IP Library Granted Patent US 9,591,688
Granted Patent B2
US 9,591,688 · App. 15/051,609 · Granted Mar 7, 2017

Detection and reporting of keepalive messages for optimization of a keepalive traffic in a mobile network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,591,688
App. No.
15/051,609
Granted
Mar 7, 2017
Kind
B2
Abstract

Detection of network transactions or keepalives for maintaining long lived connections are disclosed. A keepalive detector can detect keepalive traffic based on keepalive parameters determined from an analysis of socket level network communication log data that record data transfer events including data sent from mobile applications or clients on a mobile device and data received by the mobile applications or clients on the mobile device, timing characteristics, protocol types, etc. Various statistical analyses can be performed on the network communication data to detect keepalives, taking into account variability in intervals of the data transfer events and sizes of data sent and received on each event. The keepalive detector can also detect keepalives from stream data on a mobile device by analyzing socket level communication messages including timing characteristics and amount of data transferred to detect keepalives and report keepalives using a data structure.

Claims (52)

1. A method of identifying keepalives from a Transport Control Protocol (TCP) stream, comprising:

on a mobile device having a keepalive detector that includes a network log data analyzer, using at least a processor and memory for:

identifying, with the network log data analyzer, patterns of data sent from and received by a mobile application on a mobile device, wherein the patterns have variable intervals and sizes;

detecting, with the network log data analyzer using statistical analyses performed on the patterns of data, that a pattern from among the identified patterns is regular;

detecting, with the network log data analyzer using statistical analyses performed on the patterns of data, that a pattern from among the identified patterns includes regular byte sizes; and

identifying, with the network log data analyzer, the keepalives from the TCP stream occurring over the same TCP session based on information relating to the pattern that is detected as regular and the regular byte sizes.

2. The method of claim 1 , further including identifying network transactions from the TCP stream based on one or more network transaction parameters; wherein the one or more network transaction parameters include a regular interval and a regular size, both determined from the patterns of data sent from and received by the mobile application based on the statistical analysis.

3. The method of claim 2 , wherein the one or more network transaction parameters include similar or repeating content within the patterns of data sent from and received by the mobile application.

4. The method of claim 1 , wherein the patterns of data sent from and received by the mobile application are recorded in a network communication log along with patterns of data sent from and received by other mobile applications on the mobile device.

5. The method of claim 2 wherein examining patterns of data further comprises:

storing the one or more network transaction parameters.

6. The method of claim 1 wherein examining, using statistical analysis, patterns of data further comprises:

determining a number of times a pattern occurs during a time interval;

performing a comparison of the number of times the pattern occurs to a threshold; and

based on the comparison, determining whether the pattern has been detected as regular.

7. The method of claim 1 wherein examining, using statistical analysis, patterns of data further comprises:

determining intervals between occurrences of the pattern;

determining a first quartile and a third quartile based on the determined intervals;

determining a difference between the first quartile and the third quartile;

determining a variance based on the difference and a median interval;

performing a comparison of the variance to a threshold; and

based on the comparison, determining whether the pattern has been detected as regular.

8. The method of claim 1 wherein examining, using statistical analysis, patterns of data further comprises:

determining intervals between occurrences of the pattern;

determining a variance of the intervals;

performing a comparison of the variance to a threshold; and

based on the comparison, determining whether the pattern has been detected as regular.

9. The method of claim 1 wherein examining, using statistical analysis, patterns of data further comprises:

determining intervals between occurrences of the pattern;

determining a median of the intervals;

performing a comparison of the median to a threshold; and

based on the comparison, determining whether the pattern has been detected as regular.

10. The method of claim 1 wherein examining, using statistical analysis, patterns of data further comprises:

determining a number of times a pattern occurs sequentially;

performing a comparison of the number of times the pattern occurs sequentially to a threshold; and

based on the comparison, determining whether the pattern has been detected as regular.

11. The method of claim 2 , wherein the identified network transactions are keepalive messages.

12. The method of claim 1 wherein optimizing in real-time the data sent further comprises:

minimizing the frequency of keepalive messages.

13. A device configured for identifying keepalives from a Transport Control Protocol (TCP) stream, the device comprising:

a communication interface operable to communicatively couple the device to a network; and

a processor and a memory storing program codes, coupled to the communication interface, wherein the device includes a keepalive detector that includes a network log data analyzer, the processor operable for:

identifying, with the network log data analyzer, patterns of data sent from and received by a mobile application on a mobile device, wherein the patterns have variable intervals and sizes;

detecting, with the network log data analyzer, using statistical analyses performed on the patterns of data, that a pattern from among the identified patterns is regular;

detecting, using statistical analyses performed on the patterns of data, that a pattern from among the identified patterns includes regular byte sizes; and

identifying, with the network log data analyzer, keepalives from the TCP stream occurring over the same TCP session based on information relating to the pattern that is detected as regular and the regular byte sizes.

14. A non-transitory computer-readable storage medium containing program instructions to cause a processor to perform a method of identifying keepalives from a Transport Control Protocol (TCP) stream comprising:

on a mobile device having a keepalive detector that includes a network log data analyzer:

identifying, with the network log data analyzer, patterns of data sent from and received by a mobile application on a mobile device, wherein the patterns have variable intervals and sizes;

detecting, with the network log data analyzer, using statistical analyses performed on the patterns of data, that a pattern from among the identified patterns is regular;

detecting, with the network log data analyzer, using statistical analyses performed on the patterns of data, that a pattern from among the identified patterns includes regular byte sizes; and

identifying, with the network log data analyzer, keepalives from the TCP stream occurring over the same TCP session based on information relating to the pattern that is detected as regular and the regular byte sizes.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME AND ADDRESS PREVIOUSLY RECORDED AT REEL: 037814 FRAME: 0325. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2017
From: YOON, SUNGWOOK; FLEMING, MICHAEL; BACKHOLM, ARI; KOKHANOVSKYI, ANDRII
To: SEVEN NETWORKS, INC.
Reel/Frame 041380/0554 →
ENTITY CONVERSION Recorded Jan 17, 2017
From: SEVEN NETWORKS, INC.
To: SEVEN NETWORKS, LLC
Reel/Frame 041380/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2016
From: YOON, SUNGWOOK; FLEMING, MICHAEL; BACKHOLM, ARI; KOKHANOVDKYI, ANDRII
To: SEVEN NETWORKS, LLC
Reel/Frame 037814/0325 →