IP Library Granted Patent US 11,539,630
Granted Patent B2
US 11,539,630 · App. 15/972,232 · Granted Dec 27, 2022

Inspecting operations of a machine to detect elephant flows

Inventors: W. Andrew Lambeth (San Mateo, CA); Amit Vasant Patil (Pune, IN); Prasad Sharad Dabak (Pune, IN); Laxmikant Vithal Gunda (San Jose, CA); Vasantha Kumar Dhanasekar (Pune, IN); Justin Pettit (Los Altos Hills, CA)
Assignee: NICIRA, INC.
H04L47/2441H04L43/026
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,539,630
App. No.
15/972,232
Granted
Dec 27, 2022
Kind
B2
Abstract

Some embodiments provide a system that detects whether a data flow is an elephant flow; and if so, the system treats it differently than a mouse flow. The system of some embodiments detects an elephant flow by examining, among other items, the operations of a machine. In detecting, the system identifies an initiation of a new data flow associated with the machine. The new data flow can be an outbound data flow or an inbound data flow. The system then determines, based on the amount of data being sent or received, if the data flow is an elephant flow. The system of some embodiments identifies the initiation of a new data flow by intercepting a socket call or request to transfer a file.

Claims (47)

1. A method for detecting an elephant flow by inspecting the operations of a first virtual machine (VM) that operates on a physical host computer, the method comprising:

at a detector executing within a second VM operating on the physical host computer:

receiving information from an agent executing on the first VM regarding a file transfer initiated by an application executing on the first VM, the information comprising a size of the file to be transferred and a data flow associated with the file transfer;

determining that the file size exceeds a threshold value;

in response to the determination, specifying the data flow associated with the file transfer as an elephant flow; and

reporting that the data flow is an elephant flow, wherein a managed forwarding element that forwards data packets for the first VM is configured to process the data associated with the detected elephant flow differently from other flows not detected as elephant flows.

2. A method for detecting an elephant flow by inspecting the operations of a virtual machine (VM) that operates on a physical host computer, the method comprising:

at a detector executing within virtualization software of the physical host computer;

receiving information from an agent executing on the VM regarding a file transfer initiated by an application executing on the VM, the information comprising a size of the file to be transferred and a data flow associated with the file transfer;

determining that the file size exceeds a threshold value;

in response to the determination, specifying the data flow associated with the file transfer as an elephant flow; and

reporting that the data flow is an elephant flow, wherein a managed forwarding element that forwards data packets for the VM is configured to process the data associated with the detected elephant flow differently from other flows not detected as elephant flows.

3. The method of claim 1 , wherein the agent executing on the first VM detects an application programming interface (API) call regarding the file transfer.

4. The method of claim 3 , wherein the API call is associated with a particular data transfer protocol for transferring files between machines.

5. The method of claim 1 , wherein the information received from the agent comprises at least one of (i) the application that initiated the file transfer, (ii) user data, and (iii) whether the file transfer is inbound or outbound.

6. The method of claim 1 , wherein reporting that the data flow is an elephant flow comprises reporting the data flow to a network controller.

7. The method of claim 2 , wherein the network controller configures the managed forwarding element to process the data associated with the elephant flow differently.

8. The method of claim 2 , wherein the detector receives the information from the agent via a multiplexer module.

9. A method for detecting an elephant flow by inspecting the operations of a machine that operates on a physical host computer, the method comprising:

at a detector operating on the physical host computer:

receiving information from an agent executing on the machine via a multiplexer module, the information regarding a file transfer initiated by an application executing on the machine and comprising a size of the file to be transferred and a data flow associated with the file transfer, wherein the detector registers with the multiplexer module to receive a notification each time the agent provides information regarding initiation of a file transfer on the machine;

determining that the file size exceeds a threshold value;

in response to the determination, specifying the data flow associated with the file transfer as an elephant flow; and

reporting that the data flow is an elephant flow, wherein a managed forwarding element that forwards data packets for the machine is configured to process the data associated with the detected elephant flow differently from other flows not detected as elephant flows.

