IP Library Granted Patent US 7,809,829
Granted Patent B2
US 7,809,829 · App. 12/259,151 · Granted Oct 5, 2010

Categorizing, classifying, and identifying network flows using network and host components

Assignee: FaceTime Communications, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,809,829
App. No.
12/259,151
Granted
Oct 5, 2010
Kind
B2
Abstract

Network flows are identified by analyzing network traffic and network host information. The network host information may be collected by network host monitors associated with network hosts. Network traffic and network host information are evaluated against network flow profiles to identify network flows. If a network flows are identified with high certainty and are associated with previously identified network applications, then network flow policies can be applied to the network flows to block, throttle, accelerate, enhance, or transform the network flows. If a network flow is identified with lesser certainty or is not associated with a previously identified network application, then a new network flow profile can be created from further analysis of network traffic information, network host information, and possibly additional network host information collected to enhance the analysis. New network flow profiles can be communicated with a service provider for analysis and potential distribution to other networks.

Claims (50)

1. A method performed by a computer system for processing network traffic in a network, the method comprising:

receiving, at a first computer system that communicates with the network, network traffic being sent from or destined to applications in communication with the network;

receiving, at the first computer system, host information of a second computer system associated with at least a portion of the network traffic being sent from or destined to applications in communication with the network;

analyzing, by the first computer system, the network traffic and the host information of the second computer system to identify at least one network flow within the network traffic, the network flow attributable to an application hosted by the second computer system;

determining, by the first computer system, whether the at least one network flow attributable to an application hosted by the second computer system matches a network flow profile; and

applying a policy to the at least one network flow attributable to an application hosted by the second computer system based on a determination that the network flow attributable to an application hosted by the second computer system matches the network flow profile.

2. The method of claim 1 , further comprising:

generating, by the first computer system, a new network flow profile associated with the at least one network flow attributable to an application hosted by the second computer system based on a determination that the at least one network flow attributable to an application hosted by the second computer system does not match the network flow profile.

3. The method of claim 2 , wherein generating, by the first computer system, the new network profile for the at least one network flow attributable to an application hosted by the second computer system comprises determining, by the first computer system, a correlation of at least a portion of the network traffic and at least a portion of the host information with the at least one network flow attributable to an application hosted by the second computer system.

4. The method of claim 3 , wherein generating, by the first computer system, the new network profile for the at least one network flow attributable to an application hosted by the second computer system comprises creating, by the first computer system, a Bayesian probability network based on the correlation.

5. The method of claim 2 , wherein generating, by the first computer system, the new network profile for the at least one network flow attributable to an application hosted by the second computer system comprises:

generating, at the first computer system, a request for additional host information associated with the second computer system;

receiving, at the first computer system, the additional host information associated with the second computer system; and

further analyzing the network traffic, the host information, and the additional host information to create the new network flow profile.

6. The method of claim 2 , further comprising:

communicating, from the first computer system, the new network flow profile to a service provider.

7. The method of claim 1 , further comprising:

determining, by the first computer system, whether the network flow attributable to an application hosted by the second computer system is associated with a previously identified application; and

generating a new network flow profile associated with the at least one network flow attributable to an application hosted by the second computer system based on a determination that the network flow attributable to an application hosted by the second computer system at least partially matches the network flow profile and a determination that the network flow attributable to an application hosted by the second computer system is not associated with the previously identified application.

8. The method of claim 1 , wherein receiving, at the first computer system, the host information of the second computer system comprises receiving the host information collected by at least one network host monitor associated with the second computer system.

9. The method of claim 1 , wherein receiving, at the first computer system, the host information of the second computer system comprises receiving the host information from a program installed on the second computer system.

10. The method of claim 1 , wherein receiving, at the first computer system, the host information of the second computer system comprises receiving the host information from a program executed by the second computer system.

11. The method of claim 1 , wherein receiving, at the first computer system, the host information of the second computer system comprises receiving configuration data of the second computer system.

12. The method of claim 1 , wherein receiving, at the first computer system, the host information comprises receiving performance data of the second computer system.

13. The method of claim 1 , wherein receiving, at the first computer system, the host information comprises receiving network connection data of the second computer system.

14. The method of claim 1 , wherein receiving, at the first computer system, the host information comprises receiving user input to the second computer system.

15. The method of claim 1 , wherein receiving, at the first computer system, the host information comprises receiving system hooks associated with an operating system of the second computer system.

16. The method of claim 1 , wherein applying the policy to the at least one network flow attributable to an application hosted by the second computer system comprises communicating, from the first computer system, identifying information of the at least one network flow to a network traffic control device.

17. The method of claim 16 , wherein communicating, from the first computer system, the identifying information of the at least one network flow comprises communicating the identifying information to the network traffic control device using a network management protocol.

