IP Library Granted Patent US 9,729,416
Granted Patent B1
US 9,729,416 · App. 15/207,213 · Granted Aug 8, 2017

Anomaly detection using device relationship graphs

Inventors: Bhushan Prasad Khanal (Seattle, WA); Xue Jun Wu (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L43/0823H04L43/0876H04L43/16H04L67/1044H04L69/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,729,416
App. No.
15/207,213
Granted
Aug 8, 2017
Kind
B1
Abstract

Embodiments are directed to monitoring network traffic in a network. A device relation model that may be comprised of two or more nodes and one or more edges stored in memory of the network computer may be provided to a network monitoring computer (NMC), such that each node represents an agent and each edge represents a relationship between two agents. If error signals are detected by the NMC, the NMC perform further actions to process the error signals. The device relation model may be traversed to identify agents associated with the error signals. The network traffic associated with the error signals and the agents may be analyzed by the NMC. If the error signals are associated with anomalies in the network traffic, users may be notified. The device relation model may be updated upon discovery of new computing devices, new applications, or new associations between agents.

Claims (102)

1. A method for monitoring network traffic in a network, wherein one or more processors in a network computer execute instructions to perform actions, comprising:

providing a device relation model that is comprised of a graph for two or more nodes and one or more edges stored in memory of the network computer, wherein each node represents an agent and each edge represents a relationship between two agents; and

instantiating a network monitoring application to perform actions, including:

detecting one or more error signals;

employing network traffic from two or more non-associated agents that is correlated to add one or more phantom edges to the device relation model to associate the two or more non-associated agents with each other;

traversing the device relation model to identify one or more agents that are associated with the one or more error signals and that are associated with each other in the device relation model;

analyzing the network traffic associated with the one or more error signals and the one or more agents to identify a plurality of anomalies that correspond to more than one agent that is associated with a same error signal;

reducing an amount of the plurality of anomalies into one or more anomalies based on the graph of the device relation model; and

employing the one or more anomalies in the network traffic to update the device relation model and notifying a user of the one or more anomalies in the network.

2. The method of claim 1 , wherein providing the device relation model, further comprises:

adding one or more nodes to the device relation model based on the network traffic, wherein the one or more nodes each represent an agent in the network; and

adding one or more edges to the device relation model based on the network traffic, wherein the one or more edges correspond to an association between two agents.

3. The method of claim 1 , wherein providing the device relation model further comprises:

providing one or more weight values that are associated with the one or more edges, wherein the one or more weight values indicate a strength of an association between two agents; and

removing one or more of the one or more edges from the device relation model that are associated with a weight value that is less than a defined threshold.

4. The method of claim 1 , further comprising, updating the device relation model based on the network, wherein the device relation model is updated upon a discovery of one or more of new computing devices in the network, new applications in the network, or new associations between agents.

5. The method of claim 1 , wherein providing the device relation model, further comprises:

associating the one or more agents with applications based on their network traffic; and

assigning the one or more agents to one or more groups based on their network traffic and their associated applications.

6. The method of claim 1 , wherein analyzing the network traffic further comprises:

comparing a portion of the error signals that are associated with one or more of the one or more agents with another portion of the error signals that are associated with one or more other agents of the one or more agents; and

associating the one or more error signals with the one or more anomalies of the network traffic based on a result of the comparison.

7. The method of claim 1 , further comprising, when one or more of the one or more anomalies in the network traffic are caused by error signals associated with one or more upstream anomalies, discarding the one or more anomalies caused by the error signals associated with the one or more upstream anomalies.

8. A system for monitoring network traffic in a network comprising:

a network computer, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing a device relation model that is comprised of a graph for two or more nodes and one or more edges stored in memory of the network computer, wherein each node represents an agent and each edge represents a relationship between two agents; and

instantiating a network monitoring application to perform actions, including:

detecting one or more error signals;

employing network traffic from two or more non-associated agents that is correlated to add one or more phantom edges to the device relation model to associate the two or more non-associated agents with each other;

traversing the device relation model to identify one or more agents that are associated with the one or more error signals and that are associated with each other in the device relation model;

analyzing the network traffic associated with the one or more error signals and the one or more agents to identify a plurality of anomalies that correspond to more than one agent that is associated with a same error signal;

reducing an amount of the plurality of anomalies into one or more anomalies based on the graph of the device relation model; and

employing the one or more anomalies in the network traffic to update the device relation model and notifying a user of the one or more anomalies in the network; and

a client computer, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing one or more portions of the network traffic to the network.

9. The system of claim 8 , wherein providing the device relation model, further comprises:

adding one or more nodes to the device relation model based on the network traffic, wherein the one or more nodes each represent an agent in the network; and

adding one or more edges to the device relation model based on the network traffic, wherein the one or more edges correspond to an association between two agents.

10. The system of claim 8 , wherein providing the device relation model further comprises:

providing one or more weight values that are associated with the one or more edges, wherein the one or more weight values indicate a strength of an association between two agents; and

removing one or more of the one or more edges from the device relation model that are associated with a weight value that is less than a defined threshold.

11. The system of claim 8 , wherein the network computer's one or more processors execute instructions that perform actions, further comprising, updating the device relation model based on the network, wherein the device relation model is updated upon a discovery of one or more of new computing devices in the network, new applications in the network, or new associations between agents.

