IP Library › Granted Patent US 12,341,796
Granted Patent B2
US 12,341,796 · App. 18/040,694 · Granted Jun 24, 2025

Systems, methods, and media for distributed network monitoring using local monitoring devices

Inventors: Robert W. Techentin (Rochester, MN); David R. Holmes, III (Rochester, MN); Barry K. Gilbert (Rochester, MN)
Assignee: Mayo Foundation for Medical Education and Research
H04L63/1425H04L63/0236H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,796
App. No.
18/040,694
Granted
Jun 24, 2025
Kind
B2
Abstract

In accordance with some embodiments of the disclosed subject matter, mechanisms for distributed network monitoring are provided. In some embodiments, a system for distributed network monitoring comprises: local monitors, each comprising: a processor programmed to: generate a model of normal network traffic between a computing device and a router; receive additional traffic; calculate a metric based on a metadata parameter of the additional traffic; determine, based on the metric, whether the additional traffic is anomalous; and transmit, to a central monitoring system, information indicating that the additional traffic is anomalous; and the central monitoring system comprising: a second processor programmed to: receive information indicating that the additional traffic is anomalous; receive information related to the additional traffic; determine, based on the information, that the additional traffic is anomalous; and take an action to secure communications across the portion of the network associated with the additional traffic.

Claims (63)

1. A system for distributed network monitoring, comprising:

a plurality of local monitoring devices, each of the plurality of local monitoring devices disposed between at least one computing device and a networking router, each particular local monitoring device of the plurality of devices comprising:

at least one processor that is programmed to:

receive, over a first period of time, network traffic between the at least one computing device and the networking router associated with the particular local monitoring device;

generate a model of normal network traffic over the first period of time based on the network traffic between the at least one computing device and the networking router associated with the particular local monitoring device;

receive, over a second period of time subsequent to the first period of time, network traffic between the at least one computing device and the networking router associated with the particular local monitoring device;

calculate a metric based on a parameter of metadata associated with the network traffic received over the second period of time;

determine, based on the metric, whether the network traffic received over the second period of time is anomalous; and

in response to determining that the network traffic received over the second period of time is anomalous, transmit, to a central monitoring system, information indicating that the network traffic received over the second period of time is anomalous; and

the central monitoring system comprising:

at least one second processor that is programmed to:

receive, from a first local monitoring device of the plurality of local monitoring devices, information indicating that the network traffic received over the second period of time is anomalous;

receive, from the first local monitoring device, information related to the network traffic received by the first local monitoring device over the second period of time;

determine, based on the information related to the network traffic received by the first local monitoring device over the second period of time, that the network traffic received by the first local monitoring device over the second period of time is anomalous; and

in response to determining that the network traffic received by the first local monitoring device over the second period of time is anomalous, take an action to secure communications across a portion of the network associated with the first local monitoring device.

2. The system of claim 1 , wherein the at least one processor is further programmed to determine whether the network traffic received over the second period of time is anomalous based on the model of normal network traffic.

3. The system of claim 1 , wherein the information related to the network traffic comprises the model of normal network traffic generated by the first local monitoring device.

4. The system of claim 1 , wherein the metric comprises entropy of the parameter of metadata associated with the network traffic received over the second period of time.

5. The system of claim 1 , wherein the model of normal network traffic over the first period of time comprises a range based on an average entropy value of the parameter of metadata associated with the network traffic received over the second period of time.

6. The system of claim 1 , wherein the at least one processor comprises a field programmable gate array (FPGA), and wherein the at least one processor is programmed at least in part based on a configuration of logic gates in the FPGA.

7. An apparatus for distributed network monitoring, comprising:

at least one processor that is programmed to:

receive, over a first period of time, network traffic between at least one computing device and a networking router;

generate a model of normal network traffic over the first period of time;

receive, over a second period of time subsequent to the first period of time, network traffic between the at least one computing device and the networking router;

calculate a metric based on a parameter of metadata associated with the network traffic received over the second period of time;

determine, based on the metric and using the model of normal network traffic, that the network traffic received over the second period of time is anomalous; and

in response to determining that the network traffic received over the second period of time is anomalous, transmit, to a central monitoring system, information indicating that the network traffic received over the second period of time is anomalous.

8. The apparatus of claim 7 , wherein the at least one processor is further programmed to transmit the model of normal network traffic over the first period of time to the central monitoring system.

