IP Library Granted Patent US 10,742,529
Granted Patent B2
US 10,742,529 · App. 16/392,950 · Granted Aug 11, 2020

Hierarchichal sharding of flows from sensors to collectors

Inventors: Shashidhar Gandham (Fremont, CA); Rohit Chandra Prasad (Sunnyvale, CA); Abhishek Ranjan Singh (Pleasanton, CA); Navindra Yadav (Cupertino, CA); Khawar Deen (Sunnyvale, CA); Varun Sagar Malhotra (Sunnyvale, CA)
Assignee: Cisco Technology, Inc.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F16/122G06F16/137G06F16/162G06F16/17G06F16/173G06F16/174G06F16/1744G06F16/1748G06F16/235G06F16/2322G06F16/2365G06F16/248G06F16/24578G06F16/285G06F16/288G06F16/29G06F16/9535G06F21/53G06F21/552G06F21/566G06N20/00G06N99/00G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/2007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/145H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/10H04L67/1002H04L67/12H04L67/16H04L67/36H04L67/42H04L69/16H04L69/22H04W72/08H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595G06F2221/033G06F2221/2101G06F2221/2105G06F2221/2111G06F2221/2115G06F2221/2145H04L67/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,742,529
App. No.
16/392,950
Granted
Aug 11, 2020
Kind
B2
Abstract

Systems, methods, and computer-readable media for hierarchichal sharding of flows from sensors to collectors. A first collector can receive a first portion of a network flow from a first capturing agent and determine that a second portion of the network flow was not received from the first capturing agent. The first collector can then send the first portion of the network flow to a second collector. A third collector can receive the second portion of the network flow from a second capturing agent and determine that the third collector did not receive the first portion of the network flow. The third collector can then send the second portion of the network flow to the second collector. The second collector can then aggregate the first portion and second portion of the network flow to yield the entire portion of the network flow.

Claims (46)

1. A method for managing a plurality of collectors including at least first, second and third collectors to recombine a network flow having first and second portions that have become separated, the method comprising:

receiving, by the first collector, the first portion of a network flow;

first determining, by the first collector, that the second portion of the network flow was not received;

based on the first determining, sending, by the first collector, the first portion of the network flow to the second collector;

receiving, by the third collector, the second portion of the network flow;

second determining, by the third collector, that the first portion of the network flow was not received;

based on the second determining, sending, by the third collector, the second portion of the network flow to the second collector; and

combining, by the second collector, the first portion of the network flow and the second portion of the network flow.

2. The method of claim 1 , further comprising:

assigning a plurality of capturing agents deployed throughout a network to respective shards, each of the plurality of capturing agents being configured to capture network activity associated with a respective host and report the network activity to one or more collectors in the respective shards, wherein each of the respective shards comprises a number of assigned collectors from the plurality of collectors.

3. The method of claim 2 , wherein the first portion of the network flow is transmitted by a first capturing agent to a first shard from the respective shards, and the second portion of the network flow is transmitted by a second capturing agent to a second shard from the respective shards, wherein the first collector is part of the first shard and the third collector is part of the second shard.

4. The method of claim 2 , wherein the second collector is part of a shard from the respective shards, and wherein the second collector is assigned a flow key and hash that corresponds to the network flow.

5. The method of claim 4 , wherein the second collector is selected to receive the first portion and the second portion of the network flow from a plurality of other collectors in the shard based on the flow key and hash corresponding to the network flow.

6. The method of claim 1 , wherein the first collector and the third collector are mapped to respective shards from a first layer of shards, each of the respective shards comprising a selected group of collectors, and wherein the second collector is mapped to a shard from a second layer of shards.

7. The method of claim 6 , wherein the first layer of shards is designated to receive network flow data directly from capturing agents deployed throughout a network, and wherein the second layer of shards is designated to receive different portions of the network flow data directly from different collectors in the first layer of shards.

