IP Library Granted Patent US 10,212,224
Granted Patent B2
US 10,212,224 · App. 14/922,481 · Granted Feb 19, 2019

Device and related method for dynamic traffic mirroring

Inventors: David Kjendal (Kensington, NH); Markus Nispel (Frankfurt, DE); Ernie Eaton (Kennebunk, ME); Richard Graham (Derry, NH); Jeffrey Haskell (New Boston, NH)
Assignee: Extreme Networks, Inc.
H04L67/1095H04L41/0213H04L43/028H04L43/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,212,224
App. No.
14/922,481
Granted
Feb 19, 2019
Kind
B2
Abstract

A function is provided in a network system for the dynamic mirroring of network traffic for a variety of purposes including the identification of characteristics of the traffic. Multiple criteria are established for when, what and where to mirror the traffic. The criteria include what frames of traffic to mirror, what portions of the selected frames to mirror, one or more portals through which to mirror the selected frames, a destination for the mirroring and the establishment of a mirror in a device to carry out the mirroring. The criteria may also include when to stop the mirroring. The mirroring instructions can be changed based on the detection of a triggering event, such as authentication, device type or status, ownership of an attached function attached to the device, flow status, but not limited to that. The function may be established in one or more devices of the network.

Claims (68)

1. A device that mirrors selected frames to enhance security in a network system of a plurality of network infrastructure devices, the device comprising:

a. a physical port configured to:

receive, from an unknown device, packets including a plurality of frames, and

send selectable ones of the plurality of frames to another network infrastructure device that detects harmful network activity based on the selectable ones of the plurality of frames; and

b. processing circuitry configured to:

mirror, through a portal attached to the physical port, the selectable ones of the plurality of frames of the received packets by delivering, via a transport level tunnel, a copy of the selectable ones of the plurality of frames, to the another network infrastructure device based on one or more of criteria; and

determine that a data value in a packet field that indicates the harmful network activity has not been detected in the selectable ones of the plurality of frames;

stop the mirroring of the selectable ones of the plurality of frames, in response to determining that the data value that indicates the harmful network activity has not been detected in the selectable ones of the plurality of frames.

2. The device of claim 1 , wherein the one or more criteria includes a criterion for selecting one or more frames of the plurality of frames included in the received packets for mirroring.

3. The device of claim 1 , wherein the one or more criteria includes a criterion for selecting one or more portals through which to mirror the selectable ones of the plurality of frames.

4. The device of claim 1 , wherein the one or more criteria includes a criterion for selecting one or more portions of the plurality of frames for mirroring.

5. The device of claim 4 , wherein the one or more portions of the plurality of frames selected for mirroring is a field of the plurality of frames or a portion of the field of the plurality of frames and the field or the portion of the field is selected from a group consisting of address fields, protocol fields, length fields, byte count fields, and fields used in determining a value, meaning, placement or inclusion of other fields.

6. The device of claim 1 , wherein the criterion for stopping mirroring is based on information about an application running on the network system.

7. The device of claim 6 , wherein the information for stopping mirroring is information contained in the selectable ones of the plurality of frames.

8. The device of claim 1 , wherein the one or more criteria includes a criterion for establishing a destination of the mirrored selectable ones of the plurality of frames.

9. The device of claim 1 , configured to receive mirroring instructions for the device based on one or more of:

a. network events;

b. applications detected;

c. user authentication;

d. type of the device;

e. status of the device;

f. ownership of an attached function attached to the device; and

g. triggers.

10. The device of claim 1 , wherein the portal is a tunnel to another device of the network infrastructure.

11. The device of claim 1 , wherein the mirrored selectable ones of the plurality of frames are encapsulated in a data link layer encapsulation.

12. The device of claim 1 , wherein the portal or a type of the portal is selectable based on one or more of:

a. source address, destination address or both of the plurality of frames;

b. one or more fields in the plurality of frames to be mirrored;

c. performance;

d. security; and

e. location of a mirror, destination of the mirroring or both.

13. A method for mirroring frames of packets of a flow established in a network system signal exchange to enhance security, wherein a network system signal exchange includes a plurality of network infrastructure devices, and wherein the plurality of network infrastructure devices include a network infrastructure device configured to mirror the frames to another network infrastructure device that detects harmful network activity based on the frames, the method comprising:

a. receiving, at a physical port of the network infrastructure device, packets including a plurality of frames from an unknown device;

b. mirroring, by the network infrastructure device, through a portal attached to the physical port, selectable ones of the plurality of frames by delivering, via a transport level tunnel, a copy of the selectable ones of the plurality of frames, to the another network infrastructure device;

c. determining that a data value in a packet field that indicates the harmful network activity has not been detected in the selectable ones of the plurality of frames; and

d. stopping the mirroring of the selectable ones of the plurality of frames, in response to determining that the data value that indicates the harmful network activity has not been detected in the selectable ones of the plurality of frames.

14. The method of claim 13 , further comprising establishing one or more criteria for mirroring the selectable ones of the plurlity of frames.

15. The method of claim 14 , wherein the one or more criteria are selected from:

a. a first criterion for selecting one or more of the selectable ones of the plurality of frames for mirroring;

b. a second criterion for selecting one or more portions of the selectable ones of the frames for mirroring;

c. a third criterion for selecting the portal to mirror the selectable ones of the plurality of frames;

d. a fourth criterion for establishing a destination for the mirrored selectable ones of the plurality of frames; and

e. a fifth criterion for the establishment of a mirror in one or more of the plurality of network infrastructure devices.

16. The method of claim 13 , further comprising modifying automatically the mirroring of the selectable ones of the plurality of frames during mirroring.

17. The method of claim 13 , further comprising generating mirroring instructions based on one or more of:

a. network events;

b. applications detected;

c. user authentication;

d. type of the network infrastructure device;

e. status of the network infrastructure device;

f. ownership of an attached function attached to the network infrastructure device; and

g. triggers.

18. The method of claim 17 , further comprising modifying the mirroring instructions based on one or more of:

a. network events;

b. applications detected;

c. user authentication;

d. type of the network infrastructure device;

e. status of the network infrastructure device;

f. ownership of an attached function attached to the network infrastructure device; and

g. triggers.

19. The method of claim 13 , further comprising creating the portal in the network infrastructure device configured to mirror frames.

20. The method of claim 19 , wherein the portal or a type of the portal is selectable based on one or more of:

a. source address, destination address or both of the selectable ones of the plurality of frames;

b. one or more fields in the selectable ones of the plurality of frames to be mirrored;

c. performance;

d. security; and

e. location of a mirror, destination of the mirroring or both.

21. The method of claim 13 , wherein the network infrastructure device configured to mirror frames is a packet forwarding device of the plurality of network infrastructure devices.

Assignments (8)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2015
From: ENTERASYS NETWORKS, INC.
To: EXTREME NETWORKS, INC.
Reel/Frame 036880/0740 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2015
From: KJENDAL, DAVID; NISPEL, MARKUS; EATON, ERNIE; GRAHAM, RICHARD; HASKELL, JEFFREY
To: ENTERASYS NETWORKS, INC.
Reel/Frame 036955/0707 →
Continuity (2)
Continuation 13835815 · Mar 15, 2013
Related Publication 20160044106A1 · Feb 11, 2016