IP Library Granted Patent US 12,363,015
Granted Patent B2
US 12,363,015 · App. 17/725,404 · Granted Jul 15, 2025

Clock-synchronized edge-based network functions

Inventors: Yilong Geng (Menlo Park, CA); Balaji S. Prabhakar (Palo Alto, CA); Shiyu Liu (Mountain View, CA)
Assignee: Clockwork Systems, Inc.
H04L43/0852H04L43/0858H04L43/12H04L47/12H04L47/2433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,363,015
App. No.
17/725,404
Filed
Apr 20, 2022
Granted
Jul 15, 2025
Kind
B2
Art Unit
2473
USPC
370/252
Abstract

Network traffic is monitored to coordinate control of data flows and detect anomalies. For a data flow transmitted between sender and receiver hosts, pre-defined amounts of sent and received network traffic of the data flow is recorded. The data flow is monitored, based on time stamps of data packets in the network traffic, for an anomaly. Responsive to determining that no anomaly is detected, the recorded sent and received network traffic is overwritten with newly sent and newly received network traffic, respectively. Responsive to determining that an anomaly is detected, the data flow is paused, which causes the sender host to store the recorded sent network traffic to a first buffer and causes the receiver host the store the recorded received network traffic to a second buffer.

Claims (24)

1. A computer-implemented method for monitoring for anomalies in network traffic, the method comprising:

for a data flow transmitted between a sender host and a receiver host:

recording, on a first rolling basis, by the sender host, a first pre-defined amount of sent network traffic of the data flow;

recording, on a second rolling basis, by the receiver host, a second pre-defined amount of received network traffic of the data flow, wherein the sender host and the receiver host are clock-synchronized;

monitoring for an anomaly in the data flow based on time stamps of data packets in the network traffic;

determining whether an anomaly is detected during the monitoring;

responsive to determining that no anomaly is detected during the monitoring, overwriting the recorded sent network traffic and the recorded received network traffic with newly sent network traffic and newly received network traffic, respectively; and

responsive to determining that an anomaly is detected during the monitoring, pausing the data flow, causing the sender host to store the recorded sent network traffic to a first buffer, and causing the receiver host to store the recorded received network traffic to a second buffer, wherein determining that the anomaly is detected during the monitoring comprises determining that a one-way delay of a data packet sent by the sender host to the receiver host exceeds a threshold amount of delay, wherein the one-way delay is determined using a send time stamp applied by the sender host to data packets of the data flow as compared to a receive time stamp applied by the receiver host to the data packets, wherein the sender host and the receiver host are synchronized to a same reference clock, and wherein the send time stamp and the receive time stamp are based on the same reference clock.

2. The computer-implemented method of claim 1 , wherein the first pre-defined amount of sent network traffic and the second pre-defined amount of received network traffic are a same amount.

3. The computer-implemented method of claim 2 , wherein the same amount is measured using either a pre-defined number of most recently transmitted or received packets, or packets received during a pre-defined amount of units of time prior to a current time.

4. The computer-implemented method of claim 1 , wherein the sender host is located at either a kernel or a network interface card (NIC) of a sender device, and wherein the receiver host is located at either a kernel or a NIC of a receiver device.

5. The computer-implemented method of claim 4 , wherein the sender device is a physical machine or a virtual machine, and wherein the receiver device is a physical machine or a virtual machine.

6. The computer-implemented method of claim 1 , wherein the data flow includes data packets from a plurality of sender hosts, the plurality including the sender host, and wherein each of the plurality of sender hosts records the data packets it sends as part of the data flow.

7. The computer-implemented method of claim 6 , wherein, responsive to determining that the anomaly is detected during the monitoring, causing each of the plurality of sender hosts to store their respective recorded data packets sent as part of the data flow to respective buffers.

8. The computer-implemented method of claim 7 , further comprising, further responsive to determining that the anomaly is detected during the monitoring, retransmitting data packets associated with the anomaly from each sending host's respective buffer, and resuming the data flow.

9. The computer-implemented method of claim 8 , wherein retransmitting the data packets comprises jittering a transmission time of two or more of the data packets at the sender host to the receiver host, wherein jittering is done using one or more of predefined amounts of time or random amounts of time.

10. The computer-implemented method of claim 8 , wherein retransmitting the data packets comprises re-transmitting all of the data packets from each sending host's respective buffer.

11. A non-transitory computer-readable medium comprising memory with instructions encoded thereon for monitoring for anomalies in network traffic, the instructions, when executed by one or more processors, comprising instructions to: for a data flow transmitted between a sender host and a receiver host: record, on a first rolling basis, by the sender host, a first pre-defined amount of sent network traffic of the data flow; and record, on a second rolling basis, by the receiver host, a second pre-defined amount of received network traffic of the data flow, wherein the sender host and the receiver host are clock-synchronized; monitor for an anomaly in the data flow based on time stamps of data packets in the network traffic; determine whether an anomaly is detected during the monitoring; responsive to determining that no anomaly is detected during the monitoring, overwrite the recorded sent network traffic and the recorded received network traffic with newly sent network traffic and newly received network traffic, respectively; and responsive to determining that an anomaly is detected during the monitoring, pause the data flow, causing the sender host to store the recorded sent network traffic to a first buffer, and causing the receiver host to store the recorded received network traffic to a second buffer, wherein determining that the anomaly is detected during the monitoring comprises determining that a one-way delay of a data packet sent by the sender host to the receiver host exceeds a threshold amount of delay, wherein the one-way delay is determined using a send time stamp applied by the sender host to data packets of the data flow as compared to a receive time stamp applied by the receiver host to the data packets, wherein the sender host and the receiver host are synchronized to a same reference clock, and wherein the send time stamp and the receive time stamp are based on the same reference clock.

