IP Library Granted Patent US 12,244,566
Granted Patent B2
US 12,244,566 · App. 18/472,059 · Granted Mar 4, 2025

Self-learning egress traffic controller

Inventors: Raja Kommula (Cupertino, CA); Rahul Gupta (Kanpur, IN); Ganesh Byagoti Matad Sunkada (Bengaluru, IN); Tarun Banka (Milpitas, CA); Thayumanavan Sridhar (Sunnyvale, CA); Raj Yavatkar (Los Gatos, CA)
Assignee: Juniper Networks, Inc.
H04L63/0263G06N5/022G06N20/20H04L41/14H04L41/16H04L41/5009H04L43/0811H04L43/0888H04L63/0236H04L63/0245H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,566
App. No.
18/472,059
Granted
Mar 4, 2025
Kind
B2
Abstract

An example network system includes processing circuitry and one or more memories coupled to the processing circuitry. The one or more memories are configured to store instructions which, when executed by the processing circuitry, cause the network system to receive connection data related to an egress connection of an application service of an application. The instructions cause the network system to analyze the connection data to determine that the egress connection is an anomalous connection. The instructions cause the network system to generate a notification indicative of the egress connection being an anomalous connection and send the notification to a computing device.

Claims (41)

1. A network system comprising:

processing circuitry; and

one or more memories coupled to the processing circuitry and configured to store instructions which, when executed by the processing circuitry, cause the network system to:

receive connection data related to an egress connection of an application service of an application;

analyze the connection data to determine that the egress connection is an anomalous connection;

generate a notification indicative of the egress connection being the anomalous connection, the notification configured to affect a firewall policy of a distributed firewall on at least one network interface card (NIC) of a plurality of NICs implementing the distributed firewall; and

send the notification to a computing device.

2. The network system of claim 1 , wherein the instructions cause the network system to analyze the connection data via a machine learning model.

3. The network system of claim 2 , wherein the machine learning model is trained using previous connection data of the application.

4. The network system of claim 1 , wherein the instructions further cause the processing circuitry to generate a previous knowledge graph based on previous connection data of the application.

5. The network system of claim 4 , wherein the previous knowledge graph is indicative of each application service of the application that has previously made egress connections.

6. The network system of claim 5 , wherein as part of analyzing the connection data, the instructions cause the processing circuitry to:

generate a first knowledge graph based on the connection data, the first knowledge graph being indicative of the application service making an egress connection; and

compare the first knowledge graph to the previous knowledge graph.

7. The network system of claim 1 , wherein the connection data comprises node network metrics and firewall metrics.

8. The network system of claim 7 , wherein at least a portion of the node network metrics are associated with a cluster node, and wherein the node network metrics comprise at least one of a source IP address, a destination IP address, a source port number, a destination port number, a source workload name, a connection protocol and direction of the egress connection, or a cluster node identifier.

9. The network system of claim 7 , wherein at least a portion of the firewall metrics are associated with an instance of the distributed firewall running on the at least one NIC, and wherein the firewall metrics comprise at least one of a source IP address, a destination IP address, a source port number, a destination port number, or a direction of the egress connection.

10. The network system of claim 1 , wherein the notification comprises information associated with the egress connection.

11. A network interface card implementing an instance of a distributed firewall, the network interface card comprising:

processing circuitry; and

one or more memories coupled to the processing circuitry and configured to store instructions which, when executed by the processing circuitry, cause the network interface card to:

configure an egress connection from an application service of an application;

send, to a computing device, connection data related to the egress connection, wherein the connection data comprises firewall metrics that are associated with the instance of the distributed firewall;

receive, from the computing device and in response to sending the connection data, a notification to apply a firewall policy; and

apply the firewall policy.

12. The network interface card of claim 11 , wherein the firewall metrics comprise at least one of a source IP address, a destination IP address, a source port number, a destination port number, or a direction of the egress connection.

13. The network interface card of claim 11 , wherein the firewall policy is a new firewall policy.

14. The network interface card of claim 13 , wherein the notification to apply the firewall policy comprises the new firewall policy.

