IP Library Patent Application 18652474
Patent Application
App. No. 18/652,474

SYSTEM FOR MONITORING AND MANAGING DATACENTERS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/652,474
Abstract

An example method includes detecting, using sensors, packets throughout a datacenter. The sensors can then send packet logs to various collectors which can then identify and summarize data flows in the datacenter. The collectors can then send flow logs to an analytics module which can identify the status of the datacenter and detect an attack.

Claims (31)

1 . A method for responding to attacks on a datacenter, comprising:

receiving sensor data from a plurality of sensor processes executing in a datacenter, the sensor data including network data describing one or more network flows within the datacenter;

determining whether an attack is occurring based at least in part on comparing the received sensor data to data corresponding to a baseline operation of the datacenter; and

in response to determining the attack is occurring, modifying a security policy of the datacenter.

2 . The method of claim 1 , wherein the sensor data further includes operations data describing a software state of at least one host in the datacenter.

3 . The method of claim 1 , wherein a machine learning process is used to determine the baseline operation of the datacenter.

4 . The method of claim 1 , wherein a machine learning process is used to determine whether the attack is occurring.

5 . The method of claim 1 , wherein the sensor data includes an indication of active or previously active processes executing on an operating system on at least one host in the datacenter.

6 . The method of claim 1 , wherein the sensor data includes at least one of a of a memory and a status of an I/O device.

7 . The method of claim 1 , wherein, in response to the modifying of the security policy of the datacenter, traffic to at least one host in the datacenter is blocked.

8 . A system comprising:

one or more processors at one or more nodes; and

at least one computer-readable storage medium having stored therein instructions which, when executed by the one or more processors, cause the system to perform acts comprising:

receiving sensor data from a plurality of sensor processes executing in a datacenter, the sensor data including network data describing one or more network flows within the datacenter;

determining whether an attack is occurring based at least in part on comparing the received sensor data to data corresponding to a baseline operation of the datacenter; and

in response to determining the attack is occurring, modifying a security policy of the datacenter.

9 . The system of claim 8 , wherein the sensor data further includes operations data describing a software state of at least one host in the datacenter.

10 . The system of claim 8 , wherein the acts performed by the system include a machine learning process used to determine the baseline operation of the datacenter.

11 . The system of claim 8 , wherein the acts performed by the system include a machine learning process used to determine whether the attack is occurring.

12 . The system of claim 8 , wherein the sensor data includes an indication of active or previously active processes executing on an operating system on at least one host in the datacenter.

13 . The system of claim 8 , wherein the sensor data includes at least one of a status of a memory and a status of an I/O device.

14 . The system of claim 8 , wherein, in response to the modifying of the security policy of the datacenter, traffic to at least one host in the datacenter is blocked.

15 . A computer-readable storage medium having stored therein instructions which, when executed by one or more processors on one or more hosts, cause the one or more hosts to perform acts comprising:

receiving sensor data from a plurality of sensor processes executing in a datacenter, the sensor data including network data describing one or more network flows within the datacenter;

determining whether an attack is occurring based at least in part on comparing the received sensor data to data corresponding to a baseline operation of the datacenter; and

in response to determining the attack is occurring, modifying a security policy of the datacenter.

16 . The computer-readable storage medium of claim 15 , wherein the sensor data further includes operations data describing software state of at least one host in the datacenter.

17 . The computer-readable storage medium of claim 15 , wherein the acts performed include a machine learning process used to determine the baseline operation of the datacenter.

18 . The computer-readable storage medium of claim 15 , wherein the acts performed include a machine learning process used to determine whether the attack is occurring.

19 . The computer-readable storage medium of claim 15 , wherein the sensor data includes an indication of active or previously active processes executing on an operating system on at least one host in the datacenter.

20 . The computer-readable storage medium of claim 15 , wherein, in response to the modifying of the security policy of the datacenter, traffic to at least one host in the datacenter is blocked.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2024
From: YADAV, NAVINDRA; SINGH, ABHISHEK RANJAN; GANDHAM, SHASHIDHAR; SCHEIB, ELLEN CHRISTINE; MADANI, OMID; PARANDEHGHEIBI, ALI; PANG, JACKSON NGOC KI; JEYAKUMAR, VIMALKUMAR; WATTS, MICHAEL STANDISH; NGUYEN, HOANG VIET; DEEN, KHAWAR; PRASAD, ROHIT CHANDRA; GUPTA, SUNIL KUMAR; RAO, SUPREETH HOSUR NAGESH; GUPTA, ANUBHAV; KULSHRESHTHA, ASHUTOSH; SPADARO, ROBERTO FERNANDO; VU, HAI TRONG; MALHOTRA, VARUN SAGAR; CHANG, SHIH-CHUN; VISWANATHAN, BHARATHWAJ SANKARA; RACHITA AGASTHY, FNU; BARLOW, DUANE THOMAS
To: CISCO TECHNOLOGY, INC.
Reel/Frame 067294/0569 →