IP Library Granted Patent US 11,570,107
Granted Patent B2
US 11,570,107 · App. 17/009,612 · Granted Jan 31, 2023

Method and system for triggering augmented data collection on a network device based on traffic patterns

Inventors: Greg Veres (Waterloo, CA); Sandra Loop (Waterloo, CA)
Assignee: Exinda Networks PTY, Ltd.
H04L47/12H04L43/062H04L43/0888H04L41/0213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,570,107
App. No.
17/009,612
Granted
Jan 31, 2023
Kind
B2
Abstract

A method and system for increasing the collection of network traffic data in a network based on the occurrence of predetermined criteria. A network appliance manages network traffic in the network and passes data traffic on the network. Network traffic data is collected based on the data traffic passing through the network appliance at a normal level. It is determined whether the network traffic data indicates an abnormal condition. The collection of network traffic data is increased through the network traffic appliance when an abnormal condition is detected. The network traffic data from the increased collection is stored in a memory device.

Claims (40)

1. A traffic management system for augmenting collection by a first network device of data between computing devices in a network, the system comprising:

a processor; and

a memory, coupled to the processor, storing code that is executable by the processor to perform operations comprising:

collecting network traffic data based on the data traffic passing through the first network device at a normal level from a first set of data sources via a data collection engine coupled to the network;

monitoring the network traffic data from the data collection engine;

determining whether the network traffic data indicates an abnormal condition via a central management device;

running an application on one of the computing devices to collect network data from a second set of data sources and to increase collection of the network traffic data when an abnormal condition is determined, wherein the first set of data sources is different than the second set of data sources; and

storing the network traffic data from the increased collection in a memory device.

2. The system of claim 1 , wherein the data collection module are in a network traffic appliance coupled to the network.

3. The system of claim 1 , further comprising:

a network traffic appliance for managing network traffic data on another network; and

wherein the data collection module is in the central management device coupled to the network traffic device.

4. The system of claim 3 , wherein the central management device analyzes the network traffic data to determine the abnormal condition.

5. The system of claim 1 , wherein the data collection module monitors the increased collection of network traffic data to determine cessation of the abnormal condition.

6. The system of claim 5 , wherein collecting network traffic data returns to a normal level when the abnormal condition has ceased.

7. The system of claim 5 , wherein the code is further executable by the processor to perform:

returning the collection of network traffic data to the normal level after a predetermined time.

8. The system of claim 1 , wherein the network traffic data from the increased collection is removed from the memory device after the abnormal condition ceases.

9. The system of claim 1 , wherein the increased data collection includes network traffic data collected under the Netflow protocol.

10. The system of claim 1 , wherein the increased data collection includes at least one of network traffic data from a router, a network device or SNMP data.

11. A non-transitory, computer program product comprising code stored therein for augmenting collection by a first network device of data between computing devices in a network, wherein the code is executable by a processor to perform operations comprising:

collecting network traffic data based on the data traffic passing through the first network device at a normal level from a first set of data sources via a data collection engine coupled to the network;

monitoring the network traffic data from the data collection engine;

determining whether the network traffic data indicates an abnormal condition via a central management device;

running an application on one of the computing devices to collect network data from a second set of data sources and to increase the collection of the network traffic data when an abnormal condition is determined, wherein the first set of data sources is different than the second set of data sources; and

storing the network traffic data from the increased collection in a memory device.

12. The non-transitory, computer program product of claim 11 , wherein the code is executable by a processor to perform operations comprising:

sending the network traffic data from the increased collection to the central management device; and

analyzing the network traffic data via the central management device to determine the abnormal condition.

13. The non-transitory, computer program product of claim 11 , wherein the code is executable by a processor to perform operations comprising:

monitoring the increased collection of network traffic data to determine a cessation of the abnormal condition.

14. The non-transitory, computer program product of claim 13 , wherein the code is executable by a processor to perform operations comprising:

returning the collection of network traffic data to the normal level when the abnormal condition has ceased.

15. The non-transitory, computer program product of claim 14 , wherein the code is executable by a processor to perform operations comprising:

returning the collection of network traffic data to the normal level after a predetermined time.

16. The non-transitory, computer program product of claim 11 , wherein the code is executable by a processor to perform operations comprising:

removing from the memory device the network traffic data from the increased collection after the abnormal condition ceases.

17. The non-transitory, computer program product of claim 11 , wherein the increased data collection includes network traffic data collected under a Netflow protocol.

18. The non-transitory, computer program product of claim 11 , wherein the increased data collection includes at least one of network traffic data from a router, a network device, or SNMP data.

19. The non-transitory, computer program product of claim 12 , wherein the central management device controls a second network device monitoring traffic on a second network, the increased data collection coming exclusively from the first network traffic appliance.

Assignments (4)
SECURITY INTEREST Recorded Mar 6, 2023
From: GFI USA, LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 062888/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2023
From: AUREA SOFTWARE FZ-LLC
To: GFI SMB, INC.
Reel/Frame 062676/0670 →
CHANGE OF NAME Recorded Feb 13, 2023
From: GFI SMB, INC.
To: GFI USA, INC.
Reel/Frame 062677/0201 →
CHANGE OF NAME Recorded Feb 13, 2023
From: GFI USA, INC.
To: GFI USA, LLC
Reel/Frame 062746/0564 →
Continuity (4)
Continuation 16290692 · Mar 1, 2019
Continuation 15415312 · Jan 25, 2017
Continuation 14680744 · Apr 7, 2015
Related Publication 20200403918A1 · Dec 24, 2020
Cited By (1)
US 12,328,244