IP Library Granted Patent US 11,700,190
Granted Patent B2
US 11,700,190 · App. 17/503,097 · Granted Jul 11, 2023

Technologies for annotating process and user information for network flows

Inventors: Navindra Yadav (Cupertino, CA); Abhishek Ranjan Singh (Pleasanton, CA); Anubhav Gupta (Fremont, CA); Shashidhar Gandham (Fremont, CA); Jackson Ngoc Ki Pang (Sunnyvale, CA); Shih-Chun Chang (San Jose, CA); Hai Trong Vu (San Jose, CA)
Assignee: Cisco Technology, Inc.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F16/122G06F16/137G06F16/162G06F16/17G06F16/173G06F16/174G06F16/1744G06F16/1748G06F16/235G06F16/2322G06F16/2365G06F16/248G06F16/24578G06F16/285G06F16/288G06F16/29G06F16/9535G06F21/53G06F21/552G06F21/556G06F21/566G06N20/00G06N99/00G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/026H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/5007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/145H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/01H04L67/10H04L67/1001H04L67/12H04L67/51H04L67/75H04L69/16H04L69/22H04W72/54H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595G06F2221/033G06F2221/2101G06F2221/2105G06F2221/2111G06F2221/2115G06F2221/2145H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,700,190
App. No.
17/503,097
Granted
Jul 11, 2023
Kind
B2
Abstract

Systems, methods, and computer-readable media for annotating process and user information for network flows. In some embodiments, a capturing agent, executing on a first device in a network, can monitor a network flow associated with the first device. The first device can be, for example, a virtual machine, a hypervisor, a server, or a network device. Next, the capturing agent can generate a control flow based on the network flow. The control flow may include metadata that describes the network flow. The capturing agent can then determine which process executing on the first device is associated with the network flow and label the control flow with this information. Finally, the capturing agent can transmit the labeled control flow to a second device, such as a collector, in the network.

Claims (53)

1. A network traffic monitoring system comprising:

a plurality of distributed sensors, each sensor associated with a particular device of a plurality of physical or virtual devices, wherein:

each sensor generates network flow data based upon packets sent and/or received via a network interface local to the particular device associated with that sensor;

a first device of the plurality of physical or virtual devices is associated with at least one first sensor of the plurality of distributed sensors and comprises a virtual machine;

a second device of the plurality of physical or virtual devices is associated with at least one second sensor and comprises a container; and

a third device of the plurality of physical or virtual devices is associated with at least one third sensor comprises a network switch; and

a backend comprising a collector, an analytics module, and a presentation module, wherein the collector includes a storage, and wherein the presentation module includes one or more application programming interface (API) segments;

wherein the collector is communicably attached to a communications network and receives a plurality of network flow data from the plurality of distributed sensors via the attached communications network,

wherein the analytics module evaluates the plurality of network flow data to establish patterns of a particular behavior of the plurality of physical or virtual devices, and uses a machine learning model to evaluate received information from the plurality of network flow data, and

wherein upon identifying received information that varies from the machine learning model of the particular behavior of the plurality of physical or virtual devices, the system provides, via the presentation module, a report of anomalous flow data.

2. The network traffic monitoring system of claim 1 , wherein the analytics module further evaluates the plurality of network flow data to generate a directed control flow graph corresponding to components of a distributed application.

3. The network traffic monitoring system of claim 2 , wherein the presentation module includes a user interface, and wherein the presentation module creates a visual representation of the directed control flow graph via the user interface.

4. The network traffic monitoring system of claim 2 , wherein the analytics module annotates a node and/or an edge with one of a process ID, a process name, a username, a location, or an environment variable.

5. The network traffic monitoring system of claim 4 , wherein the presentation module includes a user interface, and wherein information about nodes, network flows, the directed control flow graph, and tags are visually represented via the user interface.

6. The network traffic monitoring system of claim 1 , wherein identifying received information that varies from the machine learning model of the particular behavior includes analyzing whether a particular flow from the plurality of network flow information complies with a security policy.

7. The network traffic monitoring system of claim 1 , wherein at least one API segment allows access via a database protocol.

