IP Library Granted Patent US 10,404,730
Granted Patent B1
US 10,404,730 · App. 15/438,489 · Granted Sep 3, 2019

High-volume network threat trace engine

Inventor: Jeffrey Charles Venable, Sr. (Union City, CA)
Assignee: Vectra Networks, Inc.
H04L63/1425G06F21/50H04L63/1433H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,404,730
App. No.
15/438,489
Granted
Sep 3, 2019
Kind
B1
Abstract

An approach for high-volume network threat tracing and detection may be implemented by storing network communications received from a plurality of hosts in an initial recording data structure, such as a rolling buffer. Identifiers may be generated for the plurality of hosts associated with the network communications by according to host identity or the behavior of a given host. Extended trace time values may be assigned to a portion of the plurality of hosts based at least in part on the identifiers, and storing the portion of the network communications that have extended trace time values may be recorded as packet capture files in long term memory.

Claims (34)

1. A method for selectively storing network traffic, comprising:

storing a set of network packets received from a plurality of hosts in an initial recording data structure, wherein the set of network packets are maintained in the initial recording data structure while the set of network packets are within a corresponding initial trace time window;

storing a subset of the set of network packets in a second recording data structure based at least in part on an identification of anomalous activity of a host, the subset of the set of network packets comprising network packets received from the host of the plurality of hosts, the anomalous activity being identified by processing the subset of the network packets, wherein the host is assigned an extended trace time window and the subset of the set of network packets are maintained in the second recording data structure while the extended trace time window has not expired, wherein the extended trace time window expires later than the initial trace time window; and

storing a new network packet from the host in the second recording data structure based at least in part on a determination that the extended trace time window has not expired.

2. The method of claim 1 , wherein an expiration of an extended trace time window for the host automatically terminates storing network packets generated by the host to the second recording data structure.

3. The method of claim 1 , further comprising storing the new network packet from the host to a long-term memory structure configured to record network traffic perpetually.

4. The method of claim 1 , wherein the extended trace time window are assigned using a lookup memory structure that stores host identifiers and corresponding extended trace time windows to be assigned.

5. The method of claim 1 , wherein the extended trace time window is proportional to how anomalous the anomalous activity is as characterized by a machine learning scheme.

6. The method of claim 1 , wherein the initial trace time window is decreased in response to an amount of the initial recording data structure memory capacity used.

7. The method of claim 1 , wherein the subset of the set of network packets are stored as one or more packet capture files.

8. The method of claim 1 , wherein a portion of the set of network packets are not associated with extended trace time windows, and wherein the portion of the set of network packets is not stored in the second recording data structure.

9. A system for selectively storing network traffic, comprising:

a memory storing a set of program code instructions; and

a processor that executes the set of program code instructions to perform a set of acts, the set of acts comprising:

storing a set of network packets received from a plurality of hosts in an initial recording data structure, wherein the set of network packets are maintained in the initial recording data structure while the set of network packets are within a corresponding initial trace time window;

storing a subset of the set of network packets in a second recording data structure based at least in part on an identification of anomalous activity of a host, the subset of the set of network packets comprising network packets received from the host of the plurality of hosts, the anomalous activity being identified by processing the subset of the network packets, wherein the host is assigned an extended trace time window and the subset of the set of network packets are maintained in the second recording data structure while the extended trace time window has not expired, wherein the extended trace time window expires later than the initial trace time window; and

storing a new network packet from the host in the second recording data structure based at least in part on a determination that the extended trace time window has not expired.

10. The system of claim 9 , wherein an expiration of an extended trace time window for the host automatically terminates storing network packets generated by the host to the second recording data structure.

11. The system of claim 9 , the set of acts further comprising storing the new network packet from the host to a long-term memory structure configured to record network traffic perpetually.

12. The system of claim 9 , wherein the extended trace time window are assigned using a lookup memory structure that stores host identifiers and corresponding extended trace time windows to be assigned.

13. The system of claim 9 , wherein the extended trace time window is proportional to how anomalous the anomalous activity is as characterized by a machine learning scheme.

14. The system of claim 9 , wherein the initial trace time window is decreased in response to an amount of the initial recording data structure memory capacity used.

15. The system of claim 9 , wherein the subset of the set of network packets are stored as one or more packet capture files.

16. A computer-program product embodied on a non-transitory computer readable storage medium having stored thereon a sequence of instructions which, when executed by a processor, causes a set of acts for selectively storing network traffic, the set of acts comprising:

storing a set of network packets received from a plurality of hosts in an initial recording data structure, wherein the set of network packets are maintained in the initial recording data structure while the set of network packets are within a corresponding initial trace time window;

storing a subset of the set of network packets in a second recording data structure based at least in part on an identification of anomalous activity of a host, the subset of the set of network packets comprising network packets received from the host of the plurality of hosts, the anomalous activity being identified by processing the subset of the network packets, wherein the host is assigned an extended trace time window and the subset of the set of network packets are maintained in the second recording data structure while the extended trace time window has not expired, wherein the extended trace time window expires later than the initial trace time window; and

storing a new network packet from the host in the second recording data structure based at least in part on a determination that the extended trace time window has not expired.

17. The computer-program product of claim 16 , wherein an expiration of an extended trace time window for the host automatically terminates storing network packets generated by the host to the second recording data structure.

18. The computer-program product of claim 16 , the set of acts further comprising storing the new network packet from the host to a long-term memory structure configured to record network traffic perpetually.

19. The computer-program product of claim 16 , wherein the extended trace time window are assigned using a lookup memory structure that stores host identifiers and corresponding extended trace time windows to be assigned.

20. The computer-program product of claim 16 , wherein the extended trace time window is proportional to how anomalous the anomalous activity is as characterized by a machine learning scheme.

21. The computer-program product of claim 16 , wherein the initial trace time window is decreased in response to an amount of the initial recording data structure memory capacity used.

22. The computer-program product of claim 16 , wherein the subset of the set of network packets are stored as one or more packet capture files.

23. The computer-program product of claim 16 , wherein a portion of the set of network packets are not associated with extended trace time windows, and wherein the portion of the set of network packets is not stored in the second recording data structure.

Assignments (6)
SECURITY INTEREST Recorded Oct 29, 2024
From: VECTRA AI, INC.
To: AB PRIVATE CREDIT INVESTORS LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 069061/0588 →
CHANGE OF NAME Recorded Sep 23, 2024
From: VECTRA NETWORKS, INC.
To: VECTRA AI, INC.
Reel/Frame 069020/0822 →
RELEASE OF SECURITY INTEREST Recorded Mar 19, 2021
From: SILVER LAKE WATERMAN FUND, L.P., AS AGENT
To: VECTRA AI, INC.
Reel/Frame 055656/0351 →
CHANGE OF NAME Recorded Nov 4, 2019
From: VECTRA NETWORKS, INC.
To: VECTRA AI, INC.
Reel/Frame 050925/0991 →
SECURITY INTEREST Recorded Mar 13, 2019
From: VECTRA AI, INC.
To: SILVER LAKE WATERMAN FUND, L.P., AS AGENT
Reel/Frame 048591/0071 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2017
From: VENABLE, JEFFREY CHARLES
To: VECTRA NETWORKS, INC.
Reel/Frame 041326/0722 →
Continuity (1)
Provisional Application 62298112 · Feb 22, 2016