IP Library Granted Patent US 10,397,329
Granted Patent B2
US 10,397,329 · App. 15/886,080 · Granted Aug 27, 2019

Methods and systems for distribution and retrieval of network traffic records

Inventor: Vincent Berk (Lebanon, NH)
Assignee: Riverbed Technology, Inc.
H04L67/1097G06F16/2255G06F16/2365H04L43/026H04L45/7453H04L63/1416H04L63/1433H04L67/10H04L67/22H04L61/6068
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,397,329
App. No.
15/886,080
Granted
Aug 27, 2019
Kind
B2
Abstract

A method includes transmitting, by a distribution server, to each of a plurality of worker computers, a request for an enumeration of Internet Protocol (IP) addresses ranked according to a criterion. The method includes receiving, by the distribution computer, from a first of the plurality of worker computers, a first partial enumeration of the requested IP addresses ranked according to the criterion, the first partial enumeration stored in a hash table. The method includes receiving, by the distribution computer, from a second of the plurality of worker computers, a second partial enumeration of the requested IP addresses ranked according to the criterion, the second partial enumeration stored in a hash table. The method includes generating, by the distribution computer, a combined enumeration including the first partial enumeration and the second partial enumeration, the combined enumeration ranked according to the criterion. The distribution computer deduplicates the combined enumeration.

Claims (30)

1. A method for generating a combined, deduplicated enumeration of network traffic records received from a plurality of worker computers in a computer network, and providing a network security assessment based on the combined, deduplicated enumeration of network traffic records, the method performed by at least one computer processor executing computer program instructions stored on at least one non-transitory computer-readable medium, the method comprising:

transmitting, by a distribution computer in the computer network, to each of the plurality of worker computers in the computer network, a request for an enumeration of Internet Protocol (IP) addresses ranked according to a criterion;

receiving, by the distribution computer, from a first of the plurality of worker computers, a first partial enumeration of the IP addresses ranked according to the criterion, the first partial enumeration stored in a hash table;

receiving, by the distribution computer, from a second of the plurality of worker computers, a second partial enumeration of the IP addresses ranked according to the criterion, the second partial enumeration stored in a hash table;

generating, by the distribution computer, a combined enumeration including the first partial enumeration and the second partial enumeration, the combined enumeration ranked according to the criterion;

deduplicating, by the distribution computer, the combined enumeration;

identifying, by the distribution computer, an abnormal communications pattern in the combined, deduplicated enumeration of network traffic records;

generating, by the distribution computer, a behavioral fingerprint based upon the identifying of the abnormal communications pattern; and

providing, by the distribution computer, a network security assessment based on the combined, deduplicated enumeration of network traffic records and the behavioral fingerprint.

2. The method of claim 1 , wherein said transmitting further comprises automatically transmitting the request at predetermined time intervals.

3. The method of claim 1 , wherein said transmitting further comprises transmitting the request for the enumeration of IP addresses associated with a protocol identified in each of a plurality of network traffic records, the enumeration of the IP addresses ranked according to the criterion.

4. The method of claim 1 , wherein said transmitting further comprises transmitting the request for the enumeration of IP addresses associated with a port identified in each of a plurality of network traffic records, the enumeration of the IP addresses ranked according to the criterion.

5. The method of claim 1 , wherein said transmitting the request for the enumeration of IP addresses further comprises transmitting a request for an enumeration of IP addresses identified as a destination address in each of a plurality of network traffic records, the enumeration of the IP addresses ranked according to the criterion.

6. The method of claim 1 , wherein said transmitting the request for the enumeration of IP addresses further comprises transmitting a request for an enumeration of IP addresses identified as a source address in each of a plurality of network traffic records, the enumeration of the IP addresses ranked according to the criterion.

7. The method of claim 1 , wherein said receiving, by the distribution computer, from the first of the plurality of worker computers, the first partial enumeration of the IP addresses further comprises receiving, by the distribution computer, a result of a search, by the first of the plurality of worker computers, for at least one IP address satisfying the criterion.

8. The method of claim 1 , wherein said receiving, by the distribution computer, from the second of the plurality of worker computers, the second partial enumeration of the IP addresses further comprises receiving, by the distribution computer, a result of a search, by the second of the plurality of worker computers, for at least one IP address satisfying the criterion.

9. The method of claim 1 , wherein said deduplicating further comprises performing hash table merging to automatically deduplicate the first partial enumeration and the second partial enumeration.

10. A non-transitory computer readable medium comprising computer program instructions tangibly stored on the non-transitory computer readable medium, wherein the computer program instructions are executable by at least one computer processor to perform a method for generating a combined, deduplicated enumeration of network traffic records received from a plurality of worker computers, and providing a network security assessment based on the combined, deduplicated enumeration of the network traffic records, the method comprising:

transmitting, by a distribution computer in a computer network, to each of a plurality of worker computers in the computer network, a request for an enumeration of Internet Protocol (IP) addresses ranked according to a criterion;

receiving, by the distribution computer, from a first of the plurality of worker computers, a first partial enumeration of the IP addresses ranked according to the criterion, the first partial enumeration stored in a hash table;

receiving, by the distribution computer, from a second of the plurality of worker computers, a second partial enumeration of the IP addresses ranked according to the criterion, the second partial enumeration stored in a hash table;

generating, by the distribution computer, a combined enumeration including the first partial enumeration and the second partial enumeration, the combined enumeration ranked according to the criterion;

deduplicating, by the distribution computer, the combined enumeration

identifying, by the distribution computer, an abnormal communications pattern in the combined, deduplicated enumeration of network traffic records;

generating, by the distribution computer, a behavioral fingerprint based upon the identifying of the abnormal communications pattern; and

providing, by the distribution computer, a network security assessment based on the combined, deduplicated enumeration of network traffic records and the behavioral fingerprint.

11. The non-transitory computer readable medium of claim 10 , wherein said transmitting further comprises automatically transmitting the request at predetermined time intervals.

12. The non-transitory computer readable medium of claim 10 , wherein said transmitting further comprises transmitting the request for the enumeration of IP addresses associated with a protocol identified in each of a plurality of network traffic records, the enumeration of the IP addresses ranked according to the criterion.

13. The non-transitory computer readable medium of claim 10 , wherein said transmitting further comprises transmitting the request for the enumeration of IP addresses associated with a port identified in each of a plurality of network traffic records, the enumeration of the IP addresses ranked according to the criterion.

14. The non-transitory computer readable medium of claim 10 , wherein said deduplicating further comprises performing hash table merging to automatically deduplicate the first partial enumeration and the second partial enumeration.

Assignments (16)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
PATENT SECURITY AGREEMENT Recorded Jul 10, 2019
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 049720/0808 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2018
From: BERK, VINCE
To: FLOWTRAQ, INC.
Reel/Frame 045531/0594 →
CERTIFICATE OF CONVERSION Recorded Apr 13, 2018
From: FLOWTRAQ, INC.
To: FLOWTRAQ, LLC
Reel/Frame 045937/0388 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2018
From: FLOWTRAQ, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 045532/0773 →
Continuity (4)
Continuation 15592353 · May 11, 2017
Continuation 14275059 · May 12, 2014
Provisional Application 61861403 · Aug 1, 2013
Related Publication 20180159932A1 · Jun 7, 2018