IP Library Granted Patent US 11,855,862
Granted Patent B2
US 11,855,862 · App. 17/507,453 · Granted Dec 26, 2023

Tagging packets for monitoring and analysis

Inventors: Xi Cheng (Beijing, CN); Caixia Jiang (Beijing, CN); Dongrui Mo (Beijing, CN); Jingchun Jason Jiang (Beijing, CN); Xiaoyan Jin (Beijing, CN); Qiong Wang (Beijing, CN); Donghai Han (Beijing, CN)
Assignee: VMWARE, INC.
H04L43/028G06F9/45558H04L43/04H04L43/10H04L47/2483H04L47/41H04L69/22G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,855,862
App. No.
17/507,453
Granted
Dec 26, 2023
Kind
B2
Abstract

Some embodiments provide a method for performing data traffic monitoring. The method processes a packet through a packet processing pipeline that includes multiple stages. At a filtering stage, the method tags the packet with a set of monitoring actions for subsequent stages to perform on the packet based on a determination that the packet matches a particular filter. For each stage of a set of packet processing stages subsequent to the filtering stage, the method (i) executes any monitoring actions specified for the stage to perform on the packet and (ii) sends the packet to a next stage in the packet processing pipeline.

Claims (26)

1. A non-transitory machine-readable medium storing a program which when executed by at least one processing unit performs data traffic monitoring, the program comprising sets of instructions for:

processing a packet through a packet processing pipeline comprising a plurality of stages by:

at a filtering stage, tagging the packet with a set of monitoring actions for subsequent stages to perform on the packet based on a determination that the packet matches a particular filter; and

for each stage of a set of packet processing stages subsequent to the filtering stage, (i) executing any monitoring actions specified for the stage to perform on the packet and (ii) sending the packet to a next stage in the packet processing pipeline.

2. The non-transitory machine-readable medium of claim 1 , wherein the filtering stage is a first stage in the packet processing pipeline, wherein the set of packet processing stages that execute monitoring actions comprises a set of intermediary packet processing stages between the filtering first stage and an encapsulation last stage.

3. The non-transitory machine-readable medium of claim 2 , wherein:

the encapsulation stage encapsulates the packet with an encapsulating header that includes data specifying the set of monitoring actions; and

the program further comprises a set of instructions for sending the encapsulated packet to a destination machine via a network.

4. The non-transitory machine-readable medium of claim 3 , wherein:

the packet processing pipeline is a first packet processing pipeline executed by a first host computer on which a source machine of the packet executes; and

a second packet processing pipeline executed by a second host computer on which the destination machine executes comprises at least one stage that executes at least one monitoring action on the packet.

5. The non-transitory machine-readable medium of claim 1 , wherein:

the packet is a first packet in a set of packets that match the particular filter; and

the set of packets belong to a same packet flow sent from a source machine executing on a set of virtualization software of a host computer that executes the packet processing pipeline.

6. The non-transitory machine-readable medium of claim 1 , wherein the program is virtualization software of a host computer that installs the filtering stage in the packet processing pipeline in response to receiving a request from a network controller to install the filtering stage to initiate a live packet monitoring session, wherein the request further specifies (i) the particular filter and (ii) the set of monitoring actions.

7. The non-transitory machine-readable medium of claim 6 , wherein the virtualization software removes the filtering stage from the packet processing pipeline in response to receiving a control message from the network controller to terminate the live packet monitoring session.

8. The non-transitory machine-readable medium of claim 1 , wherein the packet is a first packet, the program further comprising sets of instructions for, at the filtering stage:

receiving a second packet to be processed by the packet processing pipeline;

determining that the second packet does not match the particular filter; and

sending the second packet to a next stage in the packet processing pipeline without tagging the second packet.

9. A computing device comprising:

a set of processing units; and

a non-transitory machine-readable medium storing a program which when executed by at least one of the processing units performs data traffic monitoring, the program comprising sets of instructions for:

processing a packet through a packet processing pipeline comprising a plurality of stages by:

at a filtering stage, tagging the packet with a set of monitoring actions for subsequent stages to perform on the packet based on a determination that the packet matches a particular filter; and

for each stage of a set of packet processing stages subsequent to the filtering stage, (i) executing any monitoring actions specified for the stage to perform on the packet and (ii) sending the packet to a next stage in the packet processing pipeline.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2021
From: CHENG, XI; JIANG, CAIXIA; MO, DONGRUI; JIANG, JINGCHUN JASON; JIN, XIAOYAN; WANG, QIONG; HAN, DONGHAI
To: VMWARE, INC.
Reel/Frame 057889/0219 →
Priority Claims (1)
WO PCT/CN2021/119019 · Sep 17, 2021 · international
Continuity (1)
Related Publication 20230087454A1 · Mar 23, 2023