IP Library Granted Patent US 11,658,861
Granted Patent B2
US 11,658,861 · App. 17/175,551 · Granted May 23, 2023

Maps having a high branching factor

Inventor: Anil Rao (Santa Clara, CA)
Assignee: Gigamon Inc.
H04L41/046H04L12/4633H04L41/12H04L41/22H04L43/022H04L43/028H04L43/062H04L43/12H04L45/02H04L47/24H04L49/70H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,658,861
App. No.
17/175,551
Granted
May 23, 2023
Kind
B2
Abstract

Disclosed is a technique for providing packet filter maps with high branching factors in a system for managing network traffic in a visibility fabric. A high branching factor enables a map to branch out more than two ways. High branching factors can be realized by allowing a map to be affiliated with more than one action set. For example, each rule of the map may be affiliated with a unique action set that is executed only when the corresponding rule is satisfied.

Claims (78)

1. A method comprising:

identifying a plurality of network objects that are interconnected through a network visibility appliance to which data packets are to be routed for analysis;

associating each network object of the plurality of network objects with an action set;

constructing a data structure that is representative of the network visibility appliance by:

creating a separate entry for each network object of the plurality of network objects, and

establishing an association between a pair of entries for each traffic flow between a pair of network objects of the plurality of network objects,

wherein each action set includes at least one of

a pass action that is represented in the data structure as an established association, or

a drop action that is represented in the data structure as a lack of established associations;

storing the data structure in a memory that is accessible to the network visibility appliance;

routing a plurality of data packets acquired from a public cloud infrastructure through the plurality of network objects based on the data structure; and

forwarding at least some of the plurality of data packets acquired from the public cloud infrastructure to the public cloud infrastructure, after the at least some of the plurality of data packets acquired from the public cloud infrastructure have been routed through the plurality of network objects.

2. The method of claim 1 , wherein the plurality of data packets acquired from the public cloud infrastructure are indicative of traffic associated with a given user, and wherein the given user is one of a plurality of users that are able to access the public cloud infrastructure.

3. The method of claim 1 ,

wherein said forwarding comprises forwarding at least some of the data packets that were not dropped by the plurality of network objects to the public cloud infrastructure.

4. The method of claim 1 , further comprising:

causing a graph that visually represents the network visibility appliance to be presented on a display of a computing device; and

enabling an individual to specify a modification to the network visibility appliance by modifying the graph.

5. The method of claim 1 , wherein the plurality of data packets acquired from the public cloud infrastructure are replicated when leaving a network object that corresponds to an entry that has more than one established association.

6. The method of claim 1 ,

wherein the plurality of network objects includes at least one of a raw endpoint, a tunnel endpoint, an application endpoint, or a map, and

wherein

each raw endpoint, if any, receives traffic from a Network Interface Card (NIC) of the network visibility appliance,

each tunnel endpoint, if any, receives traffic from, or sends traffic to, an environment outside of the network visibility appliance,

each application endpoint, if any, receives traffic from, or sends traffic to, an application program, and

each map, if any, includes at least one rule for managing traffic.

7. An apparatus comprising:

at least one processor; and

at least one memory coupled to the at least one processor and storing instructions, execution of which by the at least one processor causes performance of operations including:

identifying a plurality of network objects that are interconnected through a network visibility appliance to which data packets are to be routed for analysis;

associating each network object of the plurality of network objects with an action set;

constructing a data structure that is representative of the network visibility appliance by:

creating a separate entry for each network object of the plurality of network objects, and

establishing an association between a pair of entries for each traffic flow between a pair of network objects of the plurality of network objects, wherein each action set includes at least one of

a pass action that is represented in the data structure as an established association, or

a drop action that is represented in the data structure as a lack of established associations;

storing the data structure in a memory that is accessible to the network visibility appliance;

routing a plurality of data packets acquired from a public cloud infrastructure through the plurality of network objects based on the data structure; and

forwarding at least some of the plurality of data packets acquired from the public cloud infrastructure to the public cloud infrastructure, after the at least some of the plurality of data packets acquired from the public cloud infrastructure have been routed through the plurality of network objects.

