IP Library Granted Patent US 10,243,862
Granted Patent B2
US 10,243,862 · App. 14/213,659 · Granted Mar 26, 2019

Systems and methods for sampling packets in a network flow

Inventors: Dominick Cafarelli (Ossining, NY); Murali Bommana (Fremont, CA); Sandeep Dahiya (San Jose, CA); Jesse C. Shu (Palo Alto, CA); Anoop V. Kartha (San Jose, CA)
Assignee: Gigamon Inc.
H04L47/2441H04L43/026H04L43/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,243,862
App. No.
14/213,659
Granted
Mar 26, 2019
Kind
B2
Abstract

A method for sampling packets for a network flow, includes: receiving a packet at a network port of a network switch appliance, the network switch appliance comprising an instrument port for communication with a network monitoring instrument; determining whether the packet belongs to a network flow that is desired to be monitored, wherein the act of determining is performed based at least in part on one or more information in a control plane using a processing unit; and passing the packet to the instrument port if the packet belongs to the network flow.

Claims (61)

1. A method comprising:

receiving a plurality of packets at a network port of a network switch appliance, the network switch appliance including an instrument port for communication with a network monitoring instrument;

identifying packets, of the received plurality of packets, as belonging to a particular network flow that is to be monitored, wherein said identifying includes

identifying, in the network switch appliance, control plane packets as belonging to the particular network flow, based on a user-associated attribute contained in the control plane packets, the control plane packets conforming to a control plane protocol, and

identifying, in the network switch appliance, data plane packets as belonging to the particular network flow, by correlating the identified control plane packets with corresponding data plane packets of the received plurality of packets, the data plane packets conforming to a data plane protocol and not to the control plane protocol; and

passing to the instrument port the packets identified as belonging to the particular network flow, including the identified control plane packets and the identified data plane packets, for delivery to the network monitoring instrument.

2. The method of claim 1 , wherein the data plane packets do not contain any user-associated attribute.

3. The method of claim 1 , further comprising:

identifying the network flow based on a hash value computed using one or more packet attributes.

4. The method of claim 1 , further comprising:

identifying the network flow based on a first flow selection criterion for a data path and a second flow selection criterion for a control path.

5. The method of claim 1 , further comprising receiving additional packets of the network flow, and passing all of the additional packets to the instrument port in response to determining that the additional packets belong to the network flow.

6. The method of claim 1 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on a 5-tuple.

7. The method of claim 1 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on one or more of a station address, a VLAN ID, and a MPLS tunnel ID.

8. The method of claim 1 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on a MPLS label stack comprising one or more MPLS label identifiers.

9. The method of claim 1 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on a calling number, a called number, a call identifier, or an information associated with the control protocol.

10. The method of claim 1 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on one or more information in a GTP control protocol, a SIP control protocol, a H323 control protocol, or a Megaco protocol.

11. The method of claim 10 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on one or more of IMSI, MSISDN, IMEI, and APN information.

12. The method of claim 1 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on a first flow selection criterion for a data path and a second flow selection criterion for a control path.

13. The method of claim 1 , wherein the identified packets are passed to the instrument port in an out-of-band configuration.

14. An apparatus comprising:

a network port to receive a plurality of packets;

an instrument port through which to communicate with a network monitoring instrument; and

a processing unit communicatively coupled with the network port and the instrument port, and configured to

identify packets, of the received plurality of packets, as belonging to a particular network flow that is to be monitored, by

identifying control plane packets as belonging to the particular network flow, based on a user-associated attribute contained in the control plane packets, the control plane packets conforming to a control plane protocol, and

identifying data plane packets as belonging to the particular network flow, by correlating the identified control plane packets with corresponding data plane packets of the received plurality of packets, the data plane packets conforming to a data plane protocol and not to the control plane protocol; and

pass to the instrument port the packets identified as belonging to the particular network flow, including the identified control plane packets and the identified data plane packets, for delivery to the network monitoring instrument.

15. The apparatus of claim 14 , wherein the data plane packets do not contain any user-associated attribute.

16. The apparatus of claim 14 , further comprising:

identifying the network flow based on a hash value computed using one or more packet attributes.

17. The apparatus of claim 14 , further comprising:

identifying the network flow based on a first flow selection criterion for a data path and a second flow selection criterion for a control path.

