IP Library Patent Application 18380864
Patent Application
App. No. 18/380,864

SECURE FRAME CAPTURE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/380,864
Abstract

Some embodiments provide a method for performing secure frame capture for an application executing on a data compute node. At the application, the method receives and parses a frame for a particular L7 protocol. The method identifies an action to perform within the application based on the parsed frame. Based on secure frame capture being enabled for the application, the method writes information regarding the frame to a capture file stored at the DCN. The information regarding the frame omits (i) any L2-L4 information and (ii) any payload data carried by the frame.

Claims (45)

1 . A method for performing secure frame capture for an application executing on a data compute node (DCN):

at the application:

receiving and parsing a frame for a particular layer 7 (L7) protocol;

identifying an action to perform within the application based on the parsed frame; and

based on secure frame capture being enabled for the application, writing information regarding the frame to a capture file stored at the DCN, said information regarding the frame omitting (i) any L2-L4 information and (ii) any payload data carried by the frame.

2 . The method of claim 1 , wherein information is written to the capture file by a hook that is enabled within the application based on secure frame capture being enabled for the application.

3 . The method of claim 2 , wherein the hook is enabled on a per-application basis within the DCN such that the hook is enabled to perform secure frame capture for at least one additional application executing on the DCN and is disabled for at least one application executing on the DCN.

4 . The method of claim 1 , wherein the particular L7 protocol is HTTP/2.

5 . The method of claim 1 , wherein the capture file is a pcap file.

6 . The method of claim 1 , wherein:

the identified action comprises dispatching payload data to the application; and

the information written to the capture file regarding the frame indicates that a data frame was received for a particular connection but does not include the payload data.

7 . The method of claim 6 , wherein the information comprises a size of the payload data.

8 . The method of claim 1 , wherein:

the frame is a control message indicating a protocol error; and

the information written to the capture file regarding the frame specifies (i) a connection indicator for the frame and (ii) the protocol error.

9 . The method of claim 1 , wherein:

the identified action comprises starting a new connection for the application; and

the information written to the capture file specifies the start of a new connection and defines a new identifier for the new connection.

10 . The method of claim 9 , wherein the new identifier is used to identify the connection for information regarding subsequent frames written to the capture file without requiring any L2-L4 information for the connection.

11 . The method of claim 1 , wherein the frame is a first frame, the method further comprising, at the application:

identifying a second frame to be sent from the application; and

writing information regarding the second frame to the capture file.

12 . The method of claim 1 , wherein an administrator logs into the DCN to analyze the capture file using a network analysis tool.

13 . The method of claim 12 , wherein the capture file comprises a global header specifying that the frame information was captured using a particular secure format without L2-L4 data, thereby enabling the network analysis tool to parse the capture file.

14 . The method of claim 12 , wherein the DCN is a virtual machine executing on a host computer within a datacenter network.

15 . A non-transitory machine-readable medium storing an application which when executed by at least one processing unit performs secure frame capture, the application executing within a data compute node (DCN), the program comprising sets of instructions for:

receiving and parsing a frame for a particular layer 7 (L7) protocol;

identifying an action to perform within the application based on the parsed frame; and

based on secure frame capture being enabled for the application, writing information regarding the frame to a capture file stored at the DCN, said information regarding the frame omitting (i) any L2-L4 information and (ii) any payload data carried by the frame.

16 . The non-transitory machine-readable medium of claim 1 , wherein information is written to the capture file by a hook that is enabled within the application based on secure frame capture being enabled for the application.

17 . The non-transitory machine-readable medium of claim 2 , wherein the hook is enabled on a per-application basis within the DCN such that the hook is enabled to perform secure frame capture for at least one additional application executing on the DCN and is disabled for at least one application executing on the DCN.

18 . The non-transitory machine-readable medium of claim 1 , wherein:

the identified action comprises dispatching payload data to the application; and

the information written to the capture file regarding the frame indicates that a data frame was received for a particular connection but does not include the payload data.

19 . The non-transitory machine-readable medium of claim 1 , wherein:

the frame is a control message indicating a protocol error; and

the information written to the capture file regarding the frame specifies (i) a connection indicator for the frame and (ii) the protocol error.

20 . The non-transitory machine-readable medium of claim 1 , wherein:

the identified action comprises starting a new connection for the application; and

the information written to the capture file specifies the start of a new connection and defines a new identifier for the new connection.

21 . The non-transitory machine-readable medium of claim 9 , wherein the new identifier is used to identify the connection for information regarding subsequent frames written to the capture file without requiring any L2-L4 information for the connection.

22 . The non-transitory machine-readable medium of claim 1 , wherein the frame is a first frame, the program further comprising sets of instructions for:

identifying a second frame to be sent from the application; and

writing information regarding the second frame to the capture file.

Assignments (1)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →