IP Library Granted Patent US 11,252,060
Granted Patent B2
US 11,252,060 · App. 16/741,528 · Granted Feb 15, 2022

Data center traffic analytics synchronization

Inventors: Khawar Deen (Sunnyvale, CA); Navindra Yadav (Cupertino, CA); Anubhav Gupta (Fremont, CA); Shashidhar Gandham (Fremont, CA); Rohit Chandra Prasad (Sunnyvale, CA); Abhishek Ranjan Singh (Pleasanton, CA); Shih-Chun Chang (San Jose, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F16/122G06F16/137G06F16/162G06F16/17G06F16/173G06F16/174G06F16/1744G06F16/1748G06F16/235G06F16/2322G06F16/2365G06F16/248G06F16/24578G06F16/285G06F16/288G06F16/29G06F16/9535G06F21/53G06F21/552G06F21/566G06N20/00G06N99/00G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/026H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/2007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/145H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/10H04L67/1002H04L67/12H04L67/16H04L67/36H04L67/42H04L69/16H04L69/22H04W72/08H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595G06F2221/033G06F2221/2101G06F2221/2105G06F2221/2111G06F2221/2115G06F2221/2145H04L67/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,252,060
App. No.
16/741,528
Filed
Jan 13, 2020
Granted
Feb 15, 2022
Kind
B2
Art Unit
2457
USPC
709/224
Abstract

A network analytics system can receive first sensor data, including first network activity and a first timestamp associated with a first clock of a first node, and second sensor data, including second network activity and a second timestamp associated with a second clock of a second node. The system can determine a first delta between the first clock and a third clock based on the first timestamp, and a second delta between the second clock and the third clock. The system can determine a first communication latency associated with a first sensor of the first node, and a second communication latency associated with a second sensor of the second node. The system can generate a report that synchronizes one or more data flows between the first node and the second node based on the first delta, the second delta, the first communication latency, and the second communication latency.

Claims (60)

1. A computer-implemented method, comprising:

receiving, by a network analytics system, first sensor data, including first network activity and a first timestamp associated with a first clock of a first node of a data center, from a first sensor of the first node, and second sensor data, including second network activity and a second timestamp associated with a second clock of a second node of the data center, from a second sensor of the second node;

determining, by the network analytics system, a first delta between the first clock and a third network clock of the network analytics system based on the first timestamp, and a second delta between and the second clock and the third clock based on the second timestamp;

determining, by the network analytics system, a first communication latency between the network analytics system and the first sensor, and a second communication latency between the network analytics system and the second sensor; and

generating, by the network analytics system, a report that synchronizes one or more data flows between the first node and the second node based on the first delta, the second delta, the first communication latency, and the second communication latency.

2. The computer-implemented method of claim 1 , further comprising:

identifying a first Layer 7 process executing within the first node that initiates the one or more data flows based on the report.

3. The computer-implemented method of claim 2 , further comprising:

identifying a second Layer 7 process executing within the second node in response to initiation of the one or more data flows based on the report.

4. The computer-implemented method of claim 2 , further comprising:

identifying a user associated with the first Layer 7 process based on the report.

5. The computer-implemented method of claim 2 , further comprising:

determining an amount of at least one of central processing unit (CPU) utilization, memory utilization, or storage utilization associated with the first Layer 7 process based on the report.

6. The computer-implemented method of claim 1 , further comprising:

identifying a network attack that initiates the one or more data flows based on the report.

7. The computer-implemented method of claim 1 , further comprising:

receiving third sensor data including third network activity and a third timestamp associated with a clock of a switch or router;

determining a third delta between the clock of the switch or router and the third clock based on the third timestamp;

determining a third communication latency between the network analytics system and the switch or router; and

determining a data path between the first node and the second node based on the first delta, the second delta, the third delta, the first communication latency, the second communication latency, and the third communication latency.

8. The computer-implemented method of claim 7 , further comprising:

receiving fourth sensor data including fourth network activity and a fourth timestamp associated with a clock of a firewall;

determining a fourth delta between the clock of the firewall and the third clock based on the fourth timestamp; and

determining a fourth communication latency between the network analytics system and the firewall,

wherein the data path is further determined based on fourth delta and the fourth communication latency.

