IP Library Granted Patent US 12,568,125
Granted Patent B2
US 12,568,125 · App. 18/619,835 · Granted Mar 3, 2026

Systems and methods for hierarchical deep packet inspection for scalable network monitoring and cyber security functions

Inventors: Anil K. Singhal (Carlisle, MA); Sanjay Munshi (Allen, TX)
Assignee: NetScout Systems, Inc.
H04L63/306H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,125
App. No.
18/619,835
Granted
Mar 3, 2026
Kind
B2
Abstract

A system and method for hierarchical network monitoring functions are disclosed. An order of execution for layer functions of a network architecture is determined. The layer functions may be distributed across multiple layers. The layers may include a sensor layer, a federated application layer, and a data lake layer. A machine learning model may be executed at a first layer. The first layer may be the sensor layer.

Claims (58)

1 . A system, comprising:

a data processing system comprising one or more processors coupled with memory, the data processing system configured to:

collect a plurality of network data packets from user equipment, network equipment, or monitoring equipment connected to a communications network;

determine an order for executing a plurality of layer functions of a hierarchical network architecture based on a priority for each layer function, wherein the hierarchical network architecture comprises a first layer, a second layer, and a third layer, the first layer being a sensor layer, the second layer being a federated application layer, and the third layer being a data lake layer, and wherein the number of layer functions in the first layer is greater than the number of layer functions in the second layer, which is greater than the number of layer functions in the third layer;

execute the plurality of layer functions according to the order using the plurality of network data packets and historical network data as input to generate network data associated with the communications network; and

execute at least one machine learning model in the sensor layer using deep packet inspection data to adaptively filter traffic and detect security threats;

adjust the communications network according to the generated network data.

2 . The system of claim 1 , wherein:

the first quantity of layer functions at the first layer comprises a traffic analysis layer function, a cloud threat detection layer function, an IDP engine layer function, a knowledge base framework layer function, and a threat intelligence feed layer function;

the second quantity of layer functions at the second layer comprises a threat detection layer function, a retrospective analysis layer function, an application mapping layer function, and an asset validation layer function; and

the third quantity of layer functions at the third layer comprises an automated response layer function, a telemetry data layer function, and a threat intelligence correlation layer function.

3 . The system of claim 1 , wherein the network architecture is a hierarchical adaptive service intelligence (ASI) architecture, a hierarchical deep packet inspection (DPI) architecture, or a combination thereof, wherein the ASI architecture comprises four layers.

4 . The system of claim 1 , wherein the order for executing the plurality of layer functions comprises instructions to:

first, executing the first quantity of layer functions at the first layer;

second, executing the second quantity of layer functions at the second layer; and

third, executing the third quantity of layer functions at the third layer.

5 . The system of claim 1 , wherein the data processing system is further configured to:

execute each layer function of each quantity of layer functions at each layer separately from other layer functions at each layer.

6 . A method, comprising:

collecting, by one or more processors, a plurality of network data packets from user equipment, network equipment, or monitoring equipment connected to a communications network;

determining, by the one or more processors, an order for executing a plurality of layer functions of a hierarchical network architecture based on a priority for each layer function, wherein the hierarchical network architecture comprises a first layer, a second layer, and a third layer, the first layer being a sensor layer, the second layer being a federated application layer, and the third layer being a data lake layer, and wherein the number of layer functions in the first layer is greater than the number of layer functions in the second layer, which is greater than the number of layer functions in the third layer;

executing, by the one or more processors, the plurality of layer functions according to the order using the plurality of network data packets and historical network data as input to generate network data associated with the communications network; and

executing, by the one or more processors, at least one machine learning model in the sensor layer using deep packet inspection data to adaptively filter traffic and detect security threats;

adjusting, by the one or more processors, the communications network according to the generated network data.

7 . The method of claim 6 , wherein:

the first quantity of layer functions at the first layer comprises a traffic analysis layer function, a cloud threat detection layer function, an IDP engine layer function, a knowledge base framework layer function, and a threat intelligence feed layer function;

the second quantity of layer functions at the second layer comprises a threat detection layer function, a retrospective analysis layer function, an application mapping layer function, and an asset validation layer function; and

the third quantity of layer functions at the third layer comprises an automated response layer function, a telemetry data layer function, and a threat intelligence correlation layer function.

8 . The method of claim 6 , wherein the network architecture is a hierarchical adaptive service intelligence (ASI) architecture, a hierarchical deep packet inspection (DPI) architecture, or a combination thereof, wherein the ASI architecture comprises four layers.

9 . The system of claim 1 , wherein the order for executing the plurality of layer functions comprises instructions to:

first, executing the first quantity of layer functions at the first layer;

second, executing the second quantity of layer functions at the second layer; and

third, executing the third quantity of layer functions at the third layer.

