IP Library Granted Patent US 10,097,404
Granted Patent B2
US 10,097,404 · App. 14/856,416 · Granted Oct 9, 2018

Methods and systems for time-based application domain classification and mapping

Inventors: Navneet Yadav (Cupertino, CA); Arivu Ramasamy (San Jose, CA); Giorgio Valentini (Walnut Creek, CA)
Assignee: CLOUDGENIX, INC.
H04L41/0668G06F17/30598G06F17/30876H04L12/4633H04L12/4641H04L43/0817H04L45/28H04L47/781H04L47/825H04L69/40H04L43/0811H04L43/10H04L45/22H04L61/1511H04L61/1523H04L61/2503H04W84/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,097,404
App. No.
14/856,416
Granted
Oct 9, 2018
Kind
B2
Abstract

A method includes detecting at a device on a network an application having an anchor domain, marking the application with a traffic source having an entry point domain that accessed the application and a time of detection and designating network flows from the traffic source within a predetermined time from the time of detection as belonging to the application.

Claims (28)

1. A method comprising:

detecting, by a configurable device on a network, an application on the network having an anchor domain;

marking, by the configurable device, any traffic source that accesses the application via the anchor domain, and identifying a corresponding time of application access by each marked traffic source;

monitoring, by the configurable device, for each marked traffic source, network flows from that traffic source; and

designating, by the configurable device, for each marked traffic source, those network flows from that traffic source that occur within a predetermined time period from the identified corresponding time of application access by that traffic source as belonging to the application.

2. The method of claim 1 , further comprising modeling, by a multi-tenant controller, application sessions of the application.

3. The method of claim 1 , further comprising predicting, by a multi-tenant controller, bandwidth requirements of the application.

4. The method of claim 1 , further comprising performing, by a multi-tenant controller, anomalous session identification, quarantine, and restriction.

5. The method of claim 1 , further comprising analyzing, by a multi-tenant controller, traffic flow information with respect to the application.

6. The method of claim 5 , wherein the analyzing of traffic flow information with respect to the application is performed on a per session basis.

7. The method of claim 1 , wherein the network flows are encrypted.

8. The method of claim 1 , wherein the network comprises connectivity selected from a group including hybrid, physical, and logical.

9. The method of claim 1 , wherein a policy string defines a business policy that applies to the network flows.

10. The method of claim 9 , wherein the policy string comprises a policy string format.

11. A networked branch device configured to:

detect an application having an anchor domain on a network;

mark, via a processor having a memory storing instructions for performing actions, any traffic source that accesses the application via the anchor domain of the application, and identify a corresponding time of application access by that marked traffic source;

monitor network flows from each marked traffic source;

designate those network flows from the any marked traffic source that occur within a predetermined time period from the identified corresponding time of application access by the marked traffic source as belonging to the application.

12. The networked branch device of claim 11 , further configured to model application sessions.

13. The networked branch device of claim 11 , further configured to predict bandwidth requirements.

14. The networked branch device of claim 11 , further configured to perform anomalous session identification, quarantine, and restriction.

15. The networked branch device of claim 11 , further configured to perform application analysis.

16. The networked branch device of claim 15 , wherein the application analysis is performed on a per session basis.

17. The networked branch device of claim 11 , wherein the network flows are encrypted.

18. The networked branch device of claim 11 , wherein the network comprises connectivity selected from a group including hybrid, physical, and logical.

19. The networked branch device of claim 11 , wherein a policy string defines a business policy for application to the network flows.

20. The networked branch device of claim 19 , wherein the policy string comprises a policy string format.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2021
From: CLOUDGENIX INC.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 058449/0010 →
RELEASE OF SECURITY INTEREST Recorded May 5, 2020
From: COMERICA BANK
To: CLOUDGENIX, INC.
Reel/Frame 052573/0502 →
SECURITY INTEREST Recorded Aug 22, 2018
From: CLOUDGENIX, INC.
To: COMERICA BANK
Reel/Frame 046668/0798 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2015
From: YADAV, NAVNEET; RAMASAMY, ARIVU; VALENTINI, GIORGIO
To: CLOUDGENIX, INC.
Reel/Frame 036692/0457 →
Continuity (2)
Provisional Application 62051293 · Sep 16, 2014
Related Publication 20160080225A1 · Mar 17, 2016
Cited By (2)
US 12,413,645 US 12,556,443