IP Library Granted Patent US 9,455,873
Granted Patent B2
US 9,455,873 · App. 13/949,163 · Granted Sep 27, 2016

End-to-end analysis of transactions in networks with traffic-altering devices

Inventors: Patrick J. Malloy (Washington, DC); Antoine Dunn (Kensington, MD); Dana Znamova (Rockville, MD); Steven Niemczyk (San Francisco, CA); Russell Mark Elsner (Bethesda, MD); Ryan Gehl (Silver Spring, MD); Alex Chernyakov (Bethesda, MD)
Assignee: RIVERBED TECHNOLOGY, INC.
H04L41/12H04L29/12952H04L61/6077H04L29/12367H04L61/2514
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,455,873
App. No.
13/949,163
Granted
Sep 27, 2016
Kind
B2
Abstract

In a network that includes intermediary nodes, such as WAN accelerators, that transform messages between nodes, an end-to-end path of the messages is determined. The determined end-to-end path is used in subsequent analyses of message traces, to identify timing and other factors related to the performance of the network relative to the propagation of these messages, including the propagation of the transformed messages. A variety of techniques are presented for determining the path of the messages, depending upon the characteristics of the collected trace data. Upon determining the message path, the traces are synchronized in time and correlations between the connections along the path are determined, including causal relationships. In a preferred embodiment, a user identifies an application process between or among particular nodes of a network, and the system provides a variety of formats for viewing statistics related to the performance of the application on the network.

Claims (72)

1. A network analysis system, comprising:

a memory configured to store trace data comprising a record of a message communicated between a first node and a second node in a network;

a topology determination module configured to determine an end-to-end path of the message between the first node and the second node, wherein the message is transformed from a first message into a transformed message by an intermediate node along the end-to-end path, the transformed message being transmitted along a portion of the end-to-end path;

a correlation module configured to correlate the first message and the transformed message from the record based on the determined end-to-end path; and

a processor configured to execute the modules.

2. The network analysis system of claim 1 , wherein the processor is further configured to:

receive the trace data and store the trace data in the memory; and

display information based on the correlation of the first message and the transformed message along the end-to-end path.

3. The network analysis system of claim 1 , wherein the topology determination module is further configured to:

distinguish traffic flows based on the trace data, including one or more traffic flows that include the first message and the transformed message; and

determine a topological arrangement of the intermediate node with respect to the first and second nodes based on the one or more traffic flows,

wherein the processor is further configured to store the determined topological arrangement for analysis of subsequent trace files.

4. The network analysis system of claim 3 , wherein the topology determination module is further configured to:

distinguish the traffic flows based on a media access control (MAC) address associated with the first message and the transformed message; and

identify the intermediate node based on the MAC address.

5. The network analysis system of claim 3 , wherein the processor is further configured to:

filter out messages that do not correlate to the first message and the transformed message; and

filter out connections that do not correspond to the one or more traffic flows.

6. The network analysis system of claim 1 , wherein the topology determination module is further configured to:

distinguish the first message from the transformed message based on a distinguishing characteristic of at least one of the first message and the transformed message; and

identify the intermediate node based on the distinguishing characteristic.

7. The network analysis system of claim 1 , wherein the topology determination module is further configured to determine the end-to-end path based on a set of times associated with propagation of a select message at the intermediate node.

8. The network analysis system of claim 1 , wherein the correlation module is further configured to correlate the transformed message and a second message, the second message comprising a recreation of the first message from the transformed message.

9. The network analysis system of claim 1 , wherein:

the trace data is stored in a plurality of trace files; and

the correlation module further comprises a synchronization module, the synchronization module configured to adjust one or more time bases of the plurality of trace files to establish a common time base among the plurality of trace files.

10. A method, comprising:

receiving, by a computing device, trace data comprising a record of a message communicated between a first node and a second node in a network;

determining, by the computing device, an end-to-end path of the message between the first node and the second node, wherein the message is transformed from a first message into a transformed message by an intermediate node along the end-to-end path, the transformed message being transmitted along a portion of the end-to-end path; and

correlating, by the computing device, the first message and the transformed message from the record based on the determined end-to-end path.

11. The method of claim 10 , further comprising:

distinguishing traffic flows based on the trace data, including one or more traffic flows that include the first message and the transformed message;

determining a topological arrangement of the intermediate node with respect to the first and second nodes based on the one or more traffic flows; and

storing the detemlined topological arrangement for analysis of subsequent trace files.

