IP Library Granted Patent US 10,756,992
Granted Patent B2
US 10,756,992 · App. 15/841,124 · Granted Aug 25, 2020

Display of network activity data

Inventors: Alkiviadis Simitsis (Santa Clara, CA); Martin Arlitt (Calgary, CA)
Assignee: MICRO FOCUS LLC
H04L43/045G06T15/00H04L41/14H04L43/0876H04L61/2007G06T2215/16H04L41/142
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,756,992
App. No.
15/841,124
Filed
Dec 13, 2017
Granted
Aug 25, 2020
Kind
B2
Examiner
KHAN, ATTA
Art Unit
2449
USPC
709/224
Abstract

According to examples, an apparatus may include a processor and a memory on which is stored machine readable instructions executable by the processor to access network activity data collected over a time period associated with a plurality of network entities, in which each of the network entities is assigned a distinct internet protocol (IP) address including a network prefix set of bits and a network entity identifier set of bits. The instructions may also cause the processor to generate representations of the network activity data corresponding to the respective network entities and display the generated representations of the network activity data corresponding to the respective network entities on an IP address block map according to the network entity identifier set of bits of the respective network entities.

Claims (65)

1. An apparatus comprising:

a processor;

a memory on which is stored machine readable instructions executable by the processor to:

access network activity data collected over a time period associated with a plurality of network entities, wherein each of the network entities is assigned a distinct internet protocol (IP) address comprising a network prefix set of bits and a network entity identifier set of bits;

convert amounts of the network activity data collected over the time period into visual representations of the network activity data of the network entities;

generate an IP address block map for the network entities by using the IP addresses assigned to the network entities to define locations of the network entities on the IP address block map;

overlay the visual representations of the network activity data of the network entities over the locations of the network entities on the IP address block map; and

cause a display of the IP address block map with the overlaid visual representations of the network activity data corresponding to the network entities.

2. The apparatus according to claim 1 , wherein a first axis of the IP address block map corresponds to a first network entity identifier set of bits of the IP addresses and a second axis of the network IP address block map corresponds to a second network entity identifier set of bits of the IP addresses.

3. The apparatus according to claim 2 , wherein the IP address block map comprises a three-dimensional map having the first axis, the second axis, and a third axis, the third axis corresponding to a third identifier set of bits of the IP addresses.

4. The apparatus according to claim 1 , wherein the network activity data corresponds to activity volumes, data volumes, or data rate.

5. The apparatus according to claim 1 , wherein the instructions are further executable by the processor to:

summarize the network activity data collected over the time period based on at least one attribute; and

generate the visual representations as representations of the summarized network activity data.

6. The apparatus according to claim 1 , wherein the IP addresses of the network entities in the network activity data are in integer form and wherein the instructions are further executable by the processor to convert the IP addresses of the network entities from the integer form to the network prefix set of bits and the network entity identifier set of bits.

7. The apparatus according to claim 1 , wherein the network activity data is stored in a data storage and wherein the instructions are further executable by the processor to:

retrieve the network activity data that is respectively associated with the network entities;

process the retrieved network activity data to output a set of tuples that identify the network activity data for each of the network entities; and

generate the visual representations of the network entities according to the set of tuples.

8. The apparatus according to claim 1 , wherein the visual representations of the network activity data have different colors, sizes, or shapes to represent different amounts of the network activity data.

9. The apparatus according to claim 1 , wherein the instructions are further executable by the processor to:

analyze the visual representations of the network activity data;

determine, from the analyzed visual representations, that an event of interest has occurred; and

based on the determination that the event of interest has occurred, output an alert.

10. The apparatus according to claim 1 , wherein the instructions are further executable by the processor to:

generate a plurality of IP address block maps that display different sets of the visual representations of the network activity data of the network entities according to the network entity identifier set of bits of the IP addresses assigned to the network entities;

analyze the generated plurality of IP address block maps to determine an IP address block map that identifies an event of interest; and

output an identification of the determined IP address block map that identifies the event of interest.

11. A computer-implemented method comprising:

accessing, by a processor, network activity data of a plurality of entities, wherein each of the entities is assigned a distinct internet protocol (IP) address, each IP address including a network prefix set of bits, a first identifier set of bits, and a second identifier set of bits;

identifying, by the processor, activity information of the entities from the accessed network activity data;

converting, by the processor, amounts of the activity information of the entities into visual representations of the activity information of the entities;

generating, by the processor, an IP address block graph for the entities by using the IP addresses assigned to the entities to define locations of the entities on the IP address block graph;

overlaying, by the processor, the visual representations of the activity information of the entities over the locations of the entities on the IP address block graph; and

outputting the IP address block graph with the overlaid visual representations of the activity information of the entities for display on a display device.

