IP Library Granted Patent US 11,463,299
Granted Patent B2
US 11,463,299 · App. 17/226,947 · Granted Oct 4, 2022

Ranking alerts based on network monitoring

Inventors: Xue Jun Wu (Seattle, WA); Nicholas Jordan Braun (Seattle, WA); Joel Benjamin Deaguero (Seattle, WA); Michael Kerber Krause Montague (Lake Forest Park, WA); Bhushan Prasad Khanal (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L41/0609G06F16/24578H04L9/006H04L41/12H04L41/145H04L41/16H04L43/08H04L43/0823H04L43/091
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,463,299
App. No.
17/226,947
Filed
Apr 9, 2021
Granted
Oct 4, 2022
Kind
B2
Art Unit
2454
USPC
709/224
Abstract

Embodiments are directed to monitoring network traffic. A monitoring engine may monitor network traffic associated with a plurality of entities in networks to provide metrics. And provide a device relation model based on the plurality of entities, the network traffic, and the metrics. An inference engine may associate each entity in the plurality of entities with an importance score based on the device relation model and the metrics such that each importance score is associated with a significance of an entity to operations of the networks. An alert engine may generate a plurality of alerts associated with the plurality of entities based on the metrics. And provide one or more alerts from the plurality of alerts to one or more users based on one or more ranked importance scores associated with one or more entities.

Claims (71)

1. A method for monitoring network traffic using one or more network computers, wherein execution of instructions by the one or more network computers perform the method comprising:

monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics;

associating each entity in the plurality of entities with an importance score based on the one or more metrics, wherein each importance score is based on a significance of an entity to one or more operations of the one or more networks and an importance of one or more other entities to the entity;

presenting one or more of the plurality of entities to a user to acquire user feedback and updating the importance score for the one or more of the plurality of entities based on the user feedback and a role of the user;

generating a plurality of alerts associated with the plurality of entities based on the importance score for each entity.

2. The method of claim 1 , further comprising:

determining the importance of the one or more other entities to the entity based on one or more of:

a same cluster having the one or more other entities and the entity as members;

a user's feedback that a set of different entities interacting with a same resource as the one or more entities is important; or

a peer user's feedback that the set of different entities interacting with the same resource is important.

3. The method of claim 1 , further comprising:

determining one or more portions of the plurality of entities that are both currently unimportant to the user and currently important to an organization or one or more peer users; and

recommending the one or more portions of the plurality of entities to the user, wherein an importance score for a recommended entity is increased based on user acceptance of the recommendation or the importance score for the recommended entity is decreased based on user non-acceptance of the recommendation.

4. The method of claim 1 , further comprising:

employing one or more agents to perform actions, including one or more of:

selectively monitoring network traffic associated with the plurality of entities;

determining one or more metrics associated with the selectively monitored network traffic; and

storing the selectively monitored network traffic.

5. The method of claim 1 , further comprising:

providing the one or more other entities based on a traversal of a device relation model; and

modifying each importance score that is associated with the one or more other entities based on the traversal.

6. The method of claim 1 , further comprising:

in response to one or more anomalies associated with one or more Public Key Infrastructure (PKI) certificates, increasing each importance score associated with each entity associated with the one or more PKI certificates.

7. The method of claim 1 , further comprising:

in response to one or more of an application shared by the entity and the one or more other entities, a dependency shared by the entity and the one or more other entities, or activities of one or more users, modifying the importance score of the entity.

8. A processor readable non-transitory storage media that includes instructions for monitoring network traffic using one or more network monitoring computers, wherein execution of the instructions by the one or more network computers perform the method comprising:

monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics;

associating each entity in the plurality of entities with an importance score based on the one or more metrics, wherein each importance score is based on a significance of an entity to one or more operations of the one or more networks and an importance of one or more entities to the entity;

presenting one or more of the plurality of entities to a user to acquire user feedback and updating the importance score for the one or more of the plurality of entities based on the user feedback and a role of the user; and

generating a plurality of alerts associated with the plurality of entities based on the importance score for each entity.