8. A non-transitory computer-readable storage media storing instructions for managing a plurality of collectors including at least first, second and third collectors to recombine a network flow having first and second portions that have become separated, which when executed by a processor cause the processor to perform operations comprising:

receiving, by the first collector, the first portion of a network flow;

first determining, by the first collector, that the second portion of the network flow was not received;

based on the first determining, sending, by the first collector, the first portion of the network flow to the second collector;

receiving, by the third collector, the second portion of the network flow;

second determining, by the third collector, that the first portion of the network flow was not received;

based on the second determining, sending, by the third collector, the second portion of the network flow to the second collector; and

combining, by the second collector, the first portion of the network flow and the second portion of the network flow.

9. The media of claim 8 , the operations further comprising:

assigning a plurality of capturing agents deployed throughout a network to respective shards, each of the plurality of capturing agents being configured to capture network activity associated with a respective host and report the network activity to one or more collectors in the respective shards, wherein each of the respective shards comprises a number of assigned collectors from the plurality of collectors.

10. The media of claim 9 , wherein the first portion of the network flow is transmitted by a first capturing agents to a first shard from the respective shards, and the second portion of the network flow is transmitted by a second capturing agents to a second shard from the respective shards, wherein the first collector is part of the first shard and the third collector is part of the second shard.

11. The media of claim 9 , wherein the second collector is part of a shard from the respective shards, and wherein the second collector is assigned a flow key and hash that corresponds to the network flow.

12. The media of claim 11 , wherein the second collector is selected to receive the first portion and the second portion of the network flow from a plurality of other collectors in the shard based on the flow key and hash corresponding to the network flow.

13. The media of claim 8 , wherein the first collector and the third collector are mapped to respective shards from a first layer of shards, each of the respective shards comprising a selected group of collectors, and wherein the second collector is mapped to a shard from a second layer of shards.

14. The media of claim 13 , wherein the first layer of shards is designated to receive network flow data directly from capturing agents deployed throughout a network, and wherein the second layer of shards is designated to receive different portions of the network flow data directly from different collectors in the first layer of shards.

15. A system for managing a plurality of collectors including at least first, second and third collectors to recombine a network flow having first and second portions that have become separated, the system comprising:

a processor; and

a computer-readable storage device having stored therein instructions which, when executed by the processor, cause the system to perform operations comprising:

receiving, by the first collector, the first portion of a network flow;

first determining, by the first collector, that the second portion of the network flow was not received;

based on the first determining, sending, by the first collector, the first portion of the network flow to the second collector;

receiving, by the third collector, the second portion of the network flow;

second determining, by the third collector, that the first portion of the network flow was not received;

based on the second determining, sending, by the third collector, the second portion of the network flow to the second collector; and

combining, by the second collector, the first portion of the network flow and the second portion of the network flow.

16. The system of claim 15 , the operations further comprising:

assigning a plurality of capturing agents deployed throughout a network to respective shards, each of the plurality of capturing agents being configured to capture network activity associated with a respective host and report the network activity to one or more collectors in the respective shards, wherein each of the respective shards comprises a number of assigned collectors from the plurality of collectors.

17. The system of claim 16 , wherein the first portion of the network flow is transmitted by a first capturing agents to a first shard from the respective shards, and the second portion of the network flow is transmitted by a second capturing agents to a second shard from the respective shards, wherein the first collector is part of the first shard and the third collector is part of the second shard.

18. The system of claim 16 , wherein the second collector is part of a shard from the respective shards, and wherein the second collector is assigned a flow key and hash that corresponds to the network flow.

19. The system of claim 18 , wherein the second collector is selected to receive the first portion and the second portion of the network flow from a plurality of other collectors in the shard based on the flow key and hash corresponding to the network flow.

20. The system of claim 15 , wherein the first collector and the third collector are mapped to respective shards from a first layer of shards, each of the respective shards comprising a selected group of collectors, and wherein the second collector is mapped to a shard from a second layer of shards.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2019
From: GANDHAM, SHASHIDHAR; PRASAD, ROHIT CHANDRA; SINGH, ABHISHEK RANJAN; YADAV, NAVINDRA; DEEN, KHAWAR; MALHOTRA, VARUN SAGAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 048988/0639 →
Continuity (3)
Continuation 15171855 · Jun 2, 2016
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20190253330A1 · Aug 15, 2019