9. The apparatus of claim 7 , further comprising:

a first Ethernet port; and

a second Ethernet port,

wherein the at least one processor that is further programmed to receive at least a portion of the network traffic received over the first period of time using the first Ethernet port.

10. The apparatus of claim 9 , wherein the at least one processor is further programmed to transmit at least the portion of the network traffic received over the first period of time to the one or more computing devices using the second Ethernet port.

11. The apparatus of claim 9 , wherein the at least one processor is further programmed to:

receive at least a second portion of the network traffic received over the first period of time using the second Ethernet port; and

transmit at least the second portion of the network traffic received over the first period of time to the networking router using the first Ethernet port.

12. The apparatus of claim 7 , wherein the metric comprises entropy of the parameter of metadata associated with the network traffic received over the second period of time.

13. The apparatus of claim 7 , wherein the parameter of metadata associated with the network traffic received over the second period of time comprises a destination port.

14. The apparatus of claim 7 , wherein the model of normal network traffic over the first period of time comprises a range based on an average entropy value of the parameter of metadata associated with the network traffic received over the second period of time.

15. The apparatus of claim 7 , wherein the at least one processor is further programmed to:

receive, from the central monitoring system, an instruction to block traffic from a source IP address that caused the network traffic received by the apparatus over the second period of time to be anomalous.

16. A method for distributed network monitoring, comprising:

receiving, over a first period of time, network traffic between at least one computing device and a networking router;

generating a model of normal network traffic over the first period of time;

receiving, over a second period of time subsequent to the first period of time, network traffic between the at least one computing device and the networking router;

calculating a metric based on a parameter of metadata associated with the network traffic received over the second period of time;

determining, based on the metric, that the network traffic received over the second period of time is anomalous; and

in response to determining that the network traffic received over the second period of time is anomalous, transmitting, to a central monitoring system, information indicating that the network traffic received over the second period of time is anomalous.

17. The method of claim 16 , further comprising transmitting the model of normal network traffic over the first period of time to the central monitoring system.

18. The method of claim 16 , comprising:

receiving information indicating that the network traffic received over the second period of time is anomalous;

receiving information related to the network traffic received over the second period of time;

confirming, based on the information related to the network traffic received over the second period of time, that the network traffic received over the second period of time is anomalous; and

in response to confirming that the network traffic received over the second period of time is anomalous, take an action to secure communications across a portion of the network associated with network traffic received over the second period of time.

19. The method of claim 18 , wherein confirming that the network traffic received over the second period of time is anomalous comprises:

identifying a cluster of local monitoring devices that includes a local monitoring device that received the network traffic over the second period of time;

comparing the information related to the network traffic received over the second period of time to a second model of normal network traffic associated with a different local monitoring device in the cluster; and

confirming that the network traffic received over the second period of time is anomalous based on the metric being anomalous compared to the second model of normal network traffic.

20. The method of claim 18 , wherein confirming that the network traffic received over the second period of time is anomalous comprises:

identifying a cluster of local monitoring devices that includes a local monitoring device that received the network traffic over the second period of time;

comparing the information related to the network traffic received over the second period of time to a third model of normal network traffic associated with the cluster of local monitoring devices, wherein the third model was generated based on models of normal network traffic associated with a plurality of local monitoring devices in the cluster; and