15. The network interface card of claim 13 , wherein as part of applying the firewall policy, the instructions cause the processing circuitry to at least one of drop the egress connection or block further egress connections from the application service.

16. A network system comprising:

processing circuitry; and

one or more memories coupled to the processing circuitry and configured to store instructions which, when executed by the processing circuitry, cause the network system to:

receive connection data related to an egress connection of an application service of an application;

send, to a computing device, the connection data;

receive, from the computing device and in response to sending the connection data, a notification indicative of the egress connection being an anomalous connection;

generate, based on the notification indicative of the egress connection being anomalous, a notification to apply a firewall policy of a distributed firewall to at least one network interface card (NIC) of a plurality of NICs implementing the distributed firewall; and

send the notification to apply the firewall policy to the at least one NIC.

17. The network system of claim 16 , wherein as part of generating the notification to apply the firewall policy, the instructions cause the processing circuitry to generate a new firewall policy.

18. The network system of claim 17 , wherein the new firewall policy is configured to cause the at least one network interface card to at least one of drop the egress connection or block further egress connections from the application service.

19. The network system of claim 17 , wherein the notification to apply the firewall policy comprises the new firewall policy.

20. The network system of claim 16 , wherein the connection data comprises node network metrics and firewall metrics.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2025
From: YAVATKAR, RAJENDRA SHIVARAM
To: JUNIPER NETWORKS, INC.
Reel/Frame 073226/0029 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2023
From: KOMMULA, RAJA; GUPTA, RAHUL; SUNKADA, GANESH BYAGOTI MATAD; BANKA, TARUN; SRIDHAR, THAYUMANAVAN; YAVATKAR, RAJ
To: JUNIPER NETWORKS, INC.
Reel/Frame 064991/0882 →
Priority Claims (1)
IN 202241069004 · Nov 30, 2022 · national
Continuity (1)
Related Publication 20240179074A1 · May 30, 2024
References Cited (108)
US 7363203B2 · Hines · 2008 [cited by applicant]
US 9424121B2 · Kushnir et al. · 2016 [cited by applicant]
US 9571394B1 · Sivaramakrishnan et al. · 2017 [cited by applicant]
US 9961571B2 · Yang et al. · 2018 [cited by applicant]
US 10171335B2 · Maheshwari et al. · 2019 [cited by applicant]
US 10235231B2 · Zhang et al. · 2019 [cited by applicant]
US 10257055B2 · Li et al. · 2019 [cited by applicant]
US 10263833B2 · Maheshwari et al. · 2019 [cited by applicant]
US 10289473B2 · Mendes et al. · 2019 [cited by applicant]
US 10373094B2 · Naous et al. · 2019 [cited by applicant]
US 10574512B1 · Mermoud et al. · 2020 [cited by applicant]
US 10616043B2 · Wang et al. · 2020 [cited by applicant]
US 10855548B2 · Garvey et al. · 2020 [cited by applicant]
US 10897389B2 · Thampy et al. · 2021 [cited by applicant]
US 11061393B2 · Abe et al. · 2021 [cited by applicant]
US 11082439B2 · Salunke et al. · 2021 [cited by applicant]
US 11138163B2 · Mdini et al. · 2021 [cited by applicant]
US 11165631B1 · Chitalia et al. · 2021 [cited by applicant]
US 11238129B2 · Jalal et al. · 2022 [cited by applicant]
US 11265336B2 · Hild · 2022 [cited by applicant]
US 11323312B1 · Banka et al. · 2022 [cited by applicant]
