IP Library Granted Patent US 9,210,135
Granted Patent B2
US 9,210,135 · App. 14/500,893 · Granted Dec 8, 2015

Resynchronization of passive monitoring of a flow based on hole detection

Inventors: Jesse Abraham Rothstein (Seattle, WA); Arindum Mukerji (Seattle, WA); Bhushan Prasad Khanal (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L63/0428H04L43/0823H04L43/0876H04L43/12H04L43/18H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,210,135
App. No.
14/500,893
Granted
Dec 8, 2015
Kind
B2
Abstract

Embodiments are directed towards resynchronizing the processing of a monitored flow based on hole detection. A network monitoring device (NMD) may be employed to passively monitor flows of packets for a session between endpoints. The NMD may receive copies of the monitored flow and perform processes on the monitored flow. In some situations, some copies of packets may not be fully processed by the NMD, creating a hole in the processing. If a hole is detected in the monitored flow and the processing of the monitored flow is desynchronized, then the NMD may suspend processing until it is resynchronized or for a remainder of the session. If the processing is desynchronized, then the NMD may resynchronize the processing by resuming the processing of the monitored flow at a downstream position of the monitored flow based on the detected hole.

Claims (76)

1. A method for improving monitoring packets of data over a network, wherein at least one network device that includes a hardware processor that executes software code that performs actions, comprising:

passively monitoring at least one flow of packets for a session between at least two endpoints;

when the at least one monitored flow is encrypted, employing a block decryption key to decrypt the encrypted monitored flow;

determining an initialization vector based on a complete block of the at least one encrypted monitored flow after detecting a hole;

employing the initialization vector to continue decryption of the encrypted monitored flow after detecting the complete block; and

when generating information from the at least one monitored flow is desynchronized based on at least detection of the hole, re-synchronizing the generating of information based at least on resuming generating information at a downstream position that is based on at least one aspect of the hole; and

wherein resuming generating information includes employing heuristics to provide a probability estimate that one or more known protocol sequences is uniquely identified in the monitored flow and employing a machine learning probability to determine data patterns of a communication boundary that provides for resynchronization of the one or more known protocol sequences in the monitored flow.

2. The method of claim 1 , further comprising at least one of:

suspending the generating of information until it is resynchronized based at least on a size of the hole; or

suspending the generating of information for a remainder of the session.

3. The method of claim 1 , wherein when the generating is desynchronized, performing other actions, including when a known sequence of data is determined to be included after the hole in the at least one monitored flow, continuing the generating of information based on the known sequence of data.

4. The method of claim 1 , wherein when the generating is desynchronized, performing other actions, including:

performing a traffic analysis on the at least one monitored flow after detecting the hole;

determining when a known sequence of data is included in the at least one monitored flow based on a result of the traffic analysis; and

when the known sequence of data is included in the at least one monitored flow, continuing the generating of information based on the known sequence of data.

5. The method of claim 1 , wherein the hole includes one or more of the packets that are successfully communicated between the at least two endpoints and corresponding copies of the packets are dropped before the generating of information.

6. The method of claim 1 , further comprising:

when the at least one monitored flow is determined to be encrypted, decrypting the at least one monitored flow based on at least a generated keystream;

advancing the generated keystream based on at least a size of the hole; and

employing the advanced keystream to continue decryption of the at least one encrypted monitored flow after detecting the hole.

7. A network device for improving monitoring packets of data over a network, comprising:

a memory for storing data and instructions; and

a processor that executes the instructions to enable actions, including:

passively monitoring at least one flow of packets for a session between at least two endpoints;

when the at least one monitored flow is encrypted, employing a block decryption key to decrypt the encrypted monitored flow;

determining an initialization vector based on a complete block of the at least one encrypted monitored flow after detecting a hole;

employing the initialization vector to continue decryption of the encrypted monitored flow after detecting the complete block; and

when generating information from at the least one monitored flow is desynchronized based on at least detection of the hole, re-synchronizing the generating of information based at least on resuming generating information at a downstream position that is based on at least one aspect of the hole when generating information from at the least one monitored flow is desynchronized based on at least detection of the hole, re-synchronizing the generating of information based at least on resuming generating information at a downstream position that is based on at least one aspect of the hole; and

wherein resuming generating information includes employing heuristics to provide a probability estimate that one or more known protocol sequences is uniquely identified in the monitored flow and employing a machine learning probability to determine data patterns of a communication boundary that provides for resynchronization of the one or more known protocol sequences in the monitored flow.

8. The network device of claim 7 , further comprising at least one of:

suspending the generating of information until it is resynchronized based at least on a size of the hole; or

suspending the generating of information for a remainder of the session.

9. The network device of claim 7 , wherein when the generating is desynchronized, performing other actions, including when a known sequence of data is determined to be included after the hole in the at least one monitored flow, continuing the generating of information based on the known sequence of data.

10. The network device of claim 7 , wherein when the generating is desynchronized, performing other actions, including:

performing a traffic analysis on the at least one monitored flow after detecting the hole;

determining when a known sequence of data is included in the at least one monitored flow based on a result of the traffic analysis; and

when the known sequence of data is included in the at least one monitored flow, continuing the generating of information based on the known sequence of data.

11. The network device of claim 7 , wherein the hole includes one or more of the packets that are successfully communicated between the at least two endpoints and corresponding copies of the packets are dropped before the generating of information.

