IP Library Granted Patent US 9,917,901
Granted Patent B2
US 9,917,901 · App. 15/592,353 · Granted Mar 13, 2018

Methods and systems for distribution and retrieval of network traffic records

Inventor: Vincent Berk (Lebanon, NH)
H04L67/1097G06F17/3033G06F17/30371H04L43/026H04L45/7453H04L63/1433H04L61/6068
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,917,901
App. No.
15/592,353
Granted
Mar 13, 2018
Kind
B2
Abstract

A method includes receiving, by a distribution server, a plurality of network traffic records. The distribution server generates a first hash from a first plurality of fields in a first of the plurality of network traffic records and generating a second hash from a second plurality of fields in a second of the plurality of network traffic records. The distribution server determines that the first and second of the plurality of network traffic records relate to a session. The method includes transmitting the first and second of the plurality of network traffic records to one of a plurality of worker computing devices selected based on the determination and on at least one of the first and second hash. The distribution server transmits a request for an enumeration of addresses ranked according to a criterion, receives partial enumerations from a plurality of worker computers, and generates a combined, deduplicated enumeration.

Claims (40)

1. A method for generating a combined, deduplicated enumeration of network traffic records received from a plurality of worker computers and providing a network security assessment based on the enumeration, the method performed by at least one computer processor executing computer program instructions stored on at least one non-transitory computer-readable medium, the method comprising:

receiving, by a distribution server in a computer network, from an exporter device, a plurality of network traffic records;

generating, by the distribution server, a first hash from a first plurality of fields in a first of the plurality of network traffic records;

generating, by the distribution server, a second hash from a second plurality of fields in a second of the plurality of network traffic records;

comparing, by the distribution server, the first hash and the second hash;

determining, by the distribution server, that the first of the plurality of network traffic records and the second of the plurality of traffic records relate to a session, based upon the comparison;

transmitting, by the distributions server, the first of the plurality of network traffic records and the second of the plurality of traffic records to one of a plurality of worker computing devices selected based on the determination and on at least one of the first hash and the second hash;

transmitting, by the distribution server, to each of the plurality of worker computers in the computer network, a request for an enumeration of Internet Protocol (IP) addresses ranked according to a criterion;

receiving, by the distribution server, from the first of the plurality of worker computers, a first partial enumeration of the requested IP addresses ranked according to the criterion, the first partial enumeration stored in a hash table;

receiving, by the distribution server, from a second of the plurality of worker computers, a second partial enumeration of the requested IP addresses ranked according to the criterion, the second partial enumeration stored in a hash table;

generating, by the distribution server, a combined enumeration including the first partial enumeration and the second partial enumeration, the combined enumeration ranked according to the criterion;

deduplicating, by the distribution server, the combined enumeration; and

providing, by the distribution server, a network security assessment based on the deduplicated combined enumeration.

2. The method of claim 1 , wherein receiving further comprises receiving, by the distribution server, from the exporter device, the plurality of network traffic records, each of the plurality of network traffic records including a source Internet Protocol (IP) address.

3. The method of claim 1 , wherein receiving further comprises receiving, by the distribution server, from the exporter device, the plurality of network traffic records, each of the plurality of network traffic records including a destination Internet Protocol (IP) address.

4. The method of claim 1 , wherein receiving further comprises receiving, by the distribution server, from the exporter device, the plurality of network traffic records, each of the plurality of network traffic records identifying a communications protocol.

5. The method of claim 1 , wherein receiving further comprises receiving, by the distribution server, from the exporter device, the plurality of network traffic records, each of the plurality of network traffic records identifying at least one communications port.

6. The method of claim 1 , wherein generating the first hash further comprises executing a hashing function using a numerical value associated with a source Internet Protocol (IP) address and a numerical value associated with a destination Internet Protocol (IP) address.

7. The method of claim 1 , wherein generating the second hash further comprises executing a hashing function using a numerical value associated with a source Internet Protocol (IP) address and a numerical value associated with a destination Internet Protocol (IP) address.

