IP Library Granted Patent US 9,584,381
Granted Patent B1
US 9,584,381 · App. 15/289,760 · Granted Feb 28, 2017

Dynamic snapshot value by turn for continuous packet capture

Inventor: Alexander Christian Leone (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L43/04H04L43/0876H04L43/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,584,381
App. No.
15/289,760
Filed
Oct 10, 2016
Granted
Feb 28, 2017
Kind
B1
Examiner
PEZZLO, JOHN
Art Unit
2465
USPC
370/252
Abstract

Embodiments are directed to capturing packets on a network. A snapshot value may be provided for a network monitoring computer (NMC). If the NMC may be provided packets of a network flow, characteristics of the network flow may be monitored. If the characteristics of the network flow indicate that a flow turn may be occurring on the network flow, the snapshot value may be modified by increasing it to a provided value. If conditions indicate that the flow turn may be complete, the snapshot value maybe reset by decreasing it to another provided value. A portion of each of the packets may be captured by the NMC, such that the size of the portion may be equivalent to the snapshot value. The captured portion of each of the packets may be stored in a memory of the NMC.

Claims (98)

1. A method for capturing packets on a network, wherein one or more processors in a network computer execute instructions to perform actions, comprising:

providing a snapshot value having a defined amount for one or more network monitoring computers (NMCs); and

when the one or more NMCs are provided a network flow, performing further actions, including:

monitoring one or more characteristics of one or more packets in the network flow, wherein the one or more characteristics include one or more of an incoming volume or an outgoing volume of the network flow;

when the one or more characteristics of the network flow indicate that a turn is occurring on the network flow, providing an increase to the amount of the snapshot value;

when one or more conditions indicate that the flow turn is complete, providing a decrease to the amount of the snapshot value;

capturing a portion of each of the one or more packets, wherein a size of the portion is based on the snapshot value; and

storing the captured portion of each of the one or more packets in a memory of the one or more NMCs.

2. The method of claim 1 , wherein the monitoring of the one or more characteristics of the network flow, further comprise:

including one or more of a change-in-traffic-volume rate, a sequence match, a response delay, a protocol state, or a response latency; and

identifying the turn based on a change of direction of the network flow, wherein the change of direction is indicated by the one or more characteristics.

3. The method of claim 1 , wherein the one or more conditions that indicate that the turn is complete, further comprise: one or more of a count of captured network packets subsequent to the occurrence of the turn that exceeds a defined threshold, a timeout expiry, or a capture byte count threshold is exceeded.

4. The method of claim 1 , further comprising:

storing the one or more packets in a memory buffer;

when the turn is occurring, capturing the one or more packets in the memory buffer using a current snapshot value; and

when the memory buffer size is exceeded, discarding one or more of the buffered one or more packets to make more room in the memory buffer.

5. The method of claim 1 , further comprising, when a new network flow is provided to the one or more NMCs, performing further actions, including:

providing an increase to the defined amount of the snapshot value provided for the new network flow; and

capturing the portion of each of the one or more packets, wherein a size of the portion is equivalent to the snapshot value.

6. The method of claim 1 , wherein providing the increase to the amount of the snapshot value further comprises, providing the increase to the amount based on one or more of a network protocol, or an application protocol.

7. The method of claim 1 , wherein providing the increase to the amount of the snapshot value further comprises, increasing the amount of the snapshot value to capture all portions of each packet.

8. The method of claim 1 , further comprising, providing the one or more packets from an off-line data store.

9. A system for capturing network traffic in a network comprising:

a network computer, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing a snapshot value having a defined amount for one or more network monitoring computers (NMCs); and

when the one or more NMCs are provided a network flow, performing further actions, including:

monitoring one or more characteristics of one or more packets in the network flow, wherein the one or more characteristics include one or more of an incoming volume or an outgoing volume of the network flow;

when the one or more characteristics of the network flow indicate that a turn is occurring on the network flow, providing an increase to the amount of the snapshot value;

when one or more conditions indicate that the flow turn is complete, providing a decrease to the amount of the snapshot value;

capturing a portion of each of the one or more packets, wherein a size of the portion is based on the snapshot value; and

storing the captured portion of each of the one or more packets in a memory of the one or more NMCs; and

a client computer, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing one or more portions of the network flow.

10. The system of claim 9 , wherein the monitoring of the one or more characteristics of the network flow, further comprise:

including one or more of a change-in-traffic-volume rate, a sequence match, a response delay, a protocol state, or a response latency; and

identifying the turn based on a change of direction of the network flow, wherein the change of direction is indicated by the one or more characteristics.

11. The system of claim 9 , wherein the one or more conditions that indicate that the turn is complete, further comprise: one or more of a count of captured network packets subsequent to the occurrence of the turn that exceeds a defined threshold, a timeout expiry, or a capture byte count threshold is exceeded.

12. The system of claim 9 , wherein the network computer's one or more processors execute instructions that perform actions, further comprising:

storing the one or more packets in a memory buffer;

when the turn is occurring, capturing the one or more packets in the memory buffer using a current snapshot value; and

when the memory buffer size is exceeded, discarding one or more of the buffered one or more packets to make more room in the memory buffer.

