IP Library Granted Patent US 10,142,353
Granted Patent B2
US 10,142,353 · App. 15/134,100 · Granted Nov 27, 2018

System for monitoring and managing datacenters

Inventors: Navindra Yadav (Cupertino, CA); Abhishek Ranjan Singh (Pleasanton, CA); Shashidhar Gandham (Fremont, CA); Ellen Christine Scheib (Mountain View, CA); Omid Madani (San Jose, CA); Ali Parandehgheibi (Sunnyvale, CA); Jackson Ngoc Ki Pang (Sunnyvale, CA); Vimalkumar Jeyakumar (Sunnyvale, CA); Michael Standish Watts (Mill Valley, CA); Hoang Viet Nguyen (Pleasanton, CA); Khawar Deen (Sunnyvale, CA); Rohit Chandra Prasad (Sunnyvale, CA); Sunil Kumar Gupta (Milpitas, CA); Supreeth Hosur Nagesh Rao (Milpitas, CA); Anubhav Gupta (Sunnyvale, CA); Ashutosh Kulshreshtha (Fremont, CA); Roberto Fernando Spadaro (Milpitas, CA); Hai Trong Vu (San Jose, CA); Varun Sagar Malhotra (Sunnyvale, CA); Shih-Chun Chang (San Jose, CA); Bharathwaj Sankara Viswanathan (Mountain View, CA); Fnu Rachita Agasthy (Sunnyvale, CA); Duane Thomas Barlow (Oakland, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/1408H04L43/04H04L63/02H04L63/1425H04L43/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,142,353
App. No.
15/134,100
Filed
Apr 20, 2016
Granted
Nov 27, 2018
Kind
B2
Art Unit
2493
USPC
726/1
Abstract

An example method includes detecting, using sensors, packets throughout a datacenter. The sensors can then send packet logs to various collectors which can then identify and summarize data flows in the datacenter. The collectors can then send flow logs to an analytics module which can identify the status of the datacenter and detect an attack.

Claims (38)

1. A system within a datacenter, comprising:

two or more sensors configured to:

capture a packet;

describe the packet in a packet log;

send the packet log to a collector;

the collector being configured to:

receive the packet logs from the two or more sensors;

determine that the packet logs describe a connection between two endpoints in a datacenter;

describe the connection in a flow log; and

an analytics module configured to:

determine a status of the datacenter, using any connections in the flow log;

detect an attack that originated from within the datacenter from at least the determined status of the datacenter; and

modify, in response to the detected attack, a security policy of the datacenter.

2. The system of claim 1 , wherein one of the two or more sensors is installed on a hypervisor.

3. The system of claim 2 , wherein one of the two or more sensors is installed on a virtual machine.

4. The system of claim 1 , wherein one of the two or more sensors is installed on a switch.

5. The system of claim 1 , wherein access to the datacenter is limited by a firewall.

6. The system of claim 1 , wherein the analytics module is further configured to: present a report describing flows in the datacenter.

7. A method executed within a datacenter, comprising:

receiving, a first packet log from a first sensor and a second packet log from a second sensor, the first packet log and the second packet log describing packets that are captured by the respective sensors;

determining that the first packet log and the second packet log describes a connection between two endpoints in a datacenter;

describing any connections within the first packet log and the second packet log in a flow log; and

sending the flow log to an analytics module determining a status of the datacenter, using any connections in the flow log;

detect an attack that originated from within the datacenter from at least the determined status of the datacenter; and

modify, in response to the detected attack, a security policy of the datacenter.

8. The method of claim 7 , wherein the first sensor is installed on a hypervisor.

9. The method of claim 8 , wherein access to the datacenter is limited by a firewall.

10. The method of claim 7 , wherein the first sensor is installed on a switch.

11. The method of claim 7 , wherein the first sensor is installed on a virtual machine.

12. A non-transitory computer-readable medium having computer readable instructions stored thereon that, when executed by a processor of a computer, cause the computer to:

receive, from a collector, a flow log describing a connection between two endpoints in a datacenter; and

determine a status of a datacenter, using the flow log, using any connections in the flow log;

detect an attack that originated from within the datacenter from at least the determined status of the datacenter; and

modify, in response to the detected attack, a security policy of the datacenter.

13. The non-transitory computer-readable medium of claim 12 , wherein the instructions further cause the computer to:

present a report describing flows in the datacenter.

14. The non-transitory computer-readable medium of claim 12 , wherein the instructions further cause the computer to:

configure a sensor to send a packet log to the collector.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2016
From: YADAV, NAVINDRA; SINGH, ABHISHEK RANJAN; GANDHAM, SHASHIDHAR; SCHEIB, ELLEN CHRISTINE; MADANI, OMID; PARANDEHGHEIBI, ALI; PANG, JACKSON NGOC KI; JEYAKUMAR, VIMALKUMAR; WATTS, MICHAEL STANDISH; NGUYEN, HOANG VIET; DEEN, KHAWAR; PRASAD, ROHIT CHANDRA; GUPTA, SUNIL KUMAR; RAO, SUPREETH HOSUR NAGESH; GUPTA, ANUBHAV; KULSHRESHTHA, ASHUTOSH; SPADARO, ROBERTO FERNANDO; VU, HAI TRONG; MALHOTRA, VARUN SAGAR; CHANG, SHIH-CHUN; VISWANATHAN, BHARATHWAJ SANKARA; RACHITA AGASTHY, FNU; BARLOW, DUANE THOMAS; SLOANE, ANDREW
To: CISCO TECHNOLOGY, INC.
Reel/Frame 038486/0606 →
Continuity (2)
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20160359872A1 · Dec 8, 2016
Cited By (18)
US 12,192,078 US 12,212,476 US 12,224,921 US 12,231,307 US 12,231,308 US 12,231,500 US 12,278,746 US 12,321,390 US 12,327,165 US 12,335,275 US 12,372,374 US 12,489,688 US 12,580,937 US 12,596,568 US 12,603,895 US 12,645,737 US 12,657,049 US 12,670,003