration;

wherein the commands include universal description, discovery, and integration (UDDI) service calls that invoke at least one web service associated with the application service provider identified from the network traffic;

wherein the parsers are programs that receive input in a form of at least one of sequential source program instructions, interactive online commands, markup tags, and a defined interface;

wherein the parsers break the input into parts including objects, methods, and associated attributes or options;

wherein a selection of the UDDI service calls is based on UDDI service calls listed by a UDDI as being associated with the application service provider identified from the network traffic;

wherein the metadata is utilized to indicate which messages of the network traffic should be authenticated, indicate which messages of the network traffic should not be authenticated, and indicate how to authenticate the messages.

2. The method as recited in claim 1 , wherein the network includes an Internet.

3. The method as recited in claim 2 , wherein the network services include web services.

4. The method as recited in claim 1 , wherein the network traffic is correlated with the metadata prior to the analysis of the network traffic.

5. The method as recited in claim 4 , wherein the correlating includes initiating the commands for retrieving the metadata as a function of the software configuration.

6. The method as recited in claim 4 , wherein the correlating includes initiating the commands for retrieving the metadata as a function of the network traffic.

7. The method as recited in claim 5 , wherein the commands include calls to other services.

8. The method as recited in claim 1 , and further comprising storing the network traffic and the metadata prior to the analysis of the network traffic.

9. The method as recited in claim 8 , wherein the analysis of the network traffic occurs after an extended period following the collection of the network traffic and the metadata.

10. The method as recited in claim 1 , wherein the network traffic is collected after the metadata is collected.

11. The method as recited in claim 1 , wherein the network traffic is collected before the metadata is collected.

12. The method as recited in claim 1 , wherein the network traffic is collected simultaneously with the metadata.

13. The method as recited in claim 1 , wherein each of the parsers is associated with a corresponding portion of the metadata.

14. The method as recited in claim 1 , wherein the analysis of the network traffic further includes processing the network traffic utilizing the parsers.

15. The method as recited in claim 14 , wherein the analysis of the network traffic further includes reporting on at least one aspect of the network traffic based on the processing.

16. The method as recited in claim 1 , wherein the analysis of the network traffic includes authenticating the network traffic.

17. The method as recited in claim 16 , wherein the network traffic is authenticated based on an authentication test involving the metadata.

18. A computer program product embodied on a non-transitory computer-readable medium, comprising:

computer code for collecting network traffic from a network;

computer code for collecting metadata associated with the network traffic from the network;

computer code for analyzing the network traffic utilizing the metadata, the analyzing including generating a plurality of parsers based on the metadata; and

computer code for identifying an application service provider from the network traffic;

wherein the computer program product is operable such that the metadata is correlated with the network traffic, and the correlated metadata is stored in a memory;

wherein the correlating of the metadata with the network traffic is carried out by generating commands based on the network traffic and a software configuration;

wherein the commands include universal description, discovery, and integration (UDDI) service calls that invoke at least one web service associated with the application service provider identified from the network traffic;

wherein the parsers are programs that receive input in a form of at least one of sequential source program instructions, interactive online commands, markup tags, and a defined interface;

wherein the parsers break the input into parts including objects, methods, and associated attributes or options;

wherein the computer program product is operable such that a selection of the UDDI service calls is based on UDDI service calls listed by a UDDI as being associated with the application service provider identified from the network traffic;

wherein the computer program product is operable such that the metadata is utilized to indicate which messages of the network traffic should be authenticated, indicate which messages of the network traffic should not be authenticated, and indicate how to authenticate the messages.

19. A system implemented in hardware, comprising:

a network traffic collector for collecting network traffic from a network;

a metadata aggregator for collecting metadata associated with the network traffic from the network;

a network analyzer coupled to the network traffic collector and the metadata aggregator, the network analyzer adapted for analyzing the network traffic utilizing the metadata; and

logic for identifying an application service provider from the network traffic;

wherein the system is operable such that the metadata is correlated with the network traffic, and the correlated metadata is stored in a memory;

wherein the system is operable such that the analysis of the network traffic includes generating a plurality of parsers based on the metadata;

wherein the correlating of the metadata with the network traffic is carried out by generating commands based on the network traffic and a software configuration;

wherein the commands include universal description, discovery, and integration (UDDI) service calls that invoke at least one web service associated with the application service provider identified from the network traffic;

wherein the parsers are programs that receive input in a form of at least one of sequential source program instructions, interactive online commands, markup tags, and a defined interface;

wherein the parsers break the input into parts including objects, methods, and associated attributes or options;

wherein the system is operable such that a selection of the UDDI service calls is based on UDDI service calls listed by a UDDI as being associated with the application service provider identified from the network traffic;

wherein the system is operable such that the metadata is utilized to indicate which messages of the network traffic should be authenticated, indicate which messages of the network traffic should not be authenticated, and indicate how to authenticate the messages.

20. A system implemented in hardware, comprising:

means for collecting network traffic from a network;

means for collecting metadata associated with the network traffic from the network;

means for analyzing the network traffic utilizing the metadata, the analyzing including generating a plurality of parsers based on the metadata; and

means for identifying an application service provider from the network traffic;

wherein the system is operable such that the metadata is correlated with the network traffic, and the correlated metadata is stored in a memory;

wherein the correlating of the metadata with the network traffic is carried out by generating commands based on the network traffic and a software configuration;

wherein the commands include universal description, discovery, and integration (UDDI) service calls that invoke at least one web service associated with the application service provider identified from the network traffic;

wherein the parsers are programs that receive input in a form of at least one of sequential source program instructions, interactive online commands, markup tags, and a defined interface;

wherein the parsers break the input into parts including objects, methods, and associated attributes or options;

wherein the system is operable such that a selection of the UDDI service calls is based on UDDI service calls listed by a UDDI as being associated with the application service provider identified from the network traffic;

wherein the system is operable such that the metadata is utilized to indicate which messages of the network traffic should be authenticated, indicate which messages of the network traffic should not be authenticated, and indicate how to authenticate the messages.

