IP Library Granted Patent US 8,953,472
Granted Patent B2
US 8,953,472 · App. 13/393,563 · Granted Feb 10, 2015

Method for monitoring a network and network including a monitoring functionality

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,953,472
App. No.
13/393,563
Granted
Feb 10, 2015
Kind
B2
Abstract

A method for monitoring a network, wherein the network has a connected graph topology, in particular a tree structure, including a plurality of monitoring nodes that collect network measurement data, a plurality of mediator nodes each performing at least the task of aggregating network measurement data received from different monitoring nodes and/or other mediator nodes, and at least one root entity that receives network measurement data and/or aggregated network measurement data from the mediator nodes, is characterized in that the aggregation of network measurement data is performed by condensing network measurement data into a summarized probabilistic data structure. Furthermore, a network including a monitoring functionality is disclosed.

Claims (36)

1. A method for monitoring a network, wherein said network has a connected graph topology, in particular a tree structure, said method comprising:

a plurality of monitoring nodes collecting network measurement data,

each of a plurality of mediator nodes performing at least a task of aggregating the collected network measurement data received from different monitoring nodes and/or other mediator nodes, and

at least one root entity that receives the collected network measurement data and/or the aggregated network measurement data from said mediator nodes,

wherein said aggregation of the collected network measurement data is performed by said mediator nodes condensing network measurement data into a summarized probabilistic data structure,

wherein each of said mediator nodes performs a pattern check on its summarized data structure for an anomalous pattern,

wherein a mediator node, in case a pattern check outputs any anomalous pattern, triggers a recursive backtracking process to the monitoring nodes and/or other mediator nodes that have collected the data measurement data relevant to the output anomalous pattern, the backtracking process using the locally cached of said summarized data structure to locate said the monitoring nodes and/or other mediator nodes that have collected the data measurement data relevant to the output anomalous pattern, and

wherein at each of said monitoring nodes and/or other mediator nodes that have collected the data measurement data relevant to the output anomalous pattern, the backtracking process recursively uses locally cached information to locate further ones of said the monitoring nodes and/or other mediator nodes that have collected the data measurement data relevant to the output anomalous pattern.

2. The method according to claim 1 , wherein said summarized data structures include Bloom Filters, sketches, or combinations thereof.

3. The method according to claim 2 , wherein each of said mediator nodes caches a local copy of said summarized data structure it has generated.

4. The method according to claim 2 , wherein each of said mediator nodes performs a pattern check on its summarized data structure.

5. The method according to claim 1 , wherein each of said mediator nodes caches a local copy of said summarized data structure it has generated.

6. The method according to claim 5 , wherein each of said mediator nodes performs a pattern check on its summarized data structure.

7. The method according to claim 1 , wherein said backtracking process is triggered by the mediator node by way of issuing a backtracking request to its children, wherein said backtracking request includes information about said anomalous pattern.

8. The method according to claim 7 , wherein each of said mediator nodes that receives a backtracking request checks its cached copy of the summarized data structure against said backtracking request.

9. The method according to claim 8 , wherein a mediator node, in case said check reveals that any node having contributed to its summarized data structure may have logged relevant data, forwards said backtracking request to its children.

10. The method according to claim 9 , wherein in case the backtracking request reaches any of said monitoring nodes, the data logged by said monitoring nodes is examined.

11. The method according to claim 8 , wherein in case the backtracking request reaches any of said monitoring nodes, the data logged by said monitoring nodes is examined.

12. The method according to claim 7 , wherein in case the backtracking request reaches any of said monitoring nodes, the data logged by said monitoring nodes is examined.

13. The method according to claim 1 , wherein said monitoring nodes release information with respect to collected network measurement data only to parties that present appropriate credentials.

14. The method according to claim 1 , wherein logs of said monitoring nodes are discarded based on a timeout.

15. The method according to claim 1 , wherein said monitoring nodes and/or said mediator nodes are configured to produce said probabilistic data structures periodically.

16. The method according to claim 1 , wherein,

said summarized probabilistic data structures are non-reversible thereby preventing leakage of information about specific users of the network.

17. The network including a monitoring functionality of monitoring a network, wherein said network comprises:

a plurality of monitoring nodes arranged as leaves in a tree structure, each said monitoring node including a probe that collects the network measurement data,

a plurality of mediator nodes arranged as inner nodes within said tree structure, each mediator node including a probe that performs at least a task of aggregating the collected network measurement data received from different monitoring nodes and/or other mediator nodes, wherein said mediator nodes perform said aggregation of the collected network measurement data by condensing network measurement data into a summarized probabilistic data structure, said summarized probabilistic data structures include local caches for recursive backtracking, and said summarized probabilistic data structures are non-reversible thereby preventing leakage of information about specific users of the network, and

at least one root entity that receives the network measurement data and/or the aggregated network measurement data from said mediator nodes.

18. A method for monitoring a network, wherein said network has a connected graph topology, in particular a tree structure, said method comprising:

a plurality of monitoring nodes collecting network measurement data,

each of a plurality of mediator nodes performing at least a task of aggregating the collected network measurement data received from different monitoring nodes and/or other mediator nodes, and

at least one root entity that receives the collected network measurement data and/or the aggregated network measurement data from said mediator nodes,

wherein said aggregation of the collected network measurement data is performed by said mediator nodes condensing network measurement data into a summarized probabilistic data structure, wherein,

at least one of said mediator nodes performing the task of aggregating the collected network measurement data, receive the collected network measurement data from both different monitoring nodes and other mediator nodes,

each of said mediator nodes performs a pattern check on its summarized data structure for an anomalous pattern, the pattern check being dependent on an application consuming the collected network measurement data, an identified anomalous pattern triggering a recursive backtracking process to the monitoring nodes and/or other mediator nodes that have collected the data measurement data relevant to the output anomalous pattern using locally cached information to locate the monitoring nodes and/or other mediator nodes that have collected the data measurement data relevant to the output anomalous pattern, and

at each of said monitoring nodes and/or other mediator nodes that have collected the data measurement data relevant to the output anomalous pattern, the backtracking process recursively uses locally cached information to locate further ones of said the monitoring nodes and/or other mediator nodes that have collected the data measurement data relevant to the output anomalous pattern.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2015
From: NEC EUROPE LTD.
To: NEC CORPORATION
Reel/Frame 036253/0232 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2012
From: DI PIETRO, ANDREA; HUICI, FELIPE; COSTANTINI, DIEGO; NICCOLINI, SAVERIO
To: NEC EUROPE LTD.
Reel/Frame 028101/0098 →