12. The non-transitory computer-readable medium of claim 11 , wherein the first pre-defined amount of sent network traffic and the second pre-defined amount of received network traffic are a same amount.

13. The non-transitory computer-readable medium of claim 12 , wherein the same amount is measured using either a pre-defined number of most recently transmitted or received packets, or packets received during a pre-defined amount of units of time prior to a current time.

14. The non-transitory computer-readable medium of claim 11 , wherein the sender host is located at either a kernel or a network interface card (NIC) of a sender device, and wherein the receiver host is located at either a kernel or a NIC of a receiver device.

15. The non-transitory computer-readable medium of claim 14 , wherein the sender device is a physical machine or a virtual machine, and wherein the receiver device is a physical machine or a virtual machine.

16. The non-transitory computer-readable medium of claim 11 , wherein the data flow includes data packets from a plurality of sender hosts, the plurality including the sender host, and wherein each of the plurality of sender hosts records the data packets it sends as part of the data flow.

17. The non-transitory computer-readable medium of claim 11 , wherein byte stamps are recorded for the data flow in persistent memory.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2022
From: GENG, YILONG; PRABHAKAR, BALAJI S.; LIU, SHIYU
To: CLOCKWORK SYSTEMS, INC.
Reel/Frame 060460/0817 →
Continuity (3)
Provisional Application 63320160 · Mar 15, 2022
Provisional Application 63178999 · Apr 23, 2021
Related Publication 20220345389A1 · Oct 27, 2022
References Cited (37)
US 7139923B1 · Chapman et al. · 2006 [cited by applicant]
US 7512980B2 · Copeland · 2009 [cited by examiner]
US 10623173B1 · Geng et al. · 2020 [cited by applicant]
US 10986029B2 · Altman · 2021 [cited by examiner]
US 11115426B1 · Pazhyannur · 2021 [cited by examiner]
US 11849016B1 · Wang · 2023 [cited by examiner]
US 20020163933A1 · Benveniste · 2002 [cited by applicant]
US 20040015582A1 · Pruthi · 2004 [cited by examiner]
US 20070015525A1 · Beming et al. · 2007 [cited by applicant]
US 20070121499A1 · Pal et al. · 2007 [cited by applicant]
US 20070237073A1 · Jutzi · 2007 [cited by applicant]
US 20070268882A1 · Breslau et al. · 2007 [cited by applicant]
US 20090024884A1 · Klein · 2009 [cited by applicant]
US 20150058852A1 · Easton et al. · 2015 [cited by applicant]
US 20160164765A1 · Aybay · 2016 [cited by applicant]
US 20160179746A1 · Hein et al. · 2016 [cited by applicant]
US 20170279921A1 · Foulkes · 2017 [cited by examiner]
US 20180025135A1 · Odom · 2018 [cited by examiner]
US 20180254990A1 · Ramaiah et al. · 2018 [cited by applicant]
US 20190349392A1 · Wetterwald et al. · 2019 [cited by applicant]
US 20200007566A1 · Wu · 2020 [cited by examiner]
US 20200112523A1 · Song et al. · 2020 [cited by applicant]
US 20200162407A1 · Tillotson · 2020 [cited by applicant]
US 20200204571A1 · Neznal et al. · 2020 [cited by applicant]
US 20220006747A1 · Khandelwal et al. · 2022 [cited by applicant]
US 20220345389A1 · Geng et al. · 2022 [cited by applicant]
JP 2005260839A · 2005 [cited by applicant]
WO WO2010089886A1 · 2010 [cited by applicant]
Ndikumana, A. “Novel Cooperative and Fully-Distributed Congestion Control Mechanism for Content Centric Networking,” IEEE Access, vol. 5, Nov. 29, 2017, pp. 27691-27706. [cited by applicant]
PCT International Search Report and Written Opinion, PCT Application No. PCT/US2023/014184, May 23, 2023, 10 pages. [cited by applicant]
Harkanson, R. et al. “Effects of TCP Transfer Buffers and Congestion Avoidance Algorithms on the End-to-End Throughput of TCP-over-TCP Tunnels,” 16th International Conference on Information Technology—New Generations, S… [cited by applicant]
PCT International Search Report and Written Opinion, PCT Application No. PCT/US2022/025843, Aug. 19, 2022, 22 pages. [cited by applicant]
PCT Invitation to Pay Additional Fees, PCT Application No. PCT/US2022/025843, Jun. 24, 2022, two pages. [cited by applicant]
European Patent Office, Extended European Search Report and Opinion, EP Patent Application No. EP 22792536.9, Jan. 27, 2025, eight pages. [cited by applicant]
Liu, S., et al. “Breaking the Transience-Equilibrium nexus: A new approach to datacenter packet transport.” 18th USENIX Symposium on Networked Systems Design and Implementation (NSDI 21), 2021, Apr. 12-14, 2021, pp. 47-… [cited by applicant]
Radhika, M., et al. “Timely: RTT-based 1-15 Congestion Control for the Datacenter”, Computer Communication Review., vol. 45, No. 5, 17 Aug. 17, 2015, pp. 537-550. [cited by applicant]
Japan Patent Office, Office Action, Japanese Patent Application No. 2024-555048. Mar. 11, 2025, four pages. [cited by applicant]