9. The computer-implemented method of claim 1 , wherein the first node and the second node reside within a same physical server.

10. The computer-implemented method of claim 1 , wherein the first report is received by a first collector of the network analytics system and the second report is received by a second collector of the network analytics system.

11. A system, comprising:

one or more processors;

memory including instructions that, when executed by the one or more processors, cause the system to:

receive first sensor data, including first network activity and a first timestamp associated with a first clock of a first node of a data center, from a first sensor of the first node, and second sensor data, including second network activity and a second timestamp associated with a second clock of a second node of the data center, from a second sensor of the second node;

determine a first delta between the first clock and a third clock of the network analytics system based on the first timestamp, and a second delta between and the second clock and the third clock based on the second timestamp;

determine a first communication latency between the network analytics system and the first sensor, and a second communication latency between the network analytics system and the second sensor;

generate a report that synchronizes one or more data flows between the first node and the second node based on the first delta, the second delta, the first communication latency, and the second communication latency; and

identify a first Layer 7 process executing within the first node that initiates the one or more data flows based on the report.

12. The system of claim 11 , further comprising further instructions that, when executed by the one or more processors, further cause the system to:

identify a second Layer 7 process executing within the second node in response to initiation of the one or more data flows based on the report.

13. The system of claim 11 , further comprising further instructions that, when executed by the one or more processors, further cause the system to:

identify a user associated with the first Layer 7 process based on the report.

14. The system of claim 11 , further comprising further instructions that, when executed by the one or more processors, further cause the system to:

determine an amount of at least one of central processing unit (CPU) utilization, memory utilization, or storage utilization associated with the first Layer 7 process based on the report.

15. A non-transitory computer-readable medium including instructions that, when executed by one or more processors of a system, cause the system to:

receive first sensor data, including first network activity and a first timestamp associated with a first clock of a first node of a data center, from a first sensor of the first node, and second sensor data, including second network activity and a second timestamp associated with a second clock of a second node of the data center, from a second sensor of the second node;

determine a first delta between the first clock and a third clock of the network analytics system based on the first timestamp, and a second delta between and the second clock and the third clock based on the second timestamp;

determine a first communication latency between the network analytics system and the first sensor, and a second communication latency between the network analytics system and the second sensor; and

generate a report that synchronizes one or more data flows between the first node and the second node based on the first delta, the second delta, the first communication latency, and the second communication latency.

16. The non-transitory computer-readable medium of claim 15 , further comprising further instructions that, when executed by the one or more processors, further cause the system to:

identify a network attack that initiates the one or more data flows based on the report.

17. The non-transitory computer-readable medium of claim 15 , further comprising further instructions that, when executed by the one or more processors, further cause the system to:

receive third sensor data including third network activity and a third timestamp associated with a clock of a switch or router;

determine a third delta between the clock of the switch or router and the third clock based on the third timestamp;

determine a third communication latency between the network analytics system and the switch or router; and

determine a data path between the first node and the second node based on the first delta, the second delta, the third delta, the first communication latency, the second communication latency, and the third communication latency.

18. The non-transitory computer-readable medium of claim 17 , further comprising further instructions that, when executed by the one or more processors, further cause the system to:

receive fourth sensor data including fourth network activity and a fourth timestamp associated with a clock of a firewall;

determine a fourth delta between the clock of the firewall and the third clock based on the fourth timestamp; and

determine a fourth communication latency between the network analytics system and the firewall,

wherein the data path is further determined based on fourth delta and the fourth communication latency.

19. The non-transitory computer-readable medium of claim 17 , wherein the first node and the second node reside within a same physical server.

20. The non-transitory computer-readable medium of claim 17 , wherein the first report is received by a first collector of the system and the second report is received by a second collector of the system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2020
From: DEEN, KHAWAR; YADAV, NAVINDRA; GUPTA, ANUBHAV; GANDHAM, SHASHIDHAR; PRASAD, ROHIT CHANDRA; SINGH, ABHISHEK RANJAN; CHANG, SHIH-CHUN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 051500/0497 →
Continuity (3)
Continuation 15040829 · Feb 10, 2016
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20200228426A1 · Jul 16, 2020