IP Library Granted Patent US 10,511,499
Granted Patent B2
US 10,511,499 · App. 16/384,697 · Granted Dec 17, 2019

Real-time configuration discovery and management

Inventors: Arindum Mukerji (Seattle, WA); Jeffery Bradford Fry (Bothell, WA)
Assignee: ExtraHop Networks, Inc.
H04L43/04H04L41/0813H04L41/0893H04L41/12H04L43/026H04L43/08H04L63/102H04L63/1408H04L67/16H04L41/0853H04L41/0869H04L41/0873H04L43/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,511,499
App. No.
16/384,697
Filed
Apr 15, 2019
Granted
Dec 17, 2019
Kind
B2
Examiner
KIM, HEE SOO
Art Unit
2457
USPC
709/224
Abstract

Embodiments are directed to monitoring network traffic in a network. A network monitoring engine may monitor networks to collect characteristics associated with network flows. The network monitoring engine may be arranged to identify entities on the network based on characteristics associated with the network flows. The network monitoring engine may provide entity profiles based on the identified entities and the characteristics. A configuration management engine may compare the entity profiles with configuration item (CI) entries in a database. The configuration management engine may provide discrepancy notices based on differences discovered during the comparison. Accordingly, the network monitoring engine may execute one or more policies to perform one or more additional actions based on the one or more discrepancies notices. Also, the configuration management engine may perform audits of an organization's information technology infrastructure to identify one or more violations of compliance policies.

Claims (60)

1. A method for monitoring network traffic in a network, wherein one or more processors in a network computer execute instructions to perform actions, comprising:

passively monitoring the network to provide a plurality of characteristics associated with one or more network flows, wherein the passive monitoring avoids decryption of encrypted packets in the one or more network flows;

employing one or more of the plurality of characteristics to determine one or more unknown entities on the network, wherein one or more profiles are determined for the one or more determined entities based on the one or more characteristics;

comparing the one or more profiles to configuration information associated with one or more previously determined other entities, wherein the comparison is employed to determine one or more differences between the one or more profiles and the configuration information; and

providing notification of the one or more determined entities and the differences between the one or more profiles for the one or more determined entities and the configuration information for the previously determined other entities.

2. The method of claim 1 , wherein the comparing further comprises:

determining the one or more differences based on employing the one or more profiles to identify one or more errors or omissions in a database for the configuration information.

3. The method of claim 1 , further comprising:

remediating the one or more determined differences by correcting one or more errors or omissions identified in a database for the configuration information based on the one or more profiles.

4. The method of claim 1 , further comprising:

in response to the one or more determined differences, performing one or more audits including a software license audit, a device license audit, an inventory audit, a security audit, or an entity relationship audit; and

employing the one or more audits to identify each determined difference that violates one or more policies.

5. The method of claim 1 , further comprising:

providing one or more device profiles that correspond to one or more network devices that are determined based on the passive monitoring of the network;

providing one or more application profiles that correspond to one or more applications that are determined based on the passive monitoring of the network; and

providing the one or more profiles based on an association of the one or more device profiles with the one or more application profiles.

6. The method of claim 1 , wherein the comparing further comprises:

employing one or more items in a database to determine configuration information that is unassociated with the one or more profiles.

7. The method of claim 1 , wherein determining the one or more entities, further comprises:

employing one or more metrics for the one or more network flows to determine the one or more entities, wherein the one or more metrics include number of connections, traffic rate, traffic direction information, duration of connections, security credentials, secure cipher suites used, types of protocols, or errors.

8. A network monitoring computer (NMC) on a network, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

passively monitoring the network to provide a plurality of characteristics associated with one or more network flows, wherein the passive monitoring avoids decryption of encrypted packets in the one or more network flows;

employing one or more of the plurality of characteristics to determine one or more unknown entities on the network, wherein one or more profiles are determined for the one or more determined entities based on the one or more characteristics;

comparing the one or more profiles to configuration information associated with one or more previously determined other entities, wherein the comparison is employed to determine one or more differences between the one or more profiles and the configuration information; and

providing notification of the one or more determined entities and the differences between the one or more profiles for the one or more determined entities and the configuration information for the previously determined other entities.

