IP Library › Granted Patent US 12,579,047
Granted Patent B2
US 12,579,047 · App. 18/786,142 · Granted Mar 17, 2026

Tracking application behavior based on packet spacing

Inventors: Duncan Roweth (Bristol, GB); Anthony M. Ford (Bristol, GB); Jonathan P. Beecroft (Bristol, GB)
Assignee: Hewlett Packard Enterprise Development LP
G06F11/3423H04L43/0876H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,579,047
App. No.
18/786,142
Granted
Mar 17, 2026
Kind
B2
Abstract

A system tracks, in a network device with multiple links, activity over a respective link for a predetermined amount of time. The activity comprises at least one of a number of idle periods or a duration of a respective idle period. The system divides a predetermined time interval into a number of bins. A bin is associated with a range of time. The system stores the tracked activity in data structure entries which each indicate the number of bins, a duration of time associated with a respective bin, and a count associated with the respective bin. The system indicates the tracked activity in the entry for the respective link by incrementing a count associated with a bin matching the duration of the respective idle period based on a first number of idle periods tracked for the matching duration. The system displays the stored tracked activity for the respective link.

Claims (93)

1 . A computer-implemented method, comprising:

tracking, in a network device with multiple links over which data is being communicated, activity over a respective link for a predetermined amount of time, the activity comprising at least one of a number of idle periods or a duration of a respective idle period;

dividing a predetermined time interval into a number of bins, a respective bin associated with a range of time within the predetermined time interval;

storing the tracked activity in data structure entries, a respective entry indicating the number of bins, a duration of time associated with a respective bin, and a count associated with the respective bin;

indicating the tracked activity in the entry for the respective link by incrementing a count associated with a bin matching the duration of the respective idle period based on a first number of idle periods tracked for the matching duration; and

displaying the stored tracked activity for the respective link.

2 . The method of claim 1 , the method further comprising:

tracking an amount of time or a number of cycles during which the link is idle by maintaining a first counter.

3 . The method of claim 1 , the method further comprising:

tracking an amount of time or a number of cycles during which the link is active by maintaining a second counter,

wherein the activity comprises at least one of a number of active periods or a duration of a respective active period, and

wherein the respective bin is associated with a duration of the respective active period.

4 . The method of claim 1 , the method further comprising:

calculating the duration of a respective idle period based on a packet size of the data being communicated and a number of total bytes being communicated for the predetermined amount of time.

5 . The method of claim 1 , the method further comprising:

tracking the activity over the respective link for the predetermined amount of time based on at least one of:

an amount of time configured by a user;

a start time or a stop time associated with an application or a service; or

an interval based on occurrence of a predefined event associated with the application or service.

6 . The method of claim 1 , the method further comprising:

displaying the stored tracked activity for the respective link as a histogram indicating the count of idle periods tracked for the duration of time associated with the respective bin.

7 . The method of claim 1 , the method further comprising:

obtaining a subset of data by filtering the stored tracked activity based on at least one of:

an application;

a traffic class; or

a service.

8 . The method of claim 7 , the method further comprising:

transmitting the stored tracked activity or the filtered stored tracked activity to at least one of:

a user;

an analytics engine;

a machine learning model; or

a pattern recognition system.

9 . The method of claim 8 , the method further comprising receiving information which facilitates:

obtaining dynamic, real-time telemetry comprising performance data for a respective application;

identifying a critical path associated with controlling performance of the respective application;

providing insight into how the respective application uses network resources by analyzing the filtered stored tracked activity;

determining whether a reported bandwidth usage is associated with sending a steady stream of packets or sending a bursty stream of packets; and

determining whether a plurality of endpoints in a system exhibit the same or different behavior.

10 . A computer system with multiple links over which data is being communicated, the computer system comprising:

a processor; and

a storage device storing instructions which when executed by the processor comprise instructions to:

track activity over a respective link for a predetermined amount of time, wherein the activity comprises at least one of a number of idle periods or a duration of a respective idle period;

divide a predetermined time interval into a number of bins, wherein a respective bin is associated with a range of time within the predetermined time interval;

store the tracked activity in a data structure, wherein an entry in the data structure indicates the number of bins, a duration of time associated with a respective bin, and a count associated with the respective bin;

mark the tracked activity in the entry for the respective link by incrementing a count associated with a bin matching the duration of the respective idle period based on a first number of idle periods tracked for the matching duration; and

display the stored tracked activity for the respective link.

