IP Library Patent Application 18951094
Patent Application
App. No. 18/951,094

PERFORMING DEEP PACKET INSPECTION IN A SOFTWARE DEFINED WIDE AREA NETWORK

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/951,094
Abstract

Some embodiments provide a method for performing deep packet inspection (DPI) for an SD-WAN (software defined, wide area network) established for an entity by a plurality of edge nodes and a set of one or more cloud gateways. At a particular edge node, the method uses local and remote deep packet inspectors to perform DPI for a packet flow. Specifically, the method initially uses the local deep packet inspector to perform a first DPI operation on a set of packets of a first packet flow to generate a set of DPI parameters for the first packet flow. The method then forwards a copy of the set of packets to the remote deep packet inspector to perform a second DPI operation to generate a second set of DPI parameters. In some embodiments, the remote deep packet inspector is accessible by a controller cluster that configures the edge nodes and the gateways.

Claims (34)

1 . A method comprising:

providing a first storage, the storage being configured to store a plurality of flow records;

selecting a flow record from the plurality of flow records;

identifying a set of parameters associated with the flow record;

obtaining performance metrics associated with the set of parameters;

performing a comparison between the performance metrics to the set of parameters;

examining, at the first storage, records of gateways to identify congested gateways based on the comparison; and

storing records associated with the congested gateways at a second storage.

2 . The method of claim 1 , wherein the storage comprises an aggregated data storage, the data storage being configured to storage flow metrics.

3 . The method of claim 1 , wherein the set of parameters comprises deep packet inspection (DPI) parameters.

4 . The method of claim 3 , wherein the DPI parameters comprise traffic type identifier and application identifiers.

5 . The method of claim 1 , wherein the second storage comprises an analysis storage.

6 . The method of claim 1 , wherein the second storage comprises an analysis storage.

7 . The method of claim 1 , wherein the records of gateways include gateway queue depth and average processing time.

8 . The method of claim 1 , further comprising categorizing the congested gateways based on geographic locations.

9 . The method of claim 1 , further comprising creating a record in a path-analysis storage.

10 . The method of claim 1 , further comprising deploying cloud gateways based at least on the comparison.

11 . A non-transitory machine readable medium storing a program, the program comprising sets of instructions for:

providing a first storage, the storage being configured to store a plurality of flow records;

selecting a flow record from the plurality of flow records;

identifying a set of parameters associated with the flow record;

obtaining performance metrics associated with the set of parameters;

performing a comparison between the performance metrics to the set of parameters;

examining, at the first storage, records of gateways to identify congested gateways based on the comparison; and

storing records associated with the congested gateways at a second storage.

12 . The non-transitory machine readable medium of claim 11 , wherein the storage comprises an aggregated data storage, the data storage being configured to storage flow metrics.

13 . The non-transitory machine readable medium of claim 11 , wherein the set of parameters comprises deep packet inspection (DPI) parameters.

14 . The non-transitory machine readable medium of claim 13 , wherein the DPI parameters comprise traffic type identifier and application identifiers.

15 . The non-transitory machine readable medium of claim 11 , wherein the second storage comprises an analysis storage.

16 . The non-transitory machine readable medium of claim 11 , wherein the second storage comprises an analysis storage.

17 . The non-transitory machine readable medium of claim 11 , wherein the records of gateways include gateway queue depth and average processing time.

18 . The non-transitory machine readable medium of claim 11 , wherein the program further comprising sets of instructions for comprising categorizing the congested gateways based on geographic locations.

19 . The non-transitory machine readable medium of claim 11 , wherein the program further comprising sets of instructions for creating a record in a path-analysis storage.

20 . The non-transitory machine readable medium of claim 11 , wherein the program further comprising sets of instructions for deploying cloud gateways based at least on the comparison.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2025
From: VMWARE, LLC
To: VELOCLOUD NETWORKS, LLC
Reel/Frame 072326/0693 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2024
From: RAMASWAMY, NAVANEETH KRISHNAN; SRINIVASAN, GANESH
To: VMWARE, INC.
Reel/Frame 069308/0207 →
CHANGE OF NAME Recorded Nov 18, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 069380/0012 →