12. The system of claim 8 , wherein providing the device relation model, further comprises:

associating the one or more agents with applications based on their network traffic; and

assigning the one or more agents to one or more groups based on their network traffic and their associated applications.

13. The system of claim 8 , wherein analyzing the network traffic further comprises:

comparing a portion of the error signals that are associated with one or more of the one or more agents with another portion of the error signals that are associated with one or more other agents of the one or more agents; and

associating the one or more error signals with the one or more anomalies of the network traffic based on a result of the comparison.

14. The system of claim 8 , wherein the network computer's one or more processors execute instructions that perform actions, further comprising, when one or more of the one or more anomalies in the network traffic are caused by error signals associated with one or more upstream anomalies, discarding the one or more anomalies caused by the error signals associated with the one or more upstream anomalies.

15. A processor readable non-transitory storage media that includes instructions for monitoring network traffic in a network, wherein execution of the instructions by one or more processors performs actions, comprising:

providing a device relation model that is comprised of a graph for two or more nodes and one or more edges stored in memory of the network computer, wherein each node represents an agent and each edge represents a relationship between two agents; and

instantiating a network monitoring application to perform actions, including:

detecting one or more error signals;

employing network traffic from two or more non-associated agents that is correlated to add one or more phantom edges to the device relation model to associate the two or more non-associated agents with each other;

traversing the device relation model to identify one or more agents that are associated with the one or more error signals and that are associated with each other in the device relation model;

analyzing the network traffic associated with the one or more error signals and the one or more agents to identify a plurality of anomalies that correspond to more than one agent that is associated with a same error signal;

reducing an amount of the plurality of anomalies into one or more anomalies based on the graph of the device relation model; and

employing the one or more anomalies in the network traffic to update the device relation model and notifying a user of the one or more anomalies in the network.

16. The media of claim 15 , wherein providing the device relation model, further comprises:

adding one or more nodes to the device relation model based on the network traffic, wherein the one or more nodes each represent an agent in the network; and

adding one or more edges to the device relation model based on the network traffic, wherein the one or more edges correspond to an association between two agents.

17. The media of claim 15 , wherein providing the device relation model further comprises:

providing one or more weight values that are associated with the one or more edges, wherein the one or more weight values indicate a strength of an association between two agents; and

removing one or more of the one or more edges from the device relation model that are associated with a weight value that is less than a defined threshold.

18. The media of claim 15 , further comprising, updating the device relation model based on the network, wherein the device relation model is updated upon a discovery of one or more of new computing devices in the network, new applications in the network, or new associations between agents.

19. The media of claim 15 , wherein providing the device relation model, further comprises:

associating the one or more agents with applications based on their network traffic; and

assigning the one or more agents to one or more groups based on their network traffic and their associated applications.

20. The media of claim 15 , wherein analyzing the network traffic further comprises:

comparing a portion of the error signals that are associated with one or more of the one or more agents with another portion of the error signals that are associated with one or more other agents of the one or more agents; and

associating the one or more error signals with the one or more anomalies of the network traffic based on a result of the comparison.

21. A network computer for monitoring network traffic in a network, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing a device relation model that is comprised of a graph for two or more nodes and one or more edges stored in memory of the network computer, wherein each node represents an agent and each edge represents a relationship between two agents; and

instantiating a network monitoring application to perform actions, including:

detecting one or more error signals;

employing network traffic from two or more non-associated agents that is correlated to add one or more phantom edges to the device relation model to associate the two or more non-associated agents with each other;

traversing the device relation model to identify one or more agents that are associated with the one or more error signals and that are associated with each other in the device relation model;

analyzing the network traffic associated with the one or more error signals and the one or more agents to identify a plurality of anomalies that correspond to more than one agent that is associated with a same error signal;

reducing an amount of the plurality of anomalies into one or more anomalies based on the graph of the device relation model; and

employing the one or more anomalies in the network traffic to update the device relation model and notifying a user of the one or more anomalies in the network.

22. The network computer of claim 21 , wherein providing the device relation model, further comprises:

adding one or more nodes to the device relation model based on the network traffic, wherein the one or more nodes each represent an agent in the network; and

adding one or more edges to the device relation model based on the network traffic, wherein the one or more edges correspond to an association between two agents.

23. The network computer of claim 21 , wherein providing the device relation model further comprises:

providing one or more weight values that are associated with the one or more edges, wherein the one or more weight values indicate a strength of an association between two agents; and

removing one or more of the one or more edges from the device relation model that are associated with a weight value that is less than a defined threshold.

24. The network computer of claim 21 , further comprising, updating the device relation model based on the network, wherein the device relation model is updated upon a discovery of one or more of new computing devices in the network, new applications in the network, or new associations between agents.

25. The network computer of claim 21 , wherein providing the device relation model, further comprises:

associating the one or more agents with applications based on their network traffic; and

assigning the one or more agents to one or more groups based on their network traffic and their associated applications.

26. The network computer of claim 21 , wherein analyzing the network traffic further comprises:

comparing a portion of the error signals that are associated with one or more of the one or more agents with another portion of the error signals that are associated with one or more other agents of the one or more agents; and

associating the one or more error signals with the one or more anomalies of the network traffic based on a result of the comparison.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2016
From: KHANAL, BHUSHAN PRASAD; WU, XUE JUN
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 039126/0276 →