12. The network device of claim 7 , further comprising:

when the at least one monitored flow is determined to be encrypted, decrypting the at least one monitored flow based on at least a generated keystream;

advancing the generated keystream based on at least a size of the hole; and

employing the advanced keystream to continue decryption of the at least one encrypted monitored flow after detecting the hole.

13. A system for improving monitoring packets of data over a network, comprising: at least two endpoints, wherein each of the at least two endpoint at least includes: a transceiver that is operative to communicate at least with at least one other endpoint over the network; and at least one network device, including: a memory for storing data and instructions; and a processor that executes the instructions to enable actions, including passively monitoring at least one flow of packets for a session between the at least two endpoints; when the at least one monitored flow is encrypted, employing a block decryption key to decrypt the encrypted monitored flow; determining an initialization vector based on a complete block of the at least one encrypted monitored flow after detecting a hole; employing the initialization vector to continue decryption of the encrypted monitored flow after detecting the complete block; and when generating information from at the least one monitored flow is desynchronized based on at least detection of the hole, re-synchronizing the generating of information based at least on resuming generating information at a downstream position that is based on at least one aspect of the hole when generating information from at the least one monitored flow is desynchronized based on at least detection of the hole, re-synchronizing the generating of information based at least on resuming generating information at a downstream position that is based on at least one aspect of the hole; and wherein resuming generating information includes employing heuristics to provide a probability estimate that one or more known protocol sequences is uniquely identified in the monitored flow and employing a machine learning probability to determine data patterns of a communication boundary that provides for re-synchronization of the one or more known protocol sequences.

14. The network device of claim 13 , further comprising at least one of:

suspending the generating of information until it is resynchronized based at least on a size of the hole; or

suspending the generating of information for a remainder of the session.

15. The network device of claim 13 , wherein when the generating is desynchronized, performing other actions, including when a known sequence of data is determined to be included after the hole in the at least one monitored flow, continuing the generating of information based on the known sequence of data.

16. The network device of claim 13 , wherein when the generating is desynchronized, performing other actions, including:

performing a traffic analysis on the at least one monitored flow after detecting the hole;

determining when a known sequence of data is included in the at least one monitored flow based on a result of the traffic analysis; and

when the known sequence of data is included in the at least one monitored flow, continuing the generating of information based on the known sequence of data.

17. The network device of claim 13 , wherein the hole includes one or more of the packets that are successfully communicated between the at least two endpoints and corresponding copies of the packets are dropped before the generating of information.

18. The network device of claim 13 , further comprising:

when the at least one monitored flow is determined to be encrypted, decrypting the at least one monitored flow based on at least a generated keystream;

advancing the generated keystream based on at least a size of the hole; and

employing the advanced keystream to continue decryption of the at least one encrypted monitored flow after detecting the hole.

19. A processor readable non-transitory storage media that includes instructions for improving monitoring packets of data over a network, wherein the execution of the instructions by a processor enables actions, comprising:

passively monitoring at least one flow of packets for a session between at least two endpoints;

when the at least one monitored flow is encrypted, employing a block decryption key to decrypt the encrypted monitored flow;

determining an initialization vector based on a complete block of the at least one encrypted monitored flow after detecting a hole;

employing the initialization vector to continue decryption of the encrypted monitored flow after detecting the complete block; and

when generating information from at the least one monitored flow is desynchronized based on at least detection of the hole, re-synchronizing the generating of information based at least on resuming generating information at a downstream position that is based on at least one aspect of the hole when generating information from at the least one monitored flow is desynchronized based on at least detection of the hole, re-synchronizing the generating of information based at least on resuming generating information at a downstream position that is based on at least one aspect of the hole; and

wherein resuming generating information includes employing heuristics to provide a probability estimate that one or more known protocol sequences is uniquely identified in the monitored flow and employing a machine learning probability to determine data patterns of a communication boundary that provides for resynchronization of the one or more known protocol sequences in the monitored flow.

20. The media of claim 19 , further comprising at least one of:

suspending the generating of information until it is resynchronized based at least on a size of the hole; or

suspending the generating of information for a remainder of the session.

21. The media of claim 19 , wherein when the generating is desynchronized, performing other actions, including when a known sequence of data is determined to be included after the hole in the at least one monitored flow, continuing the generating of information based on the known sequence of data.

22. The media of claim 19 , wherein when the generating is desynchronized, performing other actions, including:

performing a traffic analysis on the at least one monitored flow after detecting the hole;

determining when a known sequence of data is included in the at least one monitored flow based on a result of the traffic analysis; and

when the known sequence of data is included in the at least one monitored flow, continuing the generating of information based on the known sequence of data.

23. The media of claim 19 , wherein the hole includes one or more of the packets that are successfully communicated between the at least two endpoints and corresponding copies of the packets are dropped before the generating of information.

24. The media of claim 19 , further comprising:

when the at least one monitored flow is determined to be encrypted, decrypting the at least one monitored flow based on at least a generated keystream;

advancing the generated keystream based on at least a size of the hole; and

employing the advanced keystream to continue decryption of the at least one encrypted monitored flow after detecting the hole.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2014
From: ROTHSTEIN, JESSE ABRAHAM; MUKERJI, ARINDUM; KHANAL, BHUSHAN PRASAD
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 033844/0679 →
Continuity (2)
Continuation 13831673 · Mar 15, 2013
Related Publication 20150019867A1 · Jan 15, 2015