IP Library Granted Patent US 10,257,094
Granted Patent B2
US 10,257,094 · App. 15/415,229 · Granted Apr 9, 2019

Network traffic appliance for triggering augmented data collection on a network based on traffic patterns

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,257,094
App. No.
15/415,229
Granted
Apr 9, 2019
Kind
B2
Abstract

A method and system for increasing the collection of network traffic data in a network based on the occurrence of predetermined criteria. A network appliance manages network traffic in the network and passes data traffic on the network. Network traffic data is collected based on the data traffic passing through the network appliance at a normal level. It is determined whether the network traffic data indicates an abnormal condition. The collection of network traffic data is increased through the network traffic appliance when an abnormal condition is detected. The network traffic data from the increased collection is stored in a memory device.

Claims (31)

1. A network traffic appliance for regulating network traffic between computing devices in a network, comprising:

a network interface;

a data collection engine coupled to the network interface, during operation the collection module collecting network traffic data from a first set of data sources based on the data traffic passing through the network traffic appliance at a normal level;

a storage device during operation storing collected network traffic data; and

a traffic performance analysis engine coupled to the data collector module, the traffic performance analysis engine during operation monitoring the network traffic data from the data collection engine and determining whether the network traffic data indicates an abnormal condition, wherein when an abnormal condition is determined by the traffic performance analysis engine, the data collection engine collects network data from a second set of data sources and increases collection of network traffic data, and the first set of data sources is different than the second set of data sources.

2. The network traffic appliance of claim 1 , wherein the data collection engine collects network traffic data from another network traffic appliance for managing network traffic data on another network.

3. The network traffic appliance of claim 1 , wherein the data collection engine monitors the increased collection of network traffic data to determine the cessation of the abnormal condition.

4. The network traffic appliance of claim 3 , wherein collection of network traffic data is returned to the normal level when the abnormal condition has ceased.

5. The network traffic appliance of claim 3 , wherein the data collection engine returns the collection of network traffic data to the normal level after a predetermined time.

6. The network traffic appliance of claim 1 , wherein the network traffic data from the increased collection is removed from the storage device after the abnormal condition ceases.

7. The network traffic appliance of claim 1 , wherein the increased data collection includes network traffic data collected under the Nedlow protocol.

8. The network traffic appliance of claim 7 , wherein the collector module is configured as a Netflow data collector.

9. The network traffic appliance of claim 1 , wherein the increased data collection includes at least one of network traffic data from a router, a server, a firewall or a network device.

10. The network traffic appliance of claim 1 further comprising a quality of service controller executing a policy to direct network traffic managed by the network traffic appliance.

11. The network traffic appliance of claim 1 , wherein the data collection engine increases collection of network traffic data by collecting network traffic data from a data collection device in the network.

12. The network traffic appliance of claim 1 , wherein the data collection engine includes a plurality of data interfaces and each of the data interfaces collects a different source of network traffic data.

13. A method of adjusting network data management in a network traffic appliance coupled to devices in a network, the method comprising:

receiving network traffic via a network interface on the network traffic appliance;

passing data traffic to the devices in the network;

collecting network traffic data from a first set of data sources based on the data traffic passing through the network traffic appliance at a normal level via a collection module in the network traffic appliance;

determining whether the network traffic data indicates an abnormal condition via a network traffic analysis module in the network traffic appliance; and

when an abnormal condition is determined, collecting network data from a second set of data sources and increasing the collection of network traffic data through collection of network data from a second set of data sources and through the network traffic appliance, wherein the first set of data sources is different than the second set of data sources.

14. The method of claim 13 , further comprising sending the network traffic data from the increased collection to a central management device.

15. The method of claim 13 , further comprising controlling a second network traffic appliance monitoring traffic on a second network, the increased data collection coming exclusively from the first network traffic appliance.

16. The method of claim 13 , further comprising monitoring the increased collection of network traffic data to determine the cessation of the abnormal condition.

17. The method of claim 16 , further comprising returning the collection of network traffic data to the normal level when the abnormal condition has ceased.

18. The method of claim 16 , further comprising returning the collection of network traffic data to the normal level after a predetermined time.

19. The method of claim 13 , wherein the network traffic data from the increased collection is removed from the storage device after the abnormal condition ceases.

20. The method of claim 13 , wherein the increased data collection includes network traffic data collected under the Netflow protocol.

21. The method of claim 13 , wherein the increased data collection includes at least one of network traffic data from a router, a server, a firewall, or a network device.

22. The method of claim 13 , wherein the increase in collection of network traffic data includes collecting network traffic data from a data collection device in the network.

Assignments (8)
SECURITY INTEREST Recorded Mar 6, 2023
From: GFI USA, LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 062888/0560 →
RELEASE OF SECURITY INTEREST Recorded Feb 23, 2023
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: AUREA SOFTWARE, INC.; KERIO TECHNOLOGIES INC.; NEXTDOCS CORPORATION; EXINDA INC.
Reel/Frame 062787/0550 →
CHANGE OF NAME Recorded Feb 13, 2023
From: GFI USA, INC.
To: GFI USA, LLC
Reel/Frame 062746/0564 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2023
From: AUREA SOFTWARE FZ-LLC
To: GFI SMB, INC.
Reel/Frame 062676/0670 →
CHANGE OF NAME Recorded Feb 13, 2023
From: GFI SMB, INC.
To: GFI USA, INC.
Reel/Frame 062677/0201 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2021
From: EXINDA NETWORKS PTY. LIMITED
To: AUREA SOFTWARE FZ-LLC
Reel/Frame 055717/0993 →
PATENT SECURITY AGREEMENT Recorded Mar 30, 2018
From: AUREA SOFTWARE, INC.; KERIO TECHNOLOGIES INC.; NEXTDOCS CORPORATION; EXINDA INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045789/0445 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2017
From: VERES, GREG; LOOP, SANDRA
To: EXINDA NETWORKS PTY, LTD.
Reel/Frame 041081/0033 →