11 . The computer system of claim 10 , wherein the computer system operates in a network and comprises at least one of:

an ingress network switch, wherein data is being transmitted from the ingress network switch to the network over the multiple links;

an intermediate switch, wherein data is being transmitted or received over the multiple links; or

a network interface controller (NIC).

12 . The computer system of claim 10 , the instructions further to:

track an amount of time or a number of cycles during which the link is idle by maintaining a first counter.

13 . The computer system of claim 10 , the instructions further to:

track an amount of time or a number of cycles during which the link is active by maintaining a second counter,

wherein the activity comprises at least one of a number of active periods or a duration of a respective active period, and

wherein the respective bin is associated with a duration of the respective active period.

14 . The computer system of claim 10 , the instructions further to:

track the activity over the respective link for the predetermined amount of time based on at least one of:

an amount of time configured by a user;

a start time or a stop time associated with an application or a service; or

an interval based on occurrence of a predefined event associated with the application or service.

15 . The computer system of claim 10 , the instructions further to:

display the stored tracked activity for the respective link as a histogram indicating the count of idle periods tracked for the duration of time associated with the respective bin.

16 . The computer system of claim 10 , the instructions further to:

filter the stored tracked activity based on at least one of:

an application;

a traffic class; or

a service; and

transmit the stored tracked activity or the filtered stored tracked activity to at least one of:

a user;

an analytics engine;

a machine learning model; or

a pattern recognition system.

17 . The computer system of claim 10 , the instructions further to:

obtain dynamic, real-time telemetry comprising performance data for a respective application;

identify a critical path associated with controlling performance of the respective application;

provide insight into how the respective application uses network resources by analyzing the stored tracked activity;

determine whether a reported bandwidth usage is associated with sending a steady stream of packets or sending a bursty stream of packets; and

determine whether a plurality of endpoints in a system exhibit the same or different behavior.

18 . A non-transitory computer-readable medium storing instructions to:

track, in a network device with multiple links over which data is being communicated, activity over a respective link for a predetermined amount of time, the activity comprising at least one of a number of idle periods or a duration of a respective idle period;

partition a predetermined time interval into a number of bins, a respective bin associated with a range of time within the predetermined time interval;

store the tracked activity in data structure entries, a respective entry indicating the number of bins, a duration of time associated with a respective bin, and a count associated with the respective bin;

mark the tracked activity in the entry for the respective link by incrementing a count associated with a bin matching the duration of the respective idle period based on a first number of idle periods tracked for the matching duration; and

display the stored tracked activity for the respective link.

19 . The non-transitory computer-readable medium of claim 18 , the instructions further to perform at least one of:

track an amount of time or a number of cycles during which the link is idle by maintaining a first counter; or

track an amount of time or a number of cycles during which the link is active by maintaining a second counter,

the activity further comprising at least one of a number of active periods or a duration of a respective active period, and

the respective bin associated with a duration of the respective active period.

20 . The non-transitory computer-readable medium of claim 18 , the instructions further to:

filter the stored tracked activity based on at least one of an application, a traffic class, or a service; and

display the stored tracked activity or the filtered stored tracked activity for the respective link as a histogram indicating the count of idle periods tracked for the duration of time associated with the respective bin.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2025
From: HEWLETT-PACKARD LIMITED
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 069954/0352 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2025
From: HEWLETT-PACKARD LIMITED
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 069955/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2024
From: ROWETH, DUNCAN; FORD, ANTHONY M.; BEECROFT, JONATHAN P.
To: HEWLETT-PACKARD LIMITED
Reel/Frame 068279/0277 →
Continuity (1)
Related Publication 20260030132A1 · Jan 29, 2026
References Cited (8)
US 11165676B1 · Gandhi · 2021 [cited by examiner]
US 20090112899A1 · Johnson · 2009 [cited by examiner]
US 20110225288A1 · Easterday · 2011 [cited by examiner]
US 20110291748A1 · Li · 2011 [cited by examiner]
US 20160352760A1 · Mrkos · 2016 [cited by examiner]
US 20200394073A1 · Dutta · 2020 [cited by examiner]
US 20220400070A1 · Jain · 2022 [cited by examiner]
US 20240380636A1 · Kazimirsky · 2024 [cited by examiner]