IP Library Granted Patent US 10,389,574
Granted Patent B1
US 10,389,574 · App. 15/891,273 · Granted Aug 20, 2019

Ranking alerts based on network monitoring

Inventors: Xue Jun Wu (Seattle, WA); Nicholas Jordan Braun (Seattle, WA); Joel Benjamin Deaguero (Seattle, WA); Michael Kerber Krause Montague (Lake Forest Park, WA); Bhushan Prasad Khanal (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L41/0609G06F16/24578H04L9/006H04L41/12H04L41/16H04L43/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,389,574
App. No.
15/891,273
Granted
Aug 20, 2019
Kind
B1
Abstract

Embodiments are directed to monitoring network traffic. A monitoring engine may monitor network traffic associated with a plurality of entities in networks to provide metrics. And provide a device relation model based on the plurality of entities, the network traffic, and the metrics. An inference engine may associate each entity in the plurality of entities with an importance score based on the device relation model and the metrics such that each importance score is associated with a significance of an entity to operations of the networks. An alert engine may generate a plurality of alerts associated with the plurality of entities based on the metrics. And provide one or more alerts from the plurality of alerts to one or more users based on one or more ranked importance scores associated with one or more entities.

Claims (94)

1. A method for monitoring network traffic using one or more network computers, wherein execution of instructions by the one or more network computers perform the method comprising:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics; and

providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and

instantiating an inference engine to perform actions including associating each entity in the plurality of entities with an importance score based on the device relation model and the one or more metrics, wherein each importance score is based on a significance of an entity to one or more operations of the one or more networks and an importance of one or more other entities to the entity based on the one or more other entities and the entity being members of a same cluster and interacting with a same resource while non-communicating with each other: and

instantiating an alert engine to perform actions, including:

generating a plurality of alerts associated with the plurality of entities based on the one or more metrics;

providing feedback from one or more users regarding the plurality of entities, wherein the feedback includes one or more of user interaction history with one or more of the plurality of entities, importance of the user interaction with the one or more entities, or one or more roles of the one or more users that provided feedback; and

providing one or more ranked alerts to the one or more users based on the provided feedback from the one or more users and a ranking of the importance scores associated with one or more entities.

2. The method of claim 1 , wherein the actions of the inference engine further comprise, modifying the importance score associated with each entity based on one or more characteristics including one or more of resources accessed by an entity, resources provided by an entity, users that access an entity, users that are logged in to an entity, or an uptime of the entity.

3. The method of claim 1 , wherein the actions of the monitoring engine further comprise:

modifying the device relation model based on an addition or removal of one or more entities in the network; and

modifying the importance score associated with each entity based on the modification to the device relation model.

4. The method of claim 1 , wherein the inference engine performs further actions, comprising:

providing one or more other entities based on a traversal of the device relation model; and

modifying each importance score that is associated with the one or more other entities based on the traversal.

5. The method of claim 1 , wherein the actions of the inference engine further comprise, modifying the importance score of the entity based on one or more applications shared by the entity and one or more other entities, dependencies shared by the entity and the one or more other entities, or activities of the one or more users.

6. The method of claim 1 , wherein the actions of the inference engine further comprise, increasing the importance score for the entity based on a metric value that is associated with another entity that is linked to the entity.

7. The method of claim 1 , wherein the actions of the inference engine further comprises:

associating two or more entities that are communicating based on one or more public key infrastructure (PKI) certificates; and

increasing each importance score associated with the two or more associated entities based on one or more anomalies associated with the one or more PKI certificates.

8. A processor readable non-transitory storage media that includes instructions for monitoring network traffic using one or more network monitoring computers, wherein execution of the instructions by the one or more network computers perform the method comprising:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics; and

providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and

instantiating an inference engine to perform actions including associating each entity in the plurality of entities with an importance score based on the device relation model and the one or more metrics, wherein each importance score is based on a significance of an entity to one or more operations of the one or more networks and an importance of one or more other entities to the entity based on the one or more other entities and the entity being members of a same cluster and interacting with a same resource while non-communicating with each other; and

instantiating an alert engine to perform actions, including:

generating a plurality of alerts associated with the plurality of entities based on the one or more metrics;

providing feedback from one or more users regarding the plurality of entities, wherein the feedback includes one or more of user interaction history with one or more of the plurality of entities, importance of the user interaction with the one or more entities, or one or more roles of the one or more users that provided feedback; and

providing one or more ranked alerts to the one or more users based on the provided feedback from the one or more users and a ranking of the importance scores associated with one or more entities.

9. The media of claim 8 , wherein the actions of the inference engine further comprise, modifying the importance score associated with each entity based on one or more characteristics including one or more of resources accessed by an entity, resources provided by an entity, users that access an entity, users that are logged in to an entity, or an uptime of the entity.

10. The media of claim 8 , wherein the actions of the monitoring engine further comprise:

modifying the device relation model based on an addition or removal of one or more entities in the network; and

modifying the importance score associated with each entity based on the modification to the device relation model.

11. The media of claim 8 , wherein the inference engine performs further actions, comprising:

providing one or more other entities based on a traversal of the device relation model; and

modifying each importance score that is associated with the one or more other entities based on the traversal.

12. The media of claim 8 , wherein the actions of the inference engine further comprise, modifying the importance score of the entity based on one or more applications shared by the entity and one or more other entities, dependencies shared by the entity and the one or more other entities, or activities of the one or more users.

