IP Library Granted Patent US 10,686,804
Granted Patent B2
US 10,686,804 · App. 16/179,027 · Granted Jun 16, 2020

System for monitoring and managing datacenters

Inventors: Navindra Yadav (Cupertino, CA); Abhishek Ranjan Singh (Pleasanton, CA); Shashidhar Gandham (Fremont, CA); Ellen Christine Scheib (Mountain View, CA); Omid Madani (San Carlos, CA); Ali Parandehgheibi (Sunnyvale, CA); Jackson Ngoc Ki Pang (Sunnyvale, CA); Vimalkumar Jeyakumar (Los Altos, CA); Michael Standish Watts (Mill Valley, CA); Hoang Viet Nguyen (Pleasanton, CA); Khawar Deen (Sunnyvale, CA); Rohit Chandra Prasad (Sunnyvale, CA); Sunil Kumar Gupta (Milpitas, CA); Supreeth Hosur Nagesh Rao (Cupertino, CA); Anubhav Gupta (Sunnyvale, CA); Ashutosh Kulshreshtha (Cupertino, CA); Roberto Fernando Spadaro (Milpitas, CA); Hai Trong Vu (San Jose, CA); Varun Sagar Malhotra (Sunnyvale, CA); Shih-Chun Chang (San Jose, CA); Bharathwaj Sankara Viswanathan (Mountain View, CA); Fnu Rachita Agasthy (Sunnyvale, CA); Duane Thomas Barlow (Fremont, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/1408H04L43/04H04L43/0894H04L63/02H04L63/1425H04L43/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,686,804
App. No.
16/179,027
Granted
Jun 16, 2020
Kind
B2
Abstract

An example method includes detecting, using sensors, packets throughout a datacenter. The sensors can then send packet logs to various collectors which can then identify and summarize data flows in the datacenter. The collectors can then send flow logs to an analytics module which can identify the status of the datacenter and detect an attack.

Claims (56)

1. A system within a data center, comprising:

two or more sensors configured to perform operations comprising:

capturing a packet;

describing the packet in a packet log;

sending the packet log to a collector;

the collector being configured to perform operations comprising:

receiving the packet logs from the two or more sensors;

determining that the logs describe at least a flow;

describing the flow in a flow log; and

an analytics module configured to perform operations comprising:

determine a status of the data center, using any connections in the flow log;

detecting, from at least the determined status of the datacenter, an attack within the data center; and

modify, in response to the detected attack, a security policy based on the status of the data center.

2. The system of claim 1 , wherein the detecting an attack comprises detecting a spike in an amount of resources used by at least one of the sensors.

3. The system of claim 1 , wherein the detecting an attack comprises detecting a hidden process embedded in traffic between two or more reference points.

4. The system of claim 1 , wherein the detecting an attack comprises detecting a scan of a network as initiated by a command from outside of the network or from an unexpected source inside the network.

5. The system of claim 1 , wherein the detecting an attack comprises detecting spoofed packets.

6. The system of claim 1 , wherein the detecting an attack comprises detecting a packet that has a packet header field that is outside of an expected predictive header pattern.

7. The system of claim 1 , wherein the detecting an attack comprises detecting a distributed denial of service (DDOS) attack.

8. A method implemented with a data center, the method comprising:

at two or more sensors:

capturing a packet;

describing the packet in a packet log;

sending the packet log to a collector;

at the collector:

receiving the packet logs from the two or more sensors;

determining that the logs describe at least a flow;

describing the flow in a flow log; and

at an analytics module:

determining a status of the data center, using any connections in the flow log;

detecting, from at least the determined status of the datacenter, an attack within the data center; and

modifying, in response to the detected attack, a security policy based on the status of the data center.

9. The method of claim 8 , wherein the detecting an attack comprises detecting a spike in an amount of resources used by at least one of the sensors.

10. The method of claim 8 , wherein the detecting an attack comprises detecting a hidden process embedded in traffic between two or more reference points.

11. The method of claim 8 , wherein the detecting an attack comprises detecting a scan of a network as initiated by a command from outside of the network or from an unexpected source inside the network.

12. The method of claim 8 , wherein the detecting an attack comprises detecting spoofed packets.

13. The method of claim 8 , wherein the detecting an attack comprises detecting a packet that has a packet header field that is outside of an expected predictive header pattern.

14. The method of claim 8 , wherein the detecting an attack comprises detecting a distributed denial of service (DDOS) attack.

15. A non-transitory computer-readable media having computer readable instructions stored thereon that, when executed by a data center, cause components within the data center to perform operations comprising:

at two or more sensors within the data center:

capturing a packet;

describing the packet in a packet log;

sending the packet log to a collector within the data center;

at the collector within the data center:

receiving the packet logs from the two or more sensors;

determining that the logs describe at least a flow;

describing the flow in a flow log; and

at an analytics module within the data center:

determining a status of the data center, using any connections in the flow log;

detecting, from at least the determined status of the datacenter, an attack within the data center; and

modifying, in response to the detected attack, a security policy based on the status of the data center.

16. The media of claim 15 , wherein the detecting an attack comprises detecting a spike in an amount of resources used by at least one of the sensors.

17. The media of claim 15 , wherein the detecting an attack comprises detecting a hidden process embedded in traffic between two or more reference points.

18. The media of claim 15 , wherein the detecting an attack comprises detecting a scan of a network as initiated by a command from outside of the network or from an unexpected source inside the network.

19. The media of claim 15 , wherein the detecting an attack comprises detecting spoofed packets.

20. The media of claim 15 , wherein the detecting an attack comprises detecting a packet that has a packet header field that is outside of an expected predictive header pattern.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2018
From: YADAV, NAVINDRA; SINGH, ABHISHEK RANJAN; GANDHAM, SHASHIDHAR; SCHEIB, ELLEN CHRISTINE; MADANI, OMID; PARANDEHGHEIBI, ALI; PANG, JACKSON NGOC KI; JEYAKUMAR, VIMALKUMAR; WATTS, MICHAEL STANDISH; NGUYEN, HOANG VIET; DEEN, KHAWAR; PRASAD, ROHIT CHANDRA; GUPTA, SUNIL KUMAR; RAO, SUPREETH HOSUR NAGESH; GUPTA, ANUBHAV; KULSHRESHTHA, ASHUTOSH; SPADARO, ROBERTO FERNANDO; VU, HAI TRONG; MALHOTRA, VARUN SAGAR; CHANG, SHIH-CHUN; VISWANATHAN, BHARATHWAJ SANKARA; RACHITA AGASTHY, FNU; BARLOW, DUANE THOMAS
To: CISCO TECHNOLOGY, INC.
Reel/Frame 047394/0508 →
Continuity (3)
Continuation 15134100 · Apr 20, 2016
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20190081959A1 · Mar 14, 2019
Cited By (11)
US 12,192,078 US 12,212,476 US 12,224,921 US 12,231,307 US 12,231,308 US 12,278,746 US 12,335,275 US 12,596,568 US 12,657,049 US 12,670,003 US 12,718,120