9. The NMC of claim 8 , wherein the comparing further comprises:

determining the one or more differences based on employing the one or more profiles to identify one or more errors or omissions in a database for the configuration information.

10. The NMC of claim 8 , further comprising:

remediating the one or more determined differences by correcting one or more errors or omissions identified in a database for the configuration information based on the one or more profiles.

11. The NMC of claim 8 , further comprising:

in response to the one or more determined differences, performing one or more audits including a software license audit, a device license audit, an inventory audit, a security audit, or an entity relationship audit; and

employing the one or more audits to identify each determined difference that violates one or more policies.

12. The NMC of claim 8 , further comprising:

providing one or more device profiles that correspond to one or more network devices that are determined based on the passive monitoring of the network;

providing one or more application profiles that correspond to one or more applications that are determined based on the passive monitoring of the network; and

providing the one or more profiles based on an association of the one or more device profiles with the one or more application profiles.

13. The NMC of claim 8 , wherein the comparing further comprises:

employing one or more items in a database to determine configuration information that is unassociated with the one or more profiles.

14. The NMC of claim 8 , wherein determining the one or more entities, further comprises:

employing one or more metrics for the one or more network flows to determine the one or more entities, wherein the one or more metrics include number of connections, traffic rate, traffic direction information, duration of connections, security credentials, secure cipher suites used, types of protocols, or errors.

15. A processor readable non-transitory storage media that includes instructions for monitoring network traffic over a network between one or more computers, wherein execution of the instructions by one or more processors on one or more network monitoring computers (NMCs) performs actions, comprising:

passively monitoring the network to provide a plurality of characteristics associated with one or more network flows, wherein the passive monitoring avoids decryption of encrypted packets in the one or more network flows;

employing one or more of the plurality of characteristics to determine one or more unknown entities on the network, wherein one or more profiles are determined for the one or more determined entities based on the one or more characteristics;

comparing the one or more profiles to configuration information associated with one or more previously determined other entities, wherein the comparison is employed to determine one or more differences between the one or more profiles and the configuration information; and

providing notification of the one or more determined entities and the differences between the one or more profiles for the one or more determined entities and the configuration information for the previously determined other entities.

16. The media of claim 15 , wherein the comparing further comprises:

determining the one or more differences based on employing the one or more profiles to identify one or more errors or omissions in a database for the configuration information.

17. The media of claim 15 , further comprising:

remediating the one or more determined differences by correcting one or more errors or omissions identified in a database for the configuration information based on the one or more profiles.

18. The media of claim 15 , further comprising:

in response to the one or more determined differences, performing one or more audits including a software license audit, a device license audit, an inventory audit, a security audit, or an entity relationship audit; and

employing the one or more audits to identify each determined difference that violates one or more policies.

19. The media of claim 15 , further comprising:

providing one or more device profiles that correspond to one or more network devices that are determined based on the passive monitoring of the network;

providing one or more application profiles that correspond to one or more applications that are determined based on the passive monitoring of the network; and

providing the one or more profiles based on an association of the one or more device profiles with the one or more application profiles.

20. The media of claim 15 , wherein determining the one or more entities, further comprises:

employing one or more metrics for the one or more network flows to determine the one or more entities, wherein the one or more metrics include number of connections, traffic rate, traffic direction information, duration of connections, security credentials, secure cipher suites used, types of protocols, or errors.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2019
From: MUKERJI, ARINDUM; FRY, JEFFERY BRADFORD
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 048889/0019 →
Continuity (2)
Continuation 15675216 · Aug 11, 2017
Related Publication 20190245759A1 · Aug 8, 2019
Cited By (7)
US 12,225,030 US 12,309,192 US 12,355,816 US 12,483,384 US 12,587,535 US 12,647,441 US 12,652,312