IP Library Granted Patent US 9,787,567
Granted Patent B1
US 9,787,567 · App. 13/754,671 · Granted Oct 10, 2017

Systems and methods for network traffic monitoring

Inventors: Munish Mehta (Fremont, CA); Robert Edward Adams (Sunnyvale, CA); Rao Sandeep Hebbani Raghavendra (Sunnyvale, CA); Srinivasan Ramasubramanian (Redwood City, CA)
Assignee: Big Switch Networks, Inc.
H04L43/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,787,567
App. No.
13/754,671
Granted
Oct 10, 2017
Kind
B1
Abstract

A packet forwarding network may include switches that forward network traffic between end hosts and network tap devices that forward copied network traffic to an analysis network formed from client switches that are controlled by a controller. Network analysis devices and network service devices may be coupled to the client switches at interfaces of the analysis network. The controller may receive one or more network policies from a network administrator. A network policy may identify ingress interfaces, egress interfaces, matching rules, packet manipulation services to be performed. The controller may control the client switches to generate network paths that forward network packets that match the matching rules from the ingress interfaces to the egress interfaces through service devices that perform the services of the list. The controller may generate network paths for network policies based on network topology information and/or current network conditions maintained at the controller.

Claims (17)

1. A method of using a controller that controls client switches in an analysis network, the method comprising:

with the controller, receiving a network policy that identifies ingress, egress, and intermediate interfaces of the analysis network, wherein the ingress interfaces are coupled to a packet forwarding network, the egress interfaces are coupled to analysis devices, and the intermediate interfaces are coupled to service devices;

with the controller, generating network paths that forward network packets from the ingress interfaces to the egress interfaces through the client switches in the analysis network by providing flow table entries to the client switches that direct the client switches to forward the network packets from the ingress interfaces to the egress interfaces, wherein the flow table entries are stored in flow tables on the client switches, the flow table entries comprise a header field and a corresponding action field, the header field matches on a selected set of network packets, and the action field comprises an action for the client switches to perform on the set of network packets that matches the header field;

with the client switches, forwarding the network packets from the ingress interfaces to at least one service device in the service devices through a first subset of the client switches in the analysis network and at least one corresponding intermediate interface in the intermediate interfaces based on the generated network paths;

with the at least one service device, modifying information stored in the network packets;

after modifying the information stored in the network packets, with the controller, sending the network packets from the at least one service device back into the analysis network through the at least one corresponding intermediate interface; and

with the client switches, forwarding the network packets to the egress interfaces through a second subset of the client switches in the analysis network that is different from the first subset of client switches in the analysis network based on the generated network paths.

2. The method defined in claim 1 wherein the packet forwarding network forwards network traffic between end hosts of the packet forwarding network, wherein the packet forwarding network includes network tap devices that are coupled to respective ingress interfaces of the analysis network, wherein the network tap devices copy at least a portion of the network traffic of the packet forwarding network, and wherein the network tap devices forward the copied network traffic from the packet forwarding network to the ingress interfaces.

3. Computing equipment that controls client switches in an analysis network, comprising:

a processor configured to:

receive a network policy that identifies ingress, egress, and intermediate interfaces of the analysis network, wherein the ingress interfaces are coupled to a packet forwarding network, the egress interfaces are coupled to analysis devices, and the intermediate interfaces are coupled to service devices;

generate network paths that forward network packets from the ingress interfaces to the egress interfaces through the client switches in the analysis network by providing flow table entries to the client switches that direct the client switches to forward the network packets from the ingress interfaces to the egress interfaces, wherein the flow table entries are stored in flow tables on the client switches, the flow table entries comprise a header field and a corresponding action field, the header field matches on a selected set of network packets, and the action field comprises an action for the client switches to perform on the set of network packets that matches the header field;

control the client switches to forward the network packets from the ingress interfaces to at least one service device in the service devices through a first subset of the client switches in the analysis network and at least one corresponding intermediate interface in the intermediate interfaces based on the generated network paths;

control the at least one service device to modify information stored in the network packets;

control the at least one service device to send the network packets from the at east one service device back into the analysis network through the at least one corresponding intermediate interface after controlling the at least one service device to modify the information stored in the network packets; and

control the client switches to forward the network packets to the egress interfaces through a second subset of the client switches in the analysis network that is different from the first subset of client switches in the analysis network based on the generated network paths; and

a storage configured to store the received network policy.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2022
From: BIG SWITCH NETWORKS LLC
To: ARISTA NETWORKS, INC.
Reel/Frame 058793/0454 →
CHANGE OF NAME Recorded May 7, 2020
From: BIG SWITCH NETWORKS, INC.
To: BIG SWITCH NETWORKS LLC
Reel/Frame 052600/0719 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED AT REEL: 029726 FRAME: 0816. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 6, 2020
From: MEHTA, MUNISH; ADAMS, ROBERT EDWARD; HEBBANI RAGHAVENDRA, RAO SANDEEP; RAMASUBRAMANIAN, SRINIVASAN
To: BIG SWITCH NETWORKS, INC.
Reel/Frame 052585/0348 →
RELEASE OF SECURITY INTEREST Recorded Mar 24, 2020
From: SILVER LAKE WATERMAN FUND II, L.P.
To: BIG SWITCH NETWORKS, INC.; BIG SWITCH NETWORKS GC, INC.
Reel/Frame 052218/0557 →
SECURITY INTEREST Recorded Dec 20, 2018
From: BIG SWITCH NETWORKS, INC.; BIG SWITCH NETWORKS GC, INC.
To: SILVER LAKE WATERMAN FUND II, L.P., AS AGENT
Reel/Frame 049146/0615 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2013
From: MEHTA, MUNISH; ADAMS, ROBERT EDWARD; HEBBANI RAGHAVENDRA, RAO SANDEEP; RAMASUBRAMANIAN, SRINIVASAN
To: BIG SWITCH CORPORATION
Reel/Frame 029726/0816 →