IP Library Granted Patent US 9,674,053
Granted Patent B2
US 9,674,053 · App. 14/610,595 · Granted Jun 6, 2017

Automatic target selection

Inventor: Anil Rao (Santa Clara, CA)
Assignee: Gigamon Inc.
H04L43/028H04L43/062H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,674,053
App. No.
14/610,595
Granted
Jun 6, 2017
Kind
B2
Abstract

A method of identifying targets for monitoring includes: obtaining a user-defined filter map, the user-defined filter map having one or more filter rules for matching against network traffic when the user-defined filter map is used by a network system to process the network traffic; and determining a set of one or more targets by a processing unit based at least in part on the user-defined filter map, wherein the processing unit comprises a target selection module configured to access a list of available targets from a database, and select the one or more targets from the list of available targets based at least in part on the user-defined filter map.

Claims (281)

1. A method of identifying targets for monitoring, comprising:

obtaining a user-defined filter map, the user-defined filter map having one or more filter rules for matching against network traffic when the user-defined filter map is used by a network system to process the network traffic; and

determining a set of one or more targets by a processing unit based at least in part on the user-defined filter map, wherein the processing unit comprises a target selection module configured to access a list of available targets from a database, and select the one or more targets from the list of available targets based at least in part on the user-defined filter map, wherein the target selection module is configured to select the one or more targets from the list of available targets based on:

C

=

{

subset

of

V

associated

with

one

or

more

filter

components

or

V

,

R

=

i

=

1

m

C

i

,

and

F

=

j

=

1

n

R

j

wherein V represents the list of available targets.

2. The method of claim 1 , wherein the target selection module is configured to select the one or more targets from the list of available targets also based on an inclusion set I defined as:

I

=

{

targets

to

be

included

(

if

specified

)

V

(

otherwise

)

.

3. The method of claim 2 , wherein the target selection module is configured to select the one or more targets from the list of available targets also based on an exclusion set E defined as:

E

=

{

targets

to

be

excluded

(

if

specified

)

(

otherwise

)

.

4. The method of claim 3 , wherein the one or more targets constitute a target set T defined as T=(F I)−E.

5. The method of claim 1 , wherein the targets comprise a virtual machine (VM).

6. The method of claim 1 , wherein the targets comprise a virtualized Network Interface Card (vNIC).

7. The method of claim 1 , wherein the act of determining the set of one or more targets comprises determining a first set of targets that are at least one possible source(s) or recipient(s) of packets satisfying any of the one or more filter rules in the user-defined filter map.

8. The method of claim 1 , wherein the user-defined filter map comprises a first filter rule having first multiple filter components, and wherein the act of determining the set of one or more targets comprises determining a first set of targets by the processing unit that are at least one of possible source(s) or recipient(s) of packets satisfying all of the first multiple filter components of the first filter rule.

9. The method of claim 8 , wherein the user-defined filter map comprises a second filter rule having second multiple filter components, and wherein the act of determining the set of one or more targets further comprises determining a second set of targets by the processing unit that are at least one of possible source(s) or recipient(s) of packets satisfying all of the second multiple filter components of the second filter rule.

10. The method of claim 1 , wherein the obtained user-defined filter map comprises a newly created filter rule, and the act of determining the set of one or more targets is performed by the processing unit in response to the newly created filter rule.

11. The method of claim 1 , wherein the obtained user-defined filter map comprises a modified filter rule resulted from a modification of an existing filter rule, and the act of determining the set of one or more targets is performed by the processing unit in response to the modified filter rule.

12. The method of claim 1 , wherein one of the one or more filter rules comprises one or more filter components, the one or more filter components comprising information regarding a switch port, a media access control (MAC) address, a virtual local area network (VLAN) identifier, an ethertype, an Internet protocol (IP) address, a wildcard, or any combination of the foregoing.

13. A method identifying targets for monitoring, comprising:

obtaining a user-defined filter map, the user-defined filter map having one or more filter rules for matching against network traffic when the user-defined filter map is used by a network system to process the network traffic;

determining a set of one or more targets by a processing unit based at least in part on the user-defined filter map, wherein the processing unit comprises a target selection module configured to access a list of available targets from a database, and select the one or more targets from the list of available targets based at least in part on the user-defined filter map, wherein the act of determining the set of one or more targets comprises determining a first set of targets that are at least one of possible source(s) or recipient(s) of packets satisfying any of the one or more filter rules in the user-defined filter map;

obtaining information regarding an inclusion set; and

determining a second set of targets based on the information regarding the inclusion set;

wherein the set of one or more targets is determined based on: (the first set of targets)∩(the second set of targets).

14. The method of claim 13 , further comprising:

obtaining information regarding an exclusion set; and determining a third set of targets based on the information regarding the exclusion set;

wherein the set of one or more targets is determined based on: ((the first set of targets)∩(the second set of targets))−(the third set of targets).

