IP Library Granted Patent US 11,558,410
Granted Patent B2
US 11,558,410 · App. 16/877,854 · Granted Jan 17, 2023

Measurement and analysis of traffic filtered by network infrastructure

Inventors: Scott Iekel-Johnson (Ann Arbor, MI); James Edward Winquist (Ypsilanti, MI); David Watson (Ann Arbor, MI)
Assignee: Arbor Networks, Inc.
H04L63/1425H04L63/0236H04L63/0263H04L63/1416H04L63/1458H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,558,410
App. No.
16/877,854
Granted
Jan 17, 2023
Kind
B2
Abstract

A computer-implemented method and device for analyzing network packet traffic flow affected by a network security device in a communication network. Received in a network monitoring device is packet traffic flow data from a network security device that filters network traffic based upon prescribed security filter settings. The network monitoring device analyzes the received packet traffic flow data by correlating the received traffic flow data with the security filter settings prescribed in the network security device. Certain statistics are identified regarding the network traffic flow affected by the security filter settings of the network security device based upon the correlating of the received traffic flow data with the security filter settings prescribed in the network security device. A report regarding the identified statistics is preferably sent to a network administrator.

Claims (30)

1. A computer-implemented method for analyzing network packet traffic flow affected by a network security device, comprising the steps:

receiving, in a network monitoring device, packet traffic flow data from a network security device that filters network traffic based upon prescribed security filter settings;

analyzing, in the network monitoring device, the received packet traffic flow data by correlating the received traffic flow data with the security filter settings prescribed in the network security device;

identifying certain statistics regarding the network traffic flow affected by the security filter settings of the network security device based upon the correlating of the received traffic flow data with the security filter settings prescribed in the network security device;

automatically adjusting the prescribed security filter settings based upon the analyzing of the received traffic flow data associated with the prescribed security filter settings, and identifying certain statistics regarding the analyzed traffic flow; and

reporting the identified statistics to a network administrator.

2. The computer-implemented method as recited in claim 1 , wherein the prescribed security filter settings are adjusted to mitigate legitimate traffic flow from being effected by the prescribed security filter settings of the network security device.

3. The computer-implemented method as recited in claim 1 , wherein the adjusted security filter settings are sent from the network monitoring device to the network security device without user intervention.

4. The computer-implemented method as recited in claim 3 , wherein a BGP flowspec route is utilized between the network monitoring device and the network security device for prescribing the adjusted security filter settings in a security filter of the network security device.

5. The computer-implemented method as recited in claim 1 , wherein the network security device is a network router device.

6. The computer-implemented method as recited in claim 5 , wherein the network router device is located upstream of the network monitoring device relative to the network packet traffic flow.

7. The computer-implemented method as recited in claim 1 , wherein the network security device exports telemetry data to the network monitoring device regarding network traffic flow data received by the network monitoring device wherein the telemetry data traffic flow records indicate performance metrics associated with the network security filter.

8. The computer-implemented method as recited in claim 7 , wherein a network protocol utilized for sending the telemetry data from the network security device to the network monitoring device is selected from the group consisting of: Netflow, IPFIX, and sFlow.

9. The computer-implemented method as recited in claim 1 , wherein reporting the identified statistics to a network administrator includes indicating whether a network attack is currently ongoing based upon the identifying certain statistics regarding the traffic flow.

10. The computer-implemented method as recited in claim 1 , wherein reporting the identified statistics to a network administrator includes reporting traffic flow change characteristics associated with the indicated ongoing network attack so as to indicate how the current network attack is changing.

11. The computer-implemented method as recited in claim 1 , wherein reporting the identified statistics to a network administrator includes one or more data parameters associated with a network attack: origin country, IP address, network, and organization.

12. The computer-implemented method as recited in claim 1 , wherein reporting the identified statistics to a network administrator includes indicating the types of the traffic included in a network attack.

13. The computer-implemented method as recited in claim 1 , wherein the identified statistics are reported to the network administrator via one or more of: a graphical user interface (GUI), Application Program Interface (API) and a Command-Line Interface.

14. A network monitoring device for analyzing network packet traffic flow affected by a network router device configured to filter network traffic flow, comprising:

a memory configured to store instructions;

a processor disposed in communication with the memory, wherein said processor upon execution of the instructions is configured to:

receive packet traffic flow data from at least one network router device that filters network traffic based upon prescribed security filter settings;

analyze the received packet traffic flow data by correlating the received traffic flow data with the security filter settings prescribed in the at least one network router device;

identifying certain statistics regarding the network traffic flow affected by the security filter settings of the at least one network router device based upon the correlating of the received traffic flow data with the security filter settings prescribed in the at least one network router device;

automatically adjusting the prescribed security filter settings based upon the analyzing of the received traffic flow data associated with the prescribed security filter settings, and identifying certain statistics regarding the analyzed traffic flow; and

reporting the identified statistics to a network administrator.

15. The network monitoring device as recited in claim 14 , wherein the prescribed security filter settings are adjusted to mitigate legitimate traffic flow from being effected by the prescribed security filter settings of the at least one network router device.

16. The network monitoring device as recited in claim 15 , wherein a BGP flowspec route is utilized between the network monitoring device and the at least one network router device for prescribing the adjusted security filter settings in a security filter of the at least one network router device.

17. The network monitoring device as recited in claim 16 , wherein the at least one network router device exports telemetry data to the network monitoring device regarding network traffic flow data received by the at least network router device wherein the telemetry data traffic flow records indicate performance metrics associated with the network security filter.

18. The network monitoring device as recited in claim 17 , wherein reporting the identified statistics to a network administrator includes indicating whether a network attack is currently ongoing based upon the identifying certain statistics regarding the traffic flow.

Assignments (2)
SECURITY INTEREST Recorded Oct 22, 2024
From: NETSCOUT SYSTEMS, INC.; ARBOR NETWORKS LLC; NETSCOUT SYSTEMS TEXAS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069216/0007 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2020
From: IEKEL-JOHNSON, SCOTT; WINQUIST, JAMES EDWARD; WATSON, DAVID, MR.
To: ARBOR NETWORKS, INC.
Reel/Frame 054737/0484 →
Continuity (2)
Provisional Application 62854049 · May 29, 2019
Related Publication 20200382540A1 · Dec 3, 2020