IP Library Granted Patent US 11,743,161
Granted Patent B2
US 11,743,161 · App. 16/985,018 · Granted Aug 29, 2023

Container network interface monitoring

Inventors: Jakob Green (Orem, UT); Jeevan Savant (Pleasant Grove, UT); Yogesh Ahire (Chelmsford, MA); Suhas Bhanushali (Westford, MA); Danny Lobo (San Jose, CA)
Assignee: NetScout Systems, Inc.
H04L43/0894H04L43/04H04L47/31H04L47/35H04L49/9057H04L43/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,743,161
App. No.
16/985,018
Granted
Aug 29, 2023
Kind
B2
Abstract

A system and method of accessing a container environment having one or more containers is provided. The method of the disclosure includes receiving the container network namespace assigned to the container as established in a container runtime, switching from a host container network namespace to the container network namespace of the container, opening the container network interface of the container network namespace for allowing access to packets received or transmitted by the container network interface, and accessing the packets.

Claims (54)

1. A monitoring system for monitoring a container network interface (CNI) of a container network namespace, the container network namespace associated with one or more containers, wherein a container is an isolated execution environment, the monitoring system comprising:

at least one memory configured to store instructions; and

at least one processor disposed in communication with the at least one memory, wherein the at least one processor upon execution of the instructions is configured to:

provide a network monitoring application;

use the network monitoring application to determine a process ID associated with the one or more containers to determine a path to the container network namespace assigned to the container as established in a container runtime, wherein the network monitoring application receives, from a CNI plugin, the process ID, the CNI plugin comprising an application configured to exchange data between the one or more containers and the network monitoring application;

switch the network monitoring application from a host network namespace to the one or more container network namespace of the one or more containers;

use the network monitoring application to open the CNI of the container network namespace for allowing access to packets received or transmitted by the CNI; and

use the network monitoring application to access the packets.

2. The monitoring system according to claim 1 , wherein the at least one processor is further configured to:

establish a main thread of the network monitoring application configured to receive the container network namespace assigned to respective established containers, the main thread being configured to:

dispatch a packet capture thread for selected containers of the established containers, wherein the respective packet capture threads are configured to switch to the container network namespace of the container for which they were dispatched; and

execute the respective dispatched packet capture threads.

3. The monitoring system according to claim 2 ,

wherein the respective packet capture threads are further configured to access the packets and share the packets with the main thread;

wherein the main thread is further configured to:

receive the packets accessed by the respective packet captured threads; and

process the packets.

4. The monitoring system according to claim 2 , wherein the respective packet capture threads are further configured to open a container network interface of the container for which they were dispatched and provide a handle for accessing packets received or transmitted by the container network interface to the main thread; wherein the main thread is further configured to:

receive the handle provided by the respective packet captured threads;

using the handle received by the respective packet captured threads, access the packets received or transmitted by the container network interface; and

process the packets.

5. The monitoring system according to claim 2 , wherein the main thread is included in the memory space of the at least one memory.

6. The monitoring system according to claim 2 , wherein the main thread is further configured to share the packets with a remote central processor that monitors the packets.

7. The monitoring system according to claim 2 , wherein the respective packet capture threads are further configured to shut themselves down when the container for they were respectively dispatched is no longer available.

8. The monitoring system according to claim 7 , wherein the main thread is further configured to clean up the packet capture thread once it is shutdown.

9. The monitoring system according to claim 1 , wherein the packet capture threads dispatched are all included in one memory space of the at least one memory.

10. The monitoring system according to claim 1 , wherein the at least one processor is further configured to share the packets with a monitoring processor that monitors the packets.

11. The monitoring system according to claim 1 , wherein the main thread is further configured to receive user input instructing the main thread which containers are selected and/or what to process in the packets.

12. The monitoring system according to claim 1 , wherein the at least one processor is further configured to switch the network monitoring application from the container network namespace back to the host network namespace.

13. A method of monitoring a container network interface (CNI) of a container network namespace, the container network namespace associated with one or more containers, wherein a container is an isolated execution environment, the method comprising:

providing a network monitoring application;

determining, by the network monitoring application, a process ID associated with the one or more containers to determine a path to the container network namespace assigned to the one or more containers established in a container runtime, wherein the network monitoring application receives, from a CNI plugin, the process ID, the CNI plugin comprising an application configured to exchange data between the one or more containers and the network monitoring application;

switching, by the network monitoring application, from a host network namespace to the container network namespace of the one or more containers;

opening, by the network monitoring application, the CNI of the container network namespace for allowing access to packets received or transmitted by the CNI; and

accessing, by the network monitoring application, the packets.

14. The method according to claim 13 , further comprising:

establishing a main thread of the network monitoring application configured to receive the container network namespace assigned to respective established containers;

dispatching, by the main thread, a packet capture thread for selected containers of the established containers, wherein each packet capture thread is configured to switch to the container network namespace of the container for which it was dispatched; and

executing, by the main thread, each dispatched packet capture thread.

15. The method according to claim 14 , further comprising:

accessing, by the respective packet capture threads, the packets;

sharing, by the respective packet capture threads, the packets with the main packet capture thread; receiving, by the main thread, the packets accessed by the packet captured threads; and

processing, by the main thread, the packets.

16. The method according to claim 14 , further comprising:

opening, by the respective packet capture threads, a container network interface of the container for which it was dispatched;

providing, by the respective packet capture threads, a handle for accessing packets received or transmitted by the container network interface to the main thread;

receiving, by the main thread, the handle provided by the respective packet captured threads;

using, by the main thread, the handle received by the respective packet captured threads to access the packets received or transmitted by the container network interface; and

process, by the main thread, the packets.

17. The method according to claim 14 , further comprising shutting itself down, by the respective packet capture threads, when the container for it was dispatched is no longer available.

18. The method according to claim 17 , further comprising cleaning up, by the main thread, the respective packet capture threads, once they are shutdown.

19. The method according to claim 13 , further comprising sharing the packets with a monitoring processor that monitors the packets.

20. The method according to claim 13 , further comprising receiving, by the main thread, user input instructing the main thread which containers are selected and/or what to process in the packets.

21. The method according to claim 13 , further comprising switching the network monitoring application from the container network namespace back to the host network namespace.

Assignments (2)
SECURITY INTEREST Recorded Oct 22, 2024
From: NETSCOUT SYSTEMS, INC.; ARBOR NETWORKS LLC; NETSCOUT SYSTEMS TEXAS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069216/0007 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2022
From: GREEN, JAKOB, MR.; SAVANT, JEEVAN; AHIRE, YOGESH; BHANUSHALI, SUHAS; LOBO, DANNY, MR.
To: NETSCOUT SYSTEMS, INC
Reel/Frame 059268/0273 →