IP Library Granted Patent US 7,672,238
Granted Patent B2
US 7,672,238 · App. 11/835,130 · Granted Mar 2, 2010

Mapping off-network traffic to an administered network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,672,238
App. No.
11/835,130
Granted
Mar 2, 2010
Kind
B2
Abstract

Traffic flows through an administered network from an off-network source and/or to an off-network destination are simulated and analyzed by selecting an ingress and/or egress node within the administered network, the ingress node capable of collecting traffic from an off-network source, and the egress node capable of routing traffic to an off-network destination. Traffic flow is mapped from the source or ingress node through the administered network to the egress node. The traffic flow may be simulated and analyzed. The ingress and/or egress nodes may be selected in a variety of ways.

Claims (48)

1. A method of mapping network traffic flow through a model of an administered network, where at least a destination of the network traffic flow, the destination having a network address, is not within the administered network, comprising:

inspecting routing information at edge devices of the administered network;

determining one or more candidate egress nodes within the administered network that are capable of routing traffic to the destination address, based on the routing information;

selecting one or more egress nodes from among the candidate egress nodes; and

determining a path of the network traffic flow within the model of the administered network from a source of the network traffic flow, the source having a network address, or an ingress node of the administered network, to one or more of the selected egress nodes.

2. The method of claim 1 further comprising simulating the determined paths within the model of the administered network.

3. The method of claim 1 wherein selecting an egress node from among the candidate egress nodes comprises selecting the egress node prior to performing the simulation.

4. The method of claim 3 further comprising:

if the traffic source is not in the administered network, selecting an ingress node within the administered network capable of collecting traffic from the source address; and

wherein selecting an egress node from among the candidate egress nodes prior to performing the simulation comprises applying network constraints to routes from the source or ingress node to each candidate egress node, and selecting the egress node for which a corresponding route best satisfies the applied constraints.

5. The method of claim 4 wherein a network constraint comprises least cost.

6. The method of claim 4 wherein a network constraint comprises fewest hops.

7. The method of claim 4 wherein analyzing the traffic flow through the administered network to the egress node comprises performing transit network planning.

8. The method of claim 4 further comprising outputting a graphic representation of at least part of the administered network, with the mapped traffic flow depicted as a directed graph from the source or ingress node to the egress node.

9. The method of claim 2 wherein selecting an egress node from among the candidate egress nodes comprises selecting the egress node during the simulation.

10. The method of claim 9 further comprising:

if the traffic source is not in the administered network, selecting an ingress node within the administered network capable of collecting traffic from the source address; and

wherein selecting an egress node from among the candidate egress nodes comprises simulating traffic flow from the source or ingress node through the administered network and selecting the egress node based on the simulated traffic flow.

11. The method of claim 10 wherein selecting an ingress node comprises:

selecting a first ingress node capable of collecting traffic from the source address;

routing the traffic to an egress node; and

treating the egress node as a source, and routing the traffic back toward the first ingress node to discover a second ingress node.

12. The method of claim 9 wherein a route from the source or ingress node through the administered network to a selected egress node is deemed successful if it can be routed through the administered network until it reaches a node where the next hop for the destination points to an unconnected interface.

13. The method of claim 9 wherein a route from the source or ingress node through the administered network to a selected egress node is deemed a failure if a lookup in the routing table for the destination fails on any intermediate node in the administered network.

14. The method of claim 9 further comprising outputting a graphic representation of at least part of the administered network, with the mapped traffic flow depicted as an open-ended graph from the source or ingress node.

15. A non-transitory computer readable medium including one or more computer programs operative to cause a computer to map network traffic flow through a model of an administered network where at least a destination of the network traffic flow, the destination having a network address, is not within the administered network, the computer programs operative to cause the computer to perform the steps of:

inspecting routing information at edge devices of the administered network;

determining one or more candidate egress nodes within the administered network that are capable of routing traffic to the destination address, based on the routing information;

selecting one or more egress nodes from among the candidate egress nodes; and

determining the path of the network traffic flow within the model of the administered network from a source of the network traffic flow, the source having a network address, or an ingress node, of the administered network, to one or more of the selected egress nodes.

16. The computer readable medium of claim 15 wherein the computer programs are further operative to cause the computer to perform the step of simulating the determined paths within the model of the administered network.

17. The computer readable medium of claim 16 wherein selecting an egress node from among the candidate egress nodes comprises selecting the egress node prior to performing the simulation.

18. The computer readable medium of claim 17 wherein the computer programs are further operative to cause the computer to perform the step of:

if the traffic source is not in the administered network, selecting an ingress node within the administered network capable of collecting traffic from the source address; and

wherein selecting an egress node from among the candidate egress nodes prior to performing the simulation comprises applying network constraints to routes from the source or ingress node to each candidate egress node, and selecting the egress node for which a corresponding route best satisfies the applied constraints.

19. The computer readable medium of claim 18 wherein a network constraint comprises least cost.

20. The computer readable medium of claim 18 wherein a network constraint comprises fewest hops.

21. The computer readable medium of claim 18 wherein analyzing the traffic flow through the administered network to the egress node comprises performing transit network planning.

22. The computer readable medium of claim 16 wherein selecting an egress node from among the candidate egress nodes comprises selecting the egress node during the simulation.

23. The computer readable medium of claim 22 wherein the computer programs are further operative to cause the computer to perform the step of:

if the traffic source is not in the administered network, selecting an ingress node within the administered network capable of collecting traffic from the source address; and

wherein selecting an egress node from among the candidate egress nodes comprises simulating traffic flow from the source or ingress node through the administered network and selecting the egress node based on the simulated traffic flow.

24. The computer readable medium of claim 23 wherein selecting an ingress node comprises:

selecting a first ingress node capable of collecting traffic from the source address;

routing the traffic to an egress node; and

treating the egress node as a source, and routing the traffic back toward the first ingress node to discover a second ingress node.

25. The computer readable medium of claim 22 wherein a route from the source or ingress node through the administered network to a selected egress node is deemed successful if it can be routed through the administered network until it reaches a node where the next hop for the destination points to an unconnected interface.

26. The computer readable medium of claim 22 wherein a route from the source or ingress node through the administered network to a selected egress node is deemed a failure if a lookup in the routing table for the destination fails on any intermediate node in the administered network.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2013
From: OPNET TECHNOLOGIES LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 030462/0148 →
CHANGE OF NAME Recorded May 14, 2013
From: OPNET TECHNOLOGIES, INC.
To: OPNET TECHNOLOGIES LLC
Reel/Frame 030411/0290 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2007
From: SINGH, PRADEEP; HUNDLEY, KENT; MANOWITZ, DAVID; BOYD, DAVID JAMES; GUPTA, NISHANT; JEYACHANDRAN, VINOD
To: OPNET TECHNOLOGIES, INC.
Reel/Frame 019938/0622 →