IP Library Granted Patent US 9,832,140
Granted Patent B2
US 9,832,140 · App. 14/627,996 · Granted Nov 28, 2017

System and method for characterizing network traffic

Inventor: John Anthony Harper (Mountain View, CA)
Assignee: Saisei Networks, Pte Ltd.
H04L47/805H04L41/14H04L43/028H04L47/801H04L43/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,832,140
App. No.
14/627,996
Granted
Nov 28, 2017
Kind
B2
Abstract

A system monitors first traffic and identifies associations between applications that generated or received the traffic and parameters such as domain names, a remote host, and a local host referenced in the traffic. Subsequent traffic is monitored and determined to be generated by or addressed to an application according to such parameters in the subsequent traffic, such as remote host, local host, domain name, or port number. The subsequent traffic is associated with an application without requiring deep packet inspection (DPI). In particular, an application may be associated with a session based on evaluation of a single packet of the session.

Claims (16)

1. A system comprising one or more processors and one or more memory devices coupled to the one or more processors, the one or more memory devices storing executable and operational code effective to cause the one or more processors to:

evaluate first traffic to identify for each first session of a portion of first sessions in which the first traffic occurs and, according to the evaluation, identify a local host associated with the each first session, a remote host associated with the each first session, and an application of a plurality of applications associated with the each first session;

evaluate second traffic subsequent to the first traffic; and

for each second session of a plurality of second sessions in the second traffic—

identify a local host and a remote host associated with the each second session;

identify an inferred application of the plurality of applications that is associated with a same local host and a same remote host in one or more of the first sessions as the each second session; and

apply prioritization logic to subsequent traffic in the each second session according to the associating of the inferred application to the each second session;

wherein the executable and operational code effective to cause the one or more processors to identify the inferred application of the plurality of applications for the each second session by—

if (a) one or more first sessions of the portion of the first sessions are associated with a same domain name as the each second session, identifying as the inferred application, the application associated with the one or more first sessions of the portion of the first sessions associated with the same domain name as the each second session;

if not (a), then if (b) one or more first sessions of the portion of the first sessions are associated with the same remote host and the same local host as the each second session, identifying as the inferred application, the application associated with the one or more first sessions of the portion of the first sessions including the same remote host and the same remote host as the each second session; and

if not (b), then if one or more first sessions of the portion of the first sessions are associated with the same remote host as the each second session, identifying as the inferred application, the application associated with the one or more first sessions of the portion of the first sessions including the same remote host as the each second session.

2. The system of claim 1 , wherein the executable and operational code effective to cause the one or more processors to identify the inferred application of the plurality of applications for the each second session by:

if not (c), selecting the inferred application as an application that is mapped to a port associated with the each second session in a mapping database.

3. The system of claim 2 , wherein the executable and operational code effective to cause the one or more processors to identify the inferred application of the plurality of applications for the each second session by:

attempting to perform deep packet inspection (DPI) for the each second session; and

if DPI for the each second session is successful, selecting as the inferred application an application determined according to DPI.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2025
From: SAISEI NETWORKS, INC.
To: FIRSTWAVE CLOUD TECHNOLOGY LIMITED
Reel/Frame 071124/0500 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2023
From: SAISEI NETWORKS, PTE LTD.
To: SAISEI NETWORKS, INC.
Reel/Frame 064685/0507 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED ON REEL 034999 FRAME 0415. ASSIGNOR(S) HEREBY CONFIRMS THE SAISEI NETWORKS, PTE LTD.. Recorded Feb 23, 2015
From: HARPER, JOHN ANTHONY
To: SAISEI NETWORKS, INC.
Reel/Frame 035061/0757 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2015
From: HARPER, JOHN ANTHONY
To: SAISEI NETWORKS, PTE LTD.
Reel/Frame 034999/0415 →
Continuity (1)
Related Publication 20160248700A1 · Aug 25, 2016