IP Library Granted Patent US 11,477,097
Granted Patent B2
US 11,477,097 · App. 16/930,116 · Granted Oct 18, 2022

Hierarchichal sharding of flows from sensors to collectors

Inventors: Shashidhar Gandham (Fremont, CA); Rohit Chandra Prasad (Sunnyvale, CA); Abhishek Ranjan Singh (Pleasanton, CA); Navindra Yadav (Cupertino, CA); Khawar Deen (Sunnyvale, CA); Varun Sagar Malhotra (Sunnyvale, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F16/122G06F16/137G06F16/162G06F16/17G06F16/173G06F16/174G06F16/1744G06F16/1748G06F16/235G06F16/2322G06F16/2365G06F16/248G06F16/24578G06F16/285G06F16/288G06F16/29G06F16/9535G06F21/53G06F21/552G06F21/566G06N20/00G06N99/00G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/026H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/5007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/145H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/01H04L67/10H04L67/1001H04L67/12H04L67/51H04L67/75H04L69/16H04L69/22H04W72/08H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595G06F2221/033G06F2221/2101G06F2221/2105G06F2221/2111G06F2221/2115G06F2221/2145H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,477,097
App. No.
16/930,116
Granted
Oct 18, 2022
Kind
B2
Abstract

Systems, methods, and computer-readable media for hierarchichal sharding of flows from sensors to collectors. A first collector can receive a first portion of a network flow from a first capturing agent and determine that a second portion of the network flow was not received from the first capturing agent. The first collector can then send the first portion of the network flow to a second collector. A third collector can receive the second portion of the network flow from a second capturing agent and determine that the third collector did not receive the first portion of the network flow. The third collector can then send the second portion of the network flow to the second collector. The second collector can then aggregate the first portion and second portion of the network flow to yield the entire portion of the network flow.

Claims (35)

1. A method for recombining a network flow, the method comprising:

assigning a plurality of capturing agents deployed throughout a network to respective shards, each of the plurality of capturing agents being configured to capture network activity associated with a respective host and report the network activity to one or more collectors in the respective shards, wherein each of the respective shards comprises a number of assigned collectors;

receiving, by a first collector, a first portion of the network flow;

receiving, at a second collector, a second portion of the network flow from a third collector that received the second portion of the network flow but not the first portion of the network flow;

determining, by the first collector, that the second portion of the network flow was not received at the first collector;

in response to determining the second portion was not received, sending, by the first collector, the first portion of the network flow to the second collector; and

combining, by the second collector, the first portion of the network flow and the second portion of the network flow;

wherein the second collector is part of a second shard from the respective shards, and wherein the second collector is assigned a flow key and hash that corresponds to the network flow;

wherein the second collector is selected to receive the first portion and the second portion of the network flow from a plurality of other collectors based on the flow key and hash corresponding to the network flow.

2. The method of claim 1 , wherein the first portion of the network flow is transmitted by a first capturing agent to a first shard from the respective shards, wherein the first collector is part of the first shard.

3. The method of claim 1 , wherein the first collector is mapped to a respective shard from a first layer of shards, each of the respective shards comprising a selected group of collectors, and wherein the second collector is mapped to a shard from a second layer of shards.

4. A non-transitory computer-readable storage medium storing instructions to recombine a network flow, which when executed by at least one processor cause the at least one processor to perform operations comprising:

assigning a plurality of capturing agents deployed throughout a network to respective shards, each of the plurality of capturing agents being configured to capture network activity associated with a respective host and report the network activity to one or more collectors in the respective shards, wherein each of the respective shards comprises a number of assigned collectors;

receiving, by a first collector, a first portion of the network flow;

receiving, at a second collector, a second portion of the network flow from a third collector that received the second portion of the network flow but not the first portion of the network flow;

determining, by the first collector, that the second portion of the network flow was not received at the first collector;

in response to determining the second portion was not received, sending, by the first collector, the first portion of the network flow to the second collector; and

combining, by the second collector, the first portion of the network flow and the second portion of the network flow;

wherein the second collector is part of a second shard from the respective shards, and wherein the second collector is assigned a flow key and hash that corresponds to the network flow;

wherein the second collector is selected to receive the first portion and the second portion of the network flow from a plurality of other collectors based on the flow key and hash corresponding to the network flow.

5. The non-transitory computer-readable storage medium of claim 4 , wherein the first portion of the network flow is transmitted by a first capturing agent to a first shard from the respective shards, wherein the first collector is part of the first shard.

6. The non-transitory computer-readable storage medium of claim 4 , wherein the first collector is mapped to a respective shard from a first layer of shards, each of the respective shards comprising a selected group of collectors, and wherein the second collector is mapped to a shard from a second layer of shards.

7. A system that recombines a network flow, the system comprising:

at least one processor; and

at least one non-transitory computer-readable storage medium having stored therein instructions, which when executed by the at least one processor, causes the at least one processor to perform operations comprising:

assigning a plurality of capturing agents deployed throughout a network to respective shards, each of the plurality of capturing agents being configured to capture network activity associated with a respective host and report the network activity to one or more collectors in the respective shards, wherein each of the respective shards comprises a number of assigned collectors;

receiving, by a first collector, a first portion of the network flow;

receiving, at a second collector, a second portion of the network flow from a third collector that received the second portion of the network flow but not the first portion of the network flow;

determining, by the first collector, that the second portion of the network flow was not received at the first collector;

in response to determining the second portion was not received, sending, by the first collector, the first portion of the network flow to the second collector; and

combining, by the second collector, the first portion of the network flow and the second portion of the network flow;

wherein the second collector is part of a second shard from the respective shards, and wherein the second collector is assigned a flow key and hash that corresponds to the network flow;

wherein the second collector is selected to receive the first portion and the second portion of the network flow from a plurality of other collectors based on the flow key and hash corresponding to the network flow.

8. The system of claim 7 , wherein the first portion of the network flow is transmitted by a first capturing agent to a first shard from the respective shards, wherein the first collector is part of the first shard.

9. The system of claim 7 , wherein the first collector is mapped to a respective shard from a first layer of shards, each of the respective shards comprising a selected group of collectors, and wherein the second collector is mapped to a shard from a second layer of shards.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2020
From: GANDHAM, SHASHIDHAR; PRASAD, ROHIT CHANDRA; SINGH, ABHISHEK RANJAN; YADAV, NAVINDRA; DEEN, KHAWAR; MALHOTRA, VARUN SAGAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 053223/0029 →
Continuity (4)
Continuation 16392950 · Apr 24, 2019
Continuation 15171855 · Jun 2, 2016
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20200351184A1 · Nov 5, 2020