12. The method of claim 11 , wherein:

the distinguishing further comprises distinguishing the traffic flows based on a media access control (MAC) address associated with the first message and the transformed message; and

the determining the end-to-end path further comprises identifying the intermediate node based on the MAC address.

13. The method of claim 11 , further comprising:

filtering out messages that do not correlate to the first message and the transformed message; and

filtering out connections that do not correspond to the one or more traffic flows.

14. The method of claim 10 , further comprising:

distinguishing the first message from the transformed message based on a distinguishing characteristic of at least one of the first message and the transformed message; and

identifying the intermediate node based on the distinguishing characteristic.

15. The method of claim 10 , further comprising:

correlating the transformed message and a second message, the second message comprising a recreation of the first message from the transformed message.

16. The method of claim 10 , wherein the trace data is stored in a plurality of trace files, the method further comprising:

adjusting one or more time bases of the plurality of trace files to establish a common time base among the plurality of trace files;

identifying a subset of the plurality of trace files that include the correlated first message and transformed message; and

merging the subset of the plurality of trace files into a merged trace file.

17. A network analysis apparatus, comprising:

a memory configured to store trace data comprising a record of a message communicated between a first node and a second node in a network; and

a processor configured to:

determine an end-to-end path of the message between the first node and the second node, wherein the message is transformed from a first message into a transformed message by an intermediate node along the end-to-end path, the transformed message being transmitted along a portion of the end-to-end path; and

correlate the first message and the transformed message from the record based on the determined end-to-end path.

18. The network analysis apparatus of claim 17 , wherein the processor is further configured to:

distinguish traffic flows based on the trace data, including one or more traffic flows that include the first message and the transformed message;

determine a topological arrangement of the intermediate node with respect to the first and second nodes based on the one or more traffic flows; and

store the determined topological arrangement for analysis of subsequent trace files.

19. The network analysis apparatus of claim 18 , wherein the processor is further configured to:

distinguish the traffic flows based on a media access control (MAC) address associated with the first message and the transformed message; and

identify the intermediate node based on the MAC address.

20. The network analysis apparatus of claim 18 , wherein the processor is further configured to:

filter out messages that do not correlate to the first message and the transformed message; and

filter out connections that do not correspond to the one or more traffic flows.

21. The network analysis apparatus of claim 17 , wherein the processor is further configured to:

distinguish the first message from the transformed message based on a distinguishing characteristic of at least one of the first message and the transformed message; and

identify the intermediate node based on the distinguishing characteristic.

22. The network analysis apparatus of claim 17 , wherein the processor is further configured to determine the end-to-end path based on a set of times associated with propagation of a select message at the intermediate node.

23. The network analysis apparatus of claim 17 , wherein the processor is further configured to correlate the transformed message and a second message, the second message comprising a recreation of the first message from the transformed message.

24. The network analysis apparatus of claim 17 , wherein:

the trace data is stored in a plurality of trace files; and

the processor is further configured to adjust one or more time bases of the plurality of trace files to establish a common time base among the plurality of trace files.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2019
From: OPNET TECHNOLOGIES LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 048680/0549 →
CHANGE OF NAME Recorded Mar 14, 2019
From: OPNET TECHNOLOGIES, INC.
To: OPNET TECHNOLOGIES LLC
Reel/Frame 048598/0225 →
CHANGE OF NAME Recorded Mar 7, 2019
From: OPNET TECHNOLOGIES, INC.
To: OPNET TECHNOLOGIES LLC
Reel/Frame 048531/0722 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2019
From: MALLOY, PATRICK J.; DUNN, ANTOINE; ZNAMOVA, DANA; NIEMEZYK, STEVEN; ELSNER, RUSSELL MARK; GEHL, RYAN; CHERNYAKOV, ALEX
To: OPNET TECHNOLOGIES, INC.
Reel/Frame 048510/0395 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
RELEASE OF SECURITY INTEREST Recorded Mar 30, 2015
From: MORGAN STANLEY & CO. LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035285/0311 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
PATENT SECURITY AGREEMENT Recorded Sep 13, 2013
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 031216/0968 →
Continuity (3)
Continuation 12623592 · Nov 23, 2009
Provisional Application 61118322 · Nov 26, 2008
Related Publication 20140022944A1 · Jan 23, 2014