IP Library Granted Patent US 10,511,498
Granted Patent B1
US 10,511,498 · App. 14/671,457 · Granted Dec 17, 2019

Monitoring and analysis of interactions between network endpoints

Inventors: Sandhya Narayan (Saratoga, CA); Stuart M. Bailey (San Jose, CA)
Assignee: Infoblox Inc.
H04L43/04H04L43/0823H04L43/0876H04L61/1511H04L63/1408H04L63/1441H04L67/02H04L67/10H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,511,498
App. No.
14/671,457
Granted
Dec 17, 2019
Kind
B1
Abstract

Techniques for monitoring and analysis of interactions between network endpoints are disclosed. In some embodiments, a process for monitoring and analysis of interactions between network endpoints includes collecting Domain Name System (DNS) response data from a network device; determining network endpoint interactions based on an analysis of the DNS response data (e.g., using a processor); and generating a graph corresponding to the network endpoint interactions. For example, the network device can include a DNS device and/or a software-defined networking (SDN) device (e.g., an SDN switch, such as an OpenFlow switch).

Claims (91)

1. A system for monitoring and analysis of interactions between network endpoints, comprising:

a processor configured to:

collect Domain Name System (DNS) response data from a network device, comprising to:

identify DNS responses from the network device that match User Datagram Protocol (UDP) port 53;

determine network endpoint interactions based on an analysis of the DNS response data, comprising to:

identify and group the network endpoint interactions to obtain various groups of activities based on the following:

initialize a first node in a set of nodes with a first label, each node of the set of node having a unique label;

identify a maximum number of neighbors of the first node having a same label, the same label corresponding to a second node, the second node being different from the first node;

change the first label to a second label; and

group a second node with the first node to obtain a first group, the second node having the same label as the first node;

determine whether anomalous network activity has occurred based on a comparison of a first number of groups of network endpoint interactions for a first period of time and a second number of groups of network endpoint interactions for a second period of time, the first period of time being different from the second period of time, wherein to determine whether the anomalous network activity has occurred comprises to:

compare the first number of groups and the second number of groups to obtain a difference; and

in response to a determination that the difference satisfies a threshold, determine that the anomalous network activity has occurred;

in response to determination that the anomalous network activity has occurred, perform a remedial action on an enterprise network; and

generate a graph corresponding to the network endpoint interactions; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the network device includes a DNS device.

3. The system of claim 1 , wherein the network device includes a software-defined networking (SDN) device.

4. The system of claim 1 , wherein the network device includes a DNS device and/or a software-defined networking (SDN) device.

5. The system of claim 1 , wherein the network device includes a software-defined networking (SDN) switch.

6. The system of claim 1 , wherein the network device includes an OpenFlow switch.

7. The system of claim 1 , wherein the processor is further configured to:

store the DNS response data in a data store.

8. The system of claim 1 , wherein the processor is further configured to:

execute a telemetry platform, wherein the telemetry platform includes a controller for collecting the DNS response data from the network device.

9. The system of claim 1 , wherein the processor is further configured to:

configure a software-defined networking (SDN) device to send the DNS response data to a controller of a telemetry platform.

10. The system of claim 1 , wherein the processor is further configured to:

generate a report based on an analysis of the network endpoint interactions for a plurality of network endpoints internal to the enterprise network.

11. A method for monitoring and analysis of interactions between network endpoints, comprising:

collecting Domain Name System (DNS) response data from a network device, comprising:

identifying DNS responses from the network device that match User Datagram Protocol (UDP) port 53;

determining network endpoint interactions based on an analysis of the DNS response data, comprising:

identifying and grouping the network endpoint interactions to obtain various groups of activities based on the following:

initializing a first node in a set of nodes with a first label, each node of the set of node having a unique label;

identifying a maximum number of neighbors of the first node having a same label, the same label corresponding to a second node, the second node being different from the first node;

changing the first label to a second label; and

grouping a second node with the first node to obtain a first group, the second node having the same label as the first node;

determining whether anomalous network activity has occurred based on a comparison of a first number of groups of network endpoint interactions for a first period of time and a second number of groups of network endpoint interactions for a second period of time, the first period of time being different from the second period of time, wherein the determining of whether the anomalous network activity has occurred comprises:

comparing the first number of groups and the second number of groups to obtain a difference; and

in response to a determination that the difference satisfies a threshold, determining that the anomalous network activity has occurred;

in response to determination that the anomalous network activity has occurred, performing a remedial action on an enterprise network; and

generating a graph corresponding to the network endpoint interactions.

12. The method of claim 11 , wherein the network device includes a DNS device and/or a software-defined networking (SDN) device.

13. The method of claim 11 , further comprising:

storing the DNS response data in a data store.

14. The method of claim 11 , further comprising:

executing a telemetry platform, wherein the telemetry platform includes a controller for collecting the DNS response data from the network device.

15. The method of claim 11 , further comprising:

configuring a software-defined networking (SDN) device to send the DNS response data to a controller of a telemetry platform.

