IP Library Granted Patent US 10,516,585
Granted Patent B2
US 10,516,585 · App. 15/140,376 · Granted Dec 24, 2019

System and method for network information mapping and displaying

Inventors: Ali Parandehgheibi (Sunnyvale, CA); Omid Madani (San Jose, CA); Vimalkumar Jeyakumar (Sunnyvale, CA); Ellen Christine Scheib (Mountain View, CA); Navindra Yadav (Cupertino, CA); Mohammadreza Alizadeh Attar (Cambridge, MA)
Assignee: CISCO TECHNOLOGY, INC.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F16/122G06F16/137G06F16/162G06F16/17G06F16/173G06F16/174G06F16/1744G06F16/1748G06F16/235G06F16/2322G06F16/2365G06F16/248G06F16/24578G06F16/285G06F16/288G06F16/29G06F16/9535G06F21/53G06F21/552G06F21/566G06N20/00G06N99/00G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/2007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/145H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/10H04L67/1002H04L67/12H04L67/16H04L67/36H04L67/42H04L69/16H04L69/22H04W72/08H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595G06F2221/033G06F2221/2101G06F2221/2105G06F2221/2111G06F2221/2115G06F2221/2145H04L67/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,516,585
App. No.
15/140,376
Granted
Dec 24, 2019
Kind
B2
Abstract

This disclosure generally relate to a method and system for mapping network information. The present technology relates techniques that enable full-scale, dynamic network mapping of a network system. By collecting network and computing data using built-in sensors, the present technology can provide network information for system monitoring and maintenance. According to some embodiments, the present technology enables generating and displaying of network connections and data processing statistics related to numerous nodes in a network. The present technology provides useful insights and actionable knowledge for network monitoring, security, and maintenance, via intelligently summarizing and effectively displaying the complex network communications and processes of a network.

Claims (51)

1. A method comprising:

receiving aggregate network flow data using a plurality of sensors associated with a network;

determining node attributes associated with a plurality of nodes of the network, the node attributes representing at least one portion of distinctive process data or distinctive network data;

determining a score for each of the plurality of nodes based upon the determined node attributes;

generating a plurality of node clusters, based on the determined scores, from the plurality of nodes;

determining a priority order of the node attributes of the node clusters based at least on one of the distinctive process data and the distinctive network data;

displaying, on a user interface, the node attributes of the node clusters in the priority order;

receiving one or more adjustments to the aggregate network flow data;

determining updated node attributes associated with each of the plurality of nodes;

generating an updated priority order of node attributes of the node clusters based at least on updated distinctive process data and updated distinctive network data; and

displaying, on the user interface, the updated node attributes of the node clusters in the updated priority order.

2. The method of claim 1 , wherein the plurality of sensors include at least a first sensor of a physical switch of the network, a second sensor of a hypervisor associated with the physical switch, a third sensor of a virtual machine associated with the hypervisor.

3. The method of claim 1 , further comprising:

determining, based at least in part on the aggregate network flow data, a first dependency map executing in the network, the first dependency map indicating a pattern of network traffic.

4. The method of claim 3 , further comprising:

determining, based at least in part on adjusted aggregate network flow data, a second dependency map executing in the network; and

comparing the second dependency map to the first dependency map to generate a summary of the one or more adjustments including changing the number of nodes in a node cluster.

5. A system comprising:

one or more processors; and

memory including instructions that, upon being executed by the one or more processors, cause the system to perform operations comprising:

receiving aggregate network flow data using a plurality of sensors associated with a network;

determining node attributes associated with a plurality of nodes of the network, the node attributes representing at least one portion of distinctive process data or distinctive network data;

determining a score for each of the plurality of nodes based upon the determined node attributes;

generating a plurality of node clusters, based on the determined scores, from the plurality of nodes;

determining a priority order of the node attributes of the node clusters based at least on one of the distinctive process data and the distinctive network data;

displaying, on a user interface, the node attributes of the node clusters in the priority order;

receiving one or more adjustments to the aggregate network flow data;

determining updated node attributes associated with each of the plurality of nodes;

generating an updated priority order of node attributes of the node clusters based at least on updated distinctive process data and updated distinctive network data; and

displaying, on the user interface, the updated node attributes of the node clusters in the updated priority order.

6. The system of claim 5 , wherein the plurality of sensors include at least a first sensor of a physical switch of the network, a second sensor of a hypervisor associated with the physical switch, a third sensor of a virtual machine associated with the hypervisor.

7. The system of claim 5 , the operations further comprising determining, based at least in part on the aggregate network flow data, a first dependency map executing in the network, the first dependency map indicating a pattern of network traffic.

8. The system of claim 7 , the operations further comprising:

determining, based at least in part on adjusted aggregate network flow data, a second dependency map executing in the network; and

comparing the second dependency map to the first dependency map to generate a summary of the one or more adjustments including changing the number of nodes in a node cluster.

9. A non-transitory computer-readable storage media having stored therein instructions that, upon being executed by a processor, cause the processor to perform operations comprising:

receiving aggregate network flow data using a plurality of sensors associated with a network;

determining node attributes associated with a plurality of nodes of the network, the node attributes representing at least one portion of distinctive process data or distinctive network data;

determining a score for each of the plurality of nodes based upon the determined node attributes;

generating a plurality of node clusters, based on the determined scores, from the plurality of nodes;

determining a priority order of the node attributes of the node clusters based at least on one of the distinctive process data and the distinctive network data;

displaying, on a user interface, the node attributes of the node clusters in the priority order;

receiving one or more adjustments to the aggregate network flow data;

determining updated node attributes associated with each of the plurality of nodes;

generating an updated priority order of node attributes of the node clusters based at least on updated distinctive process data and updated distinctive network data; and

displaying, on the user interface, the updated node attributes of the node clusters in the updated priority order.

10. The media of claim 9 , wherein the plurality of sensors include at least a first sensor of a physical switch of the network, a second sensor of a hypervisor associated with the physical switch, a third sensor of a virtual machine associated with the hypervisor.

11. The media of claim 9 , the operations further comprising determining, based at least in part on the aggregate network flow data, a first dependency map executing in the network, the first dependency map indicating a pattern of network traffic.

12. The media of claim 11 , the operations further comprising:

determining, based at least in part on adjusted aggregate network flow data, a second dependency map executing in the network; and

comparing the second dependency map to the first dependency map to generate a summary of the one or more adjustments including changing the number of nodes in a node cluster.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2016
From: PARANDEHGHEIBI, ALI; MADANI, OMID; JEYAKUMAR, VIMALKUMAR; SCHEIB, ELLEN CHRISTINE; YADAV, NAVINDRA; ALIZADEH ATTAR, MOHAMMADREZA
To: CISCO TECHNOLOGY, INC.
Reel/Frame 038398/0467 →
Continuity (2)
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20160359679A1 · Dec 8, 2016
Cited By (3)
US 12,538,122 US 12,641,670 US 12,659,324