9. The processor readable non-transitory storage media of claim 8 , further comprising:

determining the importance of the one or more other entities to the entity based on one or more of:

a same cluster having the one or more other entities and the entity as members;

a user's feedback that a set of different entities interacting with a same resource as the one or more entities is important; or

a peer user's feedback that the set of different entities interacting with the same resource is important.

10. The processor readable non-transitory storage media of claim 8 , further comprising:

determining one or more portions of the plurality of entities that are both currently unimportant to the user and currently important to an organization or one or more peer users; and

recommending the one or more portions of the plurality of entities to the user, wherein an importance score for a recommended entity is increased based on user acceptance of the recommendation or the importance score for the recommended entity is decreased based on user non-acceptance of the recommendation.

11. The processor readable non-transitory storage media of claim 8 , further comprising:

employing one or more agents to perform actions, including one or more of:

selectively monitoring network traffic associated with the plurality of entities;

determining one or more metrics associated with the selectively monitored network traffic; and

storing the selectively monitored network traffic.

12. The processor readable non-transitory storage media of claim 8 , further comprising:

providing the one or more other entities based on a traversal of a device relation model; and

modifying each importance score that is associated with the one or more other entities based on the traversal.

13. The processor readable non-transitory storage media of claim 8 , further comprising:

in response to one or more anomalies associated with one or more Public Key Infrastructure (PKI) certificates, increasing each importance score associated with each entity associated with the one or more PKI certificates.

14. The processor readable non-transitory storage media of claim 8 , further comprising:

in response to one or more of an application shared by the entity and the one or more other entities, a dependency shared by the entity and the one or more other entities, or activities of one or more users, modifying the importance score of the entity.

15. A system for monitoring network traffic in a network: one or more network computers, comprising:

a memory that stores at least instructions; and one or more processors that execute instructions that cause performance of actions, including:

monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics;

associating each entity in the plurality of entities with an importance score based on the one or more metrics, wherein each importance score is based on a significance of an entity to one or more operations of the one or more networks and an importance of one or more entities to the entity;

presenting one or more of the plurality of entities to a user to acquire user feedback and updating the importance score for the one or more of the plurality of entities based on the user feedback and a role of the user; and

generating a plurality of alerts associated with the plurality of entities based on the importance score for each entity.

16. The system of claim 15 , further comprising:

determining one or more portions of the plurality of entities that are both currently unimportant to the user and currently important to an organization or one or more peer users; and

recommending the one or more portions of the plurality of entities to the user, wherein an importance score for a recommended entity is increased based on user acceptance of the recommendation or the importance score for the recommended entity is decreased based on user non-acceptance of the recommendation.

17. The system of claim 15 , further comprising:

employing one or more agents to perform actions, including one or more of:

selectively monitoring network traffic associated with the plurality of entities;

determining one or more metrics associated with the selectively monitored network traffic; and

storing the selectively monitored network traffic.

18. The system of claim 15 , further comprising:

providing the one or more other entities based on a traversal of a device relation model; and

modifying each importance score that is associated with the one or more other entities based on the traversal.

19. The system of claim 15 , further comprising:

in response to one or more anomalies associated with one or more Public Key Infrastructure (PKI) certificates, increasing each importance score associated with each entity associated with the one or more PKI certificates.

20. The system of claim 15 , further comprising:

in response to one or more of an application shared by the entity and the one or more other entities, a dependency shared by the entity and the one or more other entities, or activities of one or more users, modifying the importance score of the entity.

Assignments (2)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2021
From: WU, XUE JUN; BRAUN, NICHOLAS JORDAN; DEAGUERO, JOEL BENJAMIN; MONTAGUE, MICHAEL KERBER KRAUSE; KHANAL, BHUSHAN PRASAD
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 055881/0708 →
Continuity (3)
Continuation 16543243 · Aug 16, 2019
Continuation 15891273 · Feb 7, 2018
Related Publication 20220029875A1 · Jan 27, 2022
Cited By (7)
US 12,225,030 US 12,309,192 US 12,355,816 US 12,483,384 US 12,587,535 US 12,647,441 US 12,652,312