IP Library Granted Patent US 11,509,559
Granted Patent B2
US 11,509,559 · App. 16/562,258 · Granted Nov 22, 2022

Monitoring overlay networks

Inventors: Nicholas Anthony Marrone (Seattle, WA); Bryan David Skene (Seattle, WA); Ludwin Fuchs (Seattle, WA); Jeffrey Scott Hussey (Seattle, WA)
Assignee: Tempered Networks, Inc.
H04L43/0876H04L12/66H04L41/06H04L41/0893H04L43/08H04L45/64H04L63/20H04L65/102H04L67/1001H04L43/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,509,559
App. No.
16/562,258
Granted
Nov 22, 2022
Kind
B2
Abstract

Embodiments are directed to managing communication over one or more networks. A monitoring engine may be instantiated to perform actions including receiving network traffic from a physical network that may be associated with network addresses of the physical network. The monitoring engine may analyze the network traffic to associate activity with gateway identifiers (GIDs) associated with gateway computers in an overlay network such that the GIDs are separate from the network addresses. The monitoring engine may be arranged to monitor the network traffic based on monitoring rules. The monitoring engine may provide metrics associated with the gateway computers based on the monitoring of the network traffic. The monitoring engine may compare the metrics to event rules. The monitoring engine may generate events based on affirmative results of the comparison. The events may be mapped to actions based on characteristics of the events and executed.

Claims (52)

1. A method for managing communication over one or more networks using one or more network computers, wherein execution of instructions by the one or more network computers perform the method comprising:

monitoring network traffic for the one or more networks, wherein the network traffic is associated with one or more network addresses of a plurality of physical networks and is further associated with one or more gateway identifiers (GIDs) for one or more gateway computers in one or more physical networks that are private and an underlying part of one or more associated overlay networks that are public and employed by one or more relay computers in one or more physical networks that are public to establish one or more intermediate connections between the one or more gateway computers to prevent direct access and visibility of the one or more private and public physical networks and their associated network traffic by one or more nodes that are members of the overlay network, wherein the one or more nodes are interconnected endpoints in the overlay network which operates as a logical network that provides an abstraction layer to hide the underlying part of the one or more physical networks from members of the overlay network;

providing one or more metrics associated with the one or more gateway computers based on the monitoring of the network traffic over the one or more private physical networks that are the underlying part of the one or more associated overlay networks and the one or more GIDs;

generating one or more events based on one or more affirmative comparisons of the one or more metrics to one or more event rules; and

employing one or more characteristics of the one or more events to execute one or more actions based on the one or more events.

2. The method of claim 1 , further comprising:

employing a network computer as a management platform computer that provides one or more monitoring rules and one or more event rules; and

wherein monitoring the network traffic is based on the one or more monitoring rules, and wherein executing the one or more actions is based on the one or more event rules.

3. The method of claim 1 , further comprising:

determining one or more node computers that connect to the one or more gateway computers; and

generating an event that includes information about the node computer, including, one or more of the one or more GIDs, a media access control (MAC) address, a network address, a hostname, a cryptographic key, or a security certificate.

4. The method of claim 1 , further comprising:

employing the one or more relay computers configured in the overlay network to provide a communication path between two or more gateway computers in the overlay network.

5. The method of claim 1 , wherein employing the one or more characteristics of the one or more events to execute the one or more actions is performed local to a network computer that is monitoring the network traffic.

6. The method of claim 1 , further comprising monitoring one or more devices in the overlay network, wherein the devices include one or more of an individual network device, a group of network devices, or at least one network device that is associated with the one or more gateway computers.

7. The method of claim 1 , wherein executing the one or more actions further comprises:

executing one or more of an ordered sequence of sub-actions that are based on a type of the one or more events, or one or more scripts.

8. A processor readable non-transitory storage media that includes instructions for managing communication over one or more networks, wherein execution of the instructions by the one or more network computers perform the method comprising:

monitoring network traffic for the one or more networks, wherein the network traffic is associated with one or more network addresses of a plurality of physical networks and is further associated with one or more gateway identifiers (GIDs) for one or more gateway computers in one or more physical networks that are private and an underlying part of one or more associated overlay networks that are public and employed by one or more relay computers in one or more physical networks that are public to establish one or more intermediate connections between the one or more gateway computers to prevent direct access and visibility of the one or more private and public physical networks and their associated network traffic by one or more nodes that are members of the overlay network, wherein the one or more nodes are interconnected endpoints in the overlay network which operates as a logical network that provides an abstraction layer to hide the underlying part of the one or more physical networks from members of the overlay network;

providing one or more metrics associated with the one or more gateway computers based on the monitoring of the network traffic over the one or more private physical networks that are the underlying part of the one or more associated overlay networks and the one or more GIDs;

generating one or more events based on one or more affirmative comparisons of the one or more metrics to one or more event rules; and

employing one or more characteristics of the one or more events to execute one or more actions based on the one or more events.

