IP Library Granted Patent US 7,296,288
Granted Patent B1
US 7,296,288 · App. 10/295,391 · Granted Nov 13, 2007

Methods, apparatuses, and systems allowing for bandwidth management schemes responsive to utilization characteristics associated with individual users

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,296,288
App. No.
10/295,391
Granted
Nov 13, 2007
Kind
B1
Abstract

Methods, apparatuses and systems allowing for bandwidth management schemes responsive to utilization characteristics associated with individual users. In one embodiment, the present invention allows network administrators to penalize users who carry out specific questionable or suspicious activities, such as the use of proxy tunnels to disguise the true nature of the data flows in order to evade classification and control by bandwidth management devices. In one embodiment, each individual user may be accorded an initial suspicion score. Each time the user is associated with a questionable or suspicious activity (for example, detecting the set up of a connection to an outside HTTP tunnel, or peer-to-peer application flow), his or her suspicion score is downgraded. Data flows corresponding to users with sufficiently low suspicion scores, in one embodiment, can be treated in a different manner from data flows associated with other users. For example, different or more rigorous classification rules and policies can be applied to the data flows associated with suspicious users.

Claims (71)

1. A method allowing for bandwidth management schemes responsive to utilization characteristics associated with individual users, the method comprising

monitoring, at a network device, data flows relative to at least one user for indications of suspicious activity directed to evading classification of network traffic associated with the at least one user by a network traffic classification device;

maintaining a suspicion level for the at least one user based on detected indications of suspicious activity, wherein the detected indications of suspicious activity comprise a user connecting to a tunnel proxy resource operative to encrypt data flows corresponding to the user; and

applying bandwidth utilization controls to the data flows associated with the at least one user based on the respective suspicion level.

2. The method of claim 1 wherein at least one of the indications of suspicious activity comprises a user connecting to a tunnel proxy resource further comprising the step of conditionally applying a decay rate to the suspicion level, wherein the decay rate results in the lowering of the suspicion level for the user if no detected indications of suspicious activity occur during a pre-defined number of periods.

3. The method of claim 1 wherein at least one of the indications of suspicious activity comprises irregular data flow patterns.

4. The method of claim 1 wherein at least one of the indications of suspicious activity comprises a user connecting to a peer-to-peer application resource.

5. The method of claim 1 wherein at least one of the indications of suspicious activity comprises beyond a threshold number of connections to a host system.

6. The method of claim 5 wherein the host system is a server relative to the connections.

7. The method of claim 1 wherein the suspicion level is expressed as a suspicion score.

8. The method of claim 1 wherein the monitoring step comprises

collecting raw data corresponding to data flows associated with the at least one user; and

processing the collected raw data in a separate process to detect indications of suspicious activity.

9. An apparatus allowing for bandwidth management schemes responsive to utilization characteristics associated with individual users, comprising

a suspicion scoring module operative to:

monitor data flows relative to at least one user for indications of suspicious activity directed to evading classification of network traffic associated with the at least one user by a network traffic classification device; and

generate a suspicion level for the at least one user based on detected indications of suspicious activity, wherein the detected indications of suspicious activity comprise a user connecting to a tunnel proxy resource operative to encrypt data flows corresponding to the user; and

a bandwidth utilization control module operative to apply bandwidth utilization controls to data flows associated with the at least one user based at least in part on the respective suspicion levels.

10. The apparatus of claim 9 wherein the bandwidth utilization control module comprises

a packet processor, a traffic classification databases and a flow control module;

wherein the packet processor is operative to:

construct control block objects including attributes characterizing data flows traversing the apparatus, and

associate packets to control block objects;

wherein the traffic classification database is operative to:

operate on control block object attributes to identify traffic classes associated with data flows traversing the apparatus, and

associate bandwidth utilization controls to the data flows based on identified traffic classes; and

wherein the flow control module is operative to enforce bandwidth utilization controls on data flows associated with corresponding traffic classes.

11. The apparatus of claim 9 wherein the suspicion scoring module is operative to:

execute in the packet processing path to collect raw data associated with data flows traversing the bandwidth utilization control module; and

process the collected raw data in a separate process to generate suspicion levels for the at least one user.

12. The apparatus of claim 9 wherein the suspicion scoring module includes a heightened scrutiny list comprising at least one user identification; and wherein the suspicion scoring module is operative to monitor only the data flows associated with user identifications in the heightened scrutiny list.