18. The apparatus of claim 14 , further comprising receiving additional packets of the network flow, and passing all of the additional packets to the instrument port in response to determining that the additional packets belong to the network flow.

19. The apparatus of claim 14 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on a 5-tuple.

20. The apparatus of claim 14 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on one or more of a station address, a VLAN ID, and a MPLS tunnel ID.

21. The apparatus of claim 14 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on a MPLS label stack comprising one or more MPLS label identifiers.

22. The apparatus of claim 14 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on a calling number, a called number, a call identifier, or an information associated with the control protocol.

23. The apparatus of claim 14 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on one or more information in a GTP control protocol, a SIP control protocol, a H323 control protocol, or a Megaco protocol.

24. The apparatus of claim 14 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on one or more of IMSI, MSISDN, IMEI, and APN information.

25. The apparatus of claim 14 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on a first flow selection criterion for a data path and a second flow selection criterion for a control path.

26. The apparatus of claim 14 , wherein the identified packets are passed to the instrument port in an out-of-band configuration.

27. A non-transitory storage medium storing instructions, execution of which by at least one processor in a network appliance causes the network appliance to execute a method comprising:

identifying packets, of a plurality of packets received at a network port of the network appliance, as belonging to a particular network flow that is to be monitored, wherein said identifying includes

identifying, in the network appliance, control plane packets as belonging to the particular network flow, based on a user-associated attribute contained in the control plane packets, the control plane packets conforming to a control plane protocol, and

identifying, in the network appliance, data plane packets as belonging to the particular network flow, by correlating the identified control plane packets with corresponding data plane packets of the received plurality of packets, the data plane packets conforming to a data plane protocol and not to the control plane protocol; and

passing, to an instrument port of the network appliance, the packets identified as belonging to the particular network flow, including the identified control plane packets and the identified data plane packets, for delivery to a network monitoring instrument.

28. The non-transitory storage medium of claim 27 , wherein the data plane packets do not contain any user-associated attribute.

29. The non-transitory storage medium of claim 27 , further comprising:

identifying the network flow based on a hash value computed using one or more packet attributes.

30. The non-transitory storage medium of claim 27 , further comprising:

identifying the network flow based on a first flow selection criterion for a data path and a second flow selection criterion for a control path.

31. The non-transitory storage medium of claim 27 , further comprising receiving additional packets of the network flow, and passing all of the additional packets to the instrument port in response to determining that the additional packets belong to the network flow.

32. The non-transitory storage medium of claim 27 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on a 5-tuple.

33. The non-transitory storage medium of claim 27 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on one or more of a station address, a VLAN ID, and a MPLS tunnel ID.

34. The non-transitory storage medium of claim 27 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on a MPLS label stack comprising one or more MPLS label identifiers.

35. The non-transitory storage medium of claim 27 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on a calling number, a called number, a call identifier, or an information associated with the control protocol.

36. The non-transitory storage medium of claim 27 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on one or more information in a GTP control protocol, a SIP control protocol, a H323 control protocol, or a Megaco protocol.

37. The non-transitory storage medium of claim 27 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on one or more of IMSI, MSISDN, IMEI, and APN information.

38. The non-transitory storage medium of claim 27 , wherein identifying packets that belong to a particular network flow that is to be monitored is based on a first flow selection criterion for a data path and a second flow selection criterion for a control path.

39. The non-transitory storage medium of claim 27 , wherein the identified packets are passed to the instrument port in an out-of-band configuration.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Mar 11, 2022
From: JEFFERIES FINANCE LLC
To: GIGAMON INC.
Reel/Frame 059362/0491 →
SECURITY INTEREST Recorded Mar 11, 2022
From: GIGAMON INC.; ICEBRG LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 059362/0717 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 11, 2020
From: GIGAMON INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 051898/0559 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2016
From: CAFARELLI, DOMINICK; BOMMANA, MURALI; DAHIYA, SANDEEP; SHU, JESSE C.; KARTHA, ANOOP V.
To: GIGAMON INC.
Reel/Frame 037692/0028 →
Continuity (2)
Provisional Application 61800098 · Mar 15, 2013
Related Publication 20140321278A1 · Oct 30, 2014
Cited By (10)
US 12,192,078 US 12,212,476 US 12,224,921 US 12,231,307 US 12,231,308 US 12,278,746 US 12,335,275 US 12,596,568 US 12,657,049 US 12,670,003