15. An apparatus for identifying targets for monitoring, comprising:

a non-transitory medium for storing a user-defined filter map, the user-defined filter map having one or more filter rules for matching against network traffic when the user-defined filter map is used by a network system to process the network traffic;

a processing unit configured for determining a set of one or more targets based at least in part on the user-defined filter map;

wherein the processing unit comprises a target selection module configured to determine the set of one or more targets by accessing a list of available targets from a database, and selecting the one or more targets from the list of available targets based at least in part on the user-defined filter map, wherein the target selection module is configured to select the one or more targets from the list of available targets based on:

C

=

{

subset

of

V

associated

with

one

or

more

filter

components

or

V

,

R

=

i

=

1

m

C

i

,

and

F

=

j

=

1

n

R

j

wherein V represents the list of available targets.

16. The apparatus of claim 15 , wherein the target selection module is configured to select the one or more targets from the list of available targets also based on an inclusion set I defined as:

I

=

{

targets

to

be

included

(

if

specified

)

V

(

otherwise

)

.

17. The apparatus of claim 16 , wherein the target selection module is configured to select the one or more targets from the list of available targets also based on an exclusion set E defined as:

E

=

{

targets

to

be

excluded

(

if

specified

)

(

otherwise

)

.

18. The apparatus of claim 17 , wherein the one or more targets constitute a target set T defined as T=(F I)−E.

19. The apparatus of claim 15 , wherein the targets comprise a virtual machine (VM).

20. The apparatus of claim 15 , wherein the targets comprise a virtualized Network Interface Card (vNIC).

21. The apparatus of claim 15 , wherein the processing unit is configured for determining the set of one or more targets by determining a first set of targets that are at least one possible source(s) or recipient(s) of packets satisfying any of the one or more filter rules in the user-defined filter map.

22. The apparatus of claim 15 , wherein the user-defined filter map comprises a first filter rule having first multiple filter components, and wherein the processing unit is configured for determining the set of one or more targets by determining a first set of targets by the processing unit that are at least one of possible source(s) or recipient(s) of packets satisfying all of the first multiple filter components of the first filter rule.

23. The apparatus of claim 22 , wherein the user-defined filter map comprises a second filter rule having second multiple filter components, and wherein the processing unit is configured for determining the set of one or more targets further by determining a second set of targets by the processing unit that are at least one of possible source(s) or recipient(s) of packets satisfying all of the second multiple filter components of the second filter rule.

24. The apparatus of claim 15 , wherein the obtained user-defined filter map comprises a newly created filter rule, and the processing unit is configure for determining the set of one or more targets in response to the newly created filter rule.

25. The apparatus of claim 15 , wherein the obtained user-defined filter map comprises a modified filter rule resulted from a modification of an existing filter rule, and the processing unit is configured for determining the set of one or more targets in response to the modified filter rule.

26. The apparatus of claim 15 , wherein one of the one or more filter rules comprises one or more filter components, the one or more filter components comprising information regarding a switch port, a media access control (MAC) address, a virtual local area network (VLAN) identifier, an ethertype, an Internet protocol (IP) address, a wildcard, or any combination of the foregoing.

27. The apparatus for identifying targets for monitoring, comprising:

a non-transitory medium for storing a user-defined filter map, the user-defined filter map having one or more filter rules for matching against network traffic when the user-defined filter map is used by a network system to process the network traffic;

a processing unit configured for determining a set of one or more targets based at least in part on the user-defined filter map and determining the set of one or more targets by determining a first set of targets that are at least one of possible source(s) or recipient(s) of packets satisfying any of the one or more filter rules in the user-defined filter map;

wherein the processing unit comprises a target selection module configured to determine the set of one or more targets by accessing a list of available targets from a database, and selecting the one or more targets from the list of available targets based at least in part on the user-defined filter map;

obtaining information regarding an inclusion set; and

determining a second set of targets based on the information regarding the inclusion set;

wherein the processing unit is configured to determine the set of one or more targets based on: (the first set of targets)∩(the second set of targets).

28. The apparatus of claim 27 , wherein the processing unit is further configured for:

obtaining information regarding an exclusion set; and

determining a third set of targets based on the information regarding the exclusion set;

wherein the processing unit is configured to determine the set of one or more targets based on: ((the first set of targets)∩(the second set of targets))−(the third set of targets).

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Mar 11, 2022
From: JEFFERIES FINANCE LLC
To: GIGAMON INC.
Reel/Frame 059362/0491 →
SECURITY INTEREST Recorded Mar 11, 2022
From: GIGAMON INC.; ICEBRG LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 059362/0717 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 11, 2020
From: GIGAMON INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 051898/0559 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2015
From: RAO, ANIL
To: GIGAMON INC.
Reel/Frame 035256/0629 →
Continuity (1)
Related Publication 20160226726A1 · Aug 4, 2016