IP Library Granted Patent US 8,321,938
Granted Patent B2
US 8,321,938 · App. 12/369,973 · Granted Nov 27, 2012

Multi-tiered scalable network monitoring

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,321,938
App. No.
12/369,973
Granted
Nov 27, 2012
Kind
B2
Abstract

A network analysis architecture provides a suite of complementary logic operable at different temporal and spatial timescales. The distinct temporal and spatial scales define different tiers, each analyzing network events according to predetermined temporal and spatial scales of progressive magnitude. Particular event detection logic may be operable on an immediate temporal scale, while other logic identifies trends over a longer time period. Similarly, different spatial scales are appropriate to different algorithms, as in logic that examines only headers or length of packets, or inspects an entire payload or transferred file. Deployment of logic that is focused on different timing and scope of data allows timely action in the case of readily apparent deviations, and permits longer term analysis for identifying trends that emerge over time. By selecting a suite of complementary logic directed at different deviant behavior, the focus of a single logic scheme is not charged with producing absolute screening of all traffic.

Claims (53)

1. A method of gathering network traffic for analysis of undesirable trends comprising:

defining a plurality of tiers for gathering network traffic, each of the plurality of tiers having a temporal scale and spatial scale independent of the others of the plurality of tiers, the temporal scale defining the timing of observed packets and the spatial scale defining a scope of analysis performed on observed packets, the plurality of tiers including a network element tier for gathering and analyzing events at a line speed of the network traffic, and an aggregate tier for gathering and analyzing events from multiple sources;

gathering according to the temporal scale of the plurality of the tiers, data from the network traffic, the gathered data defining a plurality of events;

analyzing, according to the spatial scale of at least one of the tiers, the gathered network data, analyzing including analyzing according to the plurality of spatial scales from which the analyzed data was gathered;

determining, based on the analyzing, if the analyzed data indicates an alert, the alert indicative of remedial operations; and

generating, if an alert is indicated, a responsive action directed to the indicated remedial operations, the network element tier comprising sensors, the sensors specialized for a predetermined purpose, and gathering comprises gathering a portion of the network data, the gathered portion predetermined according to a particular sensor deployed in the respective network element and directed to an event defined by a single condition.

2. The method of claim 1 wherein the defined plurality of tiers include a network element tier, the network element tier having element logic, the element logic executing at a line speed of the network traffic, analyzing the event within a temporal scale of the line speed and a spatial scale defined by traffic gathered at a deployment point of the network element.

3. The method of claim 2 wherein the defined plurality of tiers includes an aggregated tier, the aggregated tier having aggregate logic, the aggregate logic operating on data structures received from the network element tier, the aggregate logic having a temporal scale of a plurality of events and a spatial scale of a plurality of deployed network elements.

4. The method of claim 3 wherein the plurality of tiers further comprises an archive tier, the archive tier executing archive logic, the temporal scale of the archive logic analyzing events independent of the timing of any particular attack and the spatial scale including historical trends of the gathered events.

5. The method of claim 4 further comprising:

correlating events received from the aggregated and archive tiers; and

issuing feedback to the network sensor, aggregated, and archive tiers.

6. The method of claim 3 further comprising legacy collectors, the legacy collectors for identifying trends associated with previously identified undesirable behavior, the aggregate logic invoking data from the legacy collectors for comparison with the gathered events.

7. The method of claim 1 wherein the aggregate tier comprises data structures receivable from a plurality of sensors in the network element tier and directed to analyzing events from multiple sources, the multiple sources including the plurality of network elements.

8. The method of claim 7 further comprising:

correlating events from the network element tier and the aggregated tier, correlating identifying events indicative of undesirable behavior based on others of the correlated events; and

issuing feedback to the aggregated tier for use with analyzing subsequent events.

9. The method of claim 1 wherein the sensors are responsive to the element logic for:

examining a portion of a network traffic packet, the portion being a subset of the data in the packet; and

advancing to successive packets if a particular packet is incompletely analyzed within the element time scale.

10. The method of claim 1 further comprising deploying the sensors in the network element to analyze particular portions of the message packet, the particular portion for identifying a particular sequence residing in a subset of the entire packet.

11. The method of claim 10 wherein the sensor is specialized to identify only a specific feature such that the entire packet need not be analyzed by any particular sensor such that the sensor performs at line speed.

12. The method of claim 1 wherein the line speed at which the network elements operate is substantially on the order of 10-100 Gbs/s, and wherein:

the network element tier perform without impeding the underlying traffic flow is a priority, with the recognition that all patterns or packets may not be available within the given time window;

the aggregate tier which receives data structures populated by the sensors of the network element tier and operates on data from multiple sensors, such that multiple sensory inputs are permitted to complement each other to identify an event; and

the archive tier includes logic for analyzing current data in light of historical trends observed from previous traffic for events that are not directly tied to a single packet or occurrence.