US 11323327B1 · Chitalia et al. · 2022 [cited by applicant]
US 11422882B1 · Chhabra · 2022 [cited by applicant]
US 11500757B2 · Ambichl et al. · 2022 [cited by applicant]
US 11616682B2 · Thampy et al. · 2023 [cited by applicant]
US 11636090B2 · Li et al. · 2023 [cited by applicant]
US 11645293B2 · Pelloin · 2023 [cited by applicant]
US 11658874B2 · Banka et al. · 2023 [cited by applicant]
US 11675799B2 · Pierri et al. · 2023 [cited by applicant]
US 11765014B2 · Banka et al. · 2023 [cited by applicant]
US 11809267B2 · Gusat et al. · 2023 [cited by applicant]
US 11816178B2 · Jalal et al. · 2023 [cited by applicant]
US 11887015B2 · Fahmy et al. · 2024 [cited by applicant]
US 20040088730A1 · Gopalan et al. · 2004 [cited by applicant]
US 20040268149A1 · Aaron · 2004 [cited by examiner]
US 20050276228A1 · Yavatkar · 2005 [cited by examiner]
US 20080262990A1 · Kapoor et al. · 2008 [cited by applicant]
US 20090055684A1 · Jamjoom et al. · 2009 [cited by applicant]
US 20110214157A1 · Korsunsky et al. · 2011 [cited by applicant]
US 20130298184A1 · Ermagan et al. · 2013 [cited by applicant]
US 20140157405A1 · Joll · 2014 [cited by examiner]
US 20160112443A1 · Grossman et al. · 2016 [cited by applicant]
US 20160182373A1 · Wang et al. · 2016 [cited by applicant]
US 20160308734A1 · Feller et al. · 2016 [cited by applicant]
US 20170075749A1 · Ambichl et al. · 2017 [cited by applicant]
US 20170288991A1 · Ganesh · 2017 [cited by applicant]
US 20170330096A1 · Gupta et al. · 2017 [cited by applicant]
US 20180103052A1 · Choudhury et al. · 2018 [cited by applicant]
US 20180115470A1 · Huang et al. · 2018 [cited by applicant]
US 20180131675A1 · Sengupta et al. · 2018 [cited by applicant]
US 20190068693A1 · Bernat · 2019 [cited by applicant]
US 20190141015A1 · Nellen · 2019 [cited by applicant]
US 20190196894A1 · Cherbakov et al. · 2019 [cited by applicant]
US 20200028771A1 · Wong et al. · 2020 [cited by applicant]
US 20200136973A1 · Rahman · 2020 [cited by examiner]
US 20200272973A1 · Hongtan et al. · 2020 [cited by applicant]
US 20200278892A1 · Nainar · 2020 [cited by examiner]
US 20210044623A1 · Bosch · 2021 [cited by examiner]
US 20210117242A1 · Van De Groenendaal et al. · 2021 [cited by applicant]
US 20210135967A1 · Lorga · 2021 [cited by examiner]
US 20210160262A1 · Bynum et al. · 2021 [cited by applicant]
US 20210320875A1 · Guim Bernat · 2021 [cited by examiner]
US 20210367830A1 · Jain et al. · 2021 [cited by applicant]
US 20210390423A1 · Latapie et al. · 2021 [cited by applicant]
US 20210406091A1 · Thyagaturu et al. · 2021 [cited by applicant]
US 20220006783A1 · Hassanzadeh et al. · 2022 [cited by applicant]
US 20220029929A1 · Jain et al. · 2022 [cited by applicant]
US 20220038471A1 · Sugarbaker et al. · 2022 [cited by applicant]
US 20220058042A1 · Vanjare et al. · 2022 [cited by applicant]
US 20220103431A1 · Singh et al. · 2022 [cited by applicant]
US 20220114032A1 · Bernat et al. · 2022 [cited by applicant]
US 20220116478A1 · Biederman et al. · 2022 [cited by applicant]
US 20220210028A1 · Chen et al. · 2022 [cited by applicant]
US 20220224121A1 · Jha et al. · 2022 [cited by applicant]
US 20220337555A1 · Gol et al. · 2022 [cited by applicant]
US 20220417117A1 · Tayeb et al. · 2022 [cited by applicant]
US 20220417323A1 · Julien et al. · 2022 [cited by applicant]
US 20230262093A1 · Gupta et al. · 2023 [cited by applicant]
US 20230300059A1 · Rodriguez Natal · 2023 [cited by examiner]
US 20230388346A1 · Kulshreshtha · 2023 [cited by examiner]
US 20240007342A1 · Gupta et al. · 2024 [cited by applicant]