8. The apparatus of claim 7 , such that the plurality of data packets acquired from the public cloud infrastructure are indicative of traffic associated with a given user, and the given user is one of a plurality of users that are able to access the public cloud infrastructure.

9. The apparatus of claim 7 ,

wherein said forwarding comprises forwarding at least some of the data packets that were not dropped by the plurality of network objects to the public cloud infrastructure.

10. The apparatus of claim 7 , further comprising instructions, execution of which by the at least one processor causes performance of operations including:

causing a graph that visually represents the network visibility appliance to be presented on a display of a computing device; and

enabling an individual to specify a modification to the network visibility appliance by modifying the graph.

11. The apparatus of claim 7 , such that the plurality of data packets acquired from the public cloud infrastructure are replicated when leaving a network object that corresponds to an entry that has more than one established association.

12. The apparatus of claim 7 ,

such that the plurality of network objects includes at least one of a raw endpoint, a tunnel endpoint, an application endpoint, or a map, and

such that

each raw endpoint, if any, receives traffic from a Network Interface Card (NIC) of the network visibility appliance,

each tunnel endpoint, if any, receives traffic from, or sends traffic to, an environment outside of the network visibility appliance,

each application endpoint, if any, receives traffic from, or sends traffic to, an application program, and

each map, if any, includes at least one rule for managing traffic.

13. At least one non-transitory machine-readable medium having stored therein instructions, execution of which by at least one processor causes performance of operations including:

identifying a plurality of network objects that are interconnected through a network visibility appliance to which data packets are to be routed for analysis;

associating each network object of the plurality of network objects with an action set;

constructing a data structure that is representative of the network visibility appliance by:

creating a separate entry for each network object of the plurality of network objects, and

establishing an association between a pair of entries for each traffic flow between a pair of network objects of the plurality of network objects, wherein each action set includes at least one of

a pass action that is represented in the data structure as an established association, or

a drop action that is represented in the data structure as a lack of established associations;

storing the data structure in a memory that is accessible to the network visibility appliance;

routing a plurality of data packets acquired from a public cloud infrastructure through the plurality of network objects based on the data structure; and

forwarding at least some of the plurality of data packets acquired from the public cloud infrastructure to the public cloud infrastructure, after the at least some of the plurality of data packets acquired from the public cloud infrastructure have been routed through the plurality of network objects.

14. The at least one non-transitory machine-readable medium of claim 13 , such that the plurality of data packets acquired from the public cloud infrastructure are indicative of traffic associated with a given user, and the given user is one of a plurality of users that are able to access the public cloud infrastructure.

15. The at least one non-transitory machine-readable medium of claim 13 ,

such that said forwarding comprises forwarding at least some of the data packets that were not dropped by the plurality of network objects to the public cloud infrastructure.

16. The at least one non-transitory machine-readable medium of claim 13 , further comprising instructions, execution of which by the at least one processor causes performance of operations including:

causing a graph that visually represents the network visibility appliance to be presented on a display of a computing device; and

enabling an individual to specify a modification to the network visibility appliance by modifying the graph.

17. The at least one non-transitory machine-readable medium of claim 13 , such that the plurality of data packets acquired from the public cloud infrastructure are replicated when leaving a network object that corresponds to an entry that has more than one established association.

18. The at least one non-transitory machine-readable medium of claim 13 ,

such that the plurality of network objects includes at least one of a raw endpoint, a tunnel endpoint, an application endpoint, or a map, and

such that

each raw endpoint, if any, receives traffic from a Network Interface Card (NIC) of the network visibility appliance,

each tunnel endpoint, if any, receives traffic from, or sends traffic to, an environment outside of the network visibility appliance,

each application endpoint, if any, receives traffic from, or sends traffic to, an application program, and

each map, if any, includes at least one rule for managing traffic.

Assignments (2)
SECURITY INTEREST Recorded Mar 11, 2022
From: GIGAMON INC.; ICEBRG LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 059362/0717 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2021
From: RAO, ANIL
To: GIGAMON INC.
Reel/Frame 057164/0488 →
Continuity (3)
Continuation 15815524 · Nov 16, 2017
Provisional Application 62425577 · Nov 22, 2016
Related Publication 20210168018A1 · Jun 3, 2021