18. The method of claim 1 , wherein receiving, at the first computer system, the network traffic comprises receiving network traffic collected by at least one network traffic monitor.

19. An information storage medium configured to store code operational when executed by an information processing device for processing network traffic in a network, the information storage medium comprising:

code for receiving network traffic being sent from or destined to applications in communication with the network;

code for receiving host information of a network host associated with at least a portion of the network traffic being sent from or destined to applications in communication with the network;

code for analyzing the network traffic and the host information of the network host to identify at least one network flow within the network traffic, the network flow attributable to an application hosted by the network host;

code for determining whether the at least one network flow attributable to an application hosted by the network host matches a network flow profile; and

code for applying a policy to the at least one network flow attributable to an application hosted by the network host based on a determination that the network flow attributable to an application hosted by the network host matches the network flow profile.

20. The information storage medium of claim 19 , further comprising:

code for generating a new network flow profile associated with the at least one network flow attributable to an application hosted by the network host based on a determination that the at least one network flow attributable to an application hosted by the network host does not match the network flow profile.

21. The information storage medium of claim 20 , wherein the code for generating the new network profile for the at least one network flow attributable to an application hosted by the network host comprises code for determining a correlation of at least a portion of the network traffic and at least a portion of the host information with the at least one network flow attributable to an application hosted by the network host.

22. The information storage medium of claim 21 , wherein the code for generating the new network profile for the at least one network flow attributable to an application hosted by the network host comprises code for creating a Bayesian probability network based on the correlation.

23. The information storage medium of claim 20 , wherein the code for generating the new network profile for the at least one network flow attributable to an application hosted by the network host comprises:

code for generating a request for additional host information associated with the network host;

code for receiving the additional host information associated with the second computer system; and

code for further analyzing the network traffic, the host information, and the additional host information to create the new network flow profile.

24. The information storage medium of claim 20 , further comprising:

code for communicating the new network flow profile to a service provider.

25. The information storage medium of claim 19 , wherein the code for receiving the host information of the network host comprises receiving the host information collected by at least one network host monitor associated with the network host.

26. The information storage medium of claim 19 , wherein the code for receiving the host information of the network host comprises code for receiving the host information from a program installed on the network host or from a program executed by the network host.

27. The information storage medium of claim 19 , wherein the code for receiving the host information of the network host comprises code for receiving configuration data of the network host, performance data of the network host, network connection data of the network host, user input to the network host, or system hooks associated with an operating system of the network host.

28. The information storage medium of claim 19 , wherein the code for applying the policy to the at least one network flow attributable to an application hosted by the network host comprises code for communicating identifying information of the at least one network flow to a network traffic control device.

Assignments (8)
CHANGE OF NAME Recorded Feb 24, 2025
From: ACTIANCE, INC.
To: ACTIANCE, LLC
Reel/Frame 070306/0814 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT REEL/FRAME NO. 45065/0916 Recorded Feb 22, 2022
From: PNC BANK, NATIONAL ASSOCIATION
To: MOBILEGUARD, LLC; SMARSH INC.; SKYWALKER INTERMEDIATE HOLDINGS, INC.; ACTIANCE, INC.; ACTIANCE HOLDINGS, INC.
Reel/Frame 059315/0572 →
PATENT SECURITY AGREEMENT Recorded Feb 18, 2022
From: ACTIANCE, INC.
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 059191/0423 →
RELEASE OF SECURITY INTEREST REEL/FRAME: 035527 / 0923 Recorded Jan 31, 2022
From: GOLUB CAPITAL LLC
To: ACTIANCE, INC.
Reel/Frame 058906/0160 →
SECURITY INTEREST Recorded Feb 28, 2018
From: MOBILEGUARD, LLC; SMARSH INC.; SKYWALKER INTERMEDIATE HOLDINGS, INC.; ACTIANCE, INC.; ACTIANCE HOLDINGS, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 045065/0916 →
CHANGE OF NAME Recorded May 19, 2015
From: FACETIME COMMUNICATIONS, INC.
To: ACTIANCE, INC.
Reel/Frame 035729/0433 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2015
From: KELLY, SCOTT; MANDEL, EUGENE; PETVIASHVILI, JOSEPH; CHRISTENSEN, JONATHAN; GURRAPU, SRINI
To: FACETIME COMMUNICATIONS, INC.
Reel/Frame 035659/0636 →
SECURITY INTEREST Recorded Apr 29, 2015
From: ACTIANCE, INC.
To: GOLUB CAPITAL LLC, AS AGENT
Reel/Frame 035527/0923 →
Continuity (3)
Continuation 1133639500 · Jan 19, 2006
Provisional Application 6064528300 · Jan 19, 2005
Related Publication 20090161544A1 · Jun 25, 2009