21. A method for analyzing network traffic, comprising:

collecting network traffic and metadata from a network for analyzing the network traffic and the metadata for the purpose of analyzing a web service associated therewith, and

dentifying an application service provider from the network traffic;

wherein the metadata is correlated with the network traffic, and the correlated metadata is stored in a memory;

wherein the analysis of the network traffic includes generating a plurality of parsers based on the metadata;

wherein the correlating of the metadata with the network traffic is carried out by generating commands based on the network traffic and a software configuration;

wherein the commands include universal description, discovery, and integration (UDDI) service calls that invoke at least one web service associated with the application service provider identified from the network traffic;

wherein the parsers are programs that receive input in a form of at least one of sequential source program instructions, interactive online commands, markup tags, and a defined interface;

wherein the parsers break the input into parts including objects, methods, and associated attributes or options;

wherein a selection of the UDDI service calls is based on UDDI service calls listed by a UDDI as being associated with the application service provider identified from the network traffic;

wherein the metadata is utilized to indicate which messages of the network traffic should be authenticated, indicate which messages of the network traffic should not be authenticated, and indicate how to authenticate the messages.

22. A method for analyzing network traffic associated with web services, comprising:

collecting network traffic from a plurality of application service providers over a network utilizing a processor, the network traffic being associated with web services provided by the application service providers;

collecting metadata associated with the network traffic from the network; analyzing the network traffic utilizing the metadata for investigating a quality of the web services, the analyzing including generating a plurality of parsers based on the metadata, utilizing a processor; and

identifying an application service provider from the network traffic;

wherein the metadata is correlated with the network traffic, and the correlated metadata is stored in a memory;

wherein the correlating of the metadata with the network traffic is carried out by generating commands based on the network traffic and a software configuration;

wherein the commands include universal description, discovery, and integration (UDDI) service calls that invoke at least one web service associated with the application service provider identified from the network traffic;

wherein the parsers are programs that receive input in a form of at least one of sequential source program instructions, interactive online commands, markup tags, and a defined interface;

wherein the parsers break the input into parts including objects, methods, and associated attributes or options;

wherein a selection of the UDDI service calls is based on UDDI service calls listed by a UDDI as being associated with the application service provider identified from the network traffic;

wherein the metadata is utilized to indicate which messages of the network traffic should be authenticated, indicate which messages of the network traffic should not be authenticated, and indicate how to authenticate the messages.

23. A method for analyzing network traffic associated with web services, comprising:

collecting network traffic from a network associated with web services, utilizing a processor;

correlating the network traffic and metadata associated with the network traffic by:

initiating commands, and collecting the metadata associated with the network traffic in response to the commands; storing the network traffic and the metadata;

analyzing the network traffic utilizing the metadata, the analyzing including generating a plurality of parsers based on the metadata, utilizing a processor; and

identifying an application service provider from the network traffic;

wherein the correlating of the metadata with the network traffic is carried out by generating the commands based on the network traffic and a software configuration;

wherein the commands include universal description, discovery, and integration (UDDI) service calls that invoke at least one web service associated with the application service provider identified from the network traffic;

wherein the parsers are programs that receive input in a form of at least one of sequential source program instructions, interactive online commands, markup tags, and a defined interface;

wherein the parsers break the input into parts including objects, methods, and associated attributes or options;

wherein a selection of the UDDI service calls is based on UDDI service calls listed by a UDDI as being associated with the application service provider identified from the network traffic;

wherein the metadata is utilized to indicate which messages of the network traffic should be authenticated, indicate which messages of the network traffic should not be authenticated, and indicate how to authenticate the messages.

24. The method as recited in claim 1 , wherein the metadata includes database schemas.

25. The method as recited in claim 1 , wherein the metadata includes certificates.

26. The method as recited in claim 1 , wherein the metadata is collected from the network traffic.

27. The method as recited in claim 1 , wherein the metadata includes Web Service Definition Language (WSDL) documents.

28. The method as recited in claim 1 , wherein the metadata is collected by a metadata aggregator.

29. The method as recited in claim 1 , wherein the network traffic is collected by a network traffic collector.

30. The method as recited in claim 1 , wherein the application service provider provides the at least one web service.

31. The method as recited in claim 30 , wherein the at least one web service includes at least one of a storage management service and a customer relationship management service.

32. The method as recited in claim 30 , wherein the at least one web service is accessed via a peer-to-peer arrangement.

33. The method as recited in claim 1 , wherein the collecting of the metadata uses stored information in the network traffic and preconfigured metadata.

34. The method as recited in claim 13 , wherein each of the parsers indicates a syntax that is expected of the network traffic associated with the corresponding portion of the metadata.

35. The method as recited in claim 34 , wherein if a problem with the expected syntax of the network traffic is discovered, then the problem is either reported or corrected.

36. The method as recited in claim 1 , wherein the analyzing of the network traffic includes determining whether the network traffic is correct by determining whether web service invocations and responses are correctly formed.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Jun 23, 2005
From: NETWORKS ASSOCIATES TECHNOLOGY, INC.
To: MCAFEE, INC.
Reel/Frame 016646/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2002
From: WHITMORE, BRENT S.; LA CHOLTER, WILLIAM J.; LAWLER, GEOFF
To: NETWORKS ASSOCIATES TECHNOLOGY, INC.
Reel/Frame 013491/0522 →