IP Library Granted Patent US 11,843,455
Granted Patent B2
US 11,843,455 · App. 17/227,976 · Granted Dec 12, 2023

Systems and methods for monitoring network traffic

Inventor: Andrew Bagrin (Charlotte, NC)
Assignee: NEWCO OMNINET PURCHASER, LLC
H04L43/10H04L45/02H04L45/72H04L45/74
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,843,455
App. No.
17/227,976
Granted
Dec 12, 2023
Kind
B2
Abstract

Systems and methods for monitoring network traffic. A server may receive data packets originated from a first remote computer system, the data packets having a destination of a second remote computer system. The server may determine a user of the first computer system and, based thereon, identify network traffic monitoring tools configured to connect to the server through respective distinct network addresses. The server may determine a routing path for the packets including a sequence of network addresses including the respective distinct addresses of the identified network traffic monitoring tools and a second network address corresponding to the second computer system. The second network address may be ordered after the respective distinct addresses of the identified network traffic monitoring tools in the sequence. The server may send, according to the routing path, the packets to the identified network traffic monitoring tools and the second computer system.

Claims (48)

1. A method comprising:

performing by a data packet processing system:

receiving one or more data packets originated from a first remote computer system, the one or more data packets having a destination of a second remote computer system;

determining, based on the one or more data packets, an identifier of an entity associated with the first remote computer system,

based on the identifier of the entity, identifying a plurality of network traffic monitoring tools to be applied to the one or more data packets in a first ordered sequence, wherein each of the network traffic monitoring tools in the plurality of network monitoring tools has a respective address;

obtaining a second ordered sequence of the respective addresses of the plurality of network traffic monitoring tools, wherein a position of each of the network traffic monitoring tools in the first ordered sequence of the network traffic monitoring tools matches a position of the respective address of each of the network traffic monitoring tools in the second ordered sequence of the respective addresses of the plurality of network traffic monitoring tools;

applying the network traffic monitoring tools to the one or more data packets in the first ordered sequence by accessing the respective addresses of the plurality of network traffic monitoring tools in the second ordered sequence;

after applying the network traffic monitoring tools to the one or more data packets in the first ordered sequence and before sending the one or more data packets to the second remote computer system, applying a particular network traffic monitoring tool to the one or more data packets based on a security alert provided by at least one of the plurality of network traffic monitoring tools; and

sending the one or more data packets to the second remote computer system, the network traffic monitoring tools having been applied to the one or more data packets before the one or more data packets arrive at the second remote computer system,

wherein the security alert is provided by the at least one of the plurality of network traffic monitoring tools based on application of the at least one of the plurality of network traffic monitoring tools to the one or more data packets, and

wherein the particular network traffic monitoring tool is not included in the plurality of network traffic monitoring tools.

2. The method of claim 1 , wherein the data packet processing system is a physical computing system or a virtual machine.

3. The method of claim 1 , wherein the particular network traffic monitoring tool of the plurality of network monitoring tools is configured to execute on a physical computing system or on a virtual machine.

4. The method of claim 1 , wherein the respective addresses of the plurality of network traffic monitoring tools include network addresses of the plurality of network traffic monitoring tools.

5. The method of claim 4 , wherein the network addresses of the plurality of network traffic monitoring tools include one or more Internet Protocol (IP) addresses and/or one or more Classless Inter-Domain Routing (CIDR) addresses.

6. The method of claim 4 , wherein applying the network traffic monitoring tools to the one or more data packets in the first ordered sequence by accessing the respective addresses of the plurality of network traffic monitoring tools in the second ordered sequence comprises routing the one or more data packets to the respective addresses of the plurality of network monitoring tools according to the second ordered sequence of the respective addresses.

7. The method of claim 1 , wherein the respective addresses of the plurality of network traffic monitoring tools include locations of one or more of the plurality of network traffic monitoring tools on a computer storage medium.

8. The method of claim 7 , wherein the computer storage medium comprises a memory device.

9. The method of claim 1 , wherein the particular network traffic monitoring tool is selected based on the security alert.

10. A system, comprising:

at least one data packet processing computer programmed to perform operations including:

receiving one or more data packets originated from a first remote computer system, the one or more data packets having a destination of a second remote computer system;

determining, based on the one or more data packets, an identifier of an entity associated with the first remote computer system,

based on the identifier of the entity, identifying a plurality of network traffic monitoring tools to be applied to the one or more data packets in a first ordered sequence, wherein each of the network traffic monitoring tools in the plurality of network monitoring tools has a respective address;

obtaining a second ordered sequence of the respective addresses of the plurality of network traffic monitoring tools, wherein a position of each of the network traffic monitoring tools in the first ordered sequence of the network traffic monitoring tools matches a position of the respective address of each of the network traffic monitoring tools in the second ordered sequence of the respective addresses of the plurality of network traffic monitoring tools;

