IP Library Granted Patent US 11,770,464
Granted Patent B1
US 11,770,464 · App. 17/546,844 · Granted Sep 26, 2023

Monitoring communications in a containerized environment

Inventors: Rakesh Sachdeva (Santa Clara, CA); Vikram Kapoor (Cupertino, CA)
Assignee: Lacework Inc.
H04L69/22G06F9/45558H04L41/046H04L41/142H04L67/01G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,770,464
App. No.
17/546,844
Granted
Sep 26, 2023
Kind
B1
Abstract

A frame is received at an agent. The frame is analyzed to determine that the frame is associated with a first known pod. IP information is reported to a backend process. The backend process is configured to stitch the IP information with other IP information reported by one or more additional agents to identify a second pod.

Claims (30)

1. A method comprising:

receiving a frame at a first agent configured to collect information from one or more network interfaces of a first machine in a cloud environment, wherein the frame is associated with a communication from a source pod that is an abstraction of a set of one or more containers deployed on the first machine; and

reporting, by the agent and based on the frame, a first set of connection information to a data platform configured to match the first set of connection information with a second set of connection information reported by a second agent configured to collect information from one or more network interfaces of a second machine in the cloud environment to identify a pod-to-pod communication from the source pod on the first machine to a destination pod on the second machine for representation in a pod communication graph that includes a plurality of nodes representing a plurality of pods and a plurality of edges interconnecting the plurality of nodes and representing communications between the plurality of pods, wherein the first set of connection information indicates the source pod but not the destination pod;

wherein the data platform is configured to generate the pod communication graph based on a process cluster graph, wherein clusters of the process cluster graph are regrouped by pod type to generate the pod communication graph.

2. The method of claim 1 , wherein the frame comprises an encapsulated IP frame.

3. The method of claim 1 , wherein the first set of connection information indicates a source IP address of the source pod.

4. The method of claim 3 , wherein the first set of connection information further indicates a service port and a destination port.

5. The method of claim 4 , wherein the second set of connection information indicates a destination IP address of the destination pod.

6. The method of claim 5 , wherein the second set of connection information further indicates the service port and the destination port.

7. The method of claim 1 , wherein the pod-to-pod communication comprises a communication from a client application in the source pod to an application server in the destination pod.

8. The method of claim 1 , further comprising adding, by the data platform, an edge representing the pod-to-pod communication to the pod communication graph.

9. The method of claim 8 , further comprising generating, by the data platform, an alert based on the addition of the edge representing the pod-to-pod communication to the pod communication graph.

10. The method of claim 8 , further comprising providing, by the data platform, a visualization of the pod communication graph for display.

11. The method of claim 1 , further comprising incrementing, by the data platform, statistical information based on identifying the pod-to-pod communication.

12. The method of claim 1 , wherein the data platform is configured to generate the pod communication graph further based on pod communication information, the pod communication information including information for the pod-to-pod communication from the source pod on the first machine to the destination pod on the second machine.

13. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a frame at a first agent configured to collect information from one or more network interfaces of a first machine in a cloud environment, wherein the frame is associated with a communication from a source pod that is an abstraction of a set of one or more containers deployed on the first machine; and

reporting, by the agent and based on the frame, a first set of connection information to a data platform configured to match the first set of connection information with a second set of connection information reported by a second agent configured to collect information from one or more network interfaces of a second machine in the cloud environment to identify a pod-to-pod communication from the source pod on the first machine to a destination pod on the second machine for representation in a pod communication graph that includes a plurality of nodes representing a plurality of pods and a plurality of edges interconnecting the plurality of nodes and representing communications between the plurality of pods, wherein the first set of connection information indicates the source pod but not the destination pod;

wherein the data platform is configured to generate the pod communication graph based on a process cluster graph, wherein clusters of the process cluster graph are regrouped by pod type to generate the pod communication graph.

14. The computer program product of claim 13 , wherein the frame comprises an encapsulated IP frame.

15. The computer program product of claim 13 , wherein the first set of connection information indicates a source IP address of the source pod.

16. The computer program product of claim 15 , wherein the first set of connection information further indicates a service port and a destination port.

17. The computer program product of claim 16 , wherein the second set of connection information indicates a destination IP address of the destination pod.

18. The computer program product of claim 17 , wherein the second set of connection information further indicates the service port and the destination port.

19. A system comprising:

a processor, and

a memory coupled to the processor and configured to provide the processor with instructions to:

receive a frame at a first agent configured to collect information from one or more network interfaces of a first machine in a cloud environment, wherein the frame is associated with a communication from a source pod that is an abstraction of a set of one or more containers deployed on the first machine; and

report, based on the frame, a first set of connection information to a data platform configured to match the first set of connection information with a second set of connection information reported by a second agent configured to collect information from one or more network interfaces of a second machine in the cloud environment to identify a pod-to-pod communication from the source pod on the first machine to a destination pod on the second machine for representation in a pod communication graph that includes a plurality of nodes representing a plurality of pods and a plurality of edges interconnecting the plurality of nodes and representing communications between the plurality of pods, wherein the first set of connection information indicates the source pod but not the destination pod;

wherein the data platform is configured to generate the pod communication graph based on a process cluster graph, wherein clusters of the process cluster graph are regrouped by pod type to generate the pod communication graph.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069113/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2021
From: SACHDEVA, RAKESH; KAPOOR, VIKRAM
To: LACEWORK INC.
Reel/Frame 058351/0629 →