IP Library Granted Patent US 11,909,606
Granted Patent B2
US 11,909,606 · App. 17/537,160 · Granted Feb 20, 2024

Systems and methods for determining flow and path analytics of an application of a network using sampled packet inspection

Inventors: Donald B. Grosser (Apex, NC); Chun Zhang (Cary, NC); Patrick A. Bosa (Exeter, NH); Markus Nispel (Boston, MA)
Assignee: Extreme Networks, Inc.
H04L43/028H04L41/12H04L41/142H04L43/12H04L43/18H04L43/0852H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,909,606
App. No.
17/537,160
Filed
Nov 29, 2021
Granted
Feb 20, 2024
Kind
B2
Art Unit
2414
USPC
370/252
Abstract

Systems and methods are disclosed herein for monitoring health of each switch of a plurality of switches on a network by selectively mirroring packets transmitted by each switch of the plurality of switches. In some embodiments, control circuitry generates a plurality of mirroring parameters, each mirroring parameter comprising an instruction to mirror a respective type of packet. The control circuitry transmits the plurality of mirroring parameters to each switch of the plurality of switches on the network, and receives, from a switch, a packet that was mirrored by the switch according to a mirroring parameter of the plurality of mirroring parameters. The control circuitry determines the respective type of the packet, executes an analysis of contents of the packet based on the respective type of the packet, and determines a health of the switch based on results of the analysis.

Claims (53)

1. A method, comprising:

generating a mirroring parameter that comprises an instruction to mirror a type of packet;

transmitting the mirroring parameter to each switch of a plurality of switches in a network;

receiving one or more packets, each mirrored by a respective one of the plurality of switches based on the mirroring parameter, wherein the one or more packets correspond to a web-based flow between a client and a service; and

determining an identity of a switch of the plurality of switches that dropped an acknowledgement packet corresponding to a packet of the one or more packets, wherein the switch is located along the web-based flow between the client and the service.

2. The method of claim 1 , further comprising:

receiving, from a second switch of the plurality of switches, another acknowledgement packet corresponding to another packet of the one or more packets;

analyzing contents of the other packet and the other acknowledgement packet;

determining a time difference between when the other packet was received and when the other acknowledgment packet was received; and

determining a status of an application corresponding to the web-based flow by comparing the time difference to a threshold.

3. The method of claim 1 , further comprising:

transmitting an access control list (ACL) to the switch.

4. The method of claim 1 , wherein receiving the one or more packets further comprises:

receiving the one or more packets using a sampled flow (SFlow) protocol.

5. The method of claim 1 , wherein receiving the one or more packets further comprises:

mirroring the packet of the one or more packets based at least in part on whether the packet comprises data matching a predetermined pattern of the mirroring parameter at a predetermined location.

6. The method of claim 1 , wherein the packet is a synchronization (SYN) packet.

7. The method of claim 1 , wherein the application is a transmission control protocol (TCP) application.

8. A system, comprising:

communications circuitry; and

control circuitry configured to:

generate a mirroring parameter that comprises an instruction to mirror a type of packet;

transmit the mirroring parameter to each switch of a plurality of switches in a network;

receive one or more packets, each mirrored by a respective one of the plurality of switches based on the mirroring parameter, wherein the one or more packets correspond to a web-based flow between a client and a service;

determine an identity of a switch of the plurality of switches that dropped an acknowledgement packet corresponding to a packet of the one or more packets, wherein the switch is located along the web-based flow between the client and the service.

9. The system of claim 8 , wherein the control circuitry is further configured to:

receive, from a second switch of the plurality of switches, an other acknowledgement packet corresponding to an other packet of the one or more packets;

analyze contents of the other packet and the other acknowledgement packet determine a time difference between when the other packet was received and when the other acknowledgment packet was received; and

determine a status of an application corresponding to the web-flow by comparing the time difference to a threshold.

10. The system of claim 8 , wherein to receive the one or more packets, the control circuitry is further configured to:

receive the one or more packets using a sampled flow (SFlow) protocol.

11. The system of claim 8 , wherein to receive the one or more packets, the control circuitry is further configured to mirror the packet of the one or more packets based at least in part on whether the packet comprises data matching a predetermined pattern of the mirroring parameter at a predetermined location.

12. The system of claim 8 , wherein the packet is a synchronization (SYN) packet.

13. The system of claim 8 , wherein the control circuitry is further configured to:

transmit an access control list (ACL) to the switch.

14. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, causes the at least one computing device to perform operations comprising:

generating a mirroring parameter that comprises an instruction to mirror a type of packet, wherein the type of packet is a synchronization (SYN) packet;

transmitting the mirroring parameter to each switch of a plurality of switches in a network;

receiving one or more SYN packets each mirrored by a respective one of the plurality of switches based on the mirroring parameter, wherein the one or more SYN packets correspond to a web-based flow between a client and a service; and

determining an identity of a switch of the plurality of switches that dropped an acknowledgement packet corresponding to the SYN packet of the one or more SYN packets, wherein the switch is located along the web-based flow between the client and the service.

15. The non-transitory computer-readable medium of claim 14 , the operations further comprising:

receiving, from a second switch of the plurality of switches, an other acknowledgement packet corresponding to an other SYN packet of the one or more SYN packets;

analyzing contents of the other SYN packet and the other acknowledgement packet; and

determining a time difference between when the other SYN packet was received and when the other acknowledgment packet was received; and

determining a status of an application corresponding to the web-based flow by comparing the time difference to a threshold.

16. The non-transitory computer-readable medium of claim 14 , the operations further comprising:

transmitting an access control list (ACL) to the switch.

17. The non-transitory computer-readable medium of claim 14 , wherein the receiving the one or more SYN packets further comprises:

receiving the one or more SYN packets using a sampled flow (SFlow) protocol.

18. The non-transitory computer-readable medium of claim 14 , wherein receiving the one or more SYN packets further comprises:

mirroring the SYN packet of the one or more SYN packets based at least in part on whether the SYN packet comprises data matching a predetermined pattern of the mirroring parameter at a predetermined location.

19. The non-transitory computer-readable medium of claim 16 , wherein the SYN packet is mirrored based on a match between the mirroring parameter of the ACL and a parameter of the SYN packet.

20. The non-transitory computer-readable medium of claim 14 , wherein the application is a transmission control protocol (TCP) application.

Assignments (4)
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2024
From: GROSSER, DONALD B.; ZHANG, CHUN; BOSA, PATRICK A.; NISPEL, MARKUS
To: EXTREME NETWORKS, INC.
Reel/Frame 066015/0424 →
SECURITY INTEREST Recorded Jan 4, 2024
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 066015/0469 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
Continuity (3)
Continuation 16130649 · Sep 13, 2018
Provisional Application 62592106 · Nov 29, 2017
Related Publication 20220086067A1 · Mar 17, 2022