IP Library Granted Patent US 10,382,296
Granted Patent B2
US 10,382,296 · App. 16/113,442 · Granted Aug 13, 2019

Classifying applications or activities based on network behavior

Inventors: Bhushan Prasad Khanal (Seattle, WA); Xue Jun Wu (Seattle, WA); Eric Jacob Ball (Seattle, WA); Casey Alvin Marks (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L43/04G06N20/00H04L43/026H04L43/08H04L43/12H04L67/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,296
App. No.
16/113,442
Filed
Aug 27, 2018
Granted
Aug 13, 2019
Kind
B2
Art Unit
2415
USPC
370/241
Abstract

Embodiments are directed to monitoring network traffic in a network. A network monitoring engine may be employed to monitor the network to provide metric profiles based on a plurality of characteristics associated with one or more network flows. The network monitoring engine may provide profile objects based on the metric profiles. The network monitoring engine may provide the profile objects to a classifier engine. The classifier engine provide trained activity models selected from a plurality of trained activity models that may be based on a ranked ordering of characteristics of the trained activity models and the profile objects. The classifier engine may provide classification results for the profile objects based on the trained activity models. And, the network monitoring engine may execute policies based on the classification results associated with the profile objects.

Claims (60)

1. A method for monitoring network traffic in a network, wherein one or more processors in a network computer execute instructions to perform actions, comprising:

employing a network monitoring engine to perform further actions, comprising:

providing one or more profile objects based on one or more metric profiles for one or more monitored network flows, wherein one or more metrics that correspond to a network entity in the monitored network are based on one or more characteristics of the one or more monitored network flows that are separate from other characteristics associated with the network entity; and

providing one or more device objects based on associating the one or more profile objects with one or more network entities on the network; and

employing a classifier engine to perform further actions, including:

providing one or more trained activity models; and

providing one or more classification results for the one or more device objects based on the one or more trained activity models; and

executing one or more policies based on the one or more classification results associated with the one or more device objects.

2. The method of claim 1 , further comprising:

employing a training engine to perform further actions, including:

training one or more untrained activity models based on one or more labeled profile objects and one or more characteristics of the one or more untrained activity models; and

employing one or more newly trained activity models to classify the one or more profile objects.

3. The method of claim 1 , wherein providing the one or more classification results, further comprises, employing one or more characteristics of the one or more monitored network flows to indicate one or more malicious processes or applications.

4. The method of claim 1 , wherein providing the trained activity models, further comprises selecting the provided trained activity models from a plurality of trained activity models based on a ranked ordering of one or more characteristics of the plurality of trained activity models and the one or more profile objects.

5. The method of claim 1 , wherein providing the one or more profile objects, further comprises:

selecting two or more metric profiles that are associated with a same activity; and

providing at least one profile object based on the two or more metric profiles.

6. A system for monitoring network traffic in a network:

one or more network monitoring computers (NMCs), comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

employing a network monitoring engine to perform further actions, comprising:

providing one or more profile objects based on one or more metric profiles for one or more monitored network flows, wherein one or more metrics that correspond to a network entity in the monitored network are based on one or more characteristics of the one or more network flows that are separate from other characteristics associated with the network entity; and

providing one or more device objects based on associating the one or more profile objects and one or more network entities on the network; and

employing a classifier engine to perform further actions, including:

providing one or more trained activity models; and

providing one or more classification results for the one or more device objects based on the one or more trained activity models; and

executing one or more policies based on the one or more classification results associated with the one or more device objects; and

one or more client computers, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing one or more portions of the one or more network flows.

7. The system of claim 6 , further comprising:

employing a training engine to perform further actions, including:

training one or more untrained activity models based on one or more labeled profile objects and one or more characteristics of the one or more untrained activity models; and

employing one or more newly trained activity models to classify the one or more profile objects.

8. The system of claim 6 , wherein providing the one or more classification results, further comprises, employing one or more characteristics of the one or more monitored network flows to indicate one or more malicious processes or applications.

9. The system of claim 6 , wherein providing the trained activity models, further comprises selecting the provided trained activity models from a plurality of trained activity models based on a ranked ordering of one or more characteristics of the plurality of trained activity models and the one or more profile objects.

10. The system of claim 6 , wherein providing the one or more profile objects, further comprises:

selecting two or more metric profiles that are associated with a same activity; and

providing at least one profile object based on the two or more metric profiles.

11. A processor readable non-transitory storage media that includes instructions for monitoring network traffic over a network between one or more computers, wherein execution of the instructions by one or more processors on one or more network monitoring computers (NMCs) performs actions, comprising:

employing a network monitoring engine to perform further actions, comprising:

providing one or more profile objects based on one or more metric profiles for one or more monitored network flows, wherein one or more metrics that correspond to a network entity in the monitored network are based on one or more characteristics of the one or more network flows that are separate from other characteristics associated with the network entity; and

providing one or more device objects based on associating the one or more profile objects with one or more network entities on the network; and

employing a classifier engine to perform further actions, including:

providing one or more trained activity models; and

providing one or more classification results for the one or more device objects based on the one or more trained activity models; and

executing one or more policies based on the one or more classification results associated with the one or more device objects.

12. The media of claim 11 , further comprising:

employing a training engine to perform further actions, including:

training one or more untrained activity models based on one or more labeled profile objects and one or more characteristics of the one or more untrained activity models; and

employing one or more newly trained activity models to classify the one or more profile objects.

13. The media of claim 11 , wherein providing the one or more classification results, further comprises, employing one or more characteristics of the one or more monitored network flows to indicate one or more malicious processes or applications.

14. The media of claim 11 , wherein providing the trained activity models, further comprises selecting the provided trained activity models from a plurality of trained activity models based on a ranked ordering of one or more characteristics of the plurality of trained activity models and the one or more profile objects.

15. The media of claim 11 , wherein providing the one or more profile objects, further comprises:

selecting two or more metric profiles that are associated with a same activity; and

providing at least one profile object based on the two or more metric profiles.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2018
From: KHANAL, BHUSHAN PRASAD; WU, XUE JUN; BALL, ERIC JACOB; MARKS, CASEY ALVIN
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 046712/0656 →
Continuity (2)
Continuation 15690135 · Aug 29, 2017
Related Publication 20190068465A1 · Feb 28, 2019
Cited By (7)
US 12,225,030 US 12,309,192 US 12,355,816 US 12,483,384 US 12,587,535 US 12,647,441 US 12,652,312