13. The apparatus of claim 12 wherein the user identification is a computer network address.

14. The apparatus of claim 12 wherein the user identification is a range of computer network addresses.

15. The apparatus of claim 14 wherein the range is expressed as a computer network subnet.

16. The apparatus of claim 9 wherein the suspicion scoring module is operative to maintain an exclude list comprising at least one user identification; and wherein the suspicion scoring module is operative to exclude from monitoring data flows associated with the at least one user identification on the exclude list.

17. The apparatus of claim 16 wherein the user identification is a computer network address.

18. The apparatus of claim 16 wherein the user identification is a range of computer network addresses.

19. The apparatus of claim 18 wherein the range is expressed as a computer network subnet.

20. The apparatus of claim 12 wherein the user identification is a ticket issued by a network authentication mechanism.

21. The apparatus of claim 10 further comprising a host database storing computer network addresses associated with data flows traversing the apparatus, wherein the host database maintains suspicion levels generated by the suspicion scoring module in association with the computer network addresses.

22. The apparatus of claim 10 wherein the traffic classification database maintains a traffic class for suspicious users; and wherein the suspicion scoring module is operative to change the configuration of the traffic classification database to classify data lows associated with users having a suspicion level beyond a threshold level in the traffic class for suspicious users.

23. A method allowing for bandwidth management schemes responsive to utilization characteristics associated with individual users, the method comprising

monitoring, at a network device, data flows relative to at least one user for indications of suspicious activity directed to evading classification of network traffic associated with the at least one user by a network traffic classification device;

maintaining a suspicion level for the at least one user based on detected indications of suspicious activity, wherein the detected indications of suspicious activity comprise a user connecting to a tunnel proxy resource operative to encrypt data flows corresponding to the user; and

applying a heightened level of scrutiny to data flows associated with users having a suspicion level beyond a threshold suspicion level.

24. A method allowing for bandwidth management schemes responsive to utilization characteristics associated with individual users, the method comprising

monitoring, at a network device, data flows relative to at least one user for indications of suspicious activity directed to evading classification of network traffic associated with the at least one use, by a network traffic classification device, wherein the indications of suspicious activity comprise a user connecting to a tunnel proxy resource operative to encrypt data flows corresponding to the user; and

maintaining a suspicion level for the at least one user based on detected indications of suspicious activity.

25. The method of claim 24 further comprising

reporting the suspicion level for the at least one user.

26. The method of claim 25 wherein the reporting step comprises

transmitting the suspicion level for the at least one user to a remote network device.

27. The method of claim 26 wherein the remote network device is a central management server.

28. The method of claim 24 further comprising

modifying the configuration of at least one network device in response to the suspicion level for the at least one user.

29. The method of claim 1 wherein the monitoring step comprises

analyzing network traffic associated with one or more users against one or more traffic pattern templates; and

wherein the maintaining step comprises

adjusting the suspicion level for the one or more users based on analyzing step.

30. The method of claim 1 wherein the monitoring step comprises

analyzing HTTP network traffic associated with one or more users against an HTTP traffic pattern template; and

wherein the maintaining step comprises

adjusting the suspicion level for a given user based on the analyzing step.

31. The method of claim 30 wherein the HTTP traffic pattern template comprises at least one attribute characterizing an expected behavior of regular HTTP traffic, and at least one attribute characterizing a suspicious behavior involving HTTP traffic.

32. The apparatus of claim 9 wherein the suspicion scoring module is operative to

analyze network traffic associated with one or more users against one or more traffic pattern templates; and

adjust the suspicion level for the one or more users based on analyzing step.

33. The apparatus of claim 9 wherein the suspicion scoring module is operative to

analyze HTTP network traffic associated with one or more users against an HTTP traffic pattern template; and

adjust the suspicion level for a given user based on the analyzing step.

34. The apparatus of claim 33 wherein the HTTP traffic pattern template comprises at least one attribute characterizing an expected behavior of regular HTTP traffic, and at least one attribute characterizing a suspicious behavior involving HTTP traffic.

Assignments (12)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 27727/0144 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035798/0006 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 027727/0178 Recorded Oct 16, 2012
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 029140/0170 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0144 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2011
From: PACKETEER, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 027307/0603 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2002
From: HILL, MARK; RIDDLE, GUY; PURVY, ROBERT E.
To: PACKETEER, INC.
Reel/Frame 013500/0491 →