16. A computer program product for monitoring and analysis of interactions between network endpoints, the computer program product being embodied in a tangible computer readable storage medium and comprising computer instructions for:

collecting Domain Name System (DNS) response data from a network device, comprising:

identifying DNS responses from the network device that match User Datagram Protocol (UDP) port 53;

determining network endpoint interactions based on an analysis of the DNS response data, comprising:

identifying and grouping the network endpoint interactions to obtain various groups of activities based on the following:

initializing a first node in a set of nodes with a first label, each node of the set of node having a unique label;

identifying a maximum number of neighbors of the first node having a same label, the same label corresponding to a second node, the second node being different from the first node;

changing the first label to a second label; and

grouping a second node with the first node to obtain a first group, the second node having the same label as the first node;

determining whether anomalous network activity has occurred based on a comparison of a first number of groups of network endpoint interactions for a first period of time and a second number of groups of network endpoint interactions for a second period of time, the first period of time being different from the second period of time, wherein the determining of whether the anomalous network activity has occurred comprises:

comparing the first number of groups and the second number of groups to obtain a difference; and

in response to a determination that the difference satisfies a threshold, determining that the anomalous network activity has occurred;

in response to determination that the anomalous network activity has occurred, performing a remedial action on an enterprise network; and

generating a graph corresponding to the network endpoint interactions.

17. The computer program product recited in claim 16 , wherein the network device includes a DNS device and/or a software-defined networking (SDN) device.

18. The computer program product recited in claim 16 , further comprising computer instructions for:

storing the DNS response data in a data store.

19. The computer program product recited in claim 16 , further comprising computer instructions for:

executing a telemetry platform, wherein the telemetry platform includes a controller for collecting the DNS response data from the network device.

20. The computer program product recited in claim 16 , further comprising computer instructions for:

configuring a software-defined networking (SDN) device to send the DNS response data to a controller of a telemetry platform.

21. A system for monitoring and analysis of interactions between network endpoints, comprising:

a controller for collecting network data from a plurality of network devices in an enterprise network, wherein the collecting of the network data comprises identifying DNS responses from the plurality of network devices that match User Datagram Protocol (UDP) port 53;

a data store in communication with the controller for storing the network data, comprising:

identifying and grouping the network endpoint interactions to obtain various groups of activities based on the following:

initializing a first node in a set of nodes with a first label, each node of the set of node having a unique label;

identifying a maximum number of neighbors of the first node having a same label, the same label corresponding to a second node, the second node being different from the first node;

changing the first label to a second label; and

grouping a second node with the first node to obtain a first group, the second node having the same label as the first node;

an analyzer in communication with the data store for:

performing an analysis of the network data to determine interactions between network endpoints;

determining whether anomalous network activity has occurred based on a comparison of a first number of groups of network endpoint interactions for a first period of time and a second number of groups of network endpoint interactions for a second period of time, the first period of time being different from the second period of time, wherein the determining of whether the anomalous network activity has occurred comprises:

comparing the first number of groups and the second number of groups to obtain a difference; and

in response to a determination that the difference satisfies a threshold, determining that the anomalous network activity has occurred;

in response to determination that the anomalous network activity has occurred, performing a remedial action on the enterprise network; and

a graphics visualizer in communication with the analyzer for generating a graph based on the interactions between network endpoints.

22. The system of claim 21 , wherein the plurality of network devices includes physical network devices, virtual network devices, and/or software-defined networking (SDN) devices.

23. The system of claim 21 , further comprising:

a data aggregator in communication with the controller for aggregating the network data.

24. The system of claim 21 , further comprising:

a web server in communication with the analyzer for web-based network communications with the system.

Assignments (7)
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS (RELEASES RF 040575/0549) Recorded Dec 3, 2020
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: INFOBLOX INC.
Reel/Frame 054585/0914 →
FIRST LIEN SECURITY AGREEMENT Recorded Dec 2, 2020
From: INFOBLOX INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054615/0317 →
SECOND LIEN SECURITY AGREEMENT Recorded Dec 2, 2020
From: INFOBLOX INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054615/0331 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (RELEASES RF 040579/0302) Recorded Oct 23, 2019
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: INFOBLOX, INC.
Reel/Frame 050809/0980 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 8, 2016
From: INFOBLOX INC.
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 040579/0302 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 7, 2016
From: INFOBLOX INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 040575/0549 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2015
From: NARAYAN, SANDHYA; BAILEY, STUART M.
To: INFOBLOX INC.
Reel/Frame 035819/0224 →
Continuity (1)
Provisional Application 62120829 · Feb 25, 2015
Cited By (23)
US 12,204,921 US 12,225,042 US 12,236,172 US 12,267,347 US 12,267,369 US 12,335,310 US 12,438,851 US 12,438,916 US 12,443,999 US 12,452,284 US 12,457,223 US 12,483,599 US 12,493,914 US 12,494,916 US 12,500,767 US 12,500,823 US 12,500,920 US 12,500,929 US 12,506,754 US 12,536,593 US 12,556,523 US 12,598,197 US 12,719,933