applying the network traffic monitoring tools to the one or more data packets in the first ordered sequence by accessing the respective addresses of the plurality of network traffic monitoring tools in the second ordered sequence;

after applying the network traffic monitoring tools to the one or more data packets in the first ordered sequence and before sending the one or more data packets to the second remote computer system, applying a particular network traffic monitoring tool to the one or more data packets based on a security alert provided by at least one of the plurality of network traffic monitoring tools; and

sending the one or more data packets to the second remote computer system, the network traffic monitoring tools having been applied to the one or more data packets before the one or more data packets arrive at the second remote computer system,

wherein the security alert is provided by the at least one of the plurality of network traffic monitoring tools based on application of the at least one of the plurality of network traffic monitoring tools to the one or more data packets, and

wherein the particular network traffic monitoring tool is not included in the plurality of network traffic monitoring tools.

11. The system of claim 10 , wherein the data packet processing computer comprises a physical computing system or a virtual machine.

12. The system of claim 10 , wherein the particular network traffic monitoring tool of the plurality of network monitoring tools is configured to execute on a physical computing system or on a virtual machine.

13. The system of claim 10 , wherein the respective addresses of the plurality of network traffic monitoring tools include network addresses of the plurality of network traffic monitoring tools.

14. The system of claim 13 , wherein the network addresses of the plurality of network traffic monitoring tools include one or more Internet Protocol (IP) addresses and/or one or more Classless Inter-Domain Routing (CIDR) addresses.

15. The system of claim 13 , wherein applying the network traffic monitoring tools to the one or more data packets in the first ordered sequence by accessing the respective addresses of the plurality of network traffic monitoring tools in the second ordered sequence comprises routing the one or more data packets to the respective addresses of the plurality of network monitoring tools according to the second ordered sequence of the respective addresses.

16. The system of claim 10 , wherein the respective addresses of the plurality of network traffic monitoring tools include locations of one or more of the plurality of network traffic monitoring tools on a computer storage medium.

17. The system of claim 16 , wherein the computer storage medium comprises a memory device.

18. The system of claim 10 , wherein the particular network traffic monitoring tool is selected based on the security alert.

19. A computer storage medium having instructions stored thereon that, when executed by data processing apparatus of at least one data packet processing computer, cause the data processing apparatus to perform operations including:

receiving one or more data packets originated from a first remote computer system, the one or more data packets having a destination of a second remote computer system;

determining, based on the one or more data packets, an identifier of an entity associated with the first remote computer system,

based on the identifier of the entity, identifying a plurality of network traffic monitoring tools to be applied to the one or more data packets in a first ordered sequence, wherein each of the network traffic monitoring tools in the plurality of network monitoring tools has a respective address;

obtaining a second ordered sequence of the respective addresses of the plurality of network traffic monitoring tools, wherein a position of each of the network traffic monitoring tools in the first ordered sequence of the network traffic monitoring tools matches a position of the respective address of each of the network traffic monitoring tools in the second ordered sequence of the respective addresses of the plurality of network traffic monitoring tools;

applying the network traffic monitoring tools to the one or more data packets in the first ordered sequence by accessing the respective addresses of the plurality of network traffic monitoring tools in the second ordered sequence;

after applying the network traffic monitoring tools to the one or more data packets in the first ordered sequence and before sending the one or more data packets to the second remote computer system, applying a particular network traffic monitoring tool to the one or more data packets based on a security alert provided by at least one of the plurality of network traffic monitoring tools; and

sending the one or more data packets to the second remote computer system, the network traffic monitoring tools having been applied to the one or more data packets before the one or more data packets arrive at the second remote computer system,

wherein the security alert is provided by the at least one of the plurality of network traffic monitoring tools based on application of the at least one of the plurality of network traffic monitoring tools to the one or more data packets, and

wherein the particular network traffic monitoring tool is not included in the plurality of network traffic monitoring tools.

Assignments (4)
SECURITY INTEREST Recorded Jul 1, 2024
From: NEWCO OMNINET PURCHASER, LLC
To: FIDELITY DIRECT LENDING LLC, AS AGENT
Reel/Frame 067883/0379 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2023
From: BAGRIN, ANDREW
To: MYDIGITALSHIELD, INC.
Reel/Frame 064438/0861 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2023
From: OMNINET, INC.
To: NEWCO OMNINET PURCHASER, LLC
Reel/Frame 064439/0235 →
CONFIRMATORY ASSIGNMENT Recorded Jul 31, 2023
From: MYDIGITALSHIELD, INC.; WIREPATH HOME SYSTEMS, LLC OBA SNAP AV
To: OMNINET, INC.
Reel/Frame 064442/0894 →
Continuity (3)
Continuation 15284363 · Oct 3, 2016
Provisional Application 62236798 · Oct 2, 2015
Related Publication 20220070075A1 · Mar 3, 2022