IP Library Granted Patent US 11,792,284
Granted Patent B1
US 11,792,284 · App. 17/589,361 · Granted Oct 17, 2023

Using data transformations for monitoring a cloud compute environment

Inventors: Anil K. Nanduri (Fremont, CA); Prakash Jalan (Sunnyvale, CA); Matti A. Vanninen (Cary, NC); Ammar G. Ekbote (Renton, WA); Alex Ramachandran Nirmala (Cupertino, CA); Yijou Chen (Cupertino, CA)
Assignee: Lacework, Inc.
H04L67/535G06F9/455G06F9/545G06F16/9024G06F16/9038G06F16/9535G06F16/9537G06F21/57H04L43/045H04L43/06H04L63/10H04L67/306G06F16/2456
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,792,284
App. No.
17/589,361
Granted
Oct 17, 2023
Kind
B1
Abstract

Example systems and methods monitor a cloud compute environment. An example method includes an agent obtaining a data packet from an interface in the cloud compute environment, the data packet including a source address and a non-endpoint destination address; determining, based on the non-endpoint destination address and routing information for the data packet, an endpoint destination address associated with the non-endpoint destination address of the data packet; modifying the data packet by replacing the non-endpoint destination address with the endpoint destination address; and providing, based on the modified data packet, monitoring data to a data platform.

Claims (48)

1. A method comprising:

obtaining, by an agent monitoring a cloud compute environment, a data packet from an interface of a pod managed by a container orchestration system in the cloud compute environment, the data packet including a source address and a non-endpoint destination address;

determining, by the agent and based on the non-endpoint destination address and routing information for the data packet, an endpoint destination address associated with the non-endpoint destination address of the data packet;

modifying, by the agent, the data packet by replacing the non-endpoint destination address with the endpoint destination address; and

providing, by the agent and based on the modified data packet, monitoring data to a data platform.

2. The method of claim 1 , wherein the source address comprises an IP address of a container in the cloud compute environment.

3. The method of claim 1 , wherein the source address comprises a pod IP address for the pod, the pod including a container.

4. The method of claim 1 , wherein the non-endpoint destination address comprises a service IP address associated with a service network in the cloud compute environment.

5. The method of claim 1 , wherein the non-endpoint destination address comprises a host IP address associated with a host network in the cloud compute environment.

6. The method of claim 1 , further comprising:

obtaining, by a second agent monitoring the cloud compute environment, a second data packet from a second interface in the cloud compute environment, the second data packet including a second source address and a second non-endpoint destination address;

determining, by the second agent and based on the second non-endpoint destination address and routing information for the second data packet, that the endpoint destination address is associated with the second non-endpoint destination address of the second data packet;

modifying, by the second agent, the second data packet by replacing the second non-endpoint destination address with the endpoint destination address; and

providing, by the second agent and based on the modified second data packet, second monitoring data to the data platform.

7. The method of claim 1 , further comprising:

receiving, at the data platform, the monitoring data; and

generating a polygraph based at least in part on the monitoring data.

8. A computer program product embodied in a non-transitory computer-readable medium and comprising computer instructions for:

obtaining a data packet from an interface of a pod managed by a container orchestration system in a cloud compute environment, the data packet including a source address and a non-endpoint destination address;

determining, based on the non-endpoint destination address and routing information for the data packet, an endpoint destination address associated with the non-endpoint destination address of the data packet;

modifying the data packet by replacing the non-endpoint destination address with the endpoint destination address; and

providing, based on the modified data packet, monitoring data to a data platform.

9. The computer program product of claim 8 , wherein the source address comprises an IP address of a container in the cloud compute environment.

10. The computer program product of claim 8 , wherein the source address comprises a pod IP address for the pod, the pod including a container.

11. The computer program product of claim 8 , wherein the non-endpoint destination address comprises a service IP address associated with a service network in the cloud compute environment.

12. The computer program product of claim 8 , wherein the non-endpoint destination address comprises a host IP address associated with a host network in the cloud compute environment.

13. The computer program product of claim 8 , the computer instructions further for:

obtaining a second data packet from a second interface in the cloud compute environment, the second data packet including a second source address and a second non-endpoint destination address;

determining, based on the second non-endpoint destination address and routing information for the second data packet, that the endpoint destination address is associated with the second non-endpoint destination address of the second data packet;

modifying the second data packet by replacing the second non-endpoint destination address with the endpoint destination address; and

providing, based on the modified second data packet, second monitoring data to the data platform.

14. The computer program product of claim 13 , wherein:

the source address is an endpoint source address; and

the second source address in a non-endpoint source address.

15. A system for monitoring a cloud compute environment, the system comprising:

a memory storing computer-executable instructions;

a processor to execute the computer-executable instructions to:

obtain a data packet from an interface of a pod managed by a container orchestration system in the cloud compute environment, the data packet including a source address and a non-endpoint destination address;

determine, based on the non-endpoint destination address and routing information for the data packet, an endpoint destination address associated with the non-endpoint destination address of the data packet;

modify the data packet by replacing the non-endpoint destination address with the endpoint destination address; and

provide, based on the modified data packet, monitoring data to a data platform.

16. The system of claim 15 , wherein the source address comprises an IP address of a container in the cloud compute environment.

17. The system of claim 15 , wherein the source address comprises a pod IP address for the pod, the pod including a container.

18. The system of claim 15 , wherein the non-endpoint destination address comprises a service IP address associated with a service network in the cloud compute environment.

19. The system of claim 15 , wherein the non-endpoint destination address comprises a host IP address associated with a host network in the cloud compute environment.

20. The system of claim 15 , wherein:

the non-endpoint destination address comprises a service IP address associated with a service network in the cloud compute environment; and

the endpoint destination address comprises a pod IP address associated with a second pod in the cloud compute environment.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069113/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2022
From: NANDURI, ANIL K.; JALAN, PRAKASH; VANNINEN, MATTI A.; EKBOTE, AMMAR G.; RAMACHANDRAN NIRMALA, ALEX; CHEN, YIJOU
To: LACEWORK, INC.
Reel/Frame 058835/0009 →
Continuity (6)
Continuation In Part 17504311 · Oct 18, 2021
Continuation 16665961 · Oct 28, 2019
Continuation 16134794 · Sep 18, 2018
Provisional Application 63231661 · Aug 10, 2021
Provisional Application 62650971 · Mar 30, 2018
Provisional Application 62590986 · Nov 27, 2017
Cited By (42)
US 12,212,586 US 12,217,079 US 12,219,048 US 12,219,053 US 12,231,448 US 12,244,627 US 12,244,634 US 12,267,326 US 12,277,216 US 12,278,819 US 12,278,825 US 12,278,840 US 12,278,897 US 12,284,220 US 12,287,899 US 12,353,309 US 12,353,474 US 12,395,488 US 12,406,071 US 12,411,937 US 12,411,957 US 12,417,822 US 12,425,428 US 12,432,218 US 12,443,720 US 12,443,722 US 12,481,538 US 12,489,781 US 12,495,049 US 12,500,917 US 12,505,200 US 12,506,755 US 12,524,550 US 12,531,881 US 12,547,765 US 12,579,251 US 12,585,557 US 12,645,785 US 12,645,794 US 12,657,282 US 12,688,277 US 12,695,763