IP Library Granted Patent US 9,088,508
Granted Patent B1
US 9,088,508 · App. 14/251,049 · Granted Jul 21, 2015

Incremental application of resources to network traffic flows based on heuristics and business policies

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,088,508
App. No.
14/251,049
Granted
Jul 21, 2015
Kind
B1
Abstract

Disclosed herein are system, method, and computer program product embodiments for increasingly applying network resources to traffic flows based on heuristics and policy conditions. A network determines that a traffic flow satisfies a first condition and transmits a first portion of the traffic flow to a network service. A network service then inspects the first portion of the traffic flow at a first level of detail and determines that the traffic flow satisfies a second condition. The network can then transmit a second portion of the traffic flow to the network service based on the determining the traffic flow satisfies the second condition. The network service can inspect the second portion of the traffic flow at a second level of detail, wherein the inspecting at the second level of detail requires a different amount of computing resources than the inspecting at the first level of detail.

Claims (54)

1. A computer-implemented method of inspecting network traffic, comprising:

determining that a traffic flow satisfies a first condition;

transmitting a first portion of the traffic flow to a network service based on the determining the traffic flow satisfies the first condition;

inspecting, at the network service, the first portion of the traffic flow at a first level of detail based on the first condition;

determining, based on the inspecting, that the traffic flow satisfies a second condition;

transmitting a second portion of the traffic flow to the network service based on the determining the traffic flow satisfies the second condition;

inspecting, at the network service, the second portion of the traffic flow at a second level of detail, wherein the inspecting at the second level of detail requires a different amount of computing resources than the inspecting at the first level of detail

wherein the second portion of the traffic flow comprises a larger amount of information than the first portion of the traffic flow.

2. The method of claim 1 , further comprising:

wherein the first condition comprises one of a heuristic, a policy associated with the traffic flow, or an event of interest.

3. The method of claim 1 , further comprising:

wherein the second condition comprises one of a heuristic, a policy associated with the traffic flow, or an event of interest.

4. The method of claim 1 , wherein a first portion of a traffic flow comprises a random sample of packets.

5. The method of claim 1 , further comprising:

transmitting a third portion of the traffic flow to the network service based on the inspecting the traffic flow at the second level of detail;

inspecting, at the network service, the third portion of the traffic flow at a third level of detail.

6. The method of claim 1 , further comprising:

determining that the traffic flow no longer satisfies the second condition; and

when the traffic flow is determined to no longer satisfy the second condition, inspecting, at the network service, a third portion of the traffic flow at the first level of detail.

7. The method of claim 1 , wherein the inspecting the second portion of the traffic flow at a second level of detail comprises performing an intrusion detection analysis.

8. The method of claim 1 , wherein the first condition comprises a parameter associated with the traffic flow and a level of security desired for the traffic flow.

9. A system comprising:

an analytics module configured to determine that a traffic flow satisfies a first condition;

a controller configured to configure one or more routers to:

transmit a first portion of the traffic flow to a network service based on the determining the traffic flow satisfies the first condition;

a network service configured to:

inspect the first portion of the traffic flow at a first level of detail based on the first condition; and

determine, based on the inspecting, that the traffic flow satisfies a second condition;

wherein the controller is further configured to configure one or more routers to transmit a second portion of the traffic flow to the network service based on the determining the traffic flow satisfies the second condition,

wherein the network service is further configured to inspect the second portion of the traffic flow at a second level of detail, wherein the inspecting at the second level of detail requires a different amount of computing resources than the inspecting at the first level of detail, and

wherein the second portion of the traffic flow comprises a larger amount of information than the first portion of the traffic flow.

10. The system of claim 9 , further comprising:

wherein the first condition comprises one of a heuristic, a policy associated with the traffic flow, or an event of interest.

11. The system of claim 9 , further comprising:

wherein the second condition comprises one of a heuristic, a policy associated with the traffic flow, or an event of interest.

12. The system of claim 9 , wherein a first portion of a traffic flow comprises a random sample of packets.

13. The system of claim 9 , further comprising:

transmitting a third portion of the traffic flow to the network service based on the inspecting the traffic flow at the second level of detail;

inspecting, at the network service, the third portion of the traffic flow at a third level of detail.

14. The system of claim 9 , wherein the inspecting the second portion of the traffic flow at a second level of detail comprises performing an intrusion detection analysis.

15. The system of claim 9 , wherein the first condition comprises a parameter associated with the traffic flow and a level of security desired for the traffic flow.

16. The system of claim 9 , wherein the network service is configured to determine that the traffic flow no longer satisfies the second condition, and when the traffic flow is determined to no longer satisfy the second condition, inspect, at the network service, a third portion of the traffic flow at the first level of detail.

17. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, causes the at least one computing device to perform operations comprising:

determining that a traffic flow satisfies a first condition;

transmitting a first portion of the traffic flow to a network service based on the determining the traffic flow satisfies the first condition;

inspecting, at the network service, the first portion of the traffic flow at a first level of detail based on the first condition;

determining, based on the inspecting, that the traffic flow satisfies a second condition;

transmitting a second portion of the traffic flow to the network service based on the determining the traffic flow satisfies the second condition;

inspecting, at the network service, the second portion of the traffic flow at a second level of detail, wherein the inspecting at the second level of detail requires a different amount of computing resources than the inspecting at the first level of detail,

wherein the second portion of the traffic flow comprises a larger amount of information than the first portion of the traffic flow.

18. The computer-readable medium of claim 17 , further comprising:

wherein the first condition comprises one of a heuristic, a policy associated with the traffic flow, or an event of interest.

19. The computer-readable medium of claim 17 , further comprising:

wherein the second condition comprises one of a heuristic, a policy associated with the traffic flow, or an event of interest.

Assignments (4)
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (SECOND LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0749 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (FIRST LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0858 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2014
From: TW TELECOM HOLDINGS INC.
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 034290/0955 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2014
From: CAPUTO, PETE JOSEPH, II; SELLA, WILLIAM THOMAS
To: TW TELECOM HOLDINGS, INC.
Reel/Frame 032658/0560 →