8. The method of claim 1 , wherein transmitting the request for the enumeration of IP addresses further comprises transmitting a request for an enumeration of IP addresses identified as a destination address in each of a plurality of network traffic records, the enumeration ranked according to the criterion.

9. The method of claim 1 , wherein transmitting the request for the enumeration of IP addresses further comprises transmitting a request for an enumeration of IP addresses identified as a source address in each of a plurality of network traffic records, the enumeration ranked according to the criterion.

10. The method of claim 1 , wherein transmitting the request for the enumeration of IP addresses further comprises transmitting a request for an enumeration of IP addresses associated with a protocol identified in each of a plurality of network traffic records, the enumeration ranked according to the criterion.

11. The method of claim 1 , wherein transmitting the request for the enumeration of IP addresses further comprises transmitting a request for an enumeration of IP addresses associated with a port identified in each of a plurality of network traffic records, the enumeration ranked according to the criterion.

12. The method of claim 1 , wherein receiving, by the distribution server, from the first of the plurality of worker computers, the first partial enumeration of the requested IP addresses further comprises:

receiving, by the distribution server, a result of a search, by the first of the plurality of worker computers, for at least one IP address satisfying the criterion and associated with at least one of the first of the plurality of network traffic records and the second of the plurality of traffic records transmitted to the first of the plurality of worker computing devices by the distribution server.

13. The method of claim 1 , wherein receiving, by the distribution server, from the second of the plurality of worker computers, the second partial enumeration of the requested IP addresses further comprises:

receiving, by the distribution server, a result of a search, by the second of the plurality of worker computers, for at least one IP address satisfying the criterion and associated with at least one of the first of the plurality of network traffic records and the second of the plurality of traffic records transmitted to the second of the plurality of worker computing devices by the distribution server.

14. A non-transitory computer readable medium comprising computer program instructions tangibly stored on the computer readable medium, wherein the computer program instructions are executable by at least one computer processor to perform a method for generating a combined, deduplicated enumeration of network traffic records received from a plurality of worker computers and providing a network security assessment based on the enumeration, the method comprising:

receiving, by a distribution server in a computer network, from an exporter device, a plurality of network traffic records;

generating, by the distribution server, a first hash from a first plurality of fields in a first of the plurality of network traffic records;

generating, by the distribution server, a second hash from a second plurality of fields in a second of the plurality of network traffic records;

comparing, by the distribution server, the first hash and the second hash;

determining, by the distribution server, that the first of the plurality of network traffic records and the second of the plurality of traffic records relate to a session, based upon the comparison;

transmitting, by the distributions server, the first of the plurality of network traffic records and the second of the plurality of traffic records to one of a plurality of worker computing devices selected based on the determination and on at least one of the first hash and the second hash;

transmitting, by the distribution server, to each of the plurality of worker computers in the computer network, a request for an enumeration of Internet Protocol (IP) addresses ranked according to a criterion;

receiving, by the distribution server, from the first of the plurality of worker computers, a first partial enumeration of the requested IP addresses ranked according to the criterion, the first partial enumeration stored in a hash table;

receiving, by the distribution server, from a second of the plurality of worker computers, a second partial enumeration of the requested IP addresses ranked according to the criterion, the second partial enumeration stored in a hash table;

generating, by the distribution server, a combined enumeration including the first partial enumeration and the second partial enumeration, the combined enumeration ranked according to the criterion;

deduplicating, by the distribution server, the combined enumeration; and

providing, by the distribution server, a network security assessment based on the deduplicated combined enumeration.

Assignments (16)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
PATENT SECURITY AGREEMENT Recorded Jul 10, 2019
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 049720/0808 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2018
From: FLOWTRAQ, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 045532/0773 →
CERTIFICATE OF CONVERSION Recorded Apr 13, 2018
From: FLOWTRAQ, INC.
To: FLOWTRAQ, LLC
Reel/Frame 045937/0388 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2017
From: BERK, VINCENT
To: FLOWTRAQ, INC.
Reel/Frame 042364/0792 →
Continuity (3)
Continuation 14275059 · May 12, 2014
Provisional Application 61861403 · Aug 1, 2013
Related Publication 20170244790A1 · Aug 24, 2017