13. A multi-tiered architecture for analyzing network traffic comprising:

a plurality of tiers for gathering network traffic, each of the plurality of tiers having a temporal scale and spatial scale independent of the others of the plurality of tiers, the temporal scale defining the timing of observed packets and the spatial scale defining a scope of analysis performed on observed packets, the tiers including:

a network element tier for gathering and analyzing events at a line speed of the network traffic;

an aggregate tier for gathering and analyzing events from multiple sources; and

an archive tier, the archive tier executing archive logic, the temporal scale of the archive logic analyzing events independent of the timing of any particular attack and the spatial scale including historical trends of the gathered events;

gathering, according to the temporal scale of at least one of the tiers, data from the network traffic, the gathered data defining an event;

element logic analyzing, according to the spatial scale of the network element tier, the gathered network data, and determining, based on the analyzing, events, the element logic executing at a line speed of the network traffic, analyzing the event within a temporal scale of the line speed and a spatial scale defined by traffic gathered at a deployment point of the network element;

aggregator logic analyzing, according to the spatial scale of the aggregate tier, the gathered network data, and determining, based on the analyzing, events;

a correlator, the correlator having correlation logic for analyzing the events from a plurality of the tiers;

determining, based on the analyzing, if the analyzed data indicates an alert, the alert indicative of remedial operations; and

generating, if an alert is indicated, a responsive action directed to the indicated remedial operations.

14. The architecture of claim 13 wherein network element tier comprises sensors, each of the sensors specialized for a predetermined purpose, and gathering comprises gathering a portion of the network data, the gathered portion predetermined according to a particular sensor deployed in the respective network element and directed to an event defined by a single condition.

15. The architecture of claim 14 wherein the sensors are responsive to the element logic for:

examining a portion of a network traffic packet, the portion being a subset of the data in the packet; and

advancing to successive packets if a particular packet is incompletely analyzed within the element time scale.

16. The architecture of claim 13 wherein the aggregate logic operates on data structures received from the network element tier, the aggregate logic having a temporal scale of a plurality of events and a spatial scale of a plurality of deployed network elements.

17. The architecture of claim 16 further comprising:

correlating events received from the aggregated tiers; and

issuing feedback to the network sensor tiers, the feedback recognized by the element logic for determining successive events.

18. The architecture of claim 13 wherein the plurality of tiers further comprises an archive tier, the archive tier executing archive logic, the temporal scale of the archive logic analyzing events independent of the timing of any particular attack and the spatial scale including historical trends of the gathered events.

19. A computer program product having computer program code on a non-transitory computer readable storage medium including a set of encoded instructions that, when executed by a processor, cause the computer to perform method of analyzing network, the method comprising:

defining a plurality of tiers for gathering network traffic, each of the plurality of tiers having a temporal scale and spatial scale independent of the others of the plurality of tiers, the temporal scale defining the timing of observed packets and the spatial scale defining a scope of analysis performed on observed packets, the plurality of tiers including a network element tier for gathering and analyzing events at a line speed of the network traffic, and an aggregate tier for gathering and analyzing events from multiple sources;

gathering according to the temporal scale of the plurality of the tiers, data from the network traffic, the gathered data defining a plurality of events;

analyzing, according to the spatial scale of at least one of the tiers, the gathered network data, analyzing including analyzing according to the plurality of spatial scales from which the analyzed data was gathered;

determining, based on the analyzing, if the analyzed data indicates an alert, the alert indicative of remedial operations; and

generating, if an alert is indicated, a responsive action directed to the indicated remedial operations,

the network element tier comprising sensors, the sensors specialized for a predetermined purpose, and gathering comprises gathering a portion of the network data, the gathered portion predetermined according to a particular sensor deployed in the respective network element and directed to an event defined by a single condition.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0625 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FEDERAL LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0460 →
CHANGE OF NAME Recorded Feb 16, 2016
From: RAYTHEON CYBER PRODUCTS, LLC
To: FORCEPOINT FEDERAL LLC
Reel/Frame 037821/0818 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
CHANGE OF NAME Recorded Jun 2, 2015
From: RAYTHEON CYBER PRODUCTS, INC.
To: RAYTHEON CYBER PRODUCTS, LLC
Reel/Frame 035806/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2015
From: RAYTHEON BBN TECHNOLOGIES CORP.
To: RAYTHEON CYBER PRODUCTS, INC.
Reel/Frame 035794/0226 →
CHANGE OF NAME Recorded May 28, 2010
From: BBN TECHNOLOGIES CORP.
To: RAYTHEON BBN TECHNOLOGIES CORP.
Reel/Frame 024456/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2009
From: STRAYER, WILLIAM TIMOTHY; MILLIKEN, WALTER; WATRO, RONALD JOSEPH
To: BBN TECHNOLOGIES CORPORATION
Reel/Frame 022250/0178 →