IP Library Granted Patent US 11,470,172
Granted Patent B1
US 11,470,172 · App. 17/171,938 · Granted Oct 11, 2022

Using network connections to monitor a data center

Inventors: Vikram Kapoor (Cupertino, CA); Rakesh Sachdeva (Santa Clara, CA); Samuel Joseph Pullara, III (Los Altos, CA)
Assignee: Lacework Inc.
H04L67/535G06F9/455G06F9/545G06F16/9024G06F16/9038G06F16/9537H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,470,172
App. No.
17/171,938
Filed
Feb 9, 2021
Granted
Oct 11, 2022
Kind
B1
Art Unit
2454
USPC
709/224
Abstract

An agent executes in user space on a machine and monitors for network connections. In response to detecting an initiation of a network connection, data associated with a process associated with the network connection is collected, e.g., by the agent. At least a portion of the collected process data is reported to an external node. The reported information can be used to detect anomalies in a network environment.

Claims (30)

1. A system, comprising:

a processor configured to:

monitor, by an agent executing in user space on a machine, for initiation of a network connection;

in response to detecting that the network connection has been initiated, determine a process running on the machine that is associated with the network connection and collect data associated with the process, wherein the collected process data includes information indicating whether the process is running as a container isolation; and

report at least a portion of the collected process data to an external node, wherein the external node is configured to perform analysis on a combination of: (1) the reported portion of the collected process data, and (2) additional data; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 wherein a presence of a network packet associated with the process is used by the agent as a trigger for collecting additional information about the process.

3. The system of claim 1 wherein the agent is configured to maintain connection information associated with the network connection.

4. The system of claim 3 wherein the connection information includes DNS query information.

5. The system of claim 1 wherein the processor is further configured to determine a binary associated with the process.

6. The system of claim 1 wherein the processor is further configured to determine a command line associated with the process.

7. The system of claim 1 wherein the processor is further configured to determine at least one of an IP address and a port associated with the process.

8. The system of claim 1 wherein the processor is further configured to determine an ancestor of the process.

9. The system of claim 1 wherein the process is associated with a container and the collected process data includes a container identifier for the container.

10. The system of claim 1 wherein the processor is further configured to determine a user associated with the process.

11. The system of claim 1 wherein the agent is further configured to perform deduplication prior to performing the reporting.

12. A method, comprising:

monitoring, by an agent executing in user space on a machine, for initiation of a network connection;

in response to detecting that the network connection has been initiated, determining a process running on the machine that is associated with the network connection and collecting data associated with the process, wherein the collected process data includes information indicating whether the process is running as a container isolation; and

reporting at least a portion of the collected process data to an external node, wherein the external node is configured to perform analysis on a combination of: (1) the reported portion of the collected process data, and (2) additional data.

13. The method of claim 12 wherein a presence of a network packet associated with the process is used by the agent as a trigger for collecting additional information about the process.

14. The method of claim 12 wherein the agent is configured to maintain connection information associated with the network connection.

15. The method of claim 14 wherein the connection information includes DNS query information.

16. The method of claim 12 further comprising determining a binary associated with the process.

17. The method of claim 12 further comprising determining a command line associated with the process.

18. The method of claim 12 further comprising determining at least one of an IP address and a port associated with the process.

19. The method of claim 12 further comprising determining an ancestor of the process.

20. The method of claim 12 wherein the process is associated with a container and the collected process data includes a container identifier for the container.

21. The method of claim 12 further comprising determining a user associated with the process.

22. The method of claim 12 wherein the agent is further configured to perform deduplication prior to performing the reporting.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069113/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2022
From: KAPOOR, VIKRAM; SACHDEVA, RAKESH; PULLARA, SAMUEL JOSEPH, III
To: LACEWORK, INC.
Reel/Frame 060225/0037 →
Continuity (4)
Continuation 16519534 · Jul 23, 2019
Continuation 16134836 · Sep 18, 2018
Provisional Application 62650971 · Mar 30, 2018
Provisional Application 62590986 · Nov 27, 2017