13. The media of claim 8 , wherein the actions of the inference engine further comprise, increasing the importance score for the entity based on a metric value that is associated with another entity that is linked to the entity.

14. The media of claim 8 , wherein the actions of the inference engine further comprises:

associating two or more entities that are communicating based on one or more public key infrastructure (PKI) certificates; and

increasing each importance score associated with the two or more associated entities based on one or more anomalies associated with the one or more PKI certificates.

15. A system for monitoring network traffic in a network:

one or more network computers, comprising:

a transceiver that communicates over the network; a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics; and

providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and

instantiating an inference engine to perform actions including associating each entity in the plurality of entities with an importance score based on the device relation model and the one or more metrics, wherein each importance score is based on a significance of an entity to one or more operations of the one or more networks and an importance of one or more other entities to the entity based on the one or more other entities and the entity being members of a same cluster and interacting with a same resource while non-communicating with each other; and

instantiating an alert engine to perform actions, including:

generating a plurality of alerts associated with the plurality of entities based on the one or more metrics;

providing feedback from one or more users regarding the plurality of entities, wherein the feedback includes one or more of user interaction history with one or more of the plurality of entities, importance of the user interaction with the one or more entities, or one or more roles of the one or more users that provided feedback; and

providing one or more ranked alerts to the one or more users based on the provided feedback from the one or more users and a ranking of the importance scores associated with one or more entities; and

one or more client computers, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing one or more portions of the network traffic.

16. The system of claim 15 , wherein the actions of the inference engine further comprise, modifying the importance score associated with each entity based on one or more characteristics including one or more of resources accessed by an entity, resources provided by an entity, users that access an entity, users that are logged in to an entity, or an uptime of the entity.

17. The system of claim 15 , wherein the actions of the monitoring engine further comprise:

modifying the device relation model based on an addition or removal of one or more entities in the network; and

modifying the importance score associated with each entity based on the modification to the device relation model.

18. The system of claim 15 , wherein the inference engine performs further actions, comprising:

providing one or more other entities based on a traversal of the device relation model; and

modifying each importance score that is associated with the one or more other entities based on the traversal.

19. The system of claim 15 , wherein the actions of the inference engine further comprise, modifying the importance score of the entity based on one or more applications shared by the entity and one or more other entities, dependencies shared by the entity and the one or more other entities, or activities of the one or more users.

20. The system of claim 15 , wherein the actions of the inference engine further comprise, increasing the importance score for the entity based on a metric value that is associated with another entity that is linked to the entity.

21. The system of claim 15 , wherein the actions of the inference engine further comprises:

associating two or more entities that are communicating based on one or more public key infrastructure (PKI) certificates; and

increasing each importance score associated with the two or more associated entities based on one or more anomalies associated with the one or more PKI certificates.

22. A network computer for monitoring communication over a network between two or more computers, comprising:

a transceiver that communicates over the network; a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics; and

providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and

instantiating an inference engine to perform actions including associating each entity in the plurality of entities with an importance score based on the device relation model and the one or more metrics, wherein each importance score is based on a significance of an entity to one or more operations of the one or more networks and an importance of one or more other entities to the entity based on the one or more other entities and the entity being members of a same cluster and interacting with a same resource while non-communicating with each other; and

instantiating an alert engine to perform actions, including:

generating a plurality of alerts associated with the plurality of entities based on the one or more metrics;

providing feedback from one or more users regarding the plurality of entities, wherein the feedback includes one or more of user interaction history with one or more of the plurality of entities, importance of the user interaction with the one or more entities, or one or more roles of the one or more users that provided feedback; and

providing one or more ranked alerts to the one or more users based on the provided feedback from the one or more users and a ranking of the importance scores associated with one or more entities.

23. The network computer of claim 22 , wherein the actions of the inference engine further comprise, modifying the importance score associated with each entity based on one or more characteristics including one or more of resources accessed by an entity, resources provided by an entity, users that access an entity, users that are logged in to an entity, or an uptime of the entity.

24. The network computer of claim 22 , wherein the actions of the monitoring engine further comprise:

modifying the device relation model based on an addition or removal of one or more entities in the network; and

modifying the importance score associated with each entity based on the modification to the device relation model.

25. The network computer of claim 22 , wherein the inference engine performs further actions, comprising:

providing one or more other entities based on a traversal of the device relation model; and

modifying each importance score that is associated with the one or more other entities based on the traversal.

26. The network computer of claim 22 , wherein the actions of the inference engine further comprise, modifying the importance score of the entity based on one or more applications shared by the entity and one or more other entities, dependencies shared by the entity and the one or more other entities, or activities of the one or more users.

27. The network computer of claim 22 , wherein the actions of the inference engine further comprise, increasing the importance score for the entity based on a metric value that is associated with another entity that is linked to the entity.

28. The network computer of claim 22 , wherein the actions of the inference engine further comprises:

associating two or more entities that are communicating based on one or more public key infrastructure (PKI) certificates; and

increasing each importance score associated with the two or more associated entities based on one or more anomalies associated with the one or more PKI certificates.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2018
From: WU, XUE JUN; BRAUN, NICHOLAS JORDAN; DEAGUERO, JOEL BENJAMIN; MONTAGUE, MICHAEL KERBER KRAUSE; KHANAL, BHUSHAN PRASAD
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 044860/0559 →
Cited By (7)
US 12,225,030 US 12,309,192 US 12,355,816 US 12,483,384 US 12,587,535 US 12,647,441 US 12,652,312