IP Library Granted Patent US 7,447,768
Granted Patent B2
US 7,447,768 · App. 11/336,395 · Granted Nov 4, 2008

Categorizing, classifying, and identifying network flows using network and host components

Assignee: FaceTime Communications, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,447,768
App. No.
11/336,395
Granted
Nov 4, 2008
Kind
B2
Abstract

Network flows are identified by analyzing network traffic and network host information. The network host information may be collected by network host monitors associated with network hosts. Network traffic and network host information are evaluated against network flow profiles to identify network flows. If a network flows are identified with high certainty and are associated with previously identified network applications, then network flow policies can be applied to the network flows to block, throttle, accelerate, enhance, or transform the network flows. If a network flow is identified with lesser certainty or is not associated with a previously identified network application, then a new network flow profile can be created from further analysis of network traffic information, network host information, and possibly additional network host information collected to enhance the analysis. New network flow profiles can be communicated with a service provider for analysis and potential distribution to other networks.

Claims (51)

1. A method of processing network traffic, the method comprising:

receiving network traffic information, wherein the network traffic information describes attributes of network traffic in a network;

receiving network host information, wherein the network host information describes attributes of a network host associated with at least a portion of the network traffic;

analyzing the network traffic information and the network host information to identify at least one network flow within the network traffic;

determining if the network flow matches a network flow profile; and

applying a policy to the network flow in response to a determination that the network flow matches the network flow profile.

2. The method of claim 1 , further comprising:

creating a new network flow profile in response to the determination that the network flow does not match the network flow profile.

3. The method of claim 2 , wherein creating a new network profile includes determining a correlation of at least a portion of the network traffic information and at least a portion of the network host information with the network flow.

4. The method of claim 3 , wherein creating a new network profile includes creating a Bayesian probability network based on the correlation.

5. The method of claim 2 , wherein creating the new network flow profile comprises:

requesting additional network host information in response to the determination that the network flow does not match the network flow profile;

receiving the additional network host information; and

further analyzing the network traffic information, the network host information, and the additional network host information to create the new network flow profile.

6. The method of claim 1 , further comprising:

determining if the network flow is associated with a previously identified application; and

creating a new network flow profile in response to the determination that the network flow at least partially matches the network flow profile and the determination that the network flow is not associated with the previously identified application.

7. The method of claim 1 , wherein the network host information is collected by at least one network host monitor.

8. The method of claim 1 , wherein the network host information includes a program installed on the network host.

9. The method of claim 1 , wherein the network host information includes a program executed by the network host.

10. The method of claim 1 , wherein the network host information includes configuration data of the network host.

11. The method of claim 1 , wherein the network host information includes performance data of the network host.

12. The method of claim 1 , wherein the network host information includes network connection data of the network host.

13. The method of claim 1 , wherein the network host information includes user input to the network host.

14. The method of claim 1 , wherein the network host information includes system hooks associated with an operating system of the network host.

15. The method of claim 2 , further comprising communicating the new network flow profile with a service provider.

16. The method of claim 1 , wherein applying the policy to the network flow includes communicating identifying information of the network flow to a network traffic control device.

17. The method of claim 16 , wherein the identifying information of the network flow is communicated with the network traffic control device via a network management protocol.

18. The method of claim 1 , wherein the network traffic information is collected by at least one network traffic monitor.

19. An information storage medium comprising a plurality of instructions adapted to direct an information processing device to perform an operation comprising:

receiving network traffic information, wherein the network traffic information describes attributes of network traffic in a network;

receiving network host information, wherein the network host information describes attributes of a network host associated with at least a portion of the network traffic;

analyzing the network traffic information and the network host information to identify at least one network flow within the network traffic;

determining if the network flow matches a network flow profile; and

applying a policy to the network flow in response to a determination that the network flow matches the network flow profile.

20. The information storage medium of claim 19 , further comprising:

creating a new network flow profile in response to the determination that the network flow does not match the network flow profile.

21. The information storage medium of claim 20 , wherein creating a new network profile includes determining a correlation of at least a portion of the network traffic information and at least a portion of the network host information with the network flow.

22. The information storage medium of claim 21 , wherein creating a new network profile includes creating a Bayesian probability network based on the correlation.

23. The information storage medium of claim 20 , wherein creating the new network flow profile comprises:

requesting additional network host information in response to the determination that the network flow does not match the network flow profile;

receiving the additional network host information; and

further analyzing the network traffic information, the network host information, and the additional network host information to create the new network flow profile.

24. The information storage medium of claim 19 , further comprising:

determining if the network flow is associated with a previously identified application; and

creating a new network flow profile in response to the determination that the network flow at least partially matches the network flow profile and the determination that the network flow is not associated with the previously identified application.

25. The information storage medium of claim 19 , wherein the network host information is collected by at least one network host monitor.

26. The information storage medium of claim 20 , further comprising communicating the new network flow profile with a service provider.

27. The information storage medium of claim 19 , wherein applying the policy to the network flow includes communicating identifying information of the network flow to a network traffic control device.

28. The information storage medium of claim 27 , wherein the identifying information of the network flow is communicated with the network traffic control device via a network management protocol.

29. The information storage medium of claim 19 , wherein the network traffic information is collected by at least one network traffic monitor.

Assignments (8)
CHANGE OF NAME Recorded Feb 24, 2025
From: ACTIANCE, INC.
To: ACTIANCE, LLC
Reel/Frame 070306/0814 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT REEL/FRAME NO. 45065/0916 Recorded Feb 22, 2022
From: PNC BANK, NATIONAL ASSOCIATION
To: MOBILEGUARD, LLC; SMARSH INC.; SKYWALKER INTERMEDIATE HOLDINGS, INC.; ACTIANCE, INC.; ACTIANCE HOLDINGS, INC.
Reel/Frame 059315/0572 →
PATENT SECURITY AGREEMENT Recorded Feb 18, 2022
From: ACTIANCE, INC.
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 059191/0423 →
RELEASE OF SECURITY INTEREST REEL/FRAME: 035527 / 0923 Recorded Jan 31, 2022
From: GOLUB CAPITAL LLC
To: ACTIANCE, INC.
Reel/Frame 058906/0160 →
SECURITY INTEREST Recorded Feb 28, 2018
From: MOBILEGUARD, LLC; SMARSH INC.; SKYWALKER INTERMEDIATE HOLDINGS, INC.; ACTIANCE, INC.; ACTIANCE HOLDINGS, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 045065/0916 →
CHANGE OF NAME Recorded May 15, 2015
From: FACETIME COMMUNICATIONS, INC.
To: ACTIANCE, INC.
Reel/Frame 035705/0823 →
SECURITY INTEREST Recorded Apr 29, 2015
From: ACTIANCE, INC.
To: GOLUB CAPITAL LLC, AS AGENT
Reel/Frame 035527/0923 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2006
From: KELLY, SCOTT; MANDEL, EUGENE; PETVIASHVILI, JOSEPH; CHRISTENSEN, JONATHAN; GURRAPU, SRINI
To: FACETIME COMMUNICATIONS, INC.
Reel/Frame 018076/0178 →
Continuity (2)
Provisional Application 6064528300 · Jan 19, 2005
Related Publication 20060277288A1 · Dec 7, 2006