IP Library Granted Patent US 11,522,798
Granted Patent B2
US 11,522,798 · App. 16/929,661 · Granted Dec 6, 2022

Method and system for triggering augmented data collection on a network based on traffic patterns

Inventors: Greg Veres (Waterloo, CA); Sandra Loop (Waterloo, CA)
Assignee: Aurea Software FZ-LLC
H04L47/12H04L43/062H04L43/0888H04L41/0213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,522,798
App. No.
16/929,661
Granted
Dec 6, 2022
Kind
B2
Abstract

A method and system for increasing the collection of network traffic data in a network based on the occurrence of predetermined criteria. A network appliance manages network traffic in the network and passes data traffic on the network. Network traffic data is collected based on the data traffic passing through the network appliance at a normal level. It is determined whether the network traffic data indicates an abnormal condition. The collection of network traffic data is increased through the network traffic appliance when an abnormal condition is detected. The network traffic data from the increased collection is stored in a memory device.

Claims (28)

1. A method of adjusting network data management in a network appliance coupled to devices in a network, the network appliance passing data traffic on the network, the method comprising:

collecting network traffic data from a first set of data sources based on the data traffic passing through the network appliance at a normal level; and

executing code in the network appliance to cause the network appliance to perform operations comprising:

determining whether the network traffic data indicates an abnormal condition;

when an abnormal condition is determined, increasing the collection of network traffic data through collection of network data from a second set of data sources and through the network traffic appliance, wherein the first set of data sources is different than the second set of data sources; and

storing the network traffic data from increased collection in a memory device to determine a cessation of the abnormal condition.

2. The method of claim 1 , further comprising executing code in the network appliance to cause the network appliance to further perform operations comprising monitoring the increased collection of network traffic data to determine the cessation of the abnormal condition.

3. The method of claim 2 , further comprising executing code in the network appliance to cause the network appliance to further perform operations comprising returning the collection of network traffic data to the normal level when the abnormal condition has ceased.

4. The method of claim 2 , further comprising executing code in the network appliance to cause the network appliance to further perform operations comprising returning the collection of network traffic data to the normal level after a predetermined time.

5. The method of claim 1 , wherein the network traffic data from the increased collection is removed from the memory device after the abnormal condition ceases.

6. The method of claim 1 , wherein the increased data collection includes network traffic data collected under the Netflow protocol.

7. The method of claim 1 , wherein the increased data collection includes at least one of network traffic data from a router, a server, a firewall, or a network device.

8. The method of claim 1 , wherein the increased collection of network traffic data is performed through a data collection device in the network.

9. The method of claim 8 , wherein the data collection device executes an application from a third party separate from a vendor of the network traffic appliance.

10. The method of claim 8 , wherein the data collection device is from a third party separate from the vendor of a network traffic appliance.

11. The method of claim 8 , wherein the network traffic data is in a proprietary format.

12. The method of claim 1 , wherein the collecting network traffic data at a normal level includes collecting data traffic monitored by a device in the network.

13. The method of claim 1 , wherein the determining whether the network data traffic indicates an abnormal condition includes comparing the collected network traffic data to a network traffic baseline.

14. The method of claim 1 , wherein the determining whether the network data traffic indicates an abnormal condition includes comparing the collected network traffic data with an expected network traffic pattern.

15. The method of claim 1 , wherein the determining whether the network data traffic indicates an abnormal condition includes determining application performance for an application on a device on the network in comparison to an application performance score.

16. The method of claim 1 , wherein the increase in collection of network data includes a type of network traffic data selected based on the type of abnormal condition.

17. The method of claim 1 , wherein the increase in collection of network data includes filtering for network traffic data contributing to the abnormal condition.

18. The method of claim 1 wherein the increase in collection of network traffic data includes server performance metrics data.

19. The system method of claim 1 , wherein a collection module includes a plurality of data interfaces and each of the data interfaces collects a different source of network traffic data.

20. The method of claim 1 , further comprising:

sending the network traffic data from the increased collection to a central management device;

analyzing the network traffic data via the central management device to determine the abnormal condition.

21. The method of claim 20 , wherein the central management device controls a second network traffic appliance monitoring traffic on a second network, the increased data collection coming exclusively from the first network traffic appliance.

Assignments (4)
SECURITY INTEREST Recorded Mar 6, 2023
From: GFI USA, LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 062888/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2023
From: AUREA SOFTWARE FZ-LLC
To: GFI SMB, INC.
Reel/Frame 062676/0670 →
CHANGE OF NAME Recorded Feb 13, 2023
From: GFI SMB, INC.
To: GFI USA, INC.
Reel/Frame 062677/0201 →
CHANGE OF NAME Recorded Feb 13, 2023
From: GFI USA, INC.
To: GFI USA, LLC
Reel/Frame 062746/0564 →
Continuity (4)
Continuation 16259929 · Jan 28, 2019
Continuation 15415080 · Jan 25, 2017
Continuation 14680744 · Apr 7, 2015
Related Publication 20200351203A1 · Nov 5, 2020
Cited By (1)
US 12,250,151