12. The computer-implemented method according to claim 11 , further comprising:

analyzing the visual representations of the activity information of the entities;

determining, from the analyzed visual representations, that an event of interest has occurred; and

based on the determination that the event of interest has occurred, outputting an alert.

13. The computer-implemented method according to claim 11 , wherein the visual representations of the activity information have different colors, sizes, or shapes to represent the amounts of the activity information.

14. The computer-implemented method according to claim 11 , further comprising:

summarizing the network activity data based on at least one attribute;

identifying the activity information of the entities from the summarized network activity data; and

generating the visual representations as representations of the summarized network activity data.

15. The computer-implemented method according to claim 11 , wherein the IP address block graph comprises a three dimensional (3D) graph, wherein overlaying the visual representations further comprises additionally overlaying the visual representations according to a third identifier set of bits of the IP addresses to which the visual representations correspond, and wherein a first axis of the 3D graph corresponds to a range of the first identifier set of bits of the IP addresses, a second axis of the 3D graph corresponds to a range of the second identifier set of bits of the IP addresses, and a third axis of the 3D graph corresponds to a range of the third identifier set of bits of the IP addresses.

16. The computer-implemented method according to claim 11 , further comprising:

generating a plurality of IP address block graphs representing different IP address ranges of the entities; and

combining the IP address block graphs to produce an aggregated IP address block graph representing a logical view of the entities.

17. A non-transitory computer readable medium on which is stored machine readable instructions that when executed by a processor, cause the processor to:

access network activity data of a plurality of entities, wherein each of the entities is assigned a distinct internet protocol (IP) address, each IP address including a prefix set of bits, a first identifier set of bits, and a second identifier set of bits;

identify activity information of the entities collected over a period of time from the accessed network activity data;

convert amounts of the activity information of the entities into visual representations of the activity information of the entities;

generate an IP address block graph for the entities by using the IP addresses assigned to the entities to define locations of the entities on the IP address block graph;

overlaying the visual representations of the activity information of the entities over the locations of the entities on the IP address block graph; and

cause the IP address block graph with the overlaid visual representations of the activity information of the entities to be displayed on a display device.

18. The non-transitory computer readable medium according to claim 17 , wherein the instructions are further to cause the processor to:

analyze the visual representations of the activity information of the entities;

determine, from the analyzed visual representations, that an event of interest has occurred; and

based on the determination that the event of interest has occurred, output an alert.

19. The non-transitory computer readable medium according to claim 17 , wherein the instructions are further to cause the processor to:

summarize the network activity data based on at least one attribute;

identify the activity information of the entities from the summarized network activity data; and

generate the visual representations as representations of the summarized network activity data.

20. The non-transitory computer readable medium according to claim 17 , wherein the IP address block graph comprises a three dimensional (3D) graph and wherein the instructions are further to cause the processor to:

additionally overlay the visual representations of the activity information of the entities over the locations of the entities according to a third identifier set of bits of the IP addresses to which the visual representations correspond, wherein a first axis of the 3D graph corresponds to a range of the first identifier set of bits of the IP addresses, a second axis of the 3D graph corresponds to a range of the second identifier set of bits of the IP addresses, and a third axis of the 3D graph corresponds to a range of the third identifier set of bits of the IP addresses.

Assignments (6)
RELEASE OF SECURITY INTEREST REEL/FRAME 052294/0522 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062624/0449 →
RELEASE OF SECURITY INTEREST REEL/FRAME 052295/0041 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062625/0754 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: MICRO FOCUS LLC; BORLAND SOFTWARE CORPORATION; MICRO FOCUS SOFTWARE INC.; NETIQ CORPORATION; MICRO FOCUS (US), INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 052294/0522 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: MICRO FOCUS LLC; BORLAND SOFTWARE CORPORATION; MICRO FOCUS SOFTWARE INC.; NETIQ CORPORATION; MICRO FOCUS (US), INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 052295/0041 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2018
From: SIMITSIS, ALKIVIADIS; ARLITT, MARTIN
To: ENTIT SOFTWARE LLC
Reel/Frame 045318/0867 →
Continuity (1)
Related Publication 20190182130A1 · Jun 13, 2019