IP Library Granted Patent US 9,602,366
Granted Patent B1
US 9,602,366 · App. 12/716,987 · Granted Mar 21, 2017

System and method for correcting clock discrepancy in simultaneous network traffic captures

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,602,366
App. No.
12/716,987
Granted
Mar 21, 2017
Kind
B1
Abstract

A system and method for correcting clock discrepancy in simultaneous network traffic data captures in a multi-tiered, multi-session environment. The invention uses intrinsic constraints imposed by the nature of the traffic onto the possible temporal sequence of the packets, The invention uses the intrinsic restraints of the network architecture and the protocols used at each segment along with the time stamps in the various segments to determine both an offset and scale correction to the clock readings (timestamps) in the traces in order to obtain a correct temporal sequence of packets when using multiple capture agents/engines/network monitors.

Claims (14)

1. A method for determining clock disparities between a first clock in a first network monitor positioned to capture first data in a first segment of a network and a second clock in a second network monitor positioned to capture second data in a second segment of the network, the first and second data transmitted using at least one network transmission protocol, and the first and second network segments in different tiers of a multi-tiered network system, the method comprising the steps of:

receiving the first and second data, a packet of the first data traveling through a first network path of the multi-tiered network system and a packet of the second data traveling through a second network path of the multi-tiered network system different from the first network path, the traveling through the multiple tiers of the network system including terminating the packets of the first data and of the second data at a tier of the multi-tier system;

correlating the first and second data into one or more application sessions, wherein data correlated with a first application session is first application session data that includes packets from both the first data and the second data;

identifying a correct temporal sequence of said first application session data responsive to the at least one network transmission protocol and restraints of the multi-tiered network architecture, the restraints to which the identifying is responsive including locations in the multi-tiered network structure of the first and the second network monitors; and

determining the disparity between the first and second clocks by comparing timestamps of said first application session data with said correct temporal sequence of said first application session data and accounting for the disparity when analyzing data captured by at least one of said first network monitor and said second network monitor wherein the disparity corresponds to an offset value and a scaling value wherein said offset value and said scaling value is utilized when analyzing data captured by at least one of said first network monitor and said second network monitor.

2. The method of claim 1 , wherein said first segment is between a first pair of devices in the network and a second segment is between a second pair of devices in the network wherein said first pair and second pair are different.

3. The method of claim 1 , wherein the identifying step includes the step of utilizing a first application protocol corresponding to the first application session to identify the correct temporal sequence.

4. A non-transitory computer readable storage medium structured to store instructions, to determine clock disparities between a first clock in a first network monitor positioned to capture first data in a first segment of a network and a second clock in a second network monitor positioned to capture second data in a second segment of the network, the first and second data transmitted using at least one network transmission protocol, and the first and second network segments being in different tiers of a multi-tiered network system, the instructions when executed cause a processor to perform operations including:

receiving the first and second data, a packet of the first data traveling through a first network path of the multi-tiered network system and a packet of the second data traveling through a second network path of the multi-tiered network system different from the first network path, the traveling through the multiple tiers of the network system including terminating the packets of the first data and of the second data at a tier of the multi-tier system;

correlating the first and second data into one or more application sessions, wherein data correlated with a first application session is first application session data that includes packets from both the first data and the second data;

identifying a correct temporal sequence of said first application session data responsive to the at least one network transmission protocol and restraints of the multi-tiered network architecture, the restraints to which the identifying is responsive including locations in the multi-tiered network structure of at least the first and the second network monitors; and

determining the disparity between the first and second clocks by comparing timestamps of said first application session data with said correct temporal sequence of said first application session data and accounting for the disparity when analyzing data captured by at least one of said first network monitor and said second network monitor wherein the disparity corresponds to an offset value and a scaling value wherein said offset value and said scaling value is utilized when analyzing data captured by at least one of said first network monitor and said second network monitor.

5. The non-transitory computer readable storage medium of claim 4 , wherein said first segment is between a first pair of devices in the network and a second segment is between a second pair of devices in the network wherein said first pair and second pair are different.

6. The non-transitory computer readable storage medium of claim 4 , wherein the identifying instruction includes the instruction of utilizing a first application protocol corresponding to the first application session to identify the correct temporal sequence order relationship.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Jul 14, 2015
From: KEYBANK NATIONAL ASSOCIATION
To: NETSCOUT SYSTEMS, INC.
Reel/Frame 036087/0702 →
SECURITY INTEREST Recorded Jul 14, 2015
From: NETSCOUT SYSTEMS, INC.; FIDELIA TECHNOLOGY, INC.; NETSCOUT SERVICE LEVEL CORPORATION; ONPATH TECHNOLOGIES INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 036087/0808 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2010
From: MANIN, DMITRII YURIEVICH
To: NETSCOUT SYSTEMS, INC.
Reel/Frame 024030/0050 →