IP Library Granted Patent US 12,166,640
Granted Patent B2
US 12,166,640 · App. 18/179,087 · Granted Dec 10, 2024

Determining network topology based on packet traffic

Inventor: Marcel Hild (Grasbrunn, DE)
Assignee: Red Hat, Inc.
H04L41/12G06N3/08H04L41/16H04L43/04H04L43/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,166,640
App. No.
18/179,087
Granted
Dec 10, 2024
Kind
B2
Abstract

In some implementations, a method is provided. The method includes receiving captured packet traffic, the captured packet traffic including a plurality of packets transmitted over a network. One or more communication patterns for each of one or more levels in a network stack are detected based on metadata of the captured packet traffic, each communication pattern indicating communication between two components in the network. The method further includes generating a topology of the network in view of the one or more communication patterns detected for each of the one or more levels in the network stack.

Claims (40)

1. A method comprising:

receiving captured packet traffic, the captured packet traffic including a plurality of packets transmitted over a network;

detecting, using metadata of the captured packet traffic, one or more communication patterns within each of one or more levels in a network stack, wherein each of the one or more communication patterns is detected by:

identifying one or more packets from the captured packet traffic forming a network conversation between two components in the network, each of the one or more packets having a protocol corresponding to the level in the network stack;

identifying a context among the identified one or more packets involved in the network conversation; and

detecting the communication pattern based on the network conversation, the context among the identified one or more packets, and a payload of each of the one or more packets, wherein the metadata of the captured packet traffic includes a source address, a destination address, and a protocol name for each packet of the captured packet traffic; and

generating, by a processing device, a topology of the network in view of the one or more communication patterns detected within each of the one or more levels in the network stack.

2. The method of claim 1 , wherein the topology of the network indicates for each component in the network: a type of the component and a connection between the component and one or more other components in the network.

3. The method of claim 2 , wherein generating the topology of the network comprises:

determining a type of each component in the network and a connection between each component and one or more other components in the network in view of the one or more communication patterns detected within each of the one or more levels in the network stack.

4. The method of claim 3 , wherein the determining comprises:

mapping the detected one or more communication patterns within each of the one or more levels in the network stack to a network topology from a data set of known network topologies using a neural network, the neural network being trained on the data set of known network topologies.

5. A system comprising:

a memory to store metadata; and

a processing device to:

receive captured packet traffic from a network device, the captured packet traffic including a plurality of packets transmitted over a network;

detect, using metadata of the captured packet traffic, one or more communication patterns within each of one or more levels in a network stack, wherein each of the one or more communication patterns is detected by:

identifying one or more packets from the captured packet traffic forming a network conversation between two components in the network, each of the one or more packets having a protocol corresponding to the level in the network stack;

identifying a context among the identified one or more packets involved in the network conversation; and

detecting the communication pattern based on the network conversation, the context among the identified one or more packets, and a payload of each of the one or more packets, wherein the metadata of the captured packet traffic includes a source address, a destination address, and a protocol name for each packet of the captured packet traffic; and

generate a topology of the network in view of the one or more communication patterns detected within each of the one or more levels in the network stack.

6. The system of claim 5 , wherein the topology of the network indicates for each component in the network: a type of the component and a connection between the component and one or more other components in the network.

7. The system of claim 6 , wherein to generate the topology of the network, the processing device is further to:

determine a type of each component in the network and a connection between each component and one or more other components in the network in view of the one or more communication patterns detected within each of the one or more levels in the network stack.

8. The system of claim 7 , wherein to determine the type of each component in the network and the connection between each component and one or more other components, the processing device is further to:

map the detected one or more communication patterns within each of the one or more levels in the network stack to a network topology from a data set of known network topologies using a neural network, the neural network being trained on the data set of known network topologies.

9. The system of claim 8 , wherein the topology of the network further indicates a probability that the type of each component is correct and a probability that each connection is correct.

10. A non-transitory computer-readable storage medium including instructions that, when executed by a processing device, cause the processing device to:

receive captured packet traffic, the captured packet traffic including a plurality of packets transmitted over a network;

detect, using metadata of the captured packet traffic, one or more communication patterns within each of one or more levels in a network stack, wherein each of the one or more communication patterns is detected by:

identifying one or more packets from the captured packet traffic forming a network conversation between two components in the network, each of the one or more packets having a protocol corresponding to the level in the network stack;

identifying a context among the identified one or more packets involved in the network conversation; and

detecting the communication pattern based on the network conversation, the context among the identified one or more packets, and a payload of each of the one or more packets, wherein the metadata of the captured packet traffic includes a source address, a destination address, and a protocol name for each packet of the captured packet traffic; and

generate, by the processing device, a topology of the network in view of the one or more communication patterns detected within each of the one or more levels in the network stack.

11. The non-transitory computer-readable storage medium of claim 10 , wherein the topology of the network indicates for each component in the network: a type of the component and a connection between the component and one or more other components in the network.

12. The non-transitory computer-readable storage medium of claim 11 , wherein to generate the topology of the network, the processing device is further to:

determine a type of each component in the network and a connection between each component and one or more other components in the network in view of the one or more communication patterns detected within each of the one or more levels in the network stack.

13. The non-transitory computer-readable storage medium of claim 12 , wherein to determine the type of each component in the network and the connection between each component and one or more other components, the processing device is further to:

map the detected one or more communication patterns within each of the one or more levels in the network stack to a network topology from a data set of known network topologies using a neural network, the neural network being trained on the data set of known network topologies.

14. The non-transitory computer-readable storage medium of claim 11 , wherein the topology of the network further indicates for each component in the network a probability that the type of the component is correct and a probability that each connection between the component and one or more other components in the network is correct.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2023
From: HILD, MARCEL
To: RED HAT, INC.
Reel/Frame 065634/0467 →
Continuity (2)
Continuation 16392357 · Apr 23, 2019
Related Publication 20230208721A1 · Jun 29, 2023