IP Library Granted Patent US 11,641,316
Granted Patent B2
US 11,641,316 · App. 16/915,143 · Granted May 2, 2023

Capturing data packets for analysis using a virtual machine

Inventors: Gavril Ioan Florian (Chitila, RO); Andrei I. Bunghez (Ploiesti, RO); Bogdan-Alexandru Ratiu (Segovia, ES); Anda-Maria Nicolae (Bucharest, RO)
Assignee: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE. LTD.
H04L43/0817G06F9/45558H04L12/4633H04L43/0811H04L63/0236H04L69/22G06F2009/45591G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,641,316
App. No.
16/915,143
Granted
May 2, 2023
Kind
B2
Abstract

Capturing data packets for analysis using a virtual machine including receiving, at an analyzer virtual machine, an encapsulated packet for analysis, wherein the encapsulated packet comprises a monitoring metadata header and a data packet with a data packet header; stripping the monitoring metadata header from the encapsulated packet to obtain a de-encapsulated packet comprising the data packet with the data packet header; and directing, based on the data packet header, the de-encapsulated packet to a virtual network interface associated with a packet capture application within the analyzer virtual machine.

Claims (36)

1. A method comprising:

by program instructions on a computing device,

receiving, at an analyzer virtual machine, an encapsulated packet for analysis, wherein the encapsulated packet comprises a monitoring metadata header and a mirrored data packet with a data packet header, and wherein the analyzer virtual machine is one of a plurality of virtual machines hosted on the computing device;

stripping, by the analyzer virtual machine, the monitoring metadata header from the encapsulated packet to obtain a de-encapsulated packet comprising the data packet with the data packet header; and

directing, by the analyzer virtual machine and based on the data packet header, the de-encapsulated packet to a virtual network interface associated with a packet capture application within the analyzer virtual machine for analysis by the packet capture application.

2. The method of claim 1 , wherein directing the de-encapsulated packet to the virtual network interface associated with the packet capture application within the analyzer virtual machine comprises:

filtering the de-encapsulated packet based on the data packet header; and

sending, based on the filtering, the de-encapsulated packet to the virtual network interface.

3. The method of claim 1 , wherein the virtual network interface is one of a plurality of virtual network interfaces on the analyzer virtual machine, wherein the packet capture application operates within an application layer of the analyzer virtual machine, and wherein each of the plurality of virtual network interfaces operate at a kernel layer of the analyzer virtual machine.

4. The method of claim 3 , wherein each of the plurality of virtual network interfaces is associated with a different packet capture application within the analyzer virtual machine.

5. The method of claim 1 , wherein the de-encapsulated packet is directed to the virtual network interface based on a port identified in the data packet header.

6. The method of claim 1 , wherein the monitoring metadata header is used by a host of the analyzer virtual machine to direct the encapsulated packet to the analyzer virtual machine.

7. The method of claim 1 , wherein the analyzer virtual machine receives the encapsulated packet via a virtual network.

8. An apparatus comprising a computing device, a computer processor, and a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:

receiving, at an analyzer virtual machine, an encapsulated packet for analysis, wherein the encapsulated packet comprises a monitoring metadata header and a mirrored data packet with a data packet header, and wherein the analyzer virtual machine is one of a plurality of virtual machines hosted on the computing device;

stripping, by the analyzer virtual machine, the monitoring metadata header from the encapsulated packet to obtain a de-encapsulated packet comprising the data packet with the data packet header; and

directing, by the analyzer virtual machine and based on the data packet header, the de-encapsulated packet to a virtual network interface associated with a packet capture application within the analyzer virtual machine for analysis by the packet capture application.

9. The apparatus of claim 8 , wherein directing the de-encapsulated packet to the virtual network interface associated with the packet capture application within the analyzer virtual machine comprises:

filtering the de-encapsulated packet based on the data packet header; and

sending, based on the filtering, the de-encapsulated packet to the virtual network interface.

10. The apparatus of claim 8 , wherein the virtual network interface is one of a plurality of virtual network interfaces on the analyzer virtual machine, wherein the packet capture application operates within an application layer of the analyzer virtual machine, and wherein each of the plurality of virtual network interfaces operate at a kernel layer of the analyzer virtual machine.

11. The apparatus of claim 10 , wherein each of the plurality of virtual network interfaces is associated with a different packet capture application within the analyzer virtual machine.

12. The apparatus of claim 8 , wherein the de-encapsulated packet is directed to the virtual network interface based on a port identified in the data packet header.

13. The apparatus of claim 8 , wherein the monitoring metadata header is used by a host of the analyzer virtual machine to direct the encapsulated packet to the analyzer virtual machine.

14. The apparatus of claim 8 , wherein the analyzer virtual machine receives the encapsulated packet via a virtual network.

15. A computer program product including a non-volatile computer readable storage medium and computer program instructions stored therein that, when executed, cause a computer to carry out the steps of:

receiving, at an analyzer virtual machine, an encapsulated packet for analysis, wherein the encapsulated packet comprises a monitoring metadata header and a mirrored data packet with a data packet header, and wherein the analyzer virtual machine is one of a plurality of virtual machines hosted on a virtualization platform on a computing device;

stripping, by the analyzer virtual machine, the monitoring metadata header from the encapsulated packet to obtain a de-encapsulated packet comprising the data packet with the data packet header; and

directing, by the analyzer virtual machine and based on the data packet header, the de-encapsulated packet to a virtual network interface associated with a packet capture application within the analyzer virtual machine for analysis by the packet capture application.

16. The computer program product of claim 15 , wherein directing the de-encapsulated packet to the virtual network interface associated with the packet capture application within the analyzer virtual machine comprises:

filtering the de-encapsulated packet based on the data packet header; and

sending, based on the filtering, the de-encapsulated packet to the virtual network interface.

17. The computer program product of claim 15 , wherein the virtual network interface is one of a plurality of virtual network interfaces on the analyzer virtual machine, wherein the packet capture application operates within an application layer of the analyzer virtual machine.

18. The computer program product of claim 17 , wherein each of the plurality of virtual network interfaces is associated with a different packet capture application within the analyzer virtual machine.

19. The computer program product of claim 15 , wherein the de-encapsulated packet is directed to the virtual network interface based on a port identified in the data packet header.

20. The computer program product of claim 15 , wherein the monitoring metadata header is used by a host of the analyzer virtual machine to direct the encapsulated packet to the analyzer virtual machine.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD.
To: LENOVO GLOBAL TECHNOLOGIES INTERNATIONAL LTD.
Reel/Frame 070267/0152 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: LENOVO GLOBAL TECHNOLOGIES INTERNATIONAL LIMITED
To: LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
Reel/Frame 070269/0207 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2020
From: FLORIAN, GAVRIL IOAN; BUNGHEZ, ANDREI I.; RATIU, BOGDAN-ALEXANDRU; NICOLAE, ANDA-MARIA
To: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE. LTD.
Reel/Frame 053075/0255 →
Continuity (1)
Related Publication 20210409299A1 · Dec 30, 2021