IP Library Granted Patent US 11,012,329
Granted Patent B2
US 11,012,329 · App. 16/565,109 · Granted May 18, 2021

Correlating causes and effects associated with network activity

Inventors: Eric Jacob Ball (Seattle, WA); Eric Joseph Hammerle (Seattle, WA); Benjamin Thomas Higgins (Shoreline, WA); Bhushan Prasad Khanal (Seattle, WA); Michael Kerber Krause Montague (Lake Forest Park, WA); Xue Jun Wu (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L43/062H04L43/04H04L43/08H04L43/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,012,329
App. No.
16/565,109
Filed
Sep 9, 2019
Granted
May 18, 2021
Kind
B2
Examiner
JOO, JOSHUA
Art Unit
2445
USPC
709/224
Abstract

Embodiments are directed to monitoring network traffic using a monitoring engine that monitors network traffic in networks to provide metrics. An inference engine may provide activity profiles based on portions of the network traffic where each activity profile includes features associated with the portions of network traffic. The inference engine may determine other activity profiles correlated with the activity profiles based on correlation models such that the determination of the other activity profiles occurs prior to monitoring an occurrence of other portions of the network traffic. The inference engine may modify monitoring actions of the monitoring engine based on the other activity profiles. The inference engine may provide reports based on the portions of the network traffic, the activity profiles, the other portions of the network traffic, or the other activity profiles.

Claims (70)

1. A method for monitoring network traffic using one or more network computers, wherein execution of instructions by the one or more network computers perform the method comprising:

monitoring one or more portions of network traffic to provide one or more metrics associated with a plurality of entities in one or more networks;

employing the one or more portions of the network traffic to provide one or more activity profiles;

employing one or more models to determine one or more other activity profiles that correlate with the one or more activity profiles;

monitoring one or more other portions of the monitored network traffic based on the one or more other activity profiles, wherein the determination of the one or more other activity profiles occurs separate from the monitoring of the one or more other portions of the network traffic;

determining a score for each of the one or more models based on the occurrence of the one or more other portions of network traffic subsequent to the one or more portions of the network traffic;

determining the one or more models that require re-training based on the determined score having a value that is below a threshold value;

re-training the one or more determined models based on the network traffic; and

providing one or more reports to one or more users.

2. The method of claim 1 , wherein providing the one or more reports further comprises:

providing one or more interactive reports that enable feedback from the one or more users, wherein the feedback includes:

providing one or more ratings for the one or more models; and

providing one or more associations between the one or more models and one or more of notifications, events, priorities, or triggered actions.

3. The method of claim 1 , further comprising enabling the one or more users to selectively activate or deactivate the one or more models.

4. The method of claim 1 , further comprising providing one or more weights to one or more correlations determined between at least a portion of the one or more activity profiles and the one or more other activity profiles, wherein the one or more weights are based on an importance of a correlation to the one or more users.

5. The method of claim 1 , further comprising modifying the monitoring of the network traffic based on one or more correlations between the one or more activity profiles and the one or more other activity profiles, wherein the modifications include one or more of increasing monitoring detail, decreasing monitoring detail, collecting more metrics, collecting less metrics, capturing more data packets, or capturing less data packets.

6. The method of claim 1 , further comprising:

training the one or more models based on the network traffic and the one or more activity profiles, wherein the one or more models provide correlations that predict a likelihood of the occurrence of the one or more other portions of network traffic subsequent to the occurrence of the one or more portions of the network traffic based on one or more dependencies associated with the one or more activity profiles and the one or more other activity profiles.

7. A system for monitoring network traffic in a network:

one or more network computers, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

monitoring one or more portions of network traffic to provide one or more metrics associated with a plurality of entities in one or more networks;

employing the one or more portions of the network traffic to provide one or more activity profiles;

employing one or more models to determine one or more other activity profiles that correlate with the one or more activity profiles;

monitoring one or more other portions of the monitored network traffic based on the one or more other activity profiles, wherein the determination of the one or more other activity profiles occurs separate from the monitoring of the one or more other portions of the network traffic;

determining a score for each of the one or more models based on the occurrence of the one or more other portions of network traffic subsequent to the one or more portions of the network traffic;

determining the one or more models that require re-training based on the determined score having a value that is below a threshold value;

re-training the one or more determined models based on the network traffic; and

providing one or more reports to one or more users; and

one or more client computers, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing one or more portions of the monitored network traffic.

