IP Library › Patent Application 17311087
Patent Application
App. No. 17/311,087

A System and a Method for Monitoring Traffic Flows in a Communications Network

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/311,087
Abstract

A network element and a method are configured to monitor a plurality of traffic flows conveyed in a communications network, wherein the network element comprises: at least one packet processor configured to support ACL functionality, and at least one CPU configured to track traffic flows and to export statistical data.

Claims (52)

1 . A network element configured to monitor a plurality of traffic flows conveyed in a communications network, wherein the network element comprises:

(i) at least one packet processor configured to support ACL functionality; and

(ii) at least one CPU configured to carry out:

a. tracking traffic flows; and

b. exporting statistical data.

2 . The network element of claim 1 , wherein said at least one processor is further configured to classify a plurality of incoming packets to their respective known traffic flows.

3 . The network element of claim 2 , wherein said at least one processor is further configured to classify a plurality of incoming packets into their respective known traffic flows is achieved by using a table associated with said ACL functionality.

4 . The network element of claim 3 , wherein said ACL functionality is obtained by associating a plurality of ACL rules, each representing a known traffic flow, and a default ACL rule which represents all unknown traffic flows.

5 . The network element of claim 4 , wherein said default rule is configured to initiate generation and forwarding of a copy of a packet that belongs to an unknown traffic flow to said at least one CPU.

6 . The network element of claim 4 , wherein a packet that is in conformity with one of a plurality of ACL rules representing a known traffic flow, is determined to be a packet that is associated with the known traffic flow represented by said one of the plurality of ACL rules.

7 . The network element of claim 3 , wherein said one CPU is configured to track traffic flows on a periodical basis and to retrieve information from said table associated with the ACL functionality that relates to traffic flows' life cycles, and to export statistical data by a) initiating generation of packets that comprise information relating to inactive traffic flows and b) initiating export of said packets towards a remote device that is operative to collect data that relates to said inactive traffic flows.

8 . The network element of claim 1 , further configured to monitor a flow rate of a known traffic flow, at a rate which is essentially equal to a rate at which packets that belong to said known traffic flow are received by said network element.

9 . The network element of claim 1 , wherein said monitoring of a flow rate of an unknown traffic flow is carried out in accordance with a pre-defined traffic flow sampling rate, whereby information that relates only to a part of newly detected traffic flows is taken into account, and wherein a number of newly detected traffic flows whose information is taken into account, depends on said pre-determined traffic flow sampling rate.

10 . The network element of claim 1 , wherein each of said plurality of traffic flows is characterized in that:

a. each of said plurality of traffic flows comprises a plurality of packets that comprise identical forwarding related parameters;

b. each of the plurality of traffic flows ends after a pre-defined period of time has lapsed, wherein that pre-defined period of time extends from a time at which the last packet associated with a respective traffic flow was received and/or a packet that is associated with a respective traffic flow comprises an end-of-flow characteristic; and

c. each of the plurality of traffic flows starts when a packet associated with a respective traffic flow has been first detected and/or when a packet associated with a respective traffic flow has been first detected after that respective traffic flow had been determined as a traffic flow that had been ended.

11 . The network element of claim 1 , wherein said network element is further configured to maintain statistical data characterizing each known traffic flow, by using an ACL engine comprised in said packet processor.

12 . A method for monitoring a plurality of traffic flows conveyed by a network element operative in a communications network, wherein the network element comprises:

(i) at least one packet processor configured to support ACL functionality; and

(ii) at least one CPU configured to carry out:

a. tracking of traffic flows; and

b. exporting statistical data,

and wherein said method comprises the steps of:

receiving a plurality of packets at the network element;

for each of the plurality of the packets, determining whether it belongs to a traffic flow of which a preceding packet has already been received at said network element;

if a packet is determined to belong to an active traffic flow of which a preceding packet has already been received at said network element, and wherein at least one parameter characterizing said active traffic flow is associated with a rule stored in an ACL table comprised in said at least one packet processor, said method comprises:

retrieving statistical data associated with packets determined as packets that belong to said active traffic flow, and

applying the retrieved statistical data for monitoring said active traffic flow;

if a packet is determined not to belong to any active traffic flow of which a preceding packet has already been received at said network element, the method comprises:

generating a copy of said packet that does not belong to any active traffic flow of which a preceding packet has already been received at said network element, and forwarding said copy to said at least one CPU;

generating at least one new ACL rule that represents a new traffic flow to which said packet belongs, and wherein said at least one new ACL rule is associated with at least one parameter characterizing said new traffic flow;

storing said at least one new ACL rule at an ACL table comprised at said at least one packet processor;

determining which of a plurality of proceeding packets arriving to said network element belong to said new traffic flow, wherein said packets that belong to said new traffic flow are packets which are in conformity with said at least new ACL rule; and

retrieving statistical data associated with packets determined as packets that belong to said new traffic flow and applying the retrieved statistical data for monitoring said new traffic flow.

13 . The method of claim 12 , wherein the percentage of new traffic flows for which ACL rules are generated from among the total number of new traffic flows arriving at said network element, decreases along with increasing a number of new traffic flows arriving at said network element.

14 . A non-transitory computer readable medium storing a computer program for performing a set of instructions to be executed by one or more computer processors, the computer program is adapted to perform a method for monitoring a plurality of traffic flows conveyed by a network element operative in a communications network, wherein the network element comprises:

(i) at least one packet processor configured to support ACL functionality; and

(ii) at least one CPU configured to carry out:

a. tracking of traffic flows; and

b. exporting statistical data,

and wherein said method comprises the steps of:

upon receiving a plurality of packets at the network element determining whether it belongs to a traffic flow of which a preceding packet has already been received at the network element;

if a packet is determined to belong to an active traffic flow of which a preceding packet has already been received at the network element, and wherein at least one parameter characterizing the active traffic flow is associated with a rule stored in an ACL table comprised in the at least one packet processor,

retrieving statistical data associated with packets determined as packets that belong to the active traffic flow, and

applying the retrieved statistical data for monitoring the active traffic flow;

if a packet is determined not to belong to any active traffic flow of which a preceding packet has already been received at the network element,

generating a copy of the packet that does not belong to any active traffic flow of which a preceding packet has already been received at the network element, and forwarding the copy to the at least one CPU;

generating at least one new ACL rule that represents a new traffic flow to which said packet belongs, and wherein the at least one new ACL rule is associated with at least one parameter characterizing the new traffic flow;

storing said at least one new ACL rule at an ACL table comprised at the at least one packet processor;

determining which of a plurality of proceeding packets arriving to the network element belong to the new traffic flow, wherein the packets that belong to the new traffic flow are packets which are in conformity with said at least new ACL rule; and

retrieving statistical data associated with packets determined as packets that belong to the new traffic flow and applying the retrieved statistical data for monitoring the new traffic flow.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2022
From: AT&T SERVICES, INC.
To: DRIVENETS LTD.
Reel/Frame 058770/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2021
From: SANDLER, EVGENY; KRAYDEN, AMIR; GOLLAN, KFIR; SELA, HAGAI
To: DRIVENETS LTD.
Reel/Frame 057134/0183 →
ASSIGNMENT OF 1% RIGHTS Recorded Aug 10, 2021
From: DRIVENETS LTD.
To: AT&T SERVICES, INC.
Reel/Frame 057142/0678 →