IP Library Granted Patent US 7,827,272
Granted Patent B2
US 7,827,272 · App. 10/701,155 · Granted Nov 2, 2010

Connection table for intrusion detection

Assignee: Riverbed Technology, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,827,272
App. No.
10/701,155
Granted
Nov 2, 2010
Kind
B2
Abstract

A system for detecting network intrusions and other conditions in a network is described. The system includes a plurality of collector devices that are disposed to collect data and statistical information on packets that are sent between nodes on a network. An aggregator device is disposed to receive data and statistical information from the plurality of collector devices. The aggregator device produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The aggregator runs processes that determine network events from aggregating of anomalies into network events.

Claims (42)

1. A computer system for tracking network behavior, comprising:

a processor;

a memory that stores:

a connection table that maps each host of a network to a record that stores traffic information from the host to other hosts or from the other hosts to the host in the network for a specified time interval, and

a profile table that stores historical traffic information as exponentially weighted moving average values; and

a merging mechanism configured to merge the record associated with each host for the specified time interval from the connection table into the historical traffic information in the profile table.

2. The computer system of claim 1 wherein the connection table includes a plurality of records that are indexed by source address.

3. The computer system of claim 1 wherein the connection table includes a plurality of records that are indexed by destination address.

4. The computer system of claim 1 wherein the connection table includes a plurality of records that are indexed by time.

5. The computer system of claim 1 wherein the connection table includes a plurality of records, that are record objects, which are indexed by source address, destination address and time.

6. The computer system of claim 1 wherein the connection table is a plurality of connection sub-tables each sub-table having data pertaining to network traffic over different time scales.

7. The computer system of claim 6 wherein the connection sub-tables include a time-slice connection table that operates on a small unit of time and at least one other sub-table that operates on a larger unit of time than the time slice sub-table.

8. The computer system of claim 7 wherein the at least one other sub-table holds records received from collectors over the time scale of the table.

9. The computer system of claim 5 wherein an address indexing the connection table comprises an IP address.

10. The computer system of claim 1 wherein an address indexing the connection table includes a physical layer address to IP address map that is used to determine Host ID.

11. The computer system of claim 1 wherein a host record of a first host maps that first host to a second host that communicates with the first host to a host pair record object that has information about traffic from the first to the second host and from the second host to the first host.

12. The computer system of claim 1 wherein the connection table includes two level mapping that enables a consuming device to obtain summary information about one host for a first level mapping and about traffic between any pair of hosts, in either direction, between a first host of the any pair to a second host of the any pair and from the second host of the any pair to the first host of the any pair for a second level mapping.

13. The computer system of claim 1 wherein the connection table comprises a plurality of host records, a host record stores a measure of the number of bytes, packets, and connections that occurred between hosts during a time-period.

14. The computer system of claim 13 , wherein data in the host record is organized by well known transport protocols and well-known application-level protocols.

15. The computer system of claim 13 , wherein host records have no specific memory limit.

16. The computer system of claim 1 wherein for application-level protocols and for every pair of hosts, the connection table stores statistics for traffic between hosts.

17. The computer system of claim 16 wherein the connection table stores protocol-specific records as (protocol, count) key-value pairs.

18. A computer system for tracking network behavior, the computer system comprising:

a processor;

a memory that stores:

a connection table that maps each host of a network to a record that stores traffic information from the host to other hosts or from the other hosts to the host in the network for a specified time interval,

wherein the connection table is indexed according to one or more of source address, destination address and a specified time interval, and

wherein the connection table includes records fields for storing statistical information for traffic between the hosts; and

a profile table that stores historical traffic information as exponentially weighted moving average values; and

a merging mechanism configured to merge the record associated with each host for the specified time interval from the connection table into the historical traffic information in the profile table.

19. The computer system of claim 18 wherein the plurality of records is record objects.

20. The computer system of claim 18 wherein the connection table is a second plurality of connection sub-tables, each sub-table having data pertaining to network traffic over different ones of corresponding second plurality of time scales.

21. The computer system of claim 18 wherein the connection sub-tables include a time-slice connection table that operates on a small unit of time and at least one other sub-table that operates on a larger unit of time than the time slice sub-table.

22. The computer system of claim 18 wherein the at least one other sub-table holds records received from collectors in the network over the time scale of the table.

23. The computer system of claim 18 wherein an address indexing the connection table comprises an IP address.

24. The computer system of claim 23 wherein an address indexing the connection table includes a physical layer address to IP address map that is used to determine Host ID.

25. The computer system of claim 18 wherein a host record of a first host maps that first host to a second host that communicates with the first host to a host pair record that has information about traffic from the first to the second host and from the second host to the first host.

26. The computer system of claim 18 wherein the connection table includes two level mapping that enables a consuming device to obtain summary information about one host for a first level mapping and about the traffic between any pair of hosts, in either direction, between a first host of the any pair to a second host of the any pair and from the second host of the any pair to the first host of the any pair for a second level mapping.

27. The computer system of claim 18 wherein the connection table comprises a plurality of host records, a host record stores, a measure of the number of bytes, packets, and connections that occurred between hosts during a time-period.

28. The computer system of claim 27 wherein data in the host record is organized by well known transport protocols and well-known application-level protocols.

29. The computer system of claim 28 wherein for application-level protocols and for every pair of hosts, the connection table stores statistics for traffic between hosts.

30. The computer system of claim 28 wherein the connection table stores protocol-specific records as (protocol, count) key-value pairs.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2009
From: MAZU NETWORKS, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 022542/0800 →
CHANGE OF NAME Recorded Mar 30, 2009
From: MAZU NETWORKS, INC.
To: MAZU NETWORKS, LLC
Reel/Frame 022460/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2004
From: POLETTO, MASSIMILIANO ANTONIO; RATIN, ANDREW; DUDFIELD, ANNE ELIZABETH
To: MAZU NETWORKS, INC.
Reel/Frame 015436/0628 →
Continuity (4)
Provisional Application 6042355700 · Nov 4, 2002
Provisional Application 6042729400 · Nov 18, 2002
Provisional Application 6042905000 · Nov 25, 2002
Related Publication 20040199791A1 · Oct 7, 2004