8. The system of claim 7 , wherein providing the one or more reports further comprises:

providing one or more interactive reports that enable feedback from the one or more users, wherein the feedback includes:

providing one or more ratings for the one or more models; and

providing one or more associations between the one or more models and one or more of notifications, events, priorities, or triggered actions.

9. The system of claim 7 , further comprising enabling the one or more users to selectively activate or deactivate the one or more models.

10. The system of claim 7 , further comprising providing one or more weights to one or more correlations determined between at least a portion of the one or more activity profiles and the one or more other activity profiles, wherein the one or more weights are based on an importance of a correlation to the one or more users.

11. The system of claim 7 , further comprising modifying the monitoring of the network traffic based on one or more correlations between the one or more activity profiles and the one or more other activity profiles, wherein the modifications include one or more of increasing monitoring detail, decreasing monitoring detail, collecting more metrics, collecting less metrics, capturing more data packets, or capturing less data packets.

12. The system of claim 7 , further comprising:

training the one or more models based on the network traffic and the one or more activity profiles, wherein the one or more models provide correlations that predict a likelihood of the occurrence of the one or more other portions of network traffic subsequent to the occurrence of the one or more portions of the network traffic based on one or more dependencies associated with the one or more activity profiles and the one or more other activity profiles.

13. A network computer for monitoring communication over a network between two or more computers, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

monitoring one or more portions of network traffic to provide one or more metrics associated with a plurality of entities in one or more networks;

employing the one or more portions of the network traffic to provide one or more activity profiles;

employing one or more models to determine one or more other activity profiles that correlate with the one or more activity profiles;

monitoring one or more other portions of the monitored network traffic based on the one or more other activity profiles, wherein the determination of the one or more other activity profiles occurs separate from the monitoring of the one or more other portions of the network traffic;

determining a score for each of the one or more models based on the occurrence of the one or more other portions of network traffic subsequent to the one or more portions of the network traffic;

determining the one or more models that require re-training based on the determined score having a value that is below a threshold value;

re-training the one or more determined models based on the network traffic; and

providing one or more reports to one or more users.

14. The network computer of claim 13 , wherein providing the one or more reports further comprises:

providing one or more interactive reports that enable feedback from the one or more users, wherein the feedback includes:

providing one or more ratings for the one or more models; and

providing one or more associations between the one or more models and one or more of notifications, events, priorities, or triggered actions.

15. The network computer of claim 13 , further comprising enabling the one or more users to selectively activate or deactivate the one or more models.

16. The network computer of claim 13 , further comprising providing one or more weights to one or more correlations determined between at least a portion of the one or more activity profiles and the one or more other activity profiles, wherein the one or more weights are based on an importance of a correlation to the one or more users.

17. The network computer of claim 13 , further comprising modifying the monitoring of the network traffic based on one or more correlations between the one or more activity profiles and the one or more other activity profiles, wherein the modifications include one or more of increasing monitoring detail, decreasing monitoring detail, collecting more metrics, collecting less metrics, capturing more data packets, or capturing less data packets.

18. A processor readable non-transitory storage media that includes instructions for monitoring network traffic using one or more network monitoring computers, wherein execution of the instructions by the one or more network computers perform the method comprising:

monitoring one or more portions of network traffic to provide one or more metrics associated with a plurality of entities in one or more networks;

employing the one or more portions of the network traffic to provide one or more activity profiles;

employing one or more models to determine one or more other activity profiles that correlate with the one or more activity profiles;

monitoring one or more other portions of the monitored network traffic based on the one or more other activity profiles, wherein the determination of the one or more other activity profiles occurs separate from the monitoring of the one or more other portions of the network traffic;

determining a score for each of the one or more models based on the occurrence of the one or more other portions of network traffic subsequent to the one or more portions of the network traffic;

determining the one or more models that require re-training based on the determined score having a value that is below a threshold value;

re-training the one or more determined models based on the network traffic; and

providing one or more reports to one or more users.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2019
From: BALL, ERIC JACOB; HAMMERLE, ERIC JOSEPH; HIGGINS, BENJAMIN THOMAS; KHANAL, BHUSHAN PRASAD; MONTAGUE, MICHAEL KERBER KRAUSE; WU, XUE JUN
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 050318/0959 →
Continuity (2)
Continuation 16100116 · Aug 9, 2018
Related Publication 20200052985A1 · Feb 13, 2020
Cited By (7)
US 12,225,030 US 12,309,192 US 12,355,816 US 12,483,384 US 12,587,535 US 12,647,441 US 12,652,312