IP Library Granted Patent US 8,971,196
Granted Patent B2
US 8,971,196 · App. 13/415,819 · Granted Mar 3, 2015

Distributed network traffic data collection and storage

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,971,196
App. No.
13/415,819
Granted
Mar 3, 2015
Kind
B2
Abstract

Network traffic information from multiple sources, at multiple time scales, and at multiple levels of detail are integrated so that users may more easily identify relevant network information. The network monitoring system stores and manipulates low-level and higher-level network traffic data separately to enable efficient data collection and storage. Packet traffic data is collected, stored, and analyzed at multiple locations. The network monitoring locations communicate summary and aggregate data to central modules, which combine this data to provide an end-to-end description of network traffic at coarser time scales. The network monitoring system enables users to zoom in on high-level, coarse time scale network performance data to one or more lower levels of network performance data at finer time scales. When high-level network performance data of interest is selected, corresponding low-level network performance data is retrieved from the appropriate distributed network monitoring locations to provide additional detailed information.

Claims (45)

1. A method of collecting and aggregating distributed traffic network data, the method comprising:

collecting first and second packet traffic data from first and second network locations, respectively;

storing first and second packet traffic data in first and second data storage devices at the first and second network locations, respectively;

generating first and second summary network traffic data at the first and second network locations, respectively, wherein the first and second summary network traffic data is at a first time scale coarser than a time scale associated with the first and second packet traffic data;

communicating first and second summary network traffic data from the first and second network locations to a third network location; and

storing the first and second summary network traffic data at the third network location;

wherein the first summary network traffic data includes first references adapted to retrieve at least corresponding portions of the first packet traffic data from the first network location and the second summary network traffic data includes second references adapted to retrieve at least corresponding portions of the second packet traffic data from the second network location.

2. The method of claim 1 , comprising:

generating third summary network traffic data from the first and second summary network traffic data, wherein the third summary network traffic data includes third references adapted to retrieve at least corresponding portions of the first and second summary network traffic data.

3. The method of claim 2 , wherein the first and second summary network traffic data include duplicated flow traffic data and the third summary network traffic data includes connected flow traffic data.

4. The method of claim 3 , wherein the third summary network traffic data includes related network traffic flows having one of the same source or destination as at least a portion of the connected flow traffic data.

5. The method of claim 2 , wherein the third summary network traffic data includes network traffic data at a second time scale coarser than the first time scale.

6. The method of claim 5 , wherein the network traffic data at the second time scale includes macroflow traffic data.

7. The method of claim 2 , comprising:

storing the third summary network traffic data at the third network location.

8. The method of claim 1 , wherein the first references included in the first summary network traffic data are associated with third summary network traffic data stored at the first network location and having a second time scale finer than the first time scale and coarser than the time scale associated with the first packet traffic data.

9. The method of claim 8 , wherein the third summary network traffic data includes microflow traffic data.

10. The method of claim 1 , wherein the first summary network traffic data includes an attribute common to at least a portion of the first packet traffic data.

11. The method of claim 1 , wherein the first summary network traffic data includes an aggregate attribute of at least a portion of the first packet traffic data.

12. The method of claim 1 , wherein the first summary network traffic data includes a statistical attribute determined from at least a portion of the first packet traffic data.

13. The method of claim 1 , wherein the first summary network traffic data includes a user-configured attribute of at least a portion of the first packet traffic data.

14. The method of claim 13 , wherein the user-configured attribute is determined by executing user-provided code.

15. The method of claim 1 , wherein storing first packet traffic data in the first data storage device at the first network location comprises:

identifying a portion of the first packet traffic data collected within a first time period;

identifying a packet data block reference in a data storage device file system associated with the first time period;

storing the portion of the first packet traffic data in at least one data block of the data storage device file system; and

adding a reference to the at least one data block storing the portion of the first packet traffic data to the packet data block reference.

16. The method of claim 1 , wherein collecting and storing the first packet traffic data is performed at least partially within a virtual machine application.

17. The method of claim 1 , wherein collecting and storing the first packet traffic data is performed at least partially within a network monitoring appliance.

18. A non-transitory computer-readable storage medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform a method of collecting and aggregating distributed traffic network data, the method comprising:

collecting first and second packet traffic data from first and second network locations, respectively;

storing first and second packet traffic data in first and second data storage devices at the first and second network locations, respectively;

generating first and second summary network traffic data at the first and second network locations, respectively, wherein the first and second summary network traffic data is at a first time scale coarser than a time scale associated with the first and second packet traffic data;

communicating first and second summary network traffic data from the first and second network locations to a third network location; and

storing the first and second summary network traffic data at the third network location;

wherein the first summary network traffic data includes first references adapted to retrieve at least corresponding portions of the first packet traffic data from the first network location and the second summary network traffic data includes second references adapted to retrieve at least corresponding portions of the second packet traffic data from the second network location.

19. An apparatus, comprising:

one or more processors; and

a non-transitory computer-readable storage medium storing instructions that, when executed by the one or more processors, cause the apparatus to perform a method of collecting and aggregating distributed traffic network data, the method comprising:

collecting first and second packet traffic data from first and second network locations, respectively;

storing first and second packet traffic data in first and second data storage devices at the first and second network locations, respectively;

generating first and second summary network traffic data at the first and second network locations, respectively, wherein the first and second summary network traffic data is at a first time scale coarser than a time scale associated with the first and second packet traffic data;

communicating first and second summary network traffic data from the first and second network locations to a third network location; and

storing the first and second summary network traffic data at the third network location;

wherein the first summary network traffic data includes first references adapted to retrieve at least corresponding portions of the first packet traffic data from the first network location and the second summary network traffic data includes second references adapted to retrieve at least corresponding portions of the second packet traffic data from the second network location.

Assignments (19)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2012
From: DEGIOANNI, LORIS; MCCANNE, STEVEN; WHITE, CHRISTOPHER J.; VLACHOS, DIMITRI S.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 028528/0559 →