IP Library Granted Patent US 10,382,303
Granted Patent B2
US 10,382,303 · App. 15/671,060 · Granted Aug 13, 2019

Anomaly detection using device relationship graphs

Inventors: Bhushan Prasad Khanal (Seattle, WA); Xue Jun Wu (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L43/0823H04L41/065H04L41/145H04L67/1044H04L69/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,303
App. No.
15/671,060
Filed
Aug 7, 2017
Granted
Aug 13, 2019
Kind
B2
Art Unit
2444
USPC
709/224
Abstract

Embodiments are directed to monitoring network traffic in a network. A device relation model that may be comprised of two or more nodes and one or more edges stored in memory of the network computer may be provided to a network monitoring computer (NMC), such that each node represents an agent and each edge represents a relationship between two agents. If error signals are detected by the NMC, the NMC perform further actions to process the error signals. The device relation model may be traversed to identify agents associated with the error signals. The network traffic associated with the error signals and the agents may be analyzed by the NMC. If the error signals are associated with anomalies in the network traffic, users may be notified. The device relation model may be updated upon discovery of new computing devices, new applications, or new associations between agents.

Claims (55)

1. A method for monitoring network packets over a network, wherein one or more processors in a network computer execute instructions to perform actions, comprising:

instantiating a network monitoring application to perform actions, including:

detecting one or more error signals from one or more agents that are included in a model that is comprised of a graph for two or more nodes and one or more edges, wherein each node represents an agent and each edge represents a relationship between two agents;

employing network packets communicated by two or more agents that are unassociated with the model to identify these two agents as two or more new agents for the model that have one or more relationships with each other;

updating the model with the two or more new agents and one or more phantom edges for the one or more relationships between the two or more new agents;

employing the network packets associated with the one or more error signals to identify a plurality of anomalies that correspond to more than one agent in the model that is associated with a same error signal;

employing the graph of the model to reduce an amount of the plurality of anomalies into one or more anomalies; and

notifying a user of the one or more anomalies in the network.

2. The method of claim 1 , further comprising employing the model to identify those agents that are associated with the one or more error signals and that are also associated with each other in the model.

3. The method of claim 1 , further comprising employing relationships between agents associated with the model to identify groups of agents that are associated with each other.

4. The method of claim 1 , wherein the employing of network packets communicated by the two or more agents that are unassociated with the model to identify these two agents as the two or more new agents, further comprises employing one or more of traffic patterns, configuration information, or heuristics for the network packets.

5. A system for monitoring network traffic in a network comprising:

a network computer, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating a network monitoring application to perform actions, including:

detecting one or more error signals from one or more agents that are included in a model that is comprised of a graph for two or more nodes and one or more edges, wherein each node represents an agent and each edge represents a relationship between two agents;

employing network packets communicated by two or more agents that are unassociated with the model to identify these two agents as two or more new agents for the model that have one or more relationships with each other;

updating the model with the two or more new agents and one or more phantom edges for the one or more relationships between the two or more new agents;

employing the network packets associated with the one or more error signals to identify a plurality of anomalies that correspond to more than one agent in the model that is associated with a same error signal; and

employing the graph of the model to reduce an amount of the plurality of anomalies into one or more anomalies; and

a client computer, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

receiving notification of the one or more anomalies in the network.

6. The system of claim 5 , further comprising employing the model to identify those agents that are associated with the one or more error signals and that are also associated with each other in the model.

7. The system of claim 5 , further comprising employing relationships between agents associated with the model to identify groups of agents that are associated with each other.

8. The system of claim 5 , wherein the employing of network packets communicated by the two or more agents that are unassociated with the model to identify these two agents as the two or more new agents, further comprises employing one or more of traffic patterns, configuration information, or heuristics for the network packets.

9. A network computer for monitoring network traffic in a network, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating a network monitoring application to perform actions, including:

detecting one or more error signals from one or more agents that are included in a model that is comprised of a graph for two or more nodes and one or more edges, wherein each node represents an agent and each edge represents a relationship between two agents;

employing network packets communicated by two or more agents that are unassociated with the model to identify these two agents as two or more new agents for the model that have one or more relationships with each other;

updating the model with the two or more new agents and one or more phantom edges for the one or more relationships between the two or more new agents;

employing the network packets associated with the one or more error signals to identify a plurality of anomalies that correspond to more than one agent in the model that is associated with a same error signal;

employing the graph of the model to reduce an amount of the plurality of anomalies into one or more anomalies; and

notifying a user of the one or more anomalies in the network.

10. The network computer of claim 9 , further comprising employing the model to identify those agents that are associated with the one or more error signals and that are also associated with each other in the model.

11. The network computer of claim 9 , further comprising employing relationships between agents associated with the model to identify groups of agents that are associated with each other.

12. The network computer of claim 9 , wherein the employing of network packets communicated by the two or more agents that are unassociated with the model to identify these two agents as the two or more new agents, further comprises employing one or more of traffic patterns, configuration information, or heuristics for the network packets.

13. A processor readable non-transitory storage media that includes instructions for monitoring network traffic in a network, wherein execution of the instructions by one or more processors performs actions, comprising:

instantiating a network monitoring application to perform actions, including:

detecting one or more error signals from one or more agents that are included in a model that is comprised of a graph for two or more nodes and one or more edges, wherein each node represents an agent and each edge represents a relationship between two agents;

employing network packets communicated by two or more agents that are unassociated with the model to identify these two agents as two or more new agents for the model that have one or more relationships with each other;

updating the model with the two or more new agents and one or more phantom edges for the one or more relationships between the two or more new agents;

employing the network packets associated with the one or more error signals to identify a plurality of anomalies that correspond to more than one agent in the model that is associated with a same error signal;

employing the graph of the model to reduce an amount of the plurality of anomalies into one or more anomalies; and

notifying a user of the one or more anomalies in the network.

14. The media of claim 13 , further comprising employing the model to identify those agents that are associated with the one or more error signals and that are also associated with each other in the model.

15. The media of claim 13 , further comprising employing relationships between agents associated with the model to identify groups of agents that are associated with each other.

16. The media of claim 13 , wherein the employing of network packets communicated by the two or more agents that are unassociated with the model to identify these two agents as the two or more new agents, further comprises employing one or more of traffic patterns, configuration information, or heuristics for the network packets.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2017
From: KHANAL, BHUSHAN PRASAD; WU, XUE JUN
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 043223/0936 →
Continuity (2)
Continuation 15207213 · Jul 11, 2016
Related Publication 20180013650A1 · Jan 11, 2018
Cited By (108)
US 12,206,696 US 12,225,030 US 12,244,621 US 12,261,866 US 12,267,345 US 12,284,197 US 12,309,181 US 12,309,182 US 12,309,185 US 12,309,192 US 12,309,236 US 12,316,660 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,355,816 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,381,901 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,272 US 12,452,279 US 12,457,231 US 12,463,994 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,384 US 12,483,576 US 12,489,770 US 12,489,771 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,511,110 US 12,513,221 US 12,526,297 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,932 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,535 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,647,441 US 12,652,302 US 12,652,312 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,931 US 12,706,932 US 12,706,933 US 12,706,980 US 12,712,897 US 12,719,896