13. The system of claim 9 , wherein the network computer's one or more processors execute instructions that perform actions, further comprising, when a new network flow is provided to the one or more NMCs, performing further actions, including:

providing an increase to the defined amount of the snapshot value provided for the new network flow; and

capturing the portion of each of the one or more packets, wherein a size of the portion is equivalent to the snapshot value.

14. The system of claim 9 , wherein providing the increase to the amount of the snapshot value further comprises, providing the increase to the amount based on one or more of a network protocol, or an application protocol.

15. The system of claim 9 , wherein providing the increase to the amount of the snapshot value further comprises, increasing the amount of the snapshot value to capture all portions of each packet.

16. The system of claim 9 , wherein the network computer's one or more processors execute instructions that perform actions, further comprising, providing the one or more packets from an off-line data store.

17. A processor readable non-transitory storage media that includes instructions for capturing packets on a network, wherein execution of the instructions by one or more processors performs actions, comprising:

providing a snapshot value having a defined amount for one or more network monitoring computers (NMCs); and

when the one or more NMCs are provided a network flow, performing further actions, including:

monitoring one or more characteristics of one or more packets in the network flow, wherein the one or more characteristics include one or more of an incoming volume or an outgoing volume of the network flow;

when the one or more characteristics of the network flow indicate that a turn is occurring on the network flow, providing an increase to the amount of the snapshot value;

when one or more conditions indicate that the flow turn is complete, providing a decrease to the amount of the snapshot value;

capturing a portion of each of the one or more packets, wherein a size of the portion is based on the snapshot value; and

storing the captured portion of each of the one or more packets in a memory of the one or more NMCs.

18. The media of claim 17 , wherein the monitoring of the one or more characteristics of the network flow, further comprise:

including one or more of a change-in-traffic-volume rate, a sequence match, a response delay, a protocol state, or a response latency; and

identifying the turn based on a change of direction of the network flow, wherein the change of direction is indicated by the one or more characteristics.

19. The media of claim 17 , wherein the one or more conditions that indicate that the turn is complete, further comprise, one or more of a count of captured network packets subsequent to the occurrence of the turn that exceeds a defined threshold, a timeout expiry, or a capture byte count threshold is exceeded.

20. The media of claim 17 , further comprising:

storing the one or more packets in a memory buffer;

when the turn is occurring, capturing the one or more packets in the memory buffer using a current snapshot value; and

when the memory buffer size is exceeded, discarding one or more of the buffered one or more packets to make more room in the memory buffer.

21. The media of claim 17 , further comprising, when a new network flow is provided to the one or more NMCs, performing further actions, including:

providing an increase to the defined amount of the snapshot value provided for the new network flow; and

capturing the portion of each of the one or more packets, wherein a size of the portion is equivalent to the snapshot value.

22. The media of claim 17 , wherein providing the increase to the amount of the snapshot value further comprises, providing the increase to the amount based on one or more of a network protocol, or an application protocol.

23. The media of claim 17 , wherein providing the increase to the amount of the snapshot value further comprises, increasing the amount of the snapshot value to capture all portions of each packet.

24. A network computer for capturing packets in a network, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing a snapshot value having a defined amount for one or more network monitoring computers (NMCs); and

when the one or more NMCs are provided a network flow, performing further actions, including:

monitoring one or more characteristics of one or more packets in the network flow, wherein the one or more characteristics include one or more of an incoming volume or an outgoing volume of the network flow;

when the one or more characteristics of the network flow indicate that a turn is occurring on the network flow, providing an increase to the amount of the snapshot value;

when one or more conditions indicate that the flow turn is complete, providing a decrease to the amount of the snapshot value;

capturing a portion of each of the one or more packets, wherein a size of the portion is based on the snapshot value; and

storing the captured portion of each of the one or more packets in a memory of the one or more NMCs.

25. The network computer of claim 24 , wherein the monitoring of the one or more characteristics of the network flow, further comprise:

including one or more of a change-in-traffic-volume rate, a sequence match, a response delay, a protocol state, or a response latency; and

identifying the turn based on a change of direction of the network flow, wherein the change of direction is indicated by the one or more characteristics.

26. The network computer of claim 24 , wherein the one or more conditions that indicate that the turn is complete, further comprise, one or more of a count of captured network packets subsequent to the occurrence of the turn that exceeds a defined threshold, a timeout expiry, or a capture byte count threshold is exceeded.

27. The network computer of claim 24 , further comprising:

storing the one or more packets in a memory buffer;

when the turn is occurring, capturing the one or more packets in the memory buffer using a current snapshot value; and

when the memory buffer size is exceeded, discarding one or more of the buffered one or more packets to make more room in the memory buffer.

28. The network computer of claim 24 , further comprising, when a new network flow is provided to the one or more NMCs, performing further actions, including:

providing an increase to the defined amount of the snapshot value provided for the new network flow; and

capturing the portion of each of the one or more packets, wherein a size of the portion is equivalent to the snapshot value.

29. The network computer of claim 24 , wherein providing the increase to the amount of the snapshot value further comprises, providing the increase to the amount based on one or more of a network protocol, or an application protocol.

30. The network computer of claim 24 , wherein providing the increase to the amount of the snapshot value further comprises, increasing the amount of the snapshot value to capture all portions of each packet.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2016
From: LEONE, ALEXANDER CHRISTIAN
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 039979/0621 →