confirming that the network traffic received over the second period of time is anomalous based on the metric being anomalous compared to the third model of normal network traffic.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2023
From: TECHENTIN, ROBERT W.; HOLMES, DAVID R., III; GILBERT, BARRY K.
To: MAYO FOUNDATION FOR MEDICAL EDUCATION AND RESEARCH
Reel/Frame 062611/0969 →
Continuity (2)
Provisional Application 63062216 · Aug 6, 2020
Related Publication 20230283621A1 · Sep 7, 2023
References Cited (34)
US 9438614B2 · Herz · 2016 [cited by applicant]
US 10122740B1 · Finkelshtein · 2018 [cited by examiner]
US 20090245109A1 · Hurley · 2009 [cited by examiner]
US 20100030544A1 · Gopalan · 2010 [cited by examiner]
US 20100031156A1 · Doyle · 2010 [cited by examiner]
US 20100138919A1 · Peng · 2010 [cited by examiner]
US 20110090797A1 · Beecroft · 2011 [cited by examiner]
US 20160352766A1 · Flacher · 2016 [cited by examiner]
US 20170013001A1 · Friedman · 2017 [cited by examiner]
US 20170279698A1 · Sartran et al. · 2017 [cited by applicant]
US 20170279827A1 · Savalle et al. · 2017 [cited by applicant]
US 20180337836A1 · Balabine · 2018 [cited by examiner]
Albers, P. et al., Security in Ad Hoc Networks: A General Intrusion Detection Architecture Enhancing Trust Based Approaches, In Wireless Information Systems, 2002, pp. 1-12. [cited by applicant]
Amigo, J. et al., A Brief Review of Generalized Entropies, Entropy, 2018, 20(11): 813, 21 pages. [cited by applicant]
Arackaparambil, C. et al., Distributed Monitoring of Conditional Entropy for Anomaly Detection in Streams, In 2010 IEEE International Symposium on Parallel & Distributed Processing, Workshops and Phd Forum (IPDPSW), 201… [cited by applicant]
Berezinski, P. et al., An Entropy-Based Network Anomaly Detection Method, Entropy, 2015, 17:2367-2408. [cited by applicant]
D'Otreppe, T., OpenWIPS-ng, A Modular and Open Source WIPS, Sharkfest '12 Wireshark Developer and User Conference, 2012, 36 pages. [cited by applicant]
Dlugosch, P. et al., An Efficient and Scalable Semiconductor Architecture for Parallel Automata Processing, IEEE Transactions on Parallel and Distributed Systems, 2014, 25(12): 3088-3098. [cited by applicant]
Duessel, P. et al., Detecting Zero-Day Attacks Using Context-Aware Anomaly Detection at the Application-Layer, International Journal of Information Security, 2017, 16(5):475-490. [cited by applicant]
Ghosh, A. et al., Agent-Based Distributed Intrusion Alert System, In International Workshop on Distributed Computing, 2004, pp. 240-251. [cited by applicant]
Gu, Y. et al., Detecting Anomalies in Network Traffic Using Maximum Entropy Estimation, In Proceedings of the 5th ACM SIGCOMM Conference on Internet Measurement, 2005, pp. 345-350. [cited by applicant]
Kachirski, O. et al., Intrusion Detection Using Mobile Agents in Wireless Ad Hoc Networks, Proceedings of the IEEE Workshop on Knowledge Media Networking, 2002, pp. 1-6. [cited by applicant]
Klein, E., Top 5 Open-Source NIDS Solutions, Apr. 11, 2019, 13 pages. [cited by applicant]
Lasheng, Y. et al., Agent Based Distributed Intrusion Detection System (ABDIDS), Proceedings of the Second Symposium International Computer Science and Computational Technology (ISCSCT'09), 2009, pp. 134-138. [cited by applicant]
Netbeez, Inc., NetBeez: Technology Overview and Benefits, 2015, 3 pages. [cited by applicant]
Nychis, G. et al., An Empirical Evaluation of Entropy-Based Traffic Anomaly Detection, In Proceedings of the 8th ACM SIGCOMM Conference on Internet Measurement, 2008, pp. 151-156. [cited by applicant]
Porras, P. et al., EMERALD: Event Monitoring Enabling Responses to Anomalous Live Disturbances, In Proceedings of the 20th National Information Systems Security Conference, 1997, 3:353-365. [cited by applicant]
Shannon, C., A Mathematical Theory of Communication, The Bell System Technical Journal, 1948, 27(3):379-423, 623-656. [cited by applicant]
Sommer, R. et al., Outside the Closed World: On Using Machine Learning for Network Intrusion Detection, 2010 IEEE Symposium on Security and Privacy, 2010, pp. 305-316. [cited by applicant]
Tellenbach, B. et al., Accurate Network Anomaly Classification with Generalized Entropy Metrics, Computer Networks, 2011, 55:3485-3502. [cited by applicant]
Wadden, J. et al., ANMLZoo: A Benchmark Suite for Exploring Bottlenecks in Automata Processing Engines and Architectures, In 2016 IEEE International Symposium on Workload Characterization (IISWC), 2016, pp. 1-12. [cited by applicant]
Zhang, Y. et al., Intrusion Detection Techniques for Mobile Wireless Networks, Mobile Networks and Applications, 2003, pp. 1-16. [cited by applicant]
Zhao, X. et al., A Parallel Scheme for IDS, Proceedings of the Second International Conference on Machine Learning and Cybernetics, 2003, pp. 2379-2383. [cited by applicant]
PCT International Search Report and Written Opinion, PCT/US2021/044892, Oct. 25, 2021, 12 pages. [cited by applicant]
Cited By (1)
US 12,688,282