10 . The method of claim 6 , further comprising:

executing, by the one or more processors, each layer function of each quantity of layer functions at each layer separately from other layer functions at each layer.

11 . The system of claim 1 , wherein the data processing system is further configured to:

execute the plurality of layer functions at the first layer to filter noise from the plurality of network data packets before executing the plurality of layer functions at the second layer, thereby reducing a quantity of data processed at the second layer and the third layer.

12 . The system of claim 1 , wherein the hierarchical network architecture is configured to reduce mean time to know (MTTK) for detecting security threats by executing the plurality of layer functions at the first layer in real-time and executing the plurality of layer functions at the second layer and the third layer on aggregated data from the first layer.

13 . The system of claim 1 , wherein:

the first layer comprises a traffic analysis layer function that analyzes packet headers and payload data to identify traffic patterns;

the second layer comprises a threat detection layer function that correlates the traffic patterns identified by the first layer with known threat signatures; and

the third layer comprises a threat intelligence correlation layer function that correlates detected threats with external threat intelligence feeds.

14 . The system of claim 1 , wherein the data processing system is further configured to:

store metadata and packet decodes from the plurality of network data packets at the first layer for retrospective analysis by the second layer.

15 . The system of claim 1 , wherein the at least one machine learning model comprises an ASI Flow machine learning model that conducts network behavioral analysis to generate deterministic signatures that reduce false positives.

16 . The system of claim 1 , wherein the data processing system is further configured to:

convert raw network data packets into layer 2 - 7 metadata using Deep Packet Inspection and Adaptive Service Intelligence (ASI) at the first layer; and

provide the layer 2 - 7 metadata to the second layer and the third layer for analysis.

17 . The system of claim 1 , wherein the data processing system is further configured to:

match indicators of compromise (IoCs) from a threat intelligence feed at the first layer;

match Suricata-based rules and signatures at the first layer; and

when a threat is detected at the first layer, map the threat to known MITRE ATT&CK tactics, techniques, and procedures (TTPs) for analysis at the second layer.

18 . The system of claim 1 , wherein the hierarchical network architecture is an Omnis network security architecture comprising:

network instrumentation at the first layer that performs deep packet inspection to convert raw packets into metadata;

network instrumentation at the second layer that performs federated application analysis; and

a data lake at the third layer that stores and analyzes aggregated network data.

19 . The system of claim 1 , wherein the data processing system is further configured to:

conduct forensic investigation at the second layer using the historical network data stored at the first layer to validate threats detected in real-time and reduce mean time to repair (MTTR).

Assignments (2)
SECURITY INTEREST Recorded Oct 22, 2024
From: NETSCOUT SYSTEMS, INC.; ARBOR NETWORKS LLC; NETSCOUT SYSTEMS TEXAS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069216/0007 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2024
From: SINGHAL, ANIL K.; MUNSHI, SANJAY
To: NETSCOUT SYSTEMS, INC.
Reel/Frame 066942/0584 →
Continuity (2)
Provisional Application 63455681 · Mar 30, 2023
Related Publication 20240333776A1 · Oct 3, 2024
References Cited (18)
US 6499107B1 · Gleichauf · 2002 [cited by examiner]
US 6816973B1 · Gleichauf et al. · 2004 [cited by applicant]
US 20140157405A1 · Joll · 2014 [cited by examiner]
US 20140341041A1 · Velev · 2014 [cited by examiner]
US 20170126853A1 · Goel · 2017 [cited by examiner]
US 20190245873A1 · Wu et al. · 2019 [cited by applicant]
US 20200204574A1 · Christian · 2020 [cited by examiner]
US 20200389469A1 · Litichever · 2020 [cited by examiner]
US 20210117360A1 · Kutch · 2021 [cited by examiner]
US 20210326175A1 · Herbert · 2021 [cited by examiner]
US 20220182398A1 · St. Pierre · 2022 [cited by examiner]
US 20220215948A1 · Bardot · 2022 [cited by examiner]
Deri et al., “Using Deep Packet Inspection in CyberTraffic Analysis,” 2021 IEEE International Conference on Cyber Security and Resilience (CSR), Rhodes, Greece, pp. 89-94 (Year: 2021). [cited by examiner]
Smallwood et al., “Intrusion analysis with deep packet inspection: Increasing efficiency of packet based investigations,” 2011 International Conference on Cloud and Service Computing, Hong Kong, China, pp. 342-347 (Year… [cited by examiner]
EP Article 94(3) EPC Communication dated Dec. 13, 2024 in EP Patent Application No. 24167530.5. [cited by applicant]
EP Extended Search Report dated Aug. 19, 2024 in European Patent Application No. 24167530.5. [cited by applicant]
AU Examination Report No. 1 on Australian Application No. 2024202057, dated Jan. 3, 2025. [cited by applicant]
CA Office Action dated Sep. 12, 2025 in Canadian Patent Application No. 3,233,877. [cited by applicant]