10. A non-transitory machine-readable medium storing a detector program that when executed by at least one processing unit of a physical host computer detects an elephant flow by inspecting the operations of a first virtual machine (VM) that operates on the physical host computer, the detector program executing within a second VM operating on the physical host computer and comprising sets of instructions for:

receiving information from an agent executing on the first VM regarding a file transfer initiated by an application executing on the first VM, the information comprising a size of the file to be transferred and a data flow associated with the file transfer:

determining that the file size exceeds a threshold value;

in response to the determination, specifying the data flow associated with the file transfer as an elephant flow; and

reporting that the data flow is an elephant flow, wherein a managed forwarding element that forwards data packets for the first VM is configured to process the data associated with the detected elephant flow differently from other flows not detected as elephant flows.

11. A non-transitory machine-readable medium of claim 10 , storing a detector program that when executed by at least one processing unit of a physical host computer detects an elephant flow by inspecting the operations of a virtual machine (VM) that operates on the physical host computer, the detector program executing within virtualization software of the physical host computer and comprising sets of instructions for:

receiving information from an agent executing on the VM regarding a file transfer initiated by an application executing on the VM, the information comprising a size of the file to be transferred and a data flow associated with the file transfer:

determining that the file size exceeds a threshold value;

in response to the determination, specifying the data flow associated with the file transfer as an elephant flow; and

reporting that the data flow is an elephant flow, wherein a managed forwarding element that forwards data packets for the VM is configured to process the data associated with the detected elephant flow differently from other flows not detected as elephant flows.

12. The non-transitory machine-readable medium of claim 11 , wherein the agent executing on the VM detects an application programming interface (API) call regarding the file transfer.

13. The non-transitory machine-readable medium of claim 12 , wherein the API call is associated with a particular data transfer protocol for transferring files between machines.

14. The non-transitory machine-readable medium of claim 11 , wherein the information received from the agent comprises at least one of (i) the application that initiated the file transfer, (ii) user data, and (iii) whether the file transfer is inbound or outbound.

15. The non-transitory machine-readable medium of claim 11 , wherein the set of instructions for reporting that the data flow is an elephant flow comprises a set of instructions for reporting the data flow to a network controller.

16. The non-transitory machine-readable medium of claim 10 , wherein the network controller configures the managed forwarding element to process the data associated with the elephant flow differently.

17. The non-transitory machine-readable medium of claim 10 , wherein the detector receives the information from the agent via a multiplexer module.

18. A non-transitory machine-readable medium storing a detector program that when executed by at least one processing unit of a physical host computer detects an elephant flow by inspecting the operations of a machine that operates on the physical host computer, the detector program comprising sets of instructions for:

receiving information from an agent executing on the machine via a multiplexer module, the information regarding a file transfer initiated by an application executing on the machine and comprising a size of the file to be transferred and a data flow associated with the file transfer, wherein the detector registers with the multiplexer module to receive a notification each time the agent provides information regarding initiation of a file transfer on the machine;

determining that the file size exceeds a threshold value;

in response to the determination, specifying the data flow associated with the file transfer as an elephant flow; and

reporting that the data flow is an elephant flow, wherein a managed forwarding element that forwards data packets for the machine is configured to process the data associated with the detected elephant flow differently from other flows not detected as elephant flows.

19. The non-transitory machine-readable medium of claim 18 , wherein the agent executing on the machine detects an application programming interface (API) call regarding the file transfer.

20. The method of claim 9 , wherein the information received from the agent comprises at least one of (i) the application that initiated the file transfer, (ii) user data, and (iii) whether the file transfer is inbound or outbound.

Assignments (1)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
Continuity (5)
Continuation 14502102 · Sep 30, 2014
Provisional Application 62010944 · Jun 11, 2014
Provisional Application 61973255 · Mar 31, 2014
Provisional Application 61913899 · Dec 9, 2013
Related Publication 20180331961A1 · Nov 15, 2018
Cited By (1)
US 12,401,599