9. The media of claim 8 , further comprising:

employing a network computer as a management platform computer that provides one or more monitoring rules and one or more event rules; and

wherein monitoring the network traffic is based on the one or more monitoring rules, and wherein executing the one or more actions is based on the one or more event rules.

10. The media of claim 8 , further comprising:

determining one or more node computers that connect to the one or more gateway computers; and

generating an event that includes information about the node computer, including, one or more of the one or more GIDs, a media access control (MAC) address, a network address, a hostname, a cryptographic key, or a security certificate.

11. The media of claim 8 , further comprising:

employing the one or more relay computers configured in the overlay network to provide a communication path between two or more gateway computers in the overlay network.

12. The media of claim 8 , wherein employing the one or more characteristics of the one or more events to execute the one or more actions is performed local to a network computer that is monitoring the network traffic.

13. The media of claim 8 , further comprising monitoring one or more devices in the overlay network, wherein the devices include one or more of an individual network device, a group of network devices, or at least one network device that is associated with the one or more gateway computers.

14. The media of claim 8 , wherein executing the one or more actions further comprises:

executing one or more of an ordered sequence of sub-actions that are based on a type of the one or more events, or one or more scripts.

15. A network computer for managing communication over one or more networks, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

monitoring network traffic for the one or more networks, wherein the network traffic is associated with one or more network addresses of a plurality of physical networks and is further associated with one or more gateway identifiers (GIDs) for one or more gateway computers in one or more physical networks that are private and an underlying part of one or more associated overlay networks that are public and employed by one or more relay computers in one or more physical networks that are public to establish one or more intermediate connections between the one or more gateway computers to prevent direct access and visibility of the one or more private and public physical networks and their associated network traffic by one or more nodes that are members of the overlay network, wherein the one or more nodes are interconnected endpoints in the overlay network which operates as a logical network that provides an abstraction layer to hide the underlying part of the one or more physical networks from members of the overlay network;

providing one or more metrics associated with the one or more gateway computers based on the monitoring of the network traffic over the one or more private physical networks that are the underlying part of the one or more associated overlay networks and the one or more GIDs;

generating one or more events based on one or more affirmative comparisons of the one or more metrics to one or more event rules; and

employing one or more characteristics of the one or more events to execute one or more actions based on the one or more events.

16. The network computer of claim 15 , further comprising:

employing the network computer as a management platform computer that provides one or more monitoring rules and one or more event rules; and

wherein monitoring the network traffic is based on the one or more monitoring rules, and wherein executing the one or more actions is based on the one or more event rules.

17. The network computer of claim 15 , further comprising:

determining one or more node computers that connect to the one or more gateway computers; and

generating an event that includes information about the node computer, including, one or more of the one or more GIDs, a media access control (MAC) address, a network address, a hostname, a cryptographic key, or a security certificate.

18. The network computer of claim 15 , further comprising:

employing the one or more relay computers configured in the overlay network to provide a communication path between two or more gateway computers in the overlay network.

19. The network computer of claim 15 , further comprising monitoring one or more devices in the overlay network, wherein the devices include one or more of an individual network device, a group of network devices, or at least one network device that is associated with the one or more gateway computers.

20. The network computer of claim 15 , wherein executing the one or more actions further comprises:

executing one or more of an ordered sequence of sub-actions that are based on a type of the one or more events, or one or more scripts.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2025
From: MARRONE, NICHOLAS ANTHONY; SKENE, BRYAN DAVID; FUCHS, LUDWIN; HUSSEY, JEFFREY SCOTT
To: TEMPERED NETWORKS, INC.
Reel/Frame 072928/0154 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2024
From: JOHNSON CONTROLS TYCO IP HOLDINGS LLP
To: TYCO FIRE & SECURITY GMBH
Reel/Frame 067056/0552 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2023
From: TEMPERED NETWORKS, INC.
To: JOHNSON CONTROLS TYCO IP HOLDINGS LLP
Reel/Frame 065406/0415 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2019
From: MARRONE, NICHOLAS ANTHONY; SKENE, BRYAN DAVID; FUCHS, LUDWIN; HUSSEY, JEFFREY SCOTT
To: TEMPERED NETWORKS, INC.
Reel/Frame 050295/0309 →
Continuity (3)
Continuation 16221145 · Dec 14, 2018
Continuation 15994760 · May 31, 2018
Related Publication 20190394107A1 · Dec 26, 2019
Cited By (2)
US 12,574,416 US 12,634,232