CN 113206761B · 2022 [cited by examiner]
EP 3889777A1 · 2021 [cited by applicant]
WO 2013184846A1 · 2013 [cited by applicant]
WO 2022020336A1 · 2022 [cited by applicant]
“Amazon SageMaker—Developer Guide,” retrieved from https://docs.aws.amazon.com/sagemaker/latest/dg/randomcutforest.html on Feb. 15, 2024, 6167 pp. [cited by applicant]
“CSRX Container Firewall,” retrieved from https://www.juniper.net/us/en/products/security/srx-series/csrx-containerized-firewall.html, on Feb. 15, 2024, 2 pp. [cited by applicant]
“Emerging Technologies: Adoption Growth Insights—Function Accelerator Cards Cards(Next-Gen SmartNICs, DPUs, IPUs),” Gartner Research, Sep. 14, 2021, 6 pp. [cited by applicant]
“Granger Causality,” Wikipedia, Last Updated Sep. 28, 2023, 14 pp. [cited by applicant]
“NVIDIA BlueField Networking Platform,” retrieved from https://www.nvidia.com/en-us/networking/products/data-processing-unit/, on Feb. 15, 2024, 7 pp. [cited by applicant]
“PageRank,” Wikipedia, Last Updated Oct. 19, 2023, 22 pp. [cited by applicant]
“The Istio Service Mesh,” retrieved from https://istio.io/latest/about/service-mesh/, on Feb. 15, 2024, 5 pp. [cited by applicant]
Extended Search Report from counterpart European Application No. 23211535.2 dated Feb. 1, 2024, 10 pp. [cited by applicant]
Kim et al., “A Case for SmartNIC-accelerated Private Communication,” APNet '20: Proceedings of the 4th Asia-Pacific Workshop on Networking, Aug. 2020, 8 pp. [cited by applicant]
Liu et al., “MicroHECL: High-Efficient Root Cause Localization in Large-Scale Microservice Systems,” 2021 IEEE/ACM 43rd International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP), May… [cited by applicant]
Liu et al., “Offloading Distributed Applications onto SmartNICs using iPipe,” In Proceedings of the ACM Special Interest Group on Data Communication (SIGCOMM '19), Aug. 19-23, 2019, 16 pp. [cited by applicant]
Liu et al., “Performance Characteristics of the BlueField-2 SmartNIC,” arXiv:2105.06619, May 14, 2021, 13 pp. [cited by applicant]
Meng et al., “Localizing Failure Root Causes in a Microservice through Causality Inference,” 2020 IEEE/ACM 28th International Symposium on Quality of Service (IWQoS), Jun. 2020, 10 pp. [cited by applicant]
Moro et al., “FOP4: Function Offloading Prototyping in Heterogeneous and Programmable Network Scenarios,” 2019 IEEE Conference on Network Function Virtualization and Software Defined Network, Nov. 2019, 6 pp. [cited by applicant]
Soldani et al., “Anomaly Detection and Failure Root Cause Analysis in (Micro)Service-Based Cloud Applications: a Survey,” arXiv:2105.12378, May 26, 2021, 36 pp. [cited by applicant]
Tanenbaum et al., “Distributed Systems: Principles and Paradigms,” Second Edition, Prentice-Hall, (Applicant points out, in accordance with MPEP 609.04(a), that the year of publication, 2007, is sufficiently earlier tha… [cited by applicant]
U.S. Appl. No. 18/472,042, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,050, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,092, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,111, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,123, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
Wu et al., “MicroRCA: Root Cause Localization of Performance Issues in Microservices,” IEEE/IFIP Network Operations and Management Symposium (NOMS), Apr. 2020, 10 pp. [cited by applicant]
Response to Extended Search Report dated Feb. 1, 2024, from counterpart European Application No. 23211535.2 filed Dec. 4, 2024, 20 pp. [cited by applicant]