8. The network traffic monitoring system of claim 1 , wherein at least one API segment allows access via a web server.

9. The network traffic monitoring system of claim 1 , wherein at least one API segment allows access for ad-hoc queries.

10. A method of monitoring network traffic comprising:

at a plurality of distributed sensors, each sensor associated with a particular device of a plurality of physical or virtual devices:

generating network flow data based upon packets being sent and/or received via a network interface local to the particular device; and

sending the network flow data via a communications network, wherein:

a first device of the plurality of physical or virtual devices is associated with at least one first sensor of the plurality of distributed sensors and comprises a virtual machine;

a second device of the plurality of physical or virtual devices is associated with at least one second sensor and comprises a container; and

a third device of the plurality of physical or virtual devices is associated with at least one third sensor comprises a network switch;

receiving, at a collector communicably attached to the communications network, a plurality of network flow data, each network flow data coming from a sensor of the plurality of distributed sensors;

storing at least a portion of the plurality of network flow data received by the collector; and

analyzing the plurality of network flow data received by the collector via an associated analytics module, wherein analyzing the plurality of network flow data includes:

establishing patterns of a particular behavior of the plurality of physical or virtual devices;

using a machine learning model to evaluate received information from the plurality of network flow data; and

providing, via a presentation module, a result of the analyzing.

11. The method of claim 10 , wherein analyzing the plurality of network flow data further comprises identifying received anomalous information that varies from the machine learning model of particular behavior, and wherein providing the result further comprises including analysis of the received anomalous information.

12. The method of claim 10 , wherein providing the result of the analyzing includes making the result available via an application programming interface (API).

13. The method of claim 12 , wherein the API is a database access API.

14. The method of claim 12 , wherein making the result available via an API includes allowing ad-hoc queries.

15. The method of claim 12 , wherein the API is provided via a web server.

16. The method of claim 10 , wherein providing the result of the analyzing includes making the result available via a graphical user interface.

17. Non-transitory computer-readable media encoding a set of computer-readable instructions which, when executed on one or more processors on devices connected to a network, cause one or more devices to:

at a plurality of distributed sensors, each sensor associated with a particular device of a plurality of physical or virtual devices:

generate network flow data based upon packets sent and/or received via a network interface local to the particular device; and

send the network flow data via a communications network, wherein:

a first device of the plurality of physical or virtual devices is associated with at least one first sensor of the plurality of distributed sensors and comprises a virtual machine;

a second device of the plurality of physical or virtual devices is associated with at least one second sensor and comprises a container; and

a third device of the plurality of physical or virtual devices is associated with at least one third sensor comprises a network switch;

receive, at a collector communicably attached to the communications network, a plurality of network flow data, each network flow data coming from a sensor of the plurality of distributed sensors;

store at least a portion of the plurality of network flow data received by the collector; and

analyze, via an analytics module, the plurality of network flow data received by the collector, wherein the computer-readable instructions, when executed on the one or more processors, cause the one or more devices to:

establish patterns of a particular behavior of the plurality of physical or virtual devices;

use a machine learning model to evaluate received information from the plurality of network flow data; and

provide, via a presentation module, a result of the analyzing.

18. The non-transitory computer-readable media of claim 17 , further including instructions that, when executed by the one or more processors, cause the one or more devices to make the result available via an application programming interface (API).

19. The non-transitory computer-readable media of claim 17 , further including instructions that, when executed on the one or more processors, cause the one or more devices to make the result available via a graphical user interface.

20. The non-transitory computer-readable media of claim 17 , further including instructions that, when executed on the one or more processors, cause the one or more devices to identify received anomalous information that varies from the machine learning model of the particular behavior, wherein the result of the analyzing includes analysis of the anomalous information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2021
From: YADAV, NAVINDRA; SINGH, ABHISHEK RANJAN; GUPTA, ANUBHAV; GANDHAM, SHASHIDHAR; KI PANG, JACKSON NGOC; CHANG, SHIH-CHUN; VU, HAI TRONG
To: CISCO TECHNOLOGY, INC.
Reel/Frame 057829/0557 →
Continuity (4)
Continuation 16237187 · Dec 31, 2018
Continuation 15152163 · May 11, 2016
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20220038353A1 · Feb 3, 2022
Cited By (16)
US 12,250,236 US 12,273,321 US 12,284,197 US 12,348,545 US 12,355,793 US 12,381,821 US 12,452,272 US 12,470,577 US 12,470,578 US 12,495,052 US 12,495,068 US 12,526,297 US 12,